USDOCAI is built around the HIPAA Privacy, Security and Breach Notification Rules. This page explains our safeguards and includes our Notice of Privacy Practices.
Effective date: September 1, 2025
Our safeguards
Three layers of protection
Administrative
A designated Privacy Officer and Security Officer
Regular HIPAA risk assessments and workforce training
Business Associate Agreements with every vendor that handles health information
Provider licenses verified before a clinician can see patients
A documented breach response plan
Physical
Data stored in HIPAA-eligible cloud data centers with controlled physical access
No health information kept on your phone; optional biometric login is encrypted in the device keystore
A privacy screen hides your information in the phone’s app switcher
Technical
Encryption in transit (TLS) and at rest
Least-privilege access: only you and your treating providers can open your record
Automatic sign-out after 15 minutes of inactivity
Audit logs of every view and change to health information
Signed clinical notes and consent records can’t be altered
AI and your data. The USDOCAI Assistant’s symptom screening runs on your phone. If you continue to a visit or choose to share it in a chat, a short summary (your symptom, how long, and your temperature if you measured it) goes to your doctor. If you use voice input, the recording is turned into text in our own secure cloud and deleted right away. Photos, files and voice messages you send can be opened only by you and your care team. To find a pharmacy, we send only your ZIP code to the national NPI Registry. The AI scribe only records and transcribes a visit with your consent. Speech recognition runs in our own secure cloud, not at a third-party transcription service, and the recording is deleted as soon as it’s transcribed. Your doctor reviews and signs every note, and your recordings and notes are never used to train AI models. When the scribe checks a suggestion against public references (FDA drug labeling and the National Library of Medicine), it sends only the medication, test or diagnosis name, never anything that identifies you.
Notice of Privacy Practices. This notice describes how medical information about you may be used and disclosed and how you can get access to this information. Please review it carefully.
1.How we use and share your health information
Treatment: sharing information with the doctors and clinicians who care for you.
Payment: billing you or your health plan for the care you receive.
Health care operations: running USDOCAI safely, for example quality checks, security monitoring and training.
As required or permitted by law: public health reporting, preventing a serious threat to health or safety, legal proceedings, and requests from law enforcement or health oversight agencies.
Any other use or disclosure needs your written permission, which you can withdraw at any time.
2.What we never do
Sell your health information.
Use or share it for marketing without your written permission.
Use your visit recordings or clinical notes to train AI models.
3.Your rights
Get a copy of your health record, including an electronic copy. We respond within 30 days.
Ask us to correct information you think is wrong or incomplete.
Get a list of certain disclosures we have made of your information.
Ask us to limit what we use or share, or to contact you in a specific way or place.
Get a paper copy of this notice, and choose someone to act for you.
Withdraw consent for the AI scribe at any time in the app.
You can make these requests in the app under Profile → Privacy & Security, or by contacting our Privacy Officer.
4.Our responsibilities
We are required by law to maintain the privacy and security of your protected health information.
We must follow the duties and privacy practices described in this notice and give you a copy of it.
We can change this notice; changes apply to all information we have about you, and the new notice will be available in the app and on this page.
5.Breach notification
If a breach occurs that may have compromised the privacy or security of your information, we will tell you without unreasonable delay, and no later than 60 days after we discover it.
6.Complaints and contact
If you believe your privacy rights have been violated, you can file a complaint with us or with the U.S. Department of Health and Human Services Office for Civil Rights at hhs.gov/ocr/complaints. We will never retaliate against you for filing a complaint.
Mailing address: USDOCAI, 450 E 22nd St, Lombard, IL
Website privacy
This part covers usdocai.com. Health information in the USDOCAI app is covered by the Notice of Privacy Practices above.
What we collect. When you use the early-access or contact form: your name, email address, whether you’re a patient or a provider, and your message.
How we use it. To reply to you, send you access to the app and occasional USDOCAI updates. Email chat@usdocai.com at any time to stop the updates or have your details deleted.
Who handles it. Our website host, which sends form messages to our inbox, and our email provider. We don’t sell it or share it for advertising.
Cookies and tracking. This website doesn’t use advertising or analytics cookies or third-party trackers. Its fonts and images are served from our own site.
No health information, please. Website forms aren’t meant for medical details. Use the app, where your health information is protected under HIPAA.
Children. This website isn’t directed at children under 13.