Security & data handling

Engineered to know less.

Marea is built to keep the minimum patient data we need to do the work. Audio is never stored. Your PMS chart is never replicated. The artifacts we do retain are encrypted, auditable, and yours to delete on request.

The principle

The less we store, the less can leak.

Three rules shape how Marea handles your data:

  • Audio is never stored. Calls and operatory recordings are transcribed in memory and discarded the moment the work is done.

  • Your PMS chart is never replicated. We pull what we need in real time and write outcomes back. The full chart never leaves your system.

  • We retain only the work we did for you - call summaries, generated letters, completed form submissions. Encrypted at rest and yours to delete on request.

What each product holds

Every workflow, the same answer: as little as possible.

Receptionist

Audio is never stored. Call summaries live encrypted in Marea.

Calls are transcribed in real time as they happen. The audio is never written to disk and is discarded the moment the call ends. There is nothing to play back later. The call summary (who called, what they wanted, the outcome) is retained in Marea so your team can review history. Bookings flow directly into your PMS calendar.

Scribe

Audio is never stored. The note flows to your PMS.

Operatory audio is transcribed live and used to generate the note. Both the audio and the raw transcript are discarded the moment the note is written. The finished note flows directly into the chart you already use. Marea does not retain a long-term copy.

Letters

Generated letters are retained, encrypted, with full delivery tracking.

Letters are written from the clinical note in your PMS, then stored in Marea so you can re-send, audit, and reference past correspondence. Delivery is through an encrypted portal. Every send, open, and reply is tracked. Source patient data is pulled from the PMS in real time, not migrated.

Forms

Submissions sync to your chart and stay searchable in Marea.

Completed intake submissions auto-sync into the patient's PMS record and are also retained in Marea (encrypted) so your team can search, audit, and export past submissions. E-signatures are legally binding with a full audit trail.

Compliance & certifications

Built to clear procurement before the call ends.

HIPAA

Full compliance with US healthcare privacy regulations. Business Associate Agreement available for every customer.

PIPEDA

Compliant with Canadian personal information and privacy law for practices north of the border.

SOC 2 Type I

Independent audit of our security controls covering access, encryption, availability, and incident response.

BAA included

We sign a Business Associate Agreement with every customer. No add-on, no negotiation cycle, no per-seat surcharge.

Technical safeguards

What we do for the bit we do touch.

Encrypted on the way

Every bit of data moving between your practice and Marea travels over an encrypted connection. The same kind your bank uses.

Encrypted at rest

Anything Marea keeps. Call summaries, letters, form submissions. Is locked with strong encryption when it's not being used.

Audio is never stored

Call and operatory recordings are transcribed in real time and immediately discarded. Nothing is written to disk. There's nothing to play back later.

Plugs into your PMS, doesn't replace it

Marea connects to the system you already use through a secure connection. We never migrate, copy, or replicate your patient database.

FAQ

The questions IT asks first.

Have a security review on your desk?

We'll walk through the specifics with your team. BAAs, how Marea fits with your PMS, where your data lives, and anything else IT or compliance is asking about.

Book a Demo