Security & compliance
Last updated 30 September 2026
Separation between organizations
Every record belongs to one organization, and every query is filtered by it before it reaches the database — a query that forgets to say which organization returns nothing rather than everything. Files are stored under a path that begins with the organization's identifier. Within an organization, members see their own meetings and administrators see all of them.
Signing in
There are no passwords to steal. A new account proves a mobile number once by SMS; after that you sign in with a single-use link that expires in fifteen minutes. Only the hash of a link is stored, never the link itself. Every request re-checks that the account is still active, still belongs to its organization, and has not been suspended — so removing someone takes effect at once, not at their next sign-in.
Sharing notes
Documents are emailed as links, one per recipient, each unguessable and each with an expiry date you control. Links can be revoked at any time, and a revoked link stops working immediately. Opening one is recorded, so you can see whether it was used.
Where it is kept
Recordings and documents are stored in Microsoft Azure Blob Storage, and the rest in Azure SQL. Both are encrypted at rest by the platform, and everything travels over TLS. Access to production is limited to IT Healthcare Consulting staff who need it.
Deletion
Retention is set per organization. When a meeting's period ends — or when you delete it — its audio, transcript, analysis, documents and delivery links are removed, and what remains is a record that something was there and when it went.
HIPAA
A recording of a clinical conversation is protected health information, and so is the transcript and everything built from it. No software is "HIPAA certified" — there is no such certificate. What exists is an arrangement between a covered entity and its business associates, and controls that support it. Core Meetings is built to sit inside that arrangement.
What the product already does
- Separates every organization's data and fails closed if a query forgets to say which organization it is for.
- Encrypts data in transit and at rest, in Microsoft Azure.
- Limits access inside an organization: members see their own meetings, administrators see all of them.
- Records who asked for a delivery, who received it, and when each link was opened.
- Deletes recordings, transcripts, analyses and documents when the retention period ends, and lets you delete a meeting or revoke its links immediately.
- Never uses your recordings or transcripts to train models.
What has to be in place before PHI goes in
- A signed business associate agreement between your organization and IT Healthcare Consulting.
- Only transcription and analysis providers covered by a business associate agreement enabled for your account. Ask us which are covered before you switch one on — the provider chain is configurable per organization, and an uncovered provider must not be used with PHI.
- Email delivery used with care. Meeting titles travel in the subject line and the body of the emails we send, so a title should not name a patient or a condition; the documents themselves are behind expiring links rather than attached.
- A retention period your organization can defend, and the discipline of deleting what is no longer needed.
- Your own side of HIPAA: workforce training, access reviews, incident response, and telling people they are being recorded.
Written questions about business associate agreements, subprocessors or where data sits: info@ithcc.com.
Reporting a problem
If you believe you have found a security issue, write to info@ithcc.com with enough detail to reproduce it. We would rather hear about it early, and we will not pursue anyone who reports one in good faith.
