Observer Medical by Golden Observer

HIPAA and Security

Updated September 25, 2026 · Golden Observer LLC

Observer Medical keeps what it records on a device inside the clinic. This page explains how that fits the HIPAA Privacy, Security and Breach Notification Rules (45 CFR Parts 160 and 164), what we commit to, and what stays the clinic's responsibility. It is a summary for practice managers and privacy officers, not legal advice.

Who is who under HIPAA

What we commit to in the BAA

The clinic can ask for the full BAA at any time before signing anything.

How the device protects patient information

LocationAudio, transcripts and reports stay on the device in the clinic. Nothing it records is sent to us or to any cloud service.
Our accessNone. We cannot see or hear what the device records.
Access controlOnly staff the clinic chooses, behind a PIN. The screen locks itself when nobody is using it.
Audit recordEvery view, setting change and update is recorded on the device for the clinic's privacy officer.
RetentionThe clinic sets how long recordings are kept and can delete them at any time.
PatientsThe device recognises enrolled staff by voice. It never builds a voice profile of a patient or tries to identify one.
Patient roomsThe patient-room setting keeps no words and no pictures.
End of serviceThe device is erased and a certificate of erasure is given to the clinic.

What the clinic does

Documents we provide

Reporting a concern

To report a suspected security incident, or to ask for any document above, write to [email protected]. Please describe the concern without including patient information.

Observer Medical is an operations tool. It is not a medical device, is not used for diagnosis or treatment, and is not part of any patient's medical record.