Skip to content

Help Center · Concepts & Reference

Data privacy & security

3 min read

Your clinic's records include some of the most sensitive information you handle. Rebrief is built so the people who should see that data can, and everyone else can't. This article explains the protections that are always working in the background.

Everything is tied to your clinic

When you and your team work in Rebrief, you're working inside your own clinic's private workspace. Patients, appointments, clinical notes, and odontograms all belong to your clinic.

  • Rebrief always determines which clinic you belong to from your signed-in account, not from anything typed into a link or a form. There's no way to "ask" for another clinic's records by changing a web address.
  • Records from one clinic are never shown to another. Even internal lookups confirm that a record belongs to your clinic before returning it.

Note: Each team member sees data through their own account. Sharing one login across people is discouraged, because it weakens this protection and makes it harder to know who did what.

Signing in is required

You can't reach clinical data without signing in. Every time the app loads patient information, runs the assistant, or saves a note, it first confirms you have a valid, active session.

  • If your session expires or you sign out, the app stops returning protected data until you sign in again.
  • If an administrator disables or removes your account, access is cut off even if an old link is still floating around.

Tip: Sign out when you step away from a shared operatory computer. It's the simplest way to keep the next person from acting under your account.

Sharing a record outside your clinic

Sometimes you need to send a note or record to someone who doesn't have a Rebrief account, like a referring office or the patient. Rebrief does this with a protected link instead of an unguarded attachment.

When you share something this way:

  1. Rebrief creates an encrypted link. Anyone who has the link still sees nothing until they prove who they are.
  2. You give the recipient a password through a separate channel, for example a phone call or a text message.
  3. When the recipient opens the link, they're asked for the email address you sent it to and the password.
  4. Only when both match does Rebrief unlock the record and display it.

Because the link stays locked until the right email and password are entered, the link alone isn't enough to read anything. If someone forwards it or stumbles onto it, they still can't open it without those two pieces.

Tip: Send the link and the password separately. If they ever travel together in one message, the protection is only as strong as that single message.

Patient intake links

When you send a patient a link to fill out their own intake, that link is special-purpose. It's tied to one specific patient at your clinic and expires on its own after a set period. An expired link, or a link aimed at a patient who has since moved to a different clinic, simply stops working. This keeps an old intake link from ever becoming a way into anything else.

What we don't claim

We want to be straight with you. The protections above describe how Rebrief handles your data day to day: clinic-scoped access, required sign-in, encrypted and password-gated sharing, and expiring intake links. For questions about formal compliance programs or a written agreement covering protected health information, contact the Rebrief team directly rather than relying on assumptions.

If anything in your workspace looks like it's showing data it shouldn't, stop and reach out to support right away.