Updated: May 26, 2026
This policy describes how the EvidenceMD AI Scribe Chrome Extension (the "Extension") collects, uses, stores, and shares data. The Extension is a companion to the EvidenceMD web application at evidencemd.ai and is intended only for licensed healthcare clinicians who operate under a Business Associate Agreement ("BAA") with EvidenceMD Inc. For data handling on the EvidenceMD web application, see our main Privacy Policy.
The Extension has a single purpose: AI medical scribe — capture audio of patient encounters and assist clinicians with clinical documentation inside their EHR. The Extension does not perform unrelated functions, run advertising, or include third-party analytics SDKs.
The Extension acts on the clinician's direction. Each data flow below is initiated only by an explicit clinician action in the Extension UI; no flow runs in the background or without the clinician's instruction.
| Data | When it is collected | Where it goes | Stored at rest in the Extension? |
|---|---|---|---|
| Microphone audio of patient encounters | Only while the clinician is actively recording in the widget | EvidenceMD transcription service over TLS | No — held in memory only, cleared on stop |
| Transcription text | When the clinician clicks Generate note | EvidenceMD note-generation service over TLS | No |
| Generated clinical notes | Shown to the clinician; pushed to an EHR field only when the clinician clicks Push to EHR | EvidenceMD services over TLS; EHR field via in-page DOM write that the clinician focused | No |
| EvidenceMD authentication cookie | Read once per backend call to authorize the clinician | Sent only to EvidenceMD as an Authorization: Bearer header | No — re-read per request from the EvidenceMD domain cookie jar |
| Text and form-field values from the active EHR or web page(current tab only, clinician-triggered) | Only when the clinician clicks Run CDI/UR on this page | EvidenceMD CDI/UR review service over TLS | No |
| Audit metadata (event name, timestamp, extension version, session id) | Per backend call, for HIPAA audit logging | EvidenceMD audit log; no PHI included | No |
The Extension does not read EHR page content automatically. The CDI/UR on-page review is a clinician-triggered action; it captures text and form-field values from the current tab, up to roughly 95,000 characters, and sends it to the same CDI/UR review endpoint the EvidenceMD web app uses.
Microphone access is gated by Chrome's native permission prompt. The Extension cannot capture audio until the clinician explicitly grants microphone access to the Extension, and recording only begins after the clinician clicks the Record button inside the widget.
Audio, transcripts, generated notes, and page text submitted to CDI/UR are processed solely to provide the AI medical scribe service to the authenticated clinician who initiated the action. EvidenceMD does not use this data to train AI models, to serve advertising, or for any purpose unrelated to producing or reviewing clinical documentation for the clinician who recorded or submitted it.
We share Protected Health Information (PHI) only with subprocessors that are strictly necessary to operate the medical-scribe service and that are bound by a Business Associate Agreement (BAA) with EvidenceMD. We do not sell, rent, or transfer PHI to advertising networks, data brokers, or any third party for unrelated purposes. We do not transfer, use, or sell user data for personalized advertising, to determine credit-worthiness, or for lending purposes. We do not allow humans to read user data except (a) with the clinician's explicit consent (for example, a support ticket they file), (b) when required by law, or (c) as necessary for security investigations.
A current list of subprocessors that may process PHI on our behalf is available on request from founders@evidencemd.ai.
EvidenceMD's use of information received via Chrome extension APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. We use this information solely to provide the single, user-facing AI medical-scribe purpose described in section 2 above.
All network traffic between the Extension and EvidenceMD services is TLS 1.2 or higher. The Extension stores no PHI at rest in the browser. The authentication token used for backend calls is never persisted inside the Extension; it is re-read from the EvidenceMD cookie jar for each call so that signing out of the EvidenceMD web app immediately revokes the Extension's access. Backend storage is encrypted at rest.
| Permission | Why the Extension needs it |
|---|---|
cookies | Read the EvidenceMD authentication cookie from evidencemd.ai so the Extension can call the EvidenceMD backend on the clinician's behalf without re-prompting for a password. Filtered strictly to the EvidenceMD domain. |
offscreen | Host the browser's MediaRecorder to capture encounter audio. Manifest V3 service workers cannot host MediaRecorder. |
tabs | Open the EvidenceMD sign-in tab when authentication is needed; read the current tab's URL to route the toolbar action between popup and in-page widget based on whether the page accepts content scripts; re-attach the Extension's bundled content script to already-open EHR tabs after install or update so the toolbar opens without a page reload. |
alarms | Periodically tear down the offscreen document while it is idle, to release the microphone and free memory. |
scripting | Re-inject the Extension's own bundled content script into already-open EHR tabs after install or update. Never used to execute remote or generated code; the injected file is shipped inside the Extension package and reviewed by the Chrome Web Store. |
host_permissions for EvidenceMD services and standard http(s) web pages | Read the EvidenceMD authentication cookie, call the EvidenceMD backend, and open the widget on any browser-based EHR, charting page, or demo page the clinician chooses. EvidenceMD requests broad https://*/* and http://*/* access because hospital-hosted EHR URLs are not predictable in advance; the content script is lightweight and writes to a page only after the clinician clicks Push to EHR. |
The Extension itself does not retain patient data — there is nothing stored inside the browser to delete. PHI captured by the Extension is sent to EvidenceMD services and retained per the BAA between EvidenceMD and the clinician's practice. To request deletion of server-side data, contact founders@evidencemd.ai.
The Extension is intended for use by licensed healthcare clinicians only. It is not directed at children and we do not knowingly collect personal information from anyone under 18.
Where GDPR applies, the legal basis for processing is the clinician-as-data-controller's instruction to provide the medical scribe service. EU users may exercise access, rectification, and erasure rights by contacting founders@evidencemd.ai.
We do not sell personal information.
Material changes will be announced via the EvidenceMD web application and reflected here with an updated date. The EvidenceMD main Privacy Policy governs the EvidenceMD web product; this page governs the Chrome Extension only.
EvidenceMD Inc.
8 The Green #17911
Dover, DE 19901
Email: founders@evidencemd.ai
This Chrome Extension Privacy Policy is effective as of the date listed above and applies only to the EvidenceMD AI Scribe Chrome Extension.