FAQ

Security & compliance

Common questions on privacy, clinical liability, integrations, support, data ownership, commercial terms, and product demos.

Data Privacy, Security & Compliance

Who is the Data Fiduciary and who is the Data Processor?
The hospital or clinic is the Data Fiduciary (decides purpose and means). MITTAI (CareScribe) acts as the Data Processor, operating only on the Fiduciary’s documented instructions. We apply strict safeguards, support data-principal rights, and ensure breach notification without undue delay.
Where is data hosted and how is it protected?
Hosted exclusively in India cloud data centers for sovereignty and performance. Encryption in transit (TLS 1.2+) and at rest (AES-256). HIPAA and SOC 2 Type II compliant controls with RBAC, least-privilege access, continuous monitoring, and comprehensive audit logs.
How is patient consent managed under the DPDP Act (2023)?
The Data Fiduciary (hospital) obtains valid consent. CareScribe provides configurable multilingual templates and an auditable withdrawal flow meeting the “ease of withdrawal” principle.
What is the data retention and erasure policy?
3 years for in-patient records (as per NMC 2002 regulations). 72 hours to fulfil record-copy requests. Upon expiry or verified erasure request, data is permanently deleted and a Certificate of Data Destruction is issued.
What happens in the event of a data breach?
We follow a documented Incident-Response plan (Detect → Contain → Eradicate → Recover → Notify). The Fiduciary is informed immediately, and any statutory notification to the Data Protection Board or CERT-In is supported within 6 hours for notifiable incidents.

Clinical Liability & Safety

Who is liable for errors or inaccuracies in notes?
The clinician remains responsible for the final record. CareScribe is assistive, not a replacement for clinical judgment.
How is accuracy and accountability ensured?
Workflow: Review → Edit → Approve. The clinician must review and sign-off electronically. Each approval is timestamped and stored in the audit log.
Does CareScribe meet NMC/IMC record-keeping requirements?
Yes – legible, timestamped, retrievable records complying with 72-hour copy release and 3-year retention requirements.

Integration & Interoperability

How does CareScribe integrate with existing HIMS/EMR systems?
API-first design using HL7 FHIR/REST (ABDM-aligned) standards; HL7 v2 or secure file exchange supported if required.
Can hospitals export or migrate data?
Yes – standards-based FHIR exports for portability and offboarding.
Where is CareScribe hosted?
Cloud-only deployment in India data centers with redundancy, backups, and controlled access.
How is identity and access managed?
Through SSO (OIDC/SAML), role-based access control, and comprehensive audit trails for every access and edit event.
What are your disaster-recovery and continuity measures?
Multi-zone architecture, automated backups, and regular restore testing with defined RTO/RPO objectives.

SLAs & Support

What service-level assurances are provided?
Uptime: 99.9 % monthly. Support: 24 × 7 for critical issues. P1 Critical – 1 h response / 4 h resolution P2 High – 4 h response / 1 business day P3 Normal – 1 business day response / 3 days resolution P4 Low – 2 business days response / scheduled fix
How long does implementation take?
Typical go-live within 4–6 weeks (integration, UAT, training). Clinician enablement via 1–2 hour sessions and quick-start guides.
Which devices and microphones are supported?
Web and mobile interfaces with support for clinical-grade USB or Bluetooth microphones. Offline buffering is available for temporary connectivity loss.

Data Ownership & Offboarding

Who owns the data?
The hospital and patient retain full ownership. MITTAI acts solely as a Data Processor.
Does CareScribe use customer data for AI training?
No identifiable data is ever used. Optional learning from aggregated, anonymized signals is permitted within DPDP bounds and may be opted out of at any time.
What happens when a hospital offboards?
We provide complete FHIR-standard exports, securely erase all data, and issue a Certificate of Destruction within 30–90 days.

Partnership & Commercial Terms

Is CareScribe exclusive to specific partners?
No – partnerships are non-exclusive and without any Right of First Refusal.
What pricing models are available?
Subscription-based: per clinician/year or enterprise/site license with volume and multi-year discounts.
How are liabilities handled under DPDP?
Mutual indemnities apply: MITTAI covers processor non-compliance; hospitals remain responsible for their own systems and clinical actions. Caps and terms defined in the MSA/DPA.
Do you use third-party software with restrictive licenses?
No. All open-source components use MIT or Apache-2.0 licenses; no GPL/copyleft dependencies.
Is a DPA and security evidence available?
Yes. Our DPDP-compliant DPA, SOC 2 Type II report, and HIPAA attestation can be shared under NDA along with the sub-processor list and change-notification policy.
What is the standard contract term?
12-month initial term with automatic 12-month renewal and a 60-day non-renewal notice window. Multi-year pricing available.

Product Scope & Value

Is CareScribe a medical device?
No – it is a clinical documentation and AI decision-support assistant, not diagnostic or prescriptive.
Which languages and specialties are supported?
All major Indian languages + English (others on request). Includes specialty templates for OPD, Dental, Gynae, Oncology, and General Medicine.
What results have partner sites seen?
60–70 % reduction in documentation time < 30 s draft generation for OPD notes Higher clinician satisfaction and audit readiness

Demo Guidelines & Performance

Why did CareScribe suggest a medication during a demo when none was mentioned?
If an existing patient profile is reused, the system may reference previous context. Always create and use a fresh patient record for every demo session to ensure clean, session-specific responses.
Can we conduct a demo without historical data interference?
Yes – the platform already supports a fresh-patient demo workflow that runs in real time without pulling any stored history. This is the recommended method for product demonstrations.
How is demo data secured?
Demo data follows the same HIPAA and SOC 2 Type II security standards as production data and is automatically purged after each session.
Why might long conversations occasionally lag?
Lengthy sessions can increase latency. Continuous optimizations are in place for real-time streaming and faster turnaround during extended dictations.

Documents Available on Request

Documents Available on Request
Master Service Agreement (MSA) + Data Processing Addendum (DPA) HIPAA Business Associate Agreement (if required) SLA and Support Policy

Type II Audit Report (NDA required)

Type II Audit Report (NDA required)
Sub-Processor List and Change-Policy Data Retention and Deletion Policy Implementation & Integration Guide (FHIR/HL7) Incident Response & Breach Playbook