Our Commitment
MedVox Pro is a professional medical dictation and clinical documentation service intended for use by healthcare providers and organizations. MD OfficeMail LLC recognizes that customers may use the service to create, transmit, process, or store protected health information ("PHI").
MedVox Pro is designed to support HIPAA-compliant workflows when it is properly configured, used in accordance with organizational policies, and covered by appropriate agreements. HIPAA compliance is a shared responsibility between MD OfficeMail LLC and each customer.
HIPAA does not establish or recognize an official certification for software applications. Accordingly, MD OfficeMail LLC does not represent MedVox Pro as "HIPAA certified."
Safeguards
MD OfficeMail LLC maintains administrative, technical, and physical safeguards intended to protect the confidentiality, integrity, and availability of electronic PHI handled through MedVox Pro.
Administrative Safeguards
- Access to systems and clinical information is limited according to workforce responsibilities.
- Administrative access and selected sensitive actions are logged for security, support, and accountability purposes.
- Security and privacy practices are reviewed as the service, applicable risks, and legal requirements evolve.
- Suspected security incidents are investigated and addressed according to their nature and severity.
- Workforce members and service providers are expected to handle sensitive information only as necessary to perform authorized duties.
Technical Safeguards
- Data transmitted between supported applications and MedVox Pro services is protected using encrypted network connections.
- Stored audio is encrypted, and sensitive locally cached mobile data is protected using device-supported secure storage and encryption controls.
- Passwords are stored using one-way cryptographic hashing rather than in plaintext.
- Role-based access controls restrict users to functions and records appropriate to their assigned permissions.
- Sessions, access tokens, and short-lived media authorization controls are used to reduce unauthorized access.
- The service includes controls for automatic session expiration and clearing sensitive local state.
- Audit and operational logs support monitoring and investigation of relevant system activity.
- MedVox Pro does not use clinical content or patient information for advertising or sell such information to third parties.
Physical Safeguards
MedVox Pro relies on professionally managed hosting and infrastructure providers for physical data-center protections. Access to production systems and administrative tools is restricted to authorized personnel. Customers remain responsible for securing the physical devices and networks used to access MedVox Pro.
Use and Disclosure of PHI
MD OfficeMail LLC uses PHI only as necessary to provide, maintain, secure, and support MedVox Pro; to perform services requested by an authorized customer; or as otherwise permitted or required by applicable law and the applicable Business Associate Agreement.
Clinical audio and text may be transmitted to contracted service providers when necessary to perform transcription, clinical note generation, storage, delivery, or related service functions. MD OfficeMail LLC evaluates service providers that may handle PHI and uses contractual and security measures appropriate to the services they perform. Specific subprocessors and data flows may change as the service evolves and should be reviewed as part of each customer's contracting and risk-assessment process.
MD OfficeMail LLC does not sell PHI and does not use PHI for targeted advertising.
Data Retention and Disposal
Clinical data is retained according to service functionality, customer instructions, contractual requirements, and applicable law. Authorized users and administrators may have tools to delete dictations or associated audio. Upon account closure or an authorized deletion request, information is deleted or de-identified according to applicable agreements, retention requirements, and technical limitations.
Customers are responsible for maintaining any records they are legally required to retain and should not rely on MedVox Pro as their sole legal medical-record retention system unless expressly agreed in writing.
Security Incident and Breach Response
MD OfficeMail LLC maintains processes to identify, investigate, mitigate, and document suspected security incidents involving information under its control. If MD OfficeMail LLC determines that an incident requires notification under HIPAA or an applicable Business Associate Agreement, affected customers will be notified in accordance with the applicable legal and contractual requirements.
Customers should promptly report suspected unauthorized access, disclosure, loss, or misuse of information associated with MedVox Pro.
Business Associate Agreements
MD OfficeMail LLC makes a Business Associate Agreement ("BAA") available to covered entities and other customers that require one before using MedVox Pro to handle PHI.
A signed BAA and any required service agreement should be in place before a customer submits PHI to MedVox Pro.
Customer Responsibilities
- Determining whether and how HIPAA and other laws apply to their organization and use of MedVox Pro.
- Entering into a BAA with MD OfficeMail LLC before submitting PHI when required.
- Authorizing only appropriate workforce members to access the service.
- Assigning suitable roles and promptly removing access when it is no longer required.
- Protecting passwords, devices, networks, exported files, downloaded audio, and other access credentials.
- Configuring integrations, email delivery, webhooks, and connected systems securely.
- Obtaining any patient notices, consents, or authorizations required by law or organizational policy.
- Training workforce members and maintaining appropriate privacy, security, risk-management, and incident-response policies.
- Reviewing generated transcripts, notes, and suggested medical codes for accuracy before clinical use.
- Reporting suspected security or privacy incidents without unreasonable delay.
Scope and Changes
This statement describes general practices and does not amend or replace a customer agreement, BAA, privacy policy, or other binding contract. If this statement conflicts with a signed agreement, the signed agreement controls.
MD OfficeMail LLC may update this statement to reflect changes in the service, safeguards, providers, or legal requirements. The "Last updated" date above identifies the most recent revision.