DeepScribe
DeepScribe · Ambient AI medical scribe
Ayliea's assessment: Medium RiskAyliea recommends: MonitorIn Ayliea's curated list
Verified . Risk classification and recommended policy are Ayliea's subjective assessments — not vendor certifications.
- Data residency
- United States (AWS us-east-1)
- Zero retention available
- No
- Certifications
- SOC 2 Type II
Why this rating
Signs BAAs, holds a SOC 2 Type II report (2024 audit + an Oct 2025 bridge letter), and keeps data US-only on AWS with AES-256 / TLS. But OpenAI is a named subprocessor in the documentation path, and there is no published data-retention schedule or no-training-on-PHI commitment.
Considerations before deploying
- Confirm whether raw PHI or de-identified text reaches OpenAI, and that the OpenAI path is a BAA-covered, zero-retention endpoint
- Get an explicit no-training-on-customer-PHI clause and a defined audio/transcript retention & deletion schedule in the DPA/BAA
- Request the SOC 2 Type II report and third-party HIPAA audit report (both gated) — don't rely on the FAQ self-attestation
- No verifiable HITRUST or ISO 27001; SAML SSO is Enterprise-tier only
Sources
- DeepScribe Trust Center (trust.deepscribe.ai)
- DeepScribe Trust Center — Subprocessors (trust.deepscribe.ai)
- DeepScribe Security Practices (www.deepscribe.ai)
Want this for every tool on your network?
A scoping call starts an expert assessment that maps your full AI surface — sanctioned and shadow — from the log metadata you share.
