This page explains, without jargon, what is actually done to protect sensitive health data in MedCopilot AI β so you can use it with confidence.
Two categories of sensitive personal data flow through the app:
Patient data
Identity (first name, last name, date of birth), contact details (phone, email), allergies, medical history, clinical content (notes, transcripts, generated documents).
Physician data
Professional identity, specialty, and your signature and stamp, used to authenticate the documents you generate.
Encryption at rest
Clinical content and patient demographic fields are individually encrypted in the database using a strong, industry-recognized encryption standard. Even in the event of unauthorized database access, these fields remain unreadable without the application's encryption key.
Pseudonymization before any AI call
Before any text is sent to our AI provider β dictation, note, document, patient-copilot question β MedCopilot AI automatically replaces the patient's first name, last name, phone, email, and date of birth, as well as your own name, with neutral placeholders (e.g. β¦PATIENT_PRENOMβ§). The AI never receives these values in clear text. Once the AI's response comes back, the real values are automatically restored before anything is saved or displayed.
π‘ Good to know: this pseudonymization targets the identifiers the app knows about (name, contact details, date of birth). As with any clinical document, always review AI-generated content before finalizing it.
Per-physician isolated storage
Each physician has a private, isolated file storage space. Documents, signatures, and stamps are never accessible to another account, and files are served through server-controlled links, never exposed publicly.
Encryption in transit
All communication between your browser and our servers goes through HTTPS (TLS), which prevents interception of data during transfer.
The physician always stays in control
MedCopilot AI never finalizes anything on its own. Every note, code, order, or document generated by the AI is a draft that you review, edit if needed, and explicitly validate before anything is permanently saved.
Sub-processors and data recipients
A limited number of technical providers process data to run the service: our AI provider (processes pseudonymized text for AI generation), our hosting provider (server infrastructure), and our payment provider (subscription payments β no clinical data is shared with them). No data is sold or used for advertising.
Retention and deletion
Your data stays under your control: you can request access to all of your data, or its permanent deletion, at any time by contacting us.
MedCopilot AI draws on the principles of major international health-data protection frameworks, which guide our technical and organizational choices.
European data protection regulation: data minimization, encryption, right of access and erasure.
US health information protection framework: access control, encryption, auditability.
MedCopilot AI is a clinical documentation assistance tool, not a diagnostic device. The AI proposes, the physician decides: every generated note, ICD-10 code, order, or document must be reviewed and validated by you before any clinical or legal use. By using the app, you confirm you understand this and retain full professional responsibility for the clinical decisions you make and the documents you sign.