Privacy & confidentiality
Private research support, with boundaries you can inspect.
HiDoctorly is designed for owner-scoped, evidence-bound research work. The application is not a public chat room and does not treat a clinician's private corpus as a shared training resource.
What the product enforces
- Authenticated workspace access and owner-scoped database queries.
- No cross-owner or cross-project synthesis.
- PHI and identifier screening before research intake proceeds.
- Claim-level source binding, audit events and deletion controls.
- When external retrieval is enabled, only a derived search query is sent; private case text and attached documents are not sent.
What this page does not promise
- Absolute security, legal compliance, or suitability for identifiable patient records without an institution-approved assessment.
- That external providers, networks or a user's own device are risk-free.
- That HiDoctorly replaces a privacy officer, security review, clinical governance process, or professional judgment.
Use de-identified material only. Do not enter names, medical record numbers, contact details, dates of birth or other direct identifiers. For institutional use, complete the required threat model, data-processing review, retention policy and access-control assessment before onboarding sensitive work.