Last updated: July 31, 2026

Round Smarter handles protected health information on behalf of the
physician practices and facilities that use our platform. This page
states plainly how we protect it, who we share it with, and what we will
and will not do with it. If you are evaluating Round Smarter and need
something not covered here, email admin@roundsmarter.com.

HIPAA

Round Smarter is a Business Associate under HIPAA.
We do not have a direct treatment relationship with patients. We process
PHI only on behalf of the healthcare organizations that contract with
us, and only as their written Business Associate Agreement permits.

We will sign a BAA with every customer before any PHI is
exchanged.
To request our standard BAA, email admin@roundsmarter.com with the
subject line “BAA.”

Full detail on what we process and why is in our Privacy Statement.

How data is protected

Encryption in transit TLS 1.2 or higher for all connections
Encryption at rest AES-256
EHR connectivity All API traffic between Round Smarter and PointClickCare requires
mutual TLS with a client certificate
Access control Authenticated providers only, scoped to the facilities they are
assigned to
Audit logging We log read access to PHI
Hosting Google Cloud Platform, United States regions
Data residency All PHI is stored and processed in the United States

Retention

Clinical data retrieved from an EHR is held under a 90-day
rolling retention window
per patient and data type. A record’s
timestamp refreshes each time the EHR re-emits it; records not refreshed
within 90 days are deleted by a daily sweep job. AI-derived clinical
summaries follow the same window.

Audio recordings are deleted from the device once uploaded, and
deleted server-side once the resulting documentation has been produced
and confirmed.

When a patient is discharged or a facility off-boards, retained data
for that scope is purged ahead of the normal sweep.

Artificial intelligence

Round Smarter generates documentation using large language models and
speech recognition. Our commitments:

Subprocessors

These third parties may process PHI on Round Smarter’s behalf. All
process PHI within the United States, each under a Business Associate
Agreement.

Subprocessor Purpose Location
Google Cloud Platform Application hosting, database, file storage United States
Google Cloud Vertex AI Large-language-model inference — clinical briefs, SOAP notes, order
extraction
United States
Deepgram Medical speech-to-text transcription of provider dictation United States

PointClickCare and Net Health are
the electronic health record systems we integrate with at a customer’s
direction. They are the customer’s own vendors rather than ours; we
exchange data with them only as the customer instructs.

Incident response

If a security incident affects PHI, Round Smarter notifies the
affected Covered Entity in accordance with the governing BAA and
applicable law. Our standard BAA commits us to notice well inside the
60-day outer limit HIPAA sets for business associates.

To report a suspected vulnerability or security issue, email admin@roundsmarter.com with the
subject line “Security.” We will acknowledge within two business
days.

What we are still building

We would rather tell you this than have you find out in a
questionnaire.

Contact

Email: admin@roundsmarter.com
Mail: RoundSmarter LLC, 330 3rd Street S, Unit 1121,
St. Petersburg, FL 33701


Round Smarter — RoundSmarter LLC Last updated: July 31,
2026