Privacy Policy
This policy explains what information MLS collects through the MLS web application and the MLS Assist browser extension, how we use and protect it, and the choices available to the clinicians and practices who use our service.
Contents
- Who we are
- Information we collect
- How we use information
- Single purpose & limited use
- How information is shared
- Service providers / subprocessors
- HIPAA & Business Associate context
- Data retention
- Security
- The MLS Assist extension
- Your rights & choices
- Children's privacy
- Changes to this policy
- Contact us
1. Who we are
MLS is an ambient AI medical-scribe product candidate operated by MLS Scribe LLC ("MLS," "we," "us," or "our"). MLS is being built for spine, pain-management, and physical-medicine & rehabilitation (PM&R) practices. Its web application (at mlsscribe.com) and MLS Assist browser extension support HIPAA-compliant production use for authorized accounts under executed account agreements; a synthetic local demo also remains available. They are designed to help a clinician capture a visit, draft a structured clinical note, suggest coding for review, and place an approved note into the clinician's electronic medical record (EMR).
2. Information we collect
The current release may process synthetic information entered by an evaluator, limited account/session data, and the technical data needed to run the evaluation. Do not enter real patient information. The categories below describe both the current evaluation and the intended clinical workflow, which will remain unavailable until the clinical release gate is satisfied.
Health and visit information
In the synthetic evaluation, MLS can process test audio, transcripts, dictation, highlighted text, and fictional chart content supplied by the evaluator. The intended clinical workflow would process corresponding visit and chart information on behalf of a practice, but that workflow is not released and the current build does not authorize submission of protected health information (PHI).
Patient and clinician identifiers
MLS may process clinician evaluation-account details such as name, email address, practice or specialty, and role. Synthetic patients must use fictional or de-identified labels. Real patient names, dates of birth, MRNs, and other patient identifiers are not authorized in this release.
Authentication information
To connect securely to the MLS backend, the service uses your MLS login session. The MLS Assist extension reads your existing MLS authentication token (a session token) from an open, signed-in MLS browser tab and sends it to the MLS backend as a bearer credential so the backend can confirm the request is yours. A practice may instead configure an MLS API key. These credentials authenticate you to MLS only; they are not shared with your EMR vendor or any other third party.
In the current evaluation build, the MLS bearer token may be stored in that browser's session storage and local storage so the signed-in tab and clinician-started extension action can use the same session. Supported logout clears the token. Do not use the evaluation on a shared or untrusted device. A production clinical release requires a separately verified session design and is not represented as active here.
Website and session content
When you actively use the MLS Assist panel on a web page (for example, your EMR), the extension reads content from that page — such as visible text, the structure of on-screen fields, and, for the supervised "autopilot" feature, a screenshot of the page — so it can place a note in the correct field or help you navigate. This content is processed to perform the action you requested. The extension stays dormant until you open its panel; it does not silently read pages in the background outside the features you invoke.
Account, billing, and support information
Self-service subscriptions and checkout are not enabled in this release. If billing is activated later, the payment processor—not MLS—will handle full card numbers. If you contact us for support or request an evaluation, we may keep the contact and message information you provide so we can respond; do not include PHI in support or sales messages.
Limited technical and security information
We may process basic technical information necessary to operate and secure the evaluation, such as request logs, error reports, and security events. The local synthetic demo also stores its settings and synthetic records in that browser as described under Data retention and Security below.
3. How we use information
We use the information described above only to provide and support MLS. The product is designed to:
- transcribe captured audio and generate draft clinical notes, suggested coding, and related documentation for the clinician to review, edit, and sign;
- place an approved note into the clinician's EMR and, when requested, read chart information into the clinician's MLS record;
- authenticate users, maintain sessions, and keep the service secure;
- support evaluation accounts and respond to support requests; and
- maintain, troubleshoot, and improve reliability.
MLS produces draft documentation and coding suggestions for a clinician's independent review. It does not practice medicine, and the clinician remains responsible for the content of the medical record.
4. Single purpose & limited use
The single purpose of MLS and the MLS Assist extension is clinical documentation and coding support — helping a clinician create, review, and file medical notes. We do not use the data we process for any unrelated purpose. In particular:
- We do not sell or rent personal information or health information to anyone.
- We do not use or transfer the information for advertising, and we do not build advertising or marketing profiles from it.
- We do not use or transfer the information to determine creditworthiness or for lending purposes.
- Real health or visit content is not authorized in this release. Do not send PHI through support, sales, or evaluation channels.
5. How information is shared
We share information only as needed to run the service and as described here:
- With your evaluation account. Synthetic information may be available to authorized users of the same evaluation environment, according to the roles configured there.
- With service providers (subprocessors). We use a small set of vendors to provide core functions such as AI generation, hosting, and email. They may process information needed for the requested function under their applicable terms. Production contract and BAA status must be separately verified before any clinical release. See the next section.
- For legal and safety reasons. We may disclose information if required by law, to respond to lawful requests, to enforce our agreements, or to protect the rights, safety, and security of users, the public, or MLS.
