Back to the home page

Security and privacy

This is what DocTalk does today to protect access and data, described only with what the application does. If your organization needs more detail, ask for it when you request the evaluation.

Access and sessions

Two-step sign-in
Two-step sign-in with an authenticator app is available, with recovery codes and trusted devices that can be forgotten.
Limited sessions
The session locks after inactivity and lasts at most 12 hours. When it expires you have to sign in again.
Repeated attempts
Failed sign-in attempts are limited by origin and by user, and the account is locked after several failures in a row.
Role-based permissions
Each person sees and does only what their permissions allow: screens and actions are hidden and the permissions are checked again on the server.

Data in the browser

No credentials in sight
The session is kept in an encrypted cookie that the browser cannot read from JavaScript and that only travels over HTTPS.
Drafts only in the tab
Unsaved notes live only in the open tab, not in permanent storage, and are erased when you sign out or switch instance. The application warns you before you leave with unsaved work.
No trackers
The application and this page load no analytics, advertising or third-party fonts: the browser only connects to DocTalk's own server.

Protecting the application

Security headers
HTTPS enforced (HSTS), a restrictive content policy, no embedding in other pages and no caching of screens that show data.
Checked actions
Actions that change data check that they come from the application itself, and the costliest ones are rate-limited.
Clean content
Notes are cleaned on the server before they are filed.

Human review and sources

An AI note is not filed without review
A note that comes from a dictation is not filed until the clinician confirms they have reviewed it, and the server enforces it.
Every answer cites its source
Answers link to the exact page of the record that supports them. DocTalk does not replace clinical judgment.

This public site

The form stores nothing
The evaluation request prepares an email in your email program; this site does not store what you type. Do not include patient data.
Cookies
Opening this page sets no cookies. Only your choice of language and theme is kept if you change them.

Compliance

HIPAA
DocTalk complies with HIPAA for the handling of protected health information (PHI) in the United States.

If your organization needs more detail, ask for it when you request the evaluation.

Request an evaluation