Clinical Data Protection

Privacy & Compliance Policy

How Voxtar tokenizes, secures, and safeguards clinical voice recordings and acoustic biomarker data across healthcare providers, voice agents, and EMR integrations.

Last Revised: July 23, 2026 | Effective Status: Active

1. Clinical Voice Data & Protected Health Information (PHI)

Voxtar processes voice samples strictly for clinical biomarker extraction and sub-clinical diagnostic screening (e.g. respiratory and neurological vocal indicators). All Protected Health Information (PHI) is tokenized at the edge before audio leaving the client environment. Raw audio streams are never linked to patient master records without explicit HIPAA BAA authorization.

2. Zero-Trust Edge Tokenization & Feature Vector Encryption

Voice samples are converted into non-reversible mathematical acoustic feature vectors (pitch perturbation, jitter, shimmer, fundamental frequency harmonics) at the edge node. These acoustic embeddings cannot be reverse-engineered back into audible human speech, ensuring robust protection against voice identity cloning or unintended disclosure.

3. HIPAA, GDPR & SOC 2 Type II Compliance

Voxtar complies with HIPAA Security, Privacy, and Breach Notification Rules, GDPR Article 9 regulations for biometric health data processing, and SOC 2 Type II security controls. All data in transit is encrypted via TLS 1.3, and all acoustic vector stores are protected at rest via FIPS 140-2 validated AES-256 encryption.

4. EMR Integration & Data Storage Scoping

When integrated with Electronic Medical Record (EMR) systems (via Epic FHIR R4, Cerner, or HL7 ADT), diagnostic outputs are written back directly to patient observation logs. Voxtar does not sell, license, or monetize any patient audio or acoustic feature data to third-party advertisers or external data brokers.

5. Patient Rights, Data Ownership & Permanent Erasure

Patients and health system covered entities maintain full ownership of their voice diagnostic records. You may request cryptographic erasure of all stored acoustic feature vectors and associated clinical session metadata at any time through your Voxtar console or by contacting our Data Protection Officer. Complete purging executes across active clusters and backups within 30 days.

Patient trust is paramount. Voxtar enforces zero-trust architecture across all clinical voice pipelines.