Protocol release · Blog
Notes on privacy, compliance, and practice.
Grounded, specific, and updated when something changes. Nothing here is filler written to rank for a keyword.
Document status
- Posts
- 19
- Topics
- HIPAA, BAA, PHI, practice

Aug 26, 2026 · 10 min read
HIPAA Compliant GPT vs Heidi: which workflow are you buying?
Both support clinical documentation. Heidi leads with scribing; HIPAA Compliant GPT leads with a broader medical-copilot workspace.
Read the post →
Aug 26, 2026 · 10 min read
HIPAA Compliant GPT vs Freed: scribe-first or broader clinical copilot?
Freed extends beyond note generation, but its workflow begins with the visit; HIPAA Compliant GPT begins with a broader set of clinical inputs and tasks.
Read the post →
Aug 26, 2026 · 11 min read
HIPAA Compliant GPT vs Mentalyc: broad copilot or therapy workflow?
Mentalyc is built around behavioral-health documentation and continuity; HIPAA Compliant GPT supports mental-health work inside a broader clinical AI workspace.
Read the post →
Aug 26, 2026 · 10 min read
HIPAA Compliant GPT vs Twofold: compare the real clinical workflow
Twofold leads with a medical-scribe workflow and progress features; HIPAA Compliant GPT puts transcription inside a broader clinical AI workspace.
Read the post →
Aug 26, 2026 · 12 min read
HIPAA Compliant GPT alternatives: choose the category before the vendor
The closest alternative depends on whether the buyer needs a clinical copilot, a scribe, therapy-specific documentation, enterprise controls, or an API foundation.
Read the post →
Aug 26, 2026 · 11 min read
HIPAA-compliant AI scribe cost: calculate the approved workflow
The subscription is only the visible line item; the useful unit is cost per approved note in the workflow the practice can actually govern.
Read the post →
Aug 26, 2026 · 10 min read
HIPAA-compliant AI scribe vs dictation: source control changes everything
Ambient capture and clinician dictation can end in a similar note while creating very different source, consent, privacy, and review obligations.
Read the post →
Aug 26, 2026 · 12 min read
Best AI scribes for clinicians: build a shortlist you can defend
The best shortlist starts with the clinician's workflow and discloses what was—and was not—tested instead of publishing a universal winner.
Read the post →
Aug 26, 2026 · 12 min read
Best AI scribes for psychiatry and PMHNPs: test the dangerous details
Psychiatry raises the cost of a fluent error: test attribution, uncertainty, risk language, medications, and longitudinal context.
Read the post →
Aug 26, 2026 · 11 min read
Best AI scribes for small practices: buy the workflow you can operate
For a small practice, the best product is the one the team can administer, review, and support consistently—not the one with the longest feature list.
Read the post →
Aug 26, 2026 · 12 min read
Best HIPAA-compliant AI scribes: verify the service, not the badge
HIPAA compliance is a relationship among the organization, vendor, agreement, configuration, safeguards, and actual use—not a permanent property of an app.
Read the post →
Aug 26, 2026 · 12 min read
AI medical scribe pricing comparison: normalize before you compare
A useful comparison records one date and normalizes volume, commitment, feature tier, team controls, and the cost of reaching an approved note.
Read the post →
Aug 26, 2026 · 9 min
Is Gemini HIPAA compliant? Workspace, Cloud, and the account in front of you
Gemini can support HIPAA workloads in specific Google environments. The answer still depends on the account, agreement, feature, and workflow.
Read the post →
Aug 25, 2026 · 9 min read
What makes an LLM deployment HIPAA compliant?
An LLM is not HIPAA compliant in isolation. Compliance depends on contracts, architecture, data flows, configuration, access controls, and the way people use the system.
Read the post →
Aug 25, 2026 · 8 min read
Is Claude HIPAA compliant? Enterprise, API, and feature coverage explained
Claude can support HIPAA-regulated work in specific Enterprise and API configurations under Anthropic's BAA. Consumer accounts and uncovered features are a different answer.
Read the post →
Aug 25, 2026 · 9 min read
Is ChatGPT HIPAA compliant? What healthcare teams must check
ChatGPT is not automatically HIPAA compliant. The answer depends on the exact product, BAA, configuration, enabled features, and the safeguards around the workflow.
Read the post →
Aug 10, 2026 · 6 min read
What actually makes an AI assistant HIPAA compliant
"HIPAA compliant" gets stamped on a lot of software. Here's what the phrase has to mean in practice, and the specific questions worth asking before you trust a tool with a patient's information.
Read the post →
Aug 3, 2026 · 5 min read
Why we publish a ledger instead of a trust badge
Most security pages are a row of logos and a paragraph of adjectives. Ours is a table you can audit. Here's why we built it that way, and what it cost us to do it honestly.
Read the post →
Jul 20, 2026 · 5 min read
Telling patients you use AI to help with notes
You don't need a legal disclosure to explain that you use a tool to help draft documentation. A few ways to say it plainly, without turning a visit into a policy briefing.
Read the post →