Security & compliance

Security is part of handling a patient record.

SoapBox processes protected health information to provide its service. This page explains the controls, access boundaries, and vendor requirements behind that responsibility.

What SoapBox is responsible for

Encrypting your data, controlling and logging access to it, isolating your practice from other organizations, keeping our vendors under agreement, and maintaining tested backup and recovery procedures.

What your practice controls

Who you invite into your account and what role you give them, keeping credentials private, and deciding what information you put into the platform in the first place.

Safeguards

Safeguards built into SoapBox.

PHI encryption at the data boundary

Transcripts, notes, and patient identifiers are encrypted in transit and protected at the storage boundary, including field-level controls for sensitive data.

Role and organization boundaries

Application roles, explicit organization scoping, and database policies limit which records a user can reach.

PHI access is auditable

Protected record activity is captured in audit trails designed to preserve actor and organization context.

Production vendors are BAA-gated

Production services that can process PHI must pass the application’s contractual gate, including BAAs where required.

Tenant isolation at multiple layers

Organization filters and database row-level security work together to separate practice data.

Backups and recovery

Data is backed up and restores are rehearsed, so recovery is a tested procedure rather than a hope.

Due diligence

Questions worth asking before PHI enters a platform.

Do you sign a Business Associate Agreement?

Simplicity Group Advisors, LLC enters into Business Associate Agreements when required. Contact alec@slpsoapbox.com to begin the review, and wait until the agreement is signed before entering protected health information. A request, account signup, or website acknowledgment does not execute a BAA.

Is my data used to train AI models?

SoapBox does not use your recordings, transcripts, or notes to train its own general-purpose AI models. They are processed to provide the requested service. Production PHI is sent only through approved workflows to service providers covered by the contractual safeguards required for that processing, including BAAs where required.

Where is the data stored?

In AWS, under the AWS business associate agreement, encrypted at rest and in transit.

Need a BAA or security review?

Send us the questions your practice needs answered before using SoapBox with PHI.

Ask a security question