Skip to main content
BAA on every plan Patient info flagged for your review Nothing publishes until you approve it Encrypted in transit and at rest Built only for independent medical practices

How patient information is handled.

Your staff record real screens, and real screens have patients on them. Here's exactly what happens to that information, in plain English.

Before you record

You accept our Business Associate Agreement when you create your account, before anything with patient information is recorded.

Two-factor sign-in is required before the first recording. A new account can look around first, but it can't record or upload until two-factor is turned on.

Recording works best in Chrome or Edge on the computers your staff already use. There, privacy blur runs in your browser while you record. If the blur can't start, the recorder tells you, records without it, and flags the recording for full review. If it stops partway, the recorder tells you so you can stop and re-record. Phone uploads work from any modern browser.

Detection

Recordings are scanned for names, dates, record numbers, and contact details. If the scan stops with an error, TrainBase tells you; you can run it again, and for an uploaded file blur areas by hand. A redaction agent also reviews sampled frames and reasons about what is on screen, so it can catch a patient name in a chart header, handwriting on a held-up document, and visible faces.

It is deliberately cautious. It errs toward flagging too much rather than too little, and you clear the extras in review. It is on for every workspace unless an admin turns it off.

Human review

Nothing publishes until someone on your team approves it.

The review step in the editor is where your team confirms or adjusts the flagged regions. Creators submit for admin review; they can't publish on their own.

If the redaction render or its verification scan fails, the video is held in a failed state, not published.

When you publish

Where the redaction agent is on, publishing from the Admin panel's draft editor or review queue runs a final verification scan on the finished video, at moments between the original samples. If it cannot confirm the video is clean, the video is held and you can try again.

The generated transcript goes through an automated scrub for patient identifiers before it is stored. Text your team types into it is saved as typed.

Unedited originals are deleted on a schedule: within about a day if a recording was never saved as a video, and 30 days after it was. The schedule is written into the BAA.

Access

  • Roles: owner, admin, creator, and trainee. Trainees can watch published videos and take quizzes. They cannot open unpublished originals.
  • TrainBase support staff can enter your workspace only when an admin grants access, for 5, 15, 30, or 60 minutes. During that window support can't delete anything in your workspace, change billing or sign-in settings, invite users, or open unredacted recordings. Support can stop a video that is still processing, or bring back a deleted video, which returns it to its earlier status.
  • Your audit log records each grant, each video support plays, each status change support makes, and each change support tried that was refused. Pages support only views, like your user list, aren't logged one by one.
  • Separately, TrainBase's platform administrator account can open any workspace, including original recordings, to operate and secure the service. It doesn't need a grant. Videos it opens are logged in TrainBase's own records, not in your workspace's audit log. It can't publish in your workspace, and if it takes a video down for safety, your admins are emailed.
  • Admins can deactivate a user at any time.
  • Web sessions sign out after 15 minutes of inactivity. The optional browser extension uses its own sign-in, which lasts one shift (8 hours by default) and ends when the person signs out of TrainBase or an admin deactivates them. A trainee's reusable access key, if an admin issues one, has no time limit and lasts until an admin turns it off or deactivates the trainee.
  • Your workspace audit log can be exported as CSV or JSON.

Encryption and legal

Data is encrypted in transit and at rest.

Read the Business Associate Agreement and the list of subprocessors.

What we don't claim

There is no such thing as being "HIPAA certified", and we don't say it. TrainBase provides tools that support HIPAA compliance. Compliance is a shared responsibility: record as little patient information as you can, and review every video before it publishes.

See it on a sample practice, with no patient information anywhere.

Start free Free for 14 days. No card needed.