Free for a week, then $19 for your first month
Trust & compliance

Security & trust

Twofold Health is built for healthcare providers. Every part of how we handle data reflects the sensitivity of the work you do.

HIPAA Compliant BAA included · Audio never stored · US infrastructure
  • Compliance
    HIPAA compliant
    Active
  • Data location
    US infrastructure only
    Active
  • Certification
    SOC 2 Type II in progress
    In progress
  • Model training
    Never on your data
    Active
01

HIPAA & BAA

Twofold Health signs a Business Associate Agreement with every healthcare organization that uses the platform. Our BAA covers breach notification, data residency on US infrastructure, subprocessor obligations, and breach cost responsibility.

Get our BAA
02

Infrastructure

Twofold Health is hosted on Microsoft Azure and Google Cloud Platform (GCP), running across both providers for redundancy and resilience. We maintain formal HIPAA BAAs with both Microsoft and Google, and all data is stored and processed in US-based data centers. Both platforms provide enterprise-grade availability, security controls, and compliance standards.

03

Data residency

All protected health information processed and stored by Twofold Health is hosted exclusively on United States-based infrastructure. We do not transfer or store PHI outside of the United States.

04

Audio and recording handling

Session recordings are never stored on our servers. Audio is processed to generate a transcript and note, then immediately deleted. No recording is written to disk at any point. Summarized notes are retained as part of the clinician's workflow and can be deleted at any time. Upon termination of the agreement, all PHI is returned or destroyed in accordance with our BAA.

05

Who can access your data

No one at Twofold Health can access your session transcripts, clinical notes, or patient names. Support can help with account and technical questions without ever seeing your clinical content.

06

Model training

We do not use your data to train AI models - not ours, not anyone else's. Protected health information is explicitly excluded from AI training.

07

Encryption

All data is encrypted in transit and at rest using industry-standard protocols. Patient information is encrypted at every point in the system - from capture through storage.

08

Subprocessors

All subprocessors who handle PHI on our behalf are required to sign BAAs with Twofold and are regularly assessed for HIPAA compliance. They are bound by the same confidentiality and data protection obligations as Twofold Health. Written certification is available upon request.

09

Internal security program

Twofold maintains a written information security program that includes administrative, technical, and physical safeguards. All team members complete annual HIPAA security training. Pre-employment background checks are required for all staff. Periodic risk assessments are conducted to ensure policies remain effective. Privacy and security oversight is led by our CTO.

10

SOC 2 Type II

Twofold Health is currently undergoing SOC 2 Type II certification covering Security, Availability, and Confidentiality, in partnership with Sprinto. The audit will be conducted by an independent AICPA-certified firm. We will share the report upon completion.

Common security questions

The questions clinicians ask most when evaluating an AI scribe on privacy and compliance.

No — recordings are never stored on our servers. Here's how audio is handled:

  • Processed to generate a transcript and note, then immediately deleted
  • No recording is ever written to disk at any point
  • The summarized note stays in your workflow, and you can delete it whenever you want
  • If you end your agreement, all PHI is returned or destroyed per our BAA

No. Your data is never used for AI training:

  • Not for our models, and not for anyone else's
  • Protected health information is explicitly excluded from all AI training

Yes. We sign a BAA with every healthcare organization that uses Twofold. It covers:

  • Breach notification
  • Data residency on US infrastructure
  • Subprocessor obligations
  • Breach cost responsibility

You can request a copy by emailing info@trytwofold.com.

  • Twofold staff cannot access your session transcripts, clinical notes, or patient names — not even with your permission
  • Support can help with account and technical issues without ever seeing your clinical content
  • All system access is logged and auditable

All PHI is hosted exclusively on US-based infrastructure. Specifically:

  • Hosted through Microsoft Azure and Google Cloud (GCP), where we maintain formal HIPAA BAAs
  • No PHI is transferred or stored outside the United States
  • All data is encrypted in transit and at rest, at every point in the system

Questions?

For security questions, compliance documentation, or vendor assessments, reach out directly.

info@trytwofold.com