Skip to content
SMEG
Security & PHI Handling

Real-record pilots are not yet available.

Only synthetic demonstrations are available today. The safeguards below are prerequisites for a future pilot, not claims of completed security controls, clinical validation, or authorization to process patient records.

01

Marketing site

The public website is for education, sample reports, pricing requests, and facility-level inquiry only. Do not submit PHI through public pages.

02

Approved intake

Actual records are not accepted until written facility authorization and complete applicable BAA, vendor, security, access, intake, retention, deletion, and qualified-human-validation approvals are in place. A BAA alone is insufficient.

03

AI/vendor boundary

SMEG does not use identifiable PHI to train public machine-learning models. Any production AI/vendor workflow must be scoped and approved before PHI is used.

04

Minimum necessary

Review scope should use the smallest appropriate sample and only the information needed for documentation-risk review.

05

Retention & deletion

Retention, deletion, and audit-log expectations are set during BAA/security review before PHI intake begins.

06

Human review

SMEG provides documentation-risk intelligence. Facility compliance, billing, MDS, legal, clinical, and payer-policy decisions remain with the facility.

Data flow

A buyer-safe path from inquiry to approved review.

  1. 1Public inquiry: Facility-level metadata only; no patient names, DOBs, MRNs, chart text, or uploads.
  2. 2Synthetic demonstration: Evaluate the product workflow with SMEG-supplied synthetic information only.
  3. 3Readiness review: Confirm written authorization, BAA, vendor, security, access, intake, storage, retention, deletion, and human-validation boundaries before any actual record.
  4. 4Approved review: Only after all applicable gates are complete, SMEG screens documentation-risk patterns and routes findings for qualified human validation.
  5. 5Leadership report: Facility receives plain-language risk themes, note examples, and action priorities for internal review.
Buyer checklist

What SMEG will confirm before PHI.

  • • BAA status and authorized parties
  • • Approved file-transfer or export workflow
  • • Who may access review materials
  • • Retention and deletion expectations
  • • Whether any AI/vendor service touches PHI
  • • Reporting format and distribution limits
  • • Facility compliance, billing, MDS, and legal review boundaries

Ready to scope a safe review?

Start with facility-level details. SMEG will confirm the right pricing tier and intake path before any PHI is submitted.