Security and privacy
This is what DocTalk does today to protect access and data, described only with what the application does. If your organization needs more detail, ask for it when you request the evaluation.
Access and sessions
- Two-step sign-in
- Two-step sign-in with an authenticator app is available, with recovery codes and trusted devices that can be forgotten.
- Limited sessions
- The session locks after inactivity and lasts at most 12 hours. When it expires you have to sign in again.
- Repeated attempts
- Failed sign-in attempts are limited by origin and by user, and the account is locked after several failures in a row.
- Role-based permissions
- Each person sees and does only what their permissions allow: screens and actions are hidden and the permissions are checked again on the server.
Data in the browser
- No credentials in sight
- The session is kept in an encrypted cookie that the browser cannot read from JavaScript and that only travels over HTTPS.
- Drafts only in the tab
- Unsaved notes live only in the open tab, not in permanent storage, and are erased when you sign out or switch instance. The application warns you before you leave with unsaved work.
- No trackers
- The application and this page load no analytics, advertising or third-party fonts: the browser only connects to DocTalk's own server.
Protecting the application
- Security headers
- HTTPS enforced (HSTS), a restrictive content policy, no embedding in other pages and no caching of screens that show data.
- Checked actions
- Actions that change data check that they come from the application itself, and the costliest ones are rate-limited.
- Clean content
- Notes are cleaned on the server before they are filed.
Human review and sources
- An AI note is not filed without review
- A note that comes from a dictation is not filed until the clinician confirms they have reviewed it, and the server enforces it.
- Every answer cites its source
- Answers link to the exact page of the record that supports them. DocTalk does not replace clinical judgment.
This public site
- The form stores nothing
- The evaluation request prepares an email in your email program; this site does not store what you type. Do not include patient data.
- Cookies
- Opening this page sets no cookies. Only your choice of language and theme is kept if you change them.
Compliance
- HIPAA
- DocTalk complies with HIPAA for the handling of protected health information (PHI) in the United States.
If your organization needs more detail, ask for it when you request the evaluation.
Request an evaluation