Last updated: July 31, 2026
Round Smarter handles protected health information on behalf of the
physician practices and facilities that use our platform. This page
states plainly how we protect it, who we share it with, and what we will
and will not do with it. If you are evaluating Round Smarter and need
something not covered here, email admin@roundsmarter.com.
HIPAA
Round Smarter is a Business Associate under HIPAA.
We do not have a direct treatment relationship with patients. We process
PHI only on behalf of the healthcare organizations that contract with
us, and only as their written Business Associate Agreement permits.
We will sign a BAA with every customer before any PHI is
exchanged. To request our standard BAA, email admin@roundsmarter.com with the
subject line “BAA.”
Full detail on what we process and why is in our Privacy Statement.
How data is protected
| Encryption in transit | TLS 1.2 or higher for all connections |
| Encryption at rest | AES-256 |
| EHR connectivity | All API traffic between Round Smarter and PointClickCare requires mutual TLS with a client certificate |
| Access control | Authenticated providers only, scoped to the facilities they are assigned to |
| Audit logging | We log read access to PHI |
| Hosting | Google Cloud Platform, United States regions |
| Data residency | All PHI is stored and processed in the United States |
Retention
Clinical data retrieved from an EHR is held under a 90-day
rolling retention window per patient and data type. A record’s
timestamp refreshes each time the EHR re-emits it; records not refreshed
within 90 days are deleted by a daily sweep job. AI-derived clinical
summaries follow the same window.
Audio recordings are deleted from the device once uploaded, and
deleted server-side once the resulting documentation has been produced
and confirmed.
When a patient is discharged or a facility off-boards, retained data
for that scope is purged ahead of the normal sweep.
Artificial intelligence
Round Smarter generates documentation using large language models and
speech recognition. Our commitments:
- We do not train models on PHI. Protected health
information is never used to train, retrain, or fine-tune any AI or
machine-learning model. - Our AI subprocessors do not train on your data.
Content we send them is used only to return a result to us, and is not
retained beyond the request. - We do use de-identified data to develop our products and AI
systems. Round Smarter de-identifies data to the HIPAA standard
at 45 C.F.R. § 164.514(b) and uses the result to
operate, analyze, improve, and develop its products, services, and AI
systems, and for quality monitoring — as the governing BAA permits. Data
de-identified to that standard is no longer PHI under HIPAA. We never
externally release anything that identifies any individual. We are happy
to walk your privacy officer through our de-identification method on
request. - Every output is a draft. Notes, briefs, summaries,
transcriptions, and order suggestions are unverified drafts. A licensed
provider must review and approve them before they enter the medical
record or are acted on. Round Smarter does not practice medicine and
does not make clinical decisions. - We disclose our model providers. See the
subprocessor list below. We notify customers before adding a new
subprocessor that will process PHI.
Subprocessors
These third parties may process PHI on Round Smarter’s behalf. All
process PHI within the United States, each under a Business Associate
Agreement.
| Subprocessor | Purpose | Location |
|---|---|---|
| Google Cloud Platform | Application hosting, database, file storage | United States |
| Google Cloud Vertex AI | Large-language-model inference — clinical briefs, SOAP notes, order extraction |
United States |
| Deepgram | Medical speech-to-text transcription of provider dictation | United States |
PointClickCare and Net Health are
the electronic health record systems we integrate with at a customer’s
direction. They are the customer’s own vendors rather than ours; we
exchange data with them only as the customer instructs.
Incident response
If a security incident affects PHI, Round Smarter notifies the
affected Covered Entity in accordance with the governing BAA and
applicable law. Our standard BAA commits us to notice well inside the
60-day outer limit HIPAA sets for business associates.
To report a suspected vulnerability or security issue, email admin@roundsmarter.com with the
subject line “Security.” We will acknowledge within two business
days.
What we are still building
We would rather tell you this than have you find out in a
questionnaire.
- SOC 2 Type II — not yet obtained. On our
roadmap. - HITRUST — not obtained. We do not currently sell to
health plans or large hospital systems, which are the buyers that
typically require it.
Contact
Email: admin@roundsmarter.com
Mail: RoundSmarter LLC, 330 3rd Street S, Unit 1121,
St. Petersburg, FL 33701
Round Smarter — RoundSmarter LLC Last updated: July 31,
2026