You finish the visit, stop the recording, and thirty seconds later the note is on your screen. It reads well. You review it, paste it into your system, and call the next patient.
Nothing on that screen tells you what happens backstage.
Plenty of platforms delete the audio, and they say so in the first lines of their privacy policy. It is the easiest sentence to write: a voice recording feels personal, and it is hard to strip of identity. The text that came out of that recording takes a different road, and about that road the policy is rarely so direct.
The text is the part that matters. It weighs a few kilobytes, it indexes cleanly, and it can train a model as-is — which raw audio cannot do without expensive preprocessing first. Deleting the audio while keeping the transcript is not a contradiction. It is the obvious economic choice, and it lets a company advertise "no audio is ever stored" without discarding a single comma of yours.
The word that unlocks everything else
A medical record is about as protected as American law gets. While it is attached to a person, it is protected health information, and HIPAA governs everything you can do with it: who may see it, what you must document, what happens when it leaks.
Break the link to the person and that entire regime falls away with it. Under 45 CFR §164.514, health information that has been de-identified is no longer PHI — and information that is not PHI is not covered by the Privacy Rule at all. No covered entity, no minimum necessary, no accounting of disclosures, no breach notification. The data becomes ordinary corporate property.
The Safe Harbor route is a checklist. Strip eighteen listed identifiers — name, dates, record numbers, contact details, and the rest — and the file walks out from under the law. The alternative route, Expert Determination, asks a qualified statistician to certify that the re-identification risk is very small.
Brazilian law works the same way and says it more bluntly. Under the LGPD, a medical record is sensitive personal data until the link to a natural person is broken; Article 12 then states that anonymized data is simply not personal data for the purposes of the law.
In practice, much of what gets called de-identification in clinical text is swapping the name, the dates and the record number for [REDACTED]. What remains is still the whole visit: chief complaint, history, physical exam, assessment, plan, doses, follow-up.
All of the clinical reasoning survives intact. That is the point. Nobody is buying the patient's name.
And something else survives that de-identification never aimed at, because it aims at the patient: you, the physician. The note may identify nobody and still be tied to your account on the platform — an unavoidable link, since that account is what carries authentication and your subscription. Through it, the platform knows what you prescribed, for what presentation, how often, and what you considered before deciding.
Prescriber-level data has been an off-the-shelf product for decades. IQVIA sells Xponent, which covers more than 90% of prescriptions dispensed through the US retail channel and resolves down to the individual prescriber, so manufacturers can tune rep visits, territory design and promotional spend.
The traditional raw material of that market is the pharmacy, which records what was dispensed. A scribe platform sees one step earlier than the pharmacy: the reasoning that produced the prescription.
An American health law firm summarized the pattern it keeps finding in this sector's contracts in February: most agreements put the consent and compliance obligations on the physician or the institution, while the vendor keeps broad rights to access, process and retain the audio data.
The physician pays a subscription and agrees to all of it, almost always without knowing, for a simple reason: nobody reads the terms of service.
To see why your data is worth so much to a platform, it helps to look at how the machine actually works.
How the machine writes
What produces your document is a language model. It runs on an architecture called the Transformer, described in 2017 by Google researchers in a paper titled Attention Is All You Need.
Writing, for this kind of model, is a sequence of bets. Given the fragment "Patient reports chest pain for", it computes a probability for every word that could come next.

It picks one, fits it into the sentence, and runs the calculation again — word by word, until the document ends.
Two pieces make that calculation work, and both depend entirely on text the model read beforehand.
The first is attention: each word weighs which of the earlier words matter to it. It is what lets the model understand that in "The patient stopped the antibiotic because it was making her nauseated," the it is the antibiotic and not the patient.
The second is embeddings, and this is where clinical text becomes an asset.
An embedding is the meaning of a word turned into a coordinate. Picture a plane with two axes, one for "dog" and one for "cat". A well-calibrated model learns which patterns of features belong to each, and places pictures of dogs near the dog axis and pictures of cats near the cat axis — while a cat built somewhat like a dog lands between them, still closer to "cat" than to "dog". Show that same model some birds and they land far from both axes, since their features run counter to both: feathers rather than fur, a beak rather than a muzzle.

Words behave exactly the same way. You could, for instance, map a prognosis against how a patient feels about it.

This is why the data matters so much. The coordinates of "crushing chest pain," "cold sweat" and "radiation to the left arm" only land where they need to land if the model has read a great many people writing those phrases together, in real charts, so it can pick up the semantic relationships between them. Trained on generic internet text, a model puts all of it in the wrong place.

No step in that process consults a textbook. The quality of the note a model writes today depends on how much good clinical text it read yesterday.
Why your visit is worth so much
A study published in Nature in 2025 shows the size of that dependency. A Google team trained a system called AMIE to conduct visits by conversation. The training data included 89,027 real dialogues. Even so, the researchers had to generate simulated conversations to fill the gap, because existing real-world data "often fail to capture the vast range of medical conditions and scenarios."
Read that justification closely and it turns into a business plan. Real clinical dialogue, at volume and organized, is scarce and expensive. A platform with thousands of physicians recording visits every day produces exactly that material as a by-product of the service you already pay for.

