SOC2C

Is this your company? Buyers are checking Chartnote here. Claim chartnote.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Chartnote logo

Chartnote

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Chartnote is SOC 2 Type II compliant. Chartnote also holds HIPAA, PIPEDA, GDPR, and CCPA.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Chartnote is a healthtech platform that streamlines medical documentation using AI, voice recognition, and smart templates.

Compliance & infrastructure

Hosting
AWS

Documents

2

Subprocessors

4
  • A
    Amazon Web Services · Cloud provider
    US
  • G
    Google Workspace · Identity provider
    US
  • A
    Anthropic · Engineering
    US
  • O
    OpenAI · Engineering
    US

Compliance leadership

The person who leads Chartnote's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Chartnote's penetration test vendor isn't listed yet.

Claim this profile to add it.

This listing is partial

7/11 details · 64%

SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Chartnote SOC 2 compliant?
Chartnote is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Chartnote HIPAA compliant?
According to Chartnote's public trust center, Chartnote is HIPAA compliant. On SOC2C this listing is Listed.
Is Chartnote PIPEDA compliant?
According to Chartnote's public trust center, Chartnote is PIPEDA compliant. On SOC2C this listing is Listed.
Is Chartnote GDPR compliant?
According to Chartnote's public trust center, Chartnote is GDPR compliant. On SOC2C this listing is Listed.
Is Chartnote CCPA compliant?
According to Chartnote's public trust center, Chartnote is CCPA compliant. On SOC2C this listing is Listed.

Answers published by Chartnote

Reproduced from Chartnote's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

How does Chartnote prioritize clinician and patient trust?
At Chartnote, clinician and patient trust is our top priority. We incorporate HIPAA, PIPEDA, and GDPR security standards into all aspects of data collection and processing to ensure patient data is protected at every stage.
What internal security measures does Chartnote have in place for its employees?
All Chartnote employees undergo background checks before being hired and complete annual security awareness training focusing on HIPAA, PIPEDA, GDPR, privacy, and information classification.
How does Chartnote ensure compliance with HIPAA and other security standards?
We conduct regular risk assessments to keep our policies current and relevant. Our Chief Technology Officer (CTO) oversees all aspects of privacy and security to ensure compliance with HIPAA, PIPEDA, and GDPR regulations.
What is Chartnote’s approach to secure software development?
Chartnote follows a Secure Development Lifecycle (SDLC) where all software changes undergo compliance reviews. We use infrastructure-as-code practices, and all infrastructure changes are reviewed before deployment. Engineers are trained in secure development practices.
How is patient data stored and processed on Chartnote’s platform?
Chartnote utilizes Amazon Web Services (AWS) secure data centers for hosting and data processing. We have a HIPAA Business Associate Agreement (BAA) and a Data Processing Agreement (DPA) with AWS, and AWS’s high-availability infrastructure ensures data is always accessible.