Security Practices

This document describes the security controls, infrastructure, and compliance measures that SutureNote maintains to protect patient data in accordance with HIPAA requirements.

Last updated: June 2026 Version: 2.1 security@suturenote.ai

1. HIPAA Compliance

SutureNote is built on HIPAA-eligible AWS infrastructure. All services involved in processing or storing patient data are covered by a signed Business Associate Agreement (BAA). Patient data is processed and stored only within our HIPAA-eligible AWS environment and is not shared with third parties outside that environment. To the best of our knowledge, all user data is stored in the United States.

2. Encryption

All protected health information is encrypted in transit and at rest.

3. AI & PHI Protection

SutureNote uses AI models for clinical note generation and medical transcription. All AI processing runs within our HIPAA-eligible AWS environment under a signed Business Associate Agreement.

4. Access Control

SutureNote follows a zero-trust model with minimal human access to production systems.

5. Data Management

6. Security Operations

7. Business Continuity

Measure Details
Backups Automated backups with point-in-time recovery are maintained. Database and storage are replicated across multiple availability zones.
Recovery Time Recovery procedures are designed to target restoration within hours. Failover mechanisms are in place for critical services.
Availability Architected for high availability using redundant infrastructure. Continuous health monitoring enables rapid detection and response to service disruptions.
Data Durability Stored in Amazon S3, which is built for high durability. Database replication spans multiple availability zones for resilience.

Security Inquiries

For questions about SutureNote's security practices, HIPAA compliance, or to report a security concern, contact our security team at security@suturenote.ai.