Trust
Compliance & Security
Psychiatric documentation demands the highest standards of data privacy. Here's exactly how we protect your patients' information.
Intended Use Statement
Psynopsis is a clinical decision support tool intended to assist licensed psychiatric providers with clinical documentation workflows. It does not replace clinical judgment. All diagnostic and treatment decisions remain the responsibility of the licensed healthcare provider. AI-generated documentation is a draft requiring clinician review before finalization. Psynopsis does not automate diagnosis, prescribe medications, or make treatment recommendations.
HIPAA Compliant
Full compliance with the Health Insurance Portability and Accountability Act. Administrative, physical, and technical safeguards implemented across all systems.
- AES-256 encryption at rest
- TLS 1.3 in transit
- Access controls and audit logging
- Regular security assessments
42 CFR Part 2 Compliant
Federal regulation governing the confidentiality of substance use disorder patient records. Psynopsis maintains strict separation between psychotherapy notes and progress notes.
- Psychotherapy note separation
- Substance use record protections
- Consent-based disclosure controls
- Audit trail for all access
Audio Never Stored
Audio is processed in real-time for transcription and immediately discarded. No audio recordings are ever stored on our servers or used for model training.
- Real-time processing only
- Immediate deletion after transcription
- Never used for AI training
- Verified by architecture audit
NPI Verification
Only licensed healthcare providers with valid National Provider Identifiers can access Psynopsis. Verified against the NPPES database.
- NPPES database verification
- Provider-only access
- Credential validation
- Professional community integrity
Data Handling Summary
Transparent answers to the questions your compliance officer will ask.
Subprocessors, retention periods and the Chrome extension data lifecycle are itemized in the privacy policy.
Ask any vendor
The questions to put to every AI scribe, with our answers
Each answer on the right is a fact published on this page or in the privacy policy. What each question means, and the full twelve-question list, is on what a HIPAA compliant AI scribe actually requires.
| Ask the vendor | Psynopsis |
|---|---|
| Will you sign a BAA before I enter any PHI, and on which plans? | Included with all paid plans; copy for review within one business day. |
| Is session audio stored? For how long, and where? | Never stored. Processed in real time and immediately discarded. |
| Is my data used to train models? | No. Patient data is never used to train AI models. |
| Who are the subprocessors that touch PHI, and are they under BAAs? | Listed in the privacy policy; every PHI partner is under a BAA. |
| Where is data hosted, and how is it encrypted? | United States; AES-256 at rest, TLS 1.3 in transit. |
| Who can create an account, and can I get an access log? | NPI-verified providers only; access is logged and auditable. |
| Is there a workflow that does not record the patient? | Yes: post-session dictation involves no patient audio at all. |
| How are SUD records and psychotherapy notes handled? | 42 CFR Part 2 protections and psychotherapy note separation. |
Business Associate Agreement
BAA is included with all paid plans. Need a copy for review before subscribing? We'll send one within one business day.
Most competitors require a demo call before sharing a BAA. We'll email you one directly.
Security & Compliance FAQ
Can I get a BAA before starting a paid plan?
Where is patient data stored?
Is audio from patient sessions recorded or stored?
How does Psynopsis handle psychotherapy notes vs progress notes?
Can I export or delete my data?
Stop Spending Evenings on Notes
Psychiatric documentation that understands your workflow. MSE, medication changes, SI/HI — captured in a structured draft while you focus on your patients.
HIPAA compliant · BAA included · Audio never stored