1. Our Commitment
DrDocs is built for healthcare organizations that handle protected health information every day. The platform is designed to support compliance with the Health Insurance Portability and Accountability Act (HIPAA) Security and Privacy Rules. This page describes the safeguards implemented in the DrDocs platform today. Compliance is a shared responsibility: DrDocs provides the technical safeguards described below, and your organization remains responsible for its own policies, workforce training, and appropriate use of the platform.
2. Encryption
2.1 Encryption in Transit
- All communication between your devices and DrDocs is encrypted using TLS.
- Database connections are encrypted.
- API endpoints are served exclusively over HTTPS.
2.2 Encryption at Rest
- PHI is encrypted at rest using AES-256 encryption.
- File storage (including dictation audio) is encrypted using AWS-managed encryption with KMS keys.
- Database storage is encrypted at the infrastructure level.
3. Access Control
DrDocs enforces role-based access control (RBAC) across the platform. Each user is assigned a role that determines which records and administrative functions they can access, and data access is scoped to the user's organization and team assignments. Authentication is required for all access to the platform, with account lockout protections against repeated failed sign-in attempts and rate limiting on authentication endpoints.
4. Audit Logging
The platform maintains comprehensive audit logging of administrative actions, including authentication events, password resets, and administrative changes. Audit records capture the acting user, the action performed, a timestamp, and the originating IP address, and are available for review by authorized administrators.
5. Session Management
- Sessions time out automatically after a period of inactivity.
- Administrators can review and revoke active sessions.
- Sessions expire automatically (6-hour access tokens, 7-day refresh, plus the organization's configurable inactivity timeout), and administrators can revoke any user's sessions immediately from the Sessions page.
6. Infrastructure
DrDocs runs on Amazon Web Services (AWS) infrastructure using HIPAA-eligible services. AWS data centers provide physical security, environmental controls, and redundancy. Data is backed up regularly to support recovery.
7. Business Associate Agreements
DrDocs operates under a Business Associate Agreement (BAA) with AWS covering the infrastructure services used to store and process PHI, and we are prepared to enter into Business Associate Agreements with covered entities that use the platform. Contact us to request a BAA for your organization.
8. Data Handling
- We collect only the information needed to provide the service.
- We do not sell PHI or use it for advertising.
- PHI is retained according to applicable healthcare regulations and your organization's retention policies.
- Records support soft deletion and recovery workflows to protect against accidental data loss.
9. Incident Response
We maintain incident response procedures for investigating and responding to suspected security incidents, including notification obligations under the HIPAA Breach Notification Rule where applicable.
10. Questions
For questions about HIPAA compliance, to request a BAA, or to report a security concern, contact us at:
- Email: support@drdocs.app
See also our Privacy Policy and Terms of Service.