- In a business transfer. If MLS is involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction, subject to this policy.
We do not share your information with EMR vendors except to carry out the action you direct — for example, when you approve placing a note into your own EMR session.
6. Service providers / subprocessors
MLS relies on the following categories of providers during development and synthetic evaluation. This public policy does not attest that vendor BAAs, zero-retention terms, or regulated-production configurations are currently executed or enabled. Real patient information is not authorized in this release.
| Provider | Role | What it processes |
|---|---|---|
| OpenAI | AI model provider used to transcribe audio and generate draft notes and coding suggestions | The transcript / text the clinician submits for a given generation request |
| Render | Cloud hosting for the MLS backend | Data stored and processed by the MLS application |
| Stripe | Planned payment processing; checkout is disabled in this release | No evaluation health content; payment processing is not active in the current public flow |
| Resend | Transactional email delivery | Email address and message content for service emails |
| Twilio | Planned optional phone workflow; not published in this release | No current public phone-dictation flow |
When an evaluator explicitly requests AI generation, OpenAI processes the synthetic transcript or text sent for that request. Hosted mode is designed to use a server-held key. The local synthetic demo also offers an optional per-device mode: the evaluator's OpenAI API key is stored in that browser's local storage and is sent directly from that browser to OpenAI. That mode must never be used with PHI. Vendor-contract and production- configuration evidence must be verified separately before any clinical release.
7. HIPAA & Business Associate context
Processing protected health information on behalf of a covered entity can create Business Associate obligations. MLS Scribe supports HIPAA-compliant production use for authorized accounts under executed account agreements. This policy does not itself create or execute a Business Associate Agreement — a BAA is executed with the practice during account onboarding where required.
8. Data retention
The local synthetic demo keeps its synthetic patients, notes, preferences, and optional per-device OpenAI key in browser storage until the evaluator clears local data, signs out where the flow performs that cleanup, or clears the browser's site data. This browser storage is not a hosted clinical record system and is not an encrypted backup. Limited hosted evaluation-account, support, request-log, and security data may be retained as needed to operate and secure the evaluation. Hosted clinical-record persistence and backup retention are not released and are not represented by this policy as active.
9. Security
Controls verified for the current synthetic-evaluation boundary include:
- Encryption in transit using HTTPS/TLS for connections between the web app, the extension, and the MLS backend.
- Release gating: hosted PHI routes fail closed unless the server verifies the exact clinical-release configuration and exact user grant.
- Authentication controls in the evaluated backend include hashed passwords and signed session tokens; optional two-factor authentication is available for evaluation.
- Exact-origin controls restrict authenticated extension requests to the approved MLS backend origin.
- Browser cleanup controls remove scoped local records during supported logout/clear-data actions and scrub sensitive route tokens from the address bar where those routes are used.
The local synthetic demo's browser storage is readable/compressed application storage, not AES-encrypted storage. Hosted mode is designed to keep the MLS AI-provider key on the backend; the optional local-demo key mode is the disclosed exception above. These limitations are why real patient information remains prohibited.
No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security. We encourage practices to keep their own credentials confidential and to use available security features.
10. The MLS Assist browser extension
MLS Assist is a companion browser extension that helps a clinician move a drafted note into their EMR. A few points specific to the extension:
- Consent-first. The extension stays dormant as a small badge until the clinician opens its panel. It acts only on features the clinician invokes.
- What it reads. When invoked, it may read the content and structure of the current page (and, for supervised autopilot, a screenshot) to capture a visit, structure chart information, or place a note in the correct field.
- Where data goes. The extension's only authenticated network calls go to the MLS backend. It does not send your data to your EMR vendor's servers; its interaction with the EMR happens within your own already-signed-in EMR browser session, under your direction.
- You stay in control of the record. The extension is designed not to finalize the medical record on its own — it pauses before steps such as Save or Sign and hands those decisions back to the clinician unless the clinician explicitly chooses to supervise such a step.
- Permissions. The extension requests browser permissions (such as access to page content and tabs) solely to perform the documentation features described above, consistent with its single purpose.
11. Your rights & choices
Because MLS processes most personal and health information on behalf of a practice, patients who wish to access, correct, or delete their health information should contact the clinician or practice that maintains their record; that practice directs how the information in MLS is handled. Clinicians and practices can access, update, export, or request deletion of information in their MLS account, and can contact us for assistance. Depending on where you live, you may have additional rights under applicable privacy laws; we will honor valid requests as required by law. You can stop the extension's processing at any time by closing its panel, signing out, or removing the extension.
12. Children's privacy
MLS is a professional tool for clinicians and is not directed to children, and we do not knowingly allow children to create accounts. To the extent a clinician documents care for a minor patient, that information is handled the same way as other patient health information described in this policy and remains under the responsible practice's control.
13. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above and, where appropriate, provide additional notice. Continued use of MLS after an update means you accept the revised policy.
14. Contact us
If you have questions about this policy or about how MLS handles information, contact:
MLS Scribe LLC
Email: michael@mlsscribe.com
Web: mlsscribe.com