Personal Information Governance Framework
Effective date: February 4, 2026 — Last updated: February 4, 2026
1) Purpose
Present AuraScribe personal-information governance practices and regulatory alignment.
2) Scope
- AuraScribe SaaS application (operations, support, billing).
- Professional account data (physicians, administrators).
- Transient processing of clinical data for transcription/generation.
3) Roles and responsibilities
- Designated Privacy Officer with public contact details.
- Client-side clinical leads for access governance.
- Least-privilege principle for internal access.
4) Security controls
- Encryption, logging, access control, and network segmentation.
- Incident-management process and tracked register.
5) Retention and deletion
- Account deletion based on inactivity policies or on request.
- Transient clinical data purged automatically according to active rules.
Transparency commitment
AuraScribe maintains governance documentation and evolving compliance processes to meet legal and operational requirements.