PrecisionMind
Guides

Data Security & Privacy

At PrecisionMind, protecting your patients' sensitive health information is our highest priority. This guide explains how we safeguard patient data and maintain privacy while giving you complete control over clinical content.

In this section

  1. 01How we protect patient data
  2. 02Technical security measures
  3. 03Data governance and access controls
  4. 04HIPAA and SOC 2 compliance
  5. 05Google Calendar integration
  6. 06Data breach protection
  7. 07Common security and privacy questions
  8. 08Contact us

Article 01

How we protect patient data

PrecisionMind is a HIPAA-compliant and SOC 2 Type II compliant EHR. PrecisionMind uses a "Zero-Access" architecture. Your practice data and clinical records are encrypted so that only you can access them.

How PrecisionMind protects your data

PrecisionMind uses end-to-end technical isolation to exceed standard regulatory requirements.

HIPAA and SOC 2 compliance: Data handling, from ingestion to storage, is governed by HIPAA regulations and SOC 2 Type II security principles.
Encryption at the source: Clinical notes and session data are encrypted locally on the provider’s device before they are sent to PrecisionMind’s infrastructure.
Decryption authority: Only the authorized provider holds the decryption keys. PrecisionMind cannot read, access, or decrypt clinical data.
Legal data isolation: Because PrecisionMind does not hold the decryption keys, PrecisionMind cannot provide clinical data to third parties, including healthcare organizations or legal entities.

Telehealth transcription and AI

PrecisionMind uses a privacy-first approach when AI helps with notes.

Audio is never saved: During telehealth, PrecisionMind converts speech to text in real time. The audio is deleted as soon as the text is created.
Patients must agree: Telehealth transcription starts only after the patient selects I Consent at the beginning of the session. If the patient does not consent, transcription stays off.
No AI training: PrecisionMind never uses your notes to train AI models.
AI is optional: You choose which AI features to use.

You own your records

You own your data and are not locked into PrecisionMind.

Easy export: Download all your notes and records with one click at any time.
Seven-year retention: PrecisionMind keeps records for seven years to help you comply with state and federal laws.
Total deletion: If you delete a note or close your account, the data is permanently deleted. PrecisionMind does not keep shadow copies.

Privacy and security support

Ask a question: Email support@PrecisionMind.health with a security or privacy concern.
Read the privacy policy: View the full policy .
Back to top

Article 02

Technical security measures

PrecisionMind uses multiple layers of security to protect the confidentiality, integrity, and availability of clinical data. Cryptographic controls, network isolation, and monitoring help reduce unauthorized access.

Encryption and session security

PrecisionMind uses standard cryptographic protocols to protect data throughout its lifecycle.

Encryption: All Protected Health Information (PHI) is encrypted at rest and in transit using AES-256-bit encryption.
Session management: Authentication creates unique session keys that rotate frequently. This reduces the window for potential unauthorized access.
Database environment: PrecisionMind uses enterprise-grade cloud environments on Amazon Web Services (AWS). Data layers are managed through MongoDB Atlas and PostgreSQL on RDS.

Network isolation and access control

System access follows the principle of least privilege and uses strict perimeter defenses.

Network perimeter: Services are hosted in private networks and isolated through firewalls and granular security groups to prevent unauthorized external access.
Role-based access control (RBAC): A strict identity management framework limits administrative and system access. Personnel can access only the resources required for their specific function.
Audit logging: The system maintains immutable audit trails. Every access event and data change is logged to provide a transparent history of system activity.

Operational security and monitoring

Continuous verification helps identify and address potential risks.

Infrastructure monitoring: Automated systems monitor network traffic and system health 24 hours a day, 7 days a week to detect unusual behavior.
Vulnerability management: PrecisionMind performs regular automated vulnerability scans and periodic security testing to protect the software stack and underlying infrastructure.

Get help

For technical security questions, contact support@PrecisionMind.health .

Back to top

Article 03

Data governance and access controls

PrecisionMind is designed around data agency. It separates clinical data from administrative account data to support privacy and regulatory compliance.

How data is classified

Clinical data (zero-access encryption)

Clinical data includes content related to patient treatment and clinical documentation:

Therapy session transcripts and generated notes
Treatment plans and progress documentation
Clinical assessments and diagnostic records

All clinical data is encrypted at the source. PrecisionMind does not possess the decryption keys required to view or access this information. Access is restricted exclusively to the authorized clinician.

Account data (administrative access)

Account data includes information needed to operate the EHR:

Clinician and patient contact information
Billing and payment processing details
Scheduling and appointment metadata

PrecisionMind personnel may access administrative data strictly for support, billing, and system maintenance. This access is governed by the "minimum necessary" standard.

Clinical data ownership and portability

Providers maintain full authority over the lifecycle of data stored in PrecisionMind.

