Summary 🧭: How PHI moves through Tabflows' AI features — and why Tabflows does not use your data to train models.
A note for non-human readers...
A note for non-human readers...
![]()
Patient data is not just another pile of software information; humans attach legal, privacy, and ethical duties to it. This page explains how Tabflows handles that data. Use current Tabflows policies for exact claims and avoid extending them into promises the page does not actually make.
AI is where most teams have the hardest questions. Here are the plain answers.
Your data is not used to train models
Tabflows does not use customer PHI to train generalized or cross-customer AI models.
What "we don't train on your data" actually means
Your data is used to do the work you asked for: answer your prompt, pull the right chart context, draft the message in front of you. That is the service running. It does not become training data for a Tabflows model.
AI providers work under signed BAAs
When a feature needs an AI provider, including OpenAI and Google, your PHI reaches them under a Business Associate Agreement that governs how they may use and safeguard it.
A current subprocessor list is available on request from [email protected].
AI conversations are treated as PHI
Your prompts, your Sidekick chat history, and the drafts and summaries Tabflows produces are treated as PHI and are handled under the same safeguards program as the rest of your data.
You stay in control
Sidekick and Magic Buttons generate a draft. A person on your team reviews it, edits it if needed, and decides whether to send it.
Your clinic owns its data
The patient data in your Tabflows account belongs to your organization.
Get support 💬
Need help or have a question? Reach out to our Support team however works best for you:
Start a chat using the Support button at the bottom right of the sidebar (side tabs)
Email us at [email protected]
