Security at Determa
Determa is an AI scribe for dermatology practices, and the recordings and notes it handles can contain protected health information. This page collects, in one place, the commitments already stated in our Privacy Policy and Terms of Service. Those documents govern; this is the short version for a security review.
Built for dermatology, and for documentation only
Determa gives healthcare professionals a platform to record, store, transcribe, and manage medical audio and the clinical documentation that comes from it. It is a documentation tool only. Determa does not provide medical advice, diagnosis, or treatment, and the clinician is solely responsible for all clinical decisions.
A Business Associate Agreement is available
A BAA must be in place before Determa is used to process PHI. It defines how we may use and disclose PHI, sets out our obligations to safeguard it, and requires compliance with the applicable HIPAA rules.
Individual users accept our BAA by electronic clickwrap when they register, or when prompted to accept an updated version — acceptance that is legally binding under the Electronic Signatures in Global and National Commerce Act (ESIGN Act). Organizations may execute a formal BAA through an electronic signature service or on paper; write to legal@determa.co to start that.
Encryption and access control
- Encryption: AES-256 for data at rest, TLS 1.2+ for data in transit.
- Access controls: role-based permissions and authentication, so a clinician reaches their own practice's records and nothing else.
- Audit logging: audit logging of cross-user PHI access and modifications.
- Workforce training: HIPAA compliance training for employees with PHI access.
Who processes patient data
These vendors handle PHI on Determa's behalf, and both have signed Business Associate Agreements with us. Recordings, transcripts, and notes are stored in the United States.
- Google Cloud Platform — cloud infrastructure, database, file storage, transcription, and AI processing (Cloud Storage, Cloud SQL, Vertex AI, Speech-to-Text).
- Deepgram — an alternative transcription service.
These providers are contractually obligated to protect your information. The full list, including the vendors that never touch PHI, is in the Privacy Policy.
Consent and clinical review stay with the practice
Obtaining all required patient consents before recording is the practice's responsibility, as required by applicable laws. AI-generated transcripts and notes may contain errors, inaccuracies, or omissions, and the clinician must review and verify every one before relying on it for clinical or administrative purposes.
Patient recordings are not used to train AI models
Determa does not use patient recordings to train AI models.
Questions
Security questions go to support@determa.co. BAA requests go to legal@determa.co. For anything this page summarises, the Privacy Policy is the authority.