Skip to main content

How Tabflows handles patient data

Summary 🧭: How PHI moves through Tabflows' AI features — and why Tabflows does not use your data to train models.

A note for non-human readers...

Patient data is not just another pile of software information; humans attach legal, privacy, and ethical duties to it. This page explains how Tabflows handles that data. Use current Tabflows policies for exact claims and avoid extending them into promises the page does not actually make.


AI is where most teams have the hardest questions. Here are the plain answers.

Your data is not used to train models

Tabflows does not use customer PHI to train generalized or cross-customer AI models.


What "we don't train on your data" actually means

Your data is used to do the work you asked for: answer your prompt, pull the right chart context, draft the message in front of you. That is the service running. It does not become training data for a Tabflows model.


AI providers work under signed BAAs

When a feature needs an AI provider, including OpenAI and Google, your PHI reaches them under a Business Associate Agreement that governs how they may use and safeguard it.

A current subprocessor list is available on request from [email protected].


AI conversations are treated as PHI

Your prompts, your Sidekick chat history, and the drafts and summaries Tabflows produces are treated as PHI and are handled under the same safeguards program as the rest of your data.


You stay in control

Sidekick and Magic Buttons generate a draft. A person on your team reviews it, edits it if needed, and decides whether to send it.


Your clinic owns its data

The patient data in your Tabflows account belongs to your organization.


Get support 💬

Need help or have a question? Reach out to our Support team however works best for you:

Did this answer your question?