For clinical teams
HIPAA-compliant collaboration for healthcare teams
Secure messaging, telehealth video and the clinic queue in one platform — encrypted, audited, and built around the way care teams actually work.
Start freeOne workspace for the whole care team
Clinical work does not divide neatly into a chat app, a video app and a task tracker, so it stops being three products here. Conversations, meetings, task boards and the patient queue live in one workspace, and a Space keeps a team's work to that team — its board is visible to its members and to nobody else in the organisation.
- Channels and direct messages, with mentions, files and threaded replies
- Video meetings started from any conversation, or scheduled ahead
- Task boards per Space, with the stages your clinic actually uses
- A shared whiteboard beside the cards that track the work
Built for PHI, not adapted for it
Handling patient data was the starting requirement, not a compliance module added later. Content tables carry soft-delete and retention columns so a record can be removed and stay removed; the audit log is append-only, so what happened cannot be quietly rewritten; and AI features are gated per organisation rather than switched on for everyone by default.
- Append-only audit log covering access, changes and administrative actions
- Soft-delete plus retention windows on the tables that hold content
- Per-organisation control over whether AI ever sees clinical data
- Every request re-checks the caller's organisation and membership
Your data stays on your infrastructure
There is no third-party processor sitting in the middle of this. The database, the video server, file storage and even speech-to-text run on infrastructure we operate — which means audio for live captions is transcribed without leaving the server, rather than being posted to somebody else's transcription API and becoming their copy of your consultation.
- Self-hosted PostgreSQL, not a managed database on a shared platform
- Self-hosted video server, so media is not routed through a third party
- Speech-to-text on our own hardware — caption audio never leaves it
- Private file storage with time-limited links, never public objects
Healthcare mode, when a conversation cannot be recorded
Some consultations should leave nothing behind at all. Healthcare mode is end-to-end encrypted — the encryption key is generated in the browser and never reaches our servers — and it persists nothing: no recording, no transcript, no summary. Recording and broadcasting are not discouraged in that mode, they are refused outright by the server.
- Keys generated in the browser; the API never receives one
- Recording, broadcasting and captions all refused, not merely hidden
- Nothing written to disk: no transcript, no summary, no recording
- Cannot be switched on mid-meeting, so the guarantee covers the whole call
Common questions
- Is WorkStation HIPAA compliant?
- The platform is built to HIPAA requirements: encrypted transport, an append-only audit log, retention and deletion controls, per-organisation access boundaries, and infrastructure we operate ourselves. Compliance is a shared responsibility, so talk to us about your specific workflow and a business associate agreement before handling PHI.
- Will you sign a business associate agreement?
- A BAA is part of our enterprise terms. Contact us with your requirements and we will work through the agreement alongside the technical review your organisation needs.
- Where is our data stored?
- On infrastructure we operate directly — our own database, our own video servers, our own storage. Nothing is handed to a managed third-party platform, and we can tell you exactly where every category of data lives.
- Can we stop meetings being recorded?
- Yes. Healthcare mode refuses recording entirely, at the server rather than by hiding a button. In every other mode, recording is announced to everyone in the room the moment it starts — a visible badge and a banner, driven by the meeting server rather than by the recorder's own client.
- Does the AI assistant see patient data?
- Only if your organisation explicitly enables it. AI is gated per organisation by a single setting, and every AI run is written to the audit log with the model and the outcome — never the prompt and never the output.
See it with your own workflow
Start free, or talk to us about a clinical rollout and the agreements your organisation needs.
Get started