Free for a week, then $19 for your first month
Trust & compliance

Security & trust

Twofold Health is built for healthcare providers. Every part of how we handle data reflects the sensitivity of the work you do.

HIPAA Compliant BAA included · Audio never stored · US infrastructure
  • Compliance
    HIPAA compliant
    Active
  • Data location
    US infrastructure only
    Active
  • Certification
    SOC 2 Type II in progress
    In progress
  • Model training
    Never on your data
    Active
01

HIPAA & BAA

Twofold Health signs a Business Associate Agreement with every healthcare organization that uses the platform. Our BAA covers breach notification, data residency on US infrastructure, subprocessor obligations, and breach cost responsibility.

Get our BAA
02

Infrastructure

Twofold Health is hosted on Microsoft Azure and Google Cloud Platform (GCP), running across both providers for redundancy and resilience. We maintain formal HIPAA BAAs with both Microsoft and Google, and all data is stored and processed in US-based data centers. Both platforms provide enterprise-grade availability, security controls, and compliance standards.

03

Data residency

All protected health information processed and stored by Twofold Health is hosted exclusively on United States-based infrastructure. We do not transfer or store PHI outside of the United States.

04

Audio and recording handling

Session recordings are never stored on our servers. Audio is processed to generate a transcript and note, then immediately deleted. No recording is written to disk at any point. Summarized notes are retained as part of the clinician's workflow and can be deleted at any time. Upon termination of the agreement, all PHI is returned or destroyed in accordance with our BAA.

05

Who can access your data

No one at Twofold Health can access your session transcripts, clinical notes, or patient names. Support can help with account and technical questions without ever seeing your clinical content.

06

Model training

We do not use your data to train AI models - not ours, not anyone else's. Protected health information is explicitly excluded from AI training.

07

Encryption

All data is encrypted in transit and at rest using industry-standard protocols. Patient information is encrypted at every point in the system - from capture through storage.

08

Subprocessors

All subprocessors who handle PHI on our behalf are required to sign BAAs with Twofold and are regularly assessed for HIPAA compliance. They are bound by the same confidentiality and data protection obligations as Twofold Health. Written certification is available upon request.

09

Internal security program

Twofold maintains a written information security program that includes administrative, technical, and physical safeguards. All team members complete annual HIPAA security training. Pre-employment background checks are required for all staff. Periodic risk assessments are conducted to ensure policies remain effective. Privacy and security oversight is led by our CTO.

10

SOC 2 Type II

Twofold Health is currently undergoing SOC 2 Type II certification covering Security, Availability, and Confidentiality, in partnership with Sprinto. The audit will be conducted by an independent AICPA-certified firm. We will share the report upon completion.

11

Canada — PIPEDA and PHIPA

In Ontario we act as an electronic service provider under PHIPA, and those duties apply to us directly: health information is used only to produce your documentation, never disclosed. Under PIPEDA we have a named individual accountable for privacy and report qualifying breaches to the Privacy Commissioner of Canada. Alberta and Quebec require a written agreement before disclosure, which we sign.

12

Australia — the Australian Privacy Principles

Twofold is an APP entity under the Privacy Act 1988, so the Australian Privacy Principles apply to us directly rather than through your practice. Health information is treated as sensitive information, is never used for marketing or model training, and eligible data breaches are reported to the OAIC.

Common security questions

The questions clinicians ask most when evaluating an AI scribe on privacy and compliance.

No — recordings are never stored on our servers. Here's how audio is handled:

  • Processed to generate a transcript and note, then immediately deleted
  • No recording is ever written to disk at any point
  • The summarized note stays in your workflow, and you can delete it whenever you want
  • If you end your agreement, all PHI is returned or destroyed per our BAA

No. Your data is never used for AI training:

  • Not for our models, and not for anyone else's
  • Protected health information is explicitly excluded from all AI training

Yes. We sign a BAA with every healthcare organization that uses Twofold. It covers:

  • Breach notification
  • Data residency on US infrastructure
  • Subprocessor obligations
  • Breach cost responsibility

You can request a copy by emailing info@trytwofold.com.

  • Twofold staff cannot access your session transcripts, clinical notes, or patient names — not even with your permission
  • Support can help with account and technical issues without ever seeing your clinical content
  • All system access is logged and auditable

All PHI is hosted exclusively on US-based infrastructure. Specifically:

  • Hosted through Microsoft Azure and Google Cloud (GCP), where we maintain formal HIPAA BAAs
  • No PHI is transferred or stored outside the United States
  • All data is encrypted in transit and at rest, at every point in the system

Yes, and in Ontario our duties apply to us directly:

  • PHIPA — health information is used only to produce your documentation, and never disclosed
  • PIPEDA — a named individual is accountable for privacy, and qualifying breaches go to the Privacy Commissioner of Canada
  • Alberta and Quebec — we sign the written agreement each requires before any disclosure

Yes. Twofold is an APP entity under the Privacy Act 1988, so the APPs apply to us directly:

  • Health information is treated as sensitive information
  • It is never used for marketing, or to train models
  • You can access, correct, or complain to us or the OAIC
  • Eligible data breaches are reported to the OAIC

Questions?

For security questions, compliance documentation, or vendor assessments, reach out directly.

info@trytwofold.com