HUVA Scribe
HUVA-Scribe-eCW-beta Privacy Policy
Last updated: September 2, 2026
HUVA-Scribe-eCW-beta helps a physician record a visit, review a generated SOAP note and ICD-10-CM/CPT suggestions, and save the physician-approved draft to the eClinicalWorks sandbox Progress Note opened by the physician.
Data processed
The extension processes the minimum information required for this workflow. This may include the selected patient's name, date of birth, phone number, medical history, allergies, medications, prior visit context, clinical visit audio, visit notes, generated SOAP fields, diagnosis-code suggestions, procedure-code suggestions, and field verification results.
The extension also processes bounded page structure and control state needed to locate the supported eCW workflow. Raw DOM, full URLs, authentication tokens, and clinical text are excluded from diagnostic logs.
Authentication
HUVA Account creation and login use email verification through Clerk, a third-party authentication provider. New users provide first name, last name, and email, then verify a one-time email code. Clerk manages the authentication session. The extension does not receive or store a clinician password. The common HUVA Account identity service validates the Clerk credential and creates the Account identity once when needed; HUVA Scribe then issues its own expiring access and rotating refresh tokens. HUVA Work hospital membership, role, provider mapping, subscription, payment, and credit checks are not part of this Scribe authorization flow.
After authentication and before any clinical workflow begins, the extension presents its clinical-data and audio disclosure and requires the user to affirmatively agree. The disclosure is shown again when its version changes or after logout.
Purpose and use
Information is used only to prepare a physician-reviewed Scribe draft and save that approved draft to the exact eCW Progress Note opened by the physician. Data is not sold, used for advertising, used for credit decisions, or used for unrelated analytics.
EHR navigation and field entry use deterministic code included in the extension package. A generative model does not create selectors, clicks, Save, or Lock actions. The extension does not prescribe medication, place orders, delete EHR content, or submit claims.
Storage, transmission, and retention
Visit audio remains in browser memory during recording and is uploaded to the HUVA Scribe API when the physician stops recording and requests a draft. The API forwards that bounded request for generation but does not persist raw audio in the provisional Visit. Patient context, transcript, clinician notes, SOAP fields, and codes may be stored in an encrypted provisional HUVA Scribe session for the limited period needed to finish the workflow. The Production service is configured with an eight-hour provisional-session time to live unless a shorter operational or legal retention rule applies.
Trusted Chrome local storage contains Clerk SDK session state and the rotating opaque HUVA Scribe refresh token needed to recover after service-worker suspension. Trusted Chrome session storage contains only the opaque workflow session identifier and current step, plus side-panel bindings. The short-lived Scribe access token remains in service-worker memory. Content scripts cannot access either trusted storage area. Clinical text, audio, patient identity, and raw DOM are not stored in Chrome local or sync storage, and no authentication token is exposed to an eCW page.
Approved note content is transmitted to eCW only after the physician opens and verifies the intended Progress Note and starts the write. The resulting EHR record is retained according to the healthcare organization's and eCW's policies. HUVA Account authentication records are retained according to HUVA policies and applicable legal requirements. A new personal billing or credit ledger is not part of the current Scribe workflow.
Sharing and service providers
Data is shared only with service providers required to perform the requested workflow, including Clerk for authentication, HUVA cloud services for account and Scribe processing, and eClinicalWorks as the physician-selected EHR destination. HUVA does not sell extension data or share it for advertising, data brokerage, or unrelated purposes.
Security and physician control
The extension uses HTTPS, Manifest V3, packaged executable code, allowlisted origins, server-verified Account and Scribe tokens, expiring workflow sessions, and readback verification. The physician selects the patient, reviews the medical context, approves the SOAP note and codes, opens the intended eCW Progress Note, reviews the result checklist, and separately confirms Lock.
If patient identity, encounter state, or a write result cannot be verified, the extension stops and does not automatically retry an uncertain mutation.
Contact and updates
Questions, access requests, deletion requests, or privacy concerns may be submitted through HUVA support. Material changes to these practices will be reflected in this policy and the Chrome Web Store disclosures before release.