Is this your company?Buyers are checking Chartnote here. Claim chartnote.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.
SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
Auditorraises trust
Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
Report dateraises trust
Add your most recent report period so buyers see how current your SOC 2 is.
Renewal date
Add your renewal window so buyers know your coverage is active.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is Chartnote SOC 2 compliant?
Chartnote is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Chartnote HIPAA compliant?
According to Chartnote's public trust center, Chartnote is HIPAA compliant. On SOC2C this listing is Listed.
Is Chartnote PIPEDA compliant?
According to Chartnote's public trust center, Chartnote is PIPEDA compliant. On SOC2C this listing is Listed.
Is Chartnote GDPR compliant?
According to Chartnote's public trust center, Chartnote is GDPR compliant. On SOC2C this listing is Listed.
Is Chartnote CCPA compliant?
According to Chartnote's public trust center, Chartnote is CCPA compliant. On SOC2C this listing is Listed.
Is Chartnote SOC 2 Type I or Type II?
Chartnote is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Chartnote's SOC 2 for a vendor risk assessment?
Yes. Chartnote's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Chartnote penetration tested?
Chartnote hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.
Can I get Chartnote's SOC 2 report?
Chartnote's SOC 2 report is available on request. Request access through SOC2C and we coordinate the company-side NDA and delivery.
Is Chartnote secure?
Security isn't a single yes/no, but Chartnote is SOC 2 Type II compliant and holds HIPAA, PIPEDA, GDPR, SOC 2 Type II, CCPA. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Chartnote have a bug bounty or vulnerability disclosure program?
Chartnote hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@chartnote.com or via a /security page (Chartnote lists a security contact).
Who are Chartnote's subprocessors?
Chartnote lists 4 subprocessors on its trust center, including Amazon Web Services, Google Workspace, Anthropic, OpenAI. Buyers use this for fourth-party risk review.
Where does Chartnote host or store data?
Chartnote hosts on AWS. Data residency details are on its trust center.
Where is Chartnote's trust center or security page?
Chartnote's trust center is at https://trust.chartnote.com. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.
How does Chartnote prioritize clinician and patient trust?
At Chartnote, clinician and patient trust is our top priority. We incorporate HIPAA, PIPEDA, and GDPR security standards into all aspects of data collection and processing to ensure patient data is protected at every stage.
What internal security measures does Chartnote have in place for its employees?
All Chartnote employees undergo background checks before being hired and complete annual security awareness training focusing on HIPAA, PIPEDA, GDPR, privacy, and information classification.
How does Chartnote ensure compliance with HIPAA and other security standards?
We conduct regular risk assessments to keep our policies current and relevant. Our Chief Technology Officer (CTO) oversees all aspects of privacy and security to ensure compliance with HIPAA, PIPEDA, and GDPR regulations.
What is Chartnote’s approach to secure software development?
Chartnote follows a Secure Development Lifecycle (SDLC) where all software changes undergo compliance reviews. We use infrastructure-as-code practices, and all infrastructure changes are reviewed before deployment. Engineers are trained in secure development practices.
How is patient data stored and processed on Chartnote’s platform?
Chartnote utilizes Amazon Web Services (AWS) secure data centers for hosting and data processing. We have a HIPAA Business Associate Agreement (BAA) and a Data Processing Agreement (DPA) with AWS, and AWS’s high-availability infrastructure ensures data is always accessible.
Is data encrypted on Chartnote’s platform?
Yes, all data is encrypted at rest and in transit using industry-standard encryption schemes to ensure confidentiality.
How does Chartnote manage its vendors in relation to patient information?
All vendors who may process patient information are required to be HIPAA, PIPEDA, and GDPR-compliant and sign Business Associate Agreements (BAAs) or equivalent agreements with Chartnote. We regularly review vendor security practices to ensure they maintain high standards.
Are Chartnote’s AI models compliant with HIPAA?
Yes, all AI models used by Chartnote are HIPAA, PIPEDA, and GDPR compliant and do not retain any data. Protected health information is never used for AI training purposes.
How does Chartnote handle patient information?
Patient information is encrypted both at rest and in transit. Notes and recordings are securely saved in a HIPAA, PIPEDA, and GDPR-compliant manner. Users can manually delete notes at any time or set them to automatically delete after 1-30 days. Recordings can also be set to delete automatically within the same timeframe.
Where can I find more information about Chartnote’s privacy and security practices?
For more information, please refer to Chartnote’s Platform Terms of Use, Privacy Policy, and Trust Center. Feel free to reach out if you need further details or assistance.