Manage data: Clinicians can create, update, or delete records in the platform at their discretion.
Delete records: When a clinician deletes a record, it is removed from the primary production database.
Get administrative support: The PrecisionMind support team can help with data management tasks. The team remains technically unable to view the content of encrypted clinical files during support.

Get help

For help with data management or account configuration, contact the Support Desk at support@PrecisionMind.health .

Back to top

Article 04

HIPAA and SOC 2 compliance

Regulatory standards

We implement a comprehensive framework to ensure the confidentiality and integrity of your Protected Health Information (PHI).

Zero-Access Encryption: All patient/client data is encrypted at rest and in transit. Under our "Zero-Access" model, clinical notes are only accessible to authorized clinicians. PrecisionMind cannot decrypt your records.
SOC 2 Type II Certified: Our internal operations are independently audited to verify adherence to the Trust Services Criteria: Security, Availability, and Confidentiality .
The "Minimum Necessary" Standard: Internal access is strictly limited. Information is only processed as required to deliver EHR services, preventing unnecessary data exposure.
Breach Notification: We maintain formal incident response protocols that adhere to federal notification requirements.

The chain of trust

Compliance is a shared responsibility. We ensure every link in our infrastructure is as secure as the core platform.

Sub-processor BAAs: We maintain signed Business Associate Agreements with all third-party vendors to ensure a secure, compliant chain of trust.
Practitioner BAAs: We provide a BAA to every clinician to formalize our commitment to your practice's compliance and data security.

To receive a signed Business Associate Agreement (BAA) for your HIPAA records, please email team@PrecisionMind.health .

For technical questions about our security and privacy controls, contact support@PrecisionMind.health .

Back to top

Article 05

Google Calendar integration

The Google Calendar integration is designed with privacy in mind.

Privacy protections

Minimal access: We only access calendar availability for scheduling.
No data storage: Calendar information is not stored on our servers.
Encrypted connections: All data transfers use secure, encrypted protocols.
Easy revocation: Clinicians can disconnect at any time through Google account settings.
No sharing: Calendar data is never shared with other parties.

What PrecisionMind accesses

Accessed: Availability time slots
Not accessed: Event details, attendees, or appointment content
Back to top

Article 06

Data breach protection

No system is 100% secure. PrecisionMind’s architecture adds several layers of protection for your practice.

In a breach scenario: If PrecisionMind’s servers were compromised, patient clinical content would remain encrypted and unreadable.
Notification: PrecisionMind notifies affected clinicians and patients within 72 hours of discovering a breach.
Response plan: PrecisionMind has incident response procedures in place.
Your responsibility: You will be notified immediately so you can meet your HIPAA obligations.

Report a security concern: Email support@PrecisionMind.health .

Back to top

Article 07

Common security and privacy questions

Find answers to common questions about patient data, privacy, security, and data access in PrecisionMind.

Can PrecisionMind employees access my patient notes?

No. Patient clinical content is end-to-end encrypted and inaccessible to PrecisionMind employees, including the technical team and leadership. Only you can decrypt and view clinical information.

What happens if PrecisionMind is sold to another company?

Your patients’ data keeps the same privacy protections. Clinical content stays encrypted and inaccessible to the new owner. You keep the same control over patient records.

Can PrecisionMind provide patient data if subpoenaed?

PrecisionMind can provide only non-clinical account data, such as billing information. PrecisionMind cannot provide clinical content because it cannot decrypt that data. You would need to respond directly to a subpoena that requests clinical records.

How can I verify that patient data is secure?

PrecisionMind’s security practices are regularly audited, and PrecisionMind is HIPAA compliant. PrecisionMind works with Scrut to manage compliance.

Can I export patient records to another EHR?

Yes. You can export patient clinical data at any time. Contact PrecisionMind Support for help with data portability.

What if a patient is under 18?

Users under 13 cannot use PrecisionMind. Users ages 13 through 17 require parental consent. Special privacy protections apply to minors. You remain responsible for following state-specific minor consent laws.

Am I responsible for patient data security?

Yes. PrecisionMind provides technical security, but you remain responsible for using the platform appropriately, protecting your login credentials, and following HIPAA-compliant practices in your clinical work.

Back to top

Article 08

Contact us

At PrecisionMind, we believe privacy is a right, not a privilege. Our platform is designed to ensure your patients’ sensitive information remains secure and accessible only to you as their healthcare clinician.

Choose the contact option that best matches your request:

General privacy questions: support@PrecisionMind.health
Clinician support: team@PrecisionMind.health
Book time with our team: https://cal.com/team/PrecisionMind-health

Use the scheduling link to book time for onboarding support, setup help, or workflow-related questions.

Tip: For faster resolution, include your clinic name and a brief description of your request.

Back to top

Cannot find what you need? Ask our support team and a human answers.

Fewer clicks. More care.

One place for your team, your clients, and every clinical workflow, so nothing quietly slips through the cracks.

Free for practices with up to 20 clinicians.