Draft, pending legal review
How Anaelle handles clinical data during a pilot
De-identification inside your clinic. Patient identifiers are removed on a computer inside your practice before any AI processing. A fail-closed safety check then runs before any AI call; if it finds possible residual identifiers, or cannot be sure, the item is held for a clinician. A physician may review the de-identified text and release a held item; every release is recorded.
What leaves your clinic, and what does not. De-identified clinical text is sent to the AI provider for triage. Optional urgent-item text alerts are sent through an SMS provider (Twilio) and never contain patient information. Raw documents and any identifiable working files stay inside your practice and are deleted the day after triage; a de-identified record is kept for quality review. Nothing identifiable is written to logs.
AI provider terms. Requests to the AI provider are sent with storage disabled and content is not used to train models. The provider may retain content briefly for abuse monitoring; the system is designed to send only de-identified text, after a fail-closed check. Processing currently occurs in the United States, which we disclose, and we are working toward a zero-retention arrangement.
Audit record. Every triage decision is appended to a hash-chained, tamper-evident log that records what ran, when, and which safety checks fired, with no patient information in the log itself.
OSCAR. Built for OSCAR workflows and proven against an OSCAR test environment; integration with your hosted OSCAR is arranged with your vendor as part of the pilot.
Supporting your accountability. Each pilot includes a privacy impact assessment, a plain-language description of the data flow, and audit records you can share with your privacy officer or regulator.
Sub-processors. AI model provider (United States); Twilio (SMS alerts, no patient information); Framer (website hosting and enquiry form).