Security and Compliance
Effective Date: August 26, 2026·Version 1.4
Protecting Your Health Information
MyPrechart LLC operates as a HIPAA Business Associate and takes the privacy and security of protected health information seriously. Our compliance program includes:
- Documented HIPAA privacy and security policies covering access controls, encryption in transit, incident response, and breach notification
- An executed Business Associate Agreement with Amazon Web Services, our cloud infrastructure provider
- New notes, drafts, queued requests, visit details, and custom wording are held only in the current app session. Reloading, closing the app, signing out, or changing accounts removes this new work. Copy finished notes into your agency's EMR before leaving. Older records already saved on this device remain unchanged and are available through explicit, read-only recovery; they are not loaded or sent automatically.
- Clinical content sent for narrative generation, and voice conversation audio, pass through our AWS processing infrastructure in memory only and are not written to any database or log
- The third parties that process data for us: Amazon Web Services (cloud infrastructure, AI inference through AWS Bedrock using Claude by Anthropic, voice synthesis through Amazon Polly, voice conversation through Amazon Nova Sonic, compute and operational logging), Supabase (authentication, application database, edge functions, email queue), Lovable (application hosting and transactional account email), Google Workspace (business email, calendar and collaboration, covered by an executed Business Associate Agreement), Stripe (web subscription payments), Apple (in-app purchase payments and subscription status), and the U.S. National Library of Medicine (public diagnosis code lookup, search term only, for terms not in the app's bundled code list)
- TLS 1.2 or higher on all traffic, and encryption at rest on our servers provided by our managed platforms, Supabase and Amazon Web Services. Clinical data stored on your device is not encrypted by the application itself: the app applies no application-layer encryption to its local storage (IndexedDB), which relies on your device's own disk encryption and, in the iOS app, on the optional Face ID or Touch ID app lock if you have enabled it — in a web browser there is no app-level lock
- Optional two-factor authentication (TOTP) that any user can enable from account settings. Once you have enrolled TOTP, the app requires the second factor again when a stored session is resumed, rather than trusting the stored session on its own
- Automatic sign-out after 15 minutes of inactivity
- Spellcheck and autocorrect are disabled by default on clinical text inputs, so clinical text is not sent to a platform or cloud spell-check service
- Diagnosis code lookup runs against a code list bundled in the app, so most searches never leave the device. For a term the bundled list does not contain, the lookup is proxied through our own server rather than called from the browser. Validation runs both on the device and again at our server, so a term that looks like a patient identifier is refused before any outbound request is made, and the server-side check cannot be bypassed by an out-of-date client
- An incident response plan with defined breach assessment and notification procedures
- Ongoing security risk assessment and remediation
HIPAA compliance is an ongoing process rather than a one-time certification. We continuously review and update our practices as our organization grows.
Questions
For security documentation requests, contact info@myprechart.co.
