Trust, privacy and the record · 2 of 4
The agreement, and what is never used for training
The agreement is enforced by the software rather than filed and forgotten. Who touches patient data, and what none of them are allowed to do with it.
Most software asks you to sign a business associate agreement and then trusts everyone to behave. Mesio enforces it in code, before any patient information can exist.
You cannot start without it
Until the agreement is signed, the product will not create a patient, will not accept an audio upload, will not create a note, and will not issue the credential that lets the Bridge or the browser extension reach your practice system.
It is practice-wide rather than per person. A hygienist at an unsigned practice is blocked the same as the owner, because the gate is about the practice, not about who is asking.
This is why signing appears before anything interesting. It is not paperwork placed in your way. It is the point before which the software is genuinely unable to hold anything about a patient.
Who else touches patient data
Being specific matters more here than sounding secure.
Speech recognition runs on Mesio's own infrastructure. Drafting notes, charts and related materials uses large language models from named providers, and every one of them holds an executed business associate agreement covering protected health information. Insurance eligibility goes to a clearinghouse that is likewise covered.
The current list is named in the privacy policy rather than described in the abstract, because a vendor list that says industry-leading providers is telling you nothing.
What none of them may do
Your patients' information is not used to train anyone's models. Not Mesio's, and not the providers'. That is a contractual commitment in the agreements, and it is the sentence worth holding people to.
What is kept away from all of it
Several services a product like this normally uses are deliberately kept outside the path that touches patient information, including error monitoring and product analytics. Error reports pass through a scrubber on the way out rather than relying on nobody ever logging the wrong thing.
Where you can check
The privacy policy names the providers and is updated when that list changes. If you are being asked by your own compliance reviewer for a subprocessor list, that is the page to hand them.