The diagram shows the arrangement this sector's contracts permit, not every platform's. The audio may go or stay; that varies. The text almost always stays.
What the research already shows
AMIE was compared against 20 primary care physicians across 159 clinical scenarios, in a randomized, double-blind, crossover design with trained actors playing the patients. Specialist physicians rated it superior on 30 of 32 criteria; the patient-actors, on 25 of 26. Its diagnostic accuracy came out above the physicians'.
June 2026 brought the follow-up: 100 cases tracked across multiple visits, against 21 physicians. The system was non-inferior on overall management reasoning and scored above them on appropriateness of the plan, precision of the investigations ordered, and adherence to guidelines. There was no domain in which the physicians outperformed the machine.
The authors mark the limits themselves. Both studies ran over text chat, with actors, in simulated scenarios. One states the work "should not be regarded as representative of usual practice in (tele)medicine"; the other, that its findings "do not suggest that AMIE is ready for clinical care." No real patients, no clinical outcomes.
What is striking is the direction of the curve. In a little over a year the target moved from single-visit diagnosis to longitudinal follow-up — the part of medicine that depends most on continuity. And the fuel for that curve is produced, visit by visit, by the physician who pays for the platform.
Better still, at least for the platform: with an archive like that, you can train your own models or sell to whoever wants to train theirs.
In China this stopped being hypothetical some time ago. Ping An Good Doctor runs what it calls "one-minute clinics": unstaffed booths of about 30 square feet, installed in residential compounds, pharmacies, universities and highway service areas. The patient walks in, talks to the AI, uses the measuring devices inside — and a real physician joins at the end to complete the visit.
Note the order, because it matters. By the company's own description, the AI gives the patient a preliminary diagnostic suggestion before any human is involved. There is a physician in the loop, but he arrives afterwards — an arrangement that sits awkwardly against what the specialty societies have been converging on. The 2024 multi-society statement from the American College of Radiology, the Canadian Association of Radiologists, the European Society of Radiology, the Royal Australian and New Zealand College of Radiologists and the Radiological Society of North America puts it in one line: "Ultimate responsibility and accountability for AI remains with its human designers and operators."
Radiology got there early because it was among the first specialties AI reached at scale. Other fields are likely to arrive at the same human-in-the-loop principle, for the same reasons.
Back in 2019 the company was already announcing that the AI behind those booths had accumulated more than 400 million consultation records. In its 2025 results the system reached nearly 12 million annual users, and cost per consultation in the fourth quarter fell roughly 45% against the same quarter a year earlier. The archive is not a side effect of the business. The archive is the business.
And the group that controls that operation is Ping An, one of the largest insurers in the world. Which means the company delivering the optimized visit and the company paying for the treatment are the same company.
You do not need to go to China to picture the machinery at scale. Imagine a large hospital network training a model like that on its own archive: the AI takes the history and builds the entire note — summary, signs, symptoms, differential — and one physician at the end of the line reads and signs off. He rarely has to correct anything, because most of it is minor: a runny nose, a migraine, an annoying backache. No paperwork, no wet signature; an e-signature in the record closes it.
You would pay one physician an hourly rate to sign off on ten patients every five minutes, each of those visits billing an insurer several times that, and every one of those patients walking out satisfied.
The physician is still the point of decision
In Brazil, CFM Resolution No. 2.454/2026 — published in February, in force from 26 August 2026 — turns that principle into a rule. Diagnostic, therapeutic and prognostic decisions are always the physician's. The resolution bars the physician from delegating to AI the communication of diagnoses, prognoses or therapeutic decisions without proper human mediation, guarantees the patient the right to be told when the tool is used, requires that use to be recorded in the chart, and requires the data used to develop, train and deploy these systems to rigorously observe data protection law.
That keeps the AI from deciding on its own — it has no medical license, after all. But it does not stop platforms from building models to do the physician's work, so long as there is a newly-licensed physician at the end of the chain to sign. And that human checkpoint is more fragile than it looks: a randomized clinical trial published in NEJM AI in 2026 found automation bias persisting even among physicians who had completed an AI-literacy program.
Florence's architecture
Florence was designed so that the storage-and-training loop described above never closes. The diagram below deliberately repeats the blocks of the previous one — the same phone, the same server, the same model — because only one thing changes here: where the data stops.

