Privacy Policy
1. Overview and Scope
SOAP-E, LLC ("SOAP-E," "Company," "we," "us," or "our") provides an AI-assisted clinical documentation platform designed for use by licensed healthcare professionals and their organizations (the "Service").
This Privacy Policy describes how we collect, use, disclose, and safeguard information when acting solely as a Business Associate under HIPAA, and when processing limited personal information related to user accounts.
Scope
This Policy applies to:
- Users of the SOAP-E platform
- Personal information related to user accounts
- Protected Health Information ("PHI") processed on behalf of Covered Entities
In the event of any conflict between this Privacy Policy and a signed Business Associate Agreement ("BAA"), the BAA controls with respect to PHI.
2. Regulatory Alignment
SOAP-E's privacy and security practices are designed to align with applicable laws and regulations, including:
- The Health Insurance Portability and Accountability Act of 1996 (HIPAA)
- The HIPAA Privacy, Security, and Breach Notification Rules
- Applicable state privacy and data protection laws
State Privacy Laws
Protected Health Information processed under HIPAA is exempt from most state privacy laws, including the California Consumer Privacy Act (CCPA).
State privacy law requirements, where applicable, apply only to:
- Non-PHI account information (e.g., name, email, professional credentials)
- Technical and operational data that does not constitute PHI
When state privacy laws apply to non-PHI data, individuals may have rights to access, correct, or delete such information, subject to legal exceptions and Covered Entity approval where account data is linked to clinical services.
Compliance with healthcare privacy laws depends on lawful and appropriate use of the Service by Users and Covered Entities.
3. Information We Process
3.1 Account and Authentication Information
We process limited personal information necessary to create and secure user accounts, including:
- Name and professional contact information
- Professional affiliation and role
- OAuth-based authentication identifiers from providers such as Google or Microsoft
- Account preferences and security settings
- EHR integration credentials — encrypted OAuth access tokens and refresh tokens obtained when a User or account administrator connects an Electronic Health Record system through the Service
OAuth access tokens used for user authentication are encrypted, short-lived, and used solely for authentication. SOAP-E does not access user email content, contacts, or files from authentication OAuth providers.
EHR OAuth credentials are encrypted at rest using dedicated encryption keys, stored separately from PHI, and used solely to authenticate with the connected EHR system for the purposes described in this Policy. EHR credentials are never exposed to users through the Service interface.
3.2 Protected Health Information (PHI)
SOAP-E processes PHI solely on behalf of Covered Entities for the purpose of providing clinical documentation services.
PHI processed by the Service may include:
- Audio recordings of clinical encounters
- Transcripts generated from audio recordings via AI-powered speech-to-text services
- Clinical notes, observations, assessments, and AI-generated documentation
- Patient demographic information used in documentation (e.g., date of birth)
- Consent records documenting patient authorization for recording and processing
- Patient demographic data retrieved from connected EHR systems during patient search and linking (e.g., name, date of birth, medical record number, gender) — used solely to match patients between the Service and the EHR and to facilitate document submission
3.3 Service and Operational Data
We process limited operational and technical data to maintain service reliability and security, including:
- Device and browser metadata
- IP address and coarse geographic information
- System performance metrics
- Security and access audit records
Operational logs are designed to exclude PHI.
4. How We Use Information
4.1 Core Service Functions
We use information solely to:
- Provide AI-assisted clinical documentation services
- Transmit clinical documentation to connected EHR systems at the direction of authorized Users
- Retrieve patient demographic information from connected EHR systems to facilitate patient matching and document submission
- Authenticate users and enforce access controls
- Secure the Service and prevent misuse
- Provide customer support
- Meet legal and contractual obligations
4.2 Service Reliability and Improvement
SOAP-E may analyze aggregated, de-identified operational metadata to:
- Monitor performance and availability
- Detect errors and security threats
- Improve reliability and usability
Such analysis does not involve the use of PHI or Customer Content to train or fine-tune general-purpose AI or foundation models.
5. Information Sharing and Disclosure
5.1 General Principle
SOAP-E does not sell or rent personal information or PHI.
5.2 Subprocessors and Infrastructure Providers
SOAP-E uses the following infrastructure and service providers under executed Business Associate Agreements:
- Amazon Web Services, Inc. (AWS) — Cloud hosting, infrastructure, and database services
AWS does not use PHI processed through its services to train foundation models or general-purpose AI models.
