Voicebrook
Security & Compliance

PHI is sacred. We treat it that way.

VoiceOver PRO® is HIPAA-compliant and HITRUST certified, with all data encrypted in transit and at rest. Voicebrook operates as a HIPAA Business Associate, and the hosted production environment runs in a HITRUST-certified Azure environment. Support is insourced and U.S.-based.

Quick answer

Is Voicebrook HIPAA-compliant and HITRUST certified?

Yes. Voicebrook operates as a HIPAA Business Associate and maintains a documented information security program aligned to the HIPAA Security Rule and NIST control frameworks — covering access control, encryption, logging, vulnerability management, incident response, and AI governance. A Business Associate Agreement is included in our standard Master Services Agreement, and we execute a BAA with any client that requires one. VoiceOver PRO's hosted production environment runs in a HITRUST-certified Azure environment maintained by our hosting provider. Certification artifacts and our full policy set are available under a confidentiality agreement.

  • HIPAA Business Associate
  • BAA available with every client
  • Hosted environment is HITRUST-certified
  • Encrypted in transit and at rest
  • Offline mode keeps users working during an outage

HIPAA Compliant

All data handling, storage, and transmission designed to support HIPAA-compliant use of protected health information.

HITRUST Certified

Certified against the HITRUST CSF framework — the de facto standard for healthcare information security in the U.S.

Microsoft Azure Hosted

The hosted production environment runs in a HITRUST-certified Microsoft Azure environment with enterprise-grade infrastructure controls.

Onshore Support, U.S.-based Team

All implementation, training, professional services, and support are performed by Voicebrook employees in the United States. No outsourced helpdesks, no offshore implementation partners.

Technical safeguards

The controls under the hood

Encryption in transit and at rest
Enabled
Multi-factor authentication
Supported
Role-based access control
Enterprise
Audit logging
Comprehensive
Downtime / offline mode
Built-in
Deployment options

Deploy where it fits your posture

The hosted environment is the standard. On-premises is available for federal and security-restricted environments that require it.

Voicebrook-managed hosted

Standard for most customers

Server-side infrastructure delivered as a managed service from Voicebrook's HITRUST-certified Azure environment. No servers for your IT team to provision, size, or maintain. Customer footprint: desktop client on user workstations + a small (~5 GB) centralized file share for speech profile storage.

On-premises

Federal and security-restricted environments

Voicebrook deploys and operates the platform inside your data center. Used by federal customers and security-restricted environments that require it.

Contracting & procurement

BAA and your paper.

Voicebrook operates as a HIPAA Business Associate. A Business Associate Agreement is included in our standard Master Services Agreement, and we execute a BAA with any client that requires one. If you contract on your own paper, the terms are yours.

For our HITRUST certification artifacts, full policy set, penetration-test summaries, and vendor risk assessment responses, contact our team — these are available under a confidentiality agreement as part of vendor evaluation.

See the hours come back.

30-minute walkthrough with a pathology-informatics specialist: dictating real cases, with your AP/LIS in the loop. You'll see where your time goes today, and where it comes back once Voicebrook clears the friction.

Why this matters: every report that signs out faster is a patient getting their result sooner.