Skip to main content

Privacy & Safety

Your Data is Read-Only​

ChartChat can only read your health records. It cannot add, change, or delete anything in your medical records at your doctor's office or hospital. Your records at the source remain completely unchanged.


Who Can See Your Records​

Only you can see your health records in ChartChat. ChartChat does not share your health information with any third parties. Your data is used solely to display your records to you and to power the Chat Assistant's explanations.


How Your Records Are Protected​

  • All data travels over a secure, encrypted connection.
  • ChartChat is designed to meet HIPAA standards for handling health information.
  • You must sign in with a verified account to access any records.
  • Access to each connected hospital is granted only after you personally log in and approve it on that hospital's own login page.
  • All sign-in forms are protected by security checks to prevent automated access.

How the AI Uses Your Data​

The ChartChat AI Assistant only reads data already present in your chart. It does not:

  • Store your conversations permanently after the session ends
  • Share your health data with outside services
  • Use your records to train or improve AI models
  • Provide your information to any third parties

The AI only ever sees the specific records needed to answer your current question.


Audit Log​

Every time your health data is accessed within ChartChat, it is logged. You can view this log at any time by going to Settings → Privacy & Security → View Audit Log. This gives you full visibility into your data activity.


Session Timeout​

To protect your account if you forget to log out, ChartChat automatically signs you out after a period of inactivity. You can set this duration in Settings → Privacy & Security → Session Timeout.

OptionBest for
15 minutesShared or public computers
30 minutesWork computers
60 minutesPersonal devices (default)
4 hoursPersonal devices you use frequently

If you are using a shared or public computer, we recommend setting Session Timeout to 15 minutes and always clicking Log Out when you are finished.


Two-Factor Authentication (2FA)​

Two-factor authentication adds a second layer of protection to your account. Even if someone obtains your password, they cannot sign in without the one-time code from your authenticator app.

We strongly recommend enabling 2FA. Go to Settings → Privacy & Security → Two-Factor Authentication → Enable 2FA.


Disconnecting a Hospital​

You can remove any connected hospital from your account at any time in Settings → Hospital Connections → Disconnect. After disconnecting:

  • ChartChat will no longer receive new data from that hospital
  • Records already synced remain visible in the portal
  • This does not affect your records at the hospital — it only removes ChartChat's access

Deleting Your Account​

To request full deletion of your ChartChat account and all associated data, contact ChartChat support. Note that records in your doctor's own systems are not affected — ChartChat only holds a copy of the data that was synced during your connected sessions.


Questions or Concerns​

If you have any privacy concerns or believe your account has been accessed without your permission:

  1. Change your password immediately via Settings → Privacy & Security → Send Reset Link
  2. Disable 2FA and re-enroll to invalidate any existing authenticator sessions
  3. Disconnect all hospitals and reconnect them after securing your account
  4. Contact ChartChat support to report the incident

Compliance​

StandardStatus
HIPAACompliant
Encrypted ConnectionTLS 1.2+
Secure AuthorizationSMART on FHIR
Access to Your DataRead-Only