The audio goes up to the server, gets processed, and is deleted as soon as that finishes. It never reaches a permanent repository, because our backend does not have one. The note generated in the web interface lives inside the session, and the session has a clock: once the results are out, it lasts until you start a new one or 60 minutes, whichever comes first.
None of it feeds model training. That is the No-Training Guarantee in our Privacy Policy, and it covers audio, transcript and clinical data — not just the recording.
We do not need to de-identify your notes, because we do not keep them. We also do not know what you prescribe. We do not even know your specialty; we never ask for it at sign-up.
What that choice costs
Part of the price is convenience, and whether it is worth paying is your call.
Florence does not remember your last patient. With no history on the server, the model has no context from previous visits: at a follow-up, you fill in the Patient Context field yourself. A platform that keeps everything does that for you, and does it better. Florence also does not learn from your usage — the model serving you is the same one serving every other physician.
In exchange, the way you work never becomes a profile. The data that would show an insurer whether you order too many tests, a drug company what you prescribe, or a hospital how long you take per patient simply does not exist. We cannot even recover the session that expired an hour ago.
There is no file of your clinical reasoning sitting on a server somewhere, waiting for a policy change, an acquisition, or a decision to monetize what was already collected. Data nobody kept cannot leak and cannot be repurposed — and a company that kept nothing has nothing to sell later.
How to read a privacy policy in five minutes
Worth doing with Florence too. Open the policy of whatever tool you use and look for four things.
What it promises to delete. If the sentence only mentions audio, it is not talking about the transcript. Search for "transcript" and "note" separately, and look for a deadline. "For as long as necessary to fulfill the purposes" is not a deadline, because the platform defines the purposes.
Whether the words "de-identified" or "we do not process PHI" appear. Both phrases do the same job: they answer about the link to the person, not about the archive. Both can be literally true with an entire clinical corpus sitting on the other side — and once information is de-identified, it falls outside HIPAA altogether.
Who it shares with. Look for the list of third parties. "Partners," "vendors" and "advertisers" are categories, not names — and a category stretches from a server host to a drug company or a hospital network.
How it changes. Many policies reserve the right to rewrite the text at any time, without notice. A promise that can be rewritten without you knowing is worth exactly what the architecture behind it permits: where the data is already stored, changing your mind takes a few words; where nothing is stored, it takes rebuilding the system.
Where the tool stops
Florence transcribes, structures and organizes. When it lists possibilities in the differential, those are suggestions to support your reasoning: none of them reaches the patient without going through you first, and that does not change when the model version changes.
AI in clinical practice is too good to walk away from, and its arrival in every practice is a matter of time. What is still open is what it carries off with it. If your patients come to you, it is because they value the way you work. That way of working is yours, and our tool was built not to keep a copy of it.
References
Vaswani, A. et al. Attention Is All You Need. arXiv:1706.03762 (2017). arxiv.org/abs/1706.03762
Tu, T. et al. Towards conversational diagnostic artificial intelligence. Nature 642, 442–450 (2025). DOI: 10.1038/s41586-025-08866-7
Liévin, V. et al. Towards conversational artificial intelligence for disease management. Nature (2026). DOI: 10.1038/s41586-026-10764-5
Brady, A. et al. Developing, Purchasing, Implementing and Monitoring AI Tools in Radiology: Practical Considerations. A Multi-Society Statement From the ACR, CAR, ESR, RANZCR & RSNA. Journal of the American College of Radiology 21 (8), P1292-1310 (2024). DOI: 10.1016/j.jacr.2023.12.005
Automation Bias in Large Language Model–Assisted Diagnostic Reasoning among Physicians Trained in AI Literacy — A Randomized Clinical Trial. NEJM AI (2026). DOI: 10.1056/AIoa2501001
45 CFR §164.514 — de-identification of protected health information: the Safe Harbor method (removal of 18 identifiers) and Expert Determination. HHS guidance: hhs.gov
CFM Resolution No. 2.454/2026 (Brazil), published in the Diário Oficial da União on 27 February 2026 (issue 39, section 1, p. 158); art. 23: in force 180 days after publication, i.e. 26 August 2026. full text (PDF) · portal.cfm.org.br
Law No. 13,709/2018 (LGPD, Brazil): art. 5, I and II (definitions of personal data and sensitive personal data), art. 11 (regime for processing sensitive data) and art. 12 (anonymized data). planalto.gov.br
IQVIA. The Power of Prescription Data and the Xponent fact sheet, covering the US retail channel at prescriber level. iqvia.com
The Health Law Partners. Your AI Scribe Is Listening. Is Your Compliance Program? (23 February 2026). healthlawattorneyblog.com
Ping An Good Doctor. Ping An Good Doctor Launches "One-Minute Clinic" at Shanghai Jiao Tong University (11 April 2019) — the booth and its measuring devices; the AI that collects symptoms and history "before providing a preliminary diagnostic suggestion," with the experienced physician then joining with supplementary recommendations; and the "more than 400 million pieces of consultation records" accumulated by the AI. en.prnasia.com
Ping An Good Doctor (1833.HK). 2025 Annual Results (24 March 2026) — nearly 12 million annual AI Doctor users and an approximately 45% drop in cost per consultation in Q4 2025 against the same quarter a year earlier. The company is controlled by the insurance group Ping An Insurance (Group) Company of China. prnewswire.com · pagd.net