Any subcontractor that may process PHI is contractually bound to:
- Comply with HIPAA Security Rule requirements
- Use PHI only as permitted by our BAA obligations
- Implement appropriate technical and organizational safeguards
- Not use PHI for their own purposes or to train AI models
5.3 User-Directed Transmissions to Electronic Health Record Systems
The Service allows authorized Users to transmit clinical documentation (e.g., SOAP notes) to Electronic Health Record ("EHR") systems connected by the User or their account administrator. When a User initiates an EHR submission:
- PHI is transmitted directly from SOAP-E to the designated EHR system at the User's explicit direction
- The transmission is authenticated using encrypted OAuth credentials specific to the connected EHR
- SOAP-E acts as a conduit, transmitting PHI back to the Covered Entity's own EHR infrastructure — this is a return of PHI to the Covered Entity, not a disclosure to a third party
- EHR systems are not subprocessors or subcontractors of SOAP-E and are not covered under SOAP-E's Business Associate Agreement
To facilitate EHR submissions, the Service may also retrieve limited patient demographic information from the connected EHR system (e.g., name, date of birth, medical record number) for the sole purpose of matching a patient in the Service to the corresponding patient record in the EHR.
5.4 Legal and Regulatory Disclosures
We may disclose information when required to do so by law, regulation, or valid legal process, including disclosures to health oversight authorities.
5.5 Business Transfers
In the event of a merger, acquisition, or asset sale, information will remain subject to equivalent privacy protections and applicable legal restrictions.
6. Security Safeguards
SOAP-E implements administrative, physical, and technical safeguards designed to protect information, including:
- Encryption in transit and at rest
- Role-based access controls and multi-factor authentication
- Secure secrets management
- Continuous monitoring and incident response procedures
SOAP-E personnel do not have routine access to decrypted PHI, except as required for:
- Security incident investigation and response
- Customer support with explicit authorization
- Legal or regulatory compliance obligations
All such access is subject to strict access controls, audit logging, and oversight.
7. HIPAA Rights and Responsibilities
SOAP-E acts solely as a Business Associate under HIPAA.
Your Rights
To the extent SOAP-E maintains PHI in a Designated Record Set on behalf of a Covered Entity, SOAP-E will support Covered Entity obligations related to:
- Access requests
- Amendments
- Accounting of disclosures
Requests regarding patient rights should generally be directed to the Covered Entity.
8. Data Retention and Deletion
Retention Policy Hierarchy
Data retention is governed by the following hierarchy of controlling documents:
- For PHI: The executed Business Associate Agreement controls all retention, deletion, and return obligations
- For non-PHI personal information: This Privacy Policy governs retention periods
- For all data: Applicable federal and state legal requirements, including medical record retention laws, may mandate minimum retention periods
General Retention Principles
SOAP-E retains information only as necessary to provide the Service, meet contractual obligations, and comply with applicable law.
Retention periods may vary based on:
- Covered Entity configuration and contractual requirements
- Applicable state medical record retention laws
- Legal hold, litigation, or regulatory investigation requirements
- Backup and disaster recovery schedules
SOAP-E does not independently determine medical record retention obligations — such determinations remain the responsibility of the Covered Entity.
Audio Recording Retention
Audio recordings of clinical encounters are promptly deleted after processing. Transcripts and AI-generated documentation derived from audio recordings are retained as PHI and governed by the BAA retention policy.
Consent records documenting patient authorization for recording and processing are retained for audit and compliance purposes for the duration of the service relationship and as required by applicable law.
Deletion Upon Termination
Upon termination of services, PHI will be handled in accordance with BAA requirements:
- Returned to Covered Entity in a usable format, if feasible
- Destroyed in accordance with NIST 800-88 or equivalent standards, if feasible
- Retained under continued protections if return or destruction is infeasible, with limited use and disclosure as required by law
9. User Choices and Account Controls
Users may:
- Update account information
- Configure security settings
- Manage communication preferences
- Request account deactivation
Requests involving PHI may be subject to Covered Entity approval and legal requirements.
9.1 Data Deletion Requests
Users may submit requests to delete specific patient data through the Service, including audio recordings, transcripts, generated notes, or all data associated with a patient. Deletion requests are reviewed and processed in accordance with the BAA and applicable law.
Deletion may be delayed or limited by applicable federal or state medical record retention requirements, legal hold or litigation requirements, or regulatory investigation obligations. Users will be notified of the status and completion of deletion requests through the Service.
9.2 Consent Management
The Service provides tools for documenting patient consent to audio recording and AI processing. Users may review consent records for their patients through the Service. Consent records are maintained as part of the compliance audit trail and are not subject to routine deletion.
11. International Processing
The Service is hosted in the United States. Authorized remote access may occur from approved jurisdictions under strict access controls and audit logging.
12. Incident Response and Breach Notification
SOAP-E maintains an incident response program designed to identify, contain, and remediate security incidents.
Breach Notification
In the event of a Breach of Unsecured PHI, SOAP-E will notify affected Covered Entities without unreasonable delay and in accordance with HIPAA Breach Notification Rule requirements.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the Service or by other appropriate means.
14. Contact Information
Privacy Officer
Questions or concerns may be directed to:
Email: support@soap-e.com
By using the Service, you acknowledge that you have read and understood this Privacy Policy.
Questions about this Privacy Policy? Contact our Privacy Officer at support@soap-e.com