mednbotmednbot
Legal

MednBot for Chrome — Privacy Policy

Effective: September 28, 2026

Overview

MednBot for Chrome is a browser extension for clinicians who use the MednBot platform. It shows the clinician's own finished visit notes in a side panel and, when the clinician asks, inserts a note — or fills a whole note form — in the electronic health record (EHR) open in their browser. Nothing is ever submitted to the EHR; every filled field is outlined for the clinician's review.

Pairing and your MednBot account

The extension is paired to one clinician with a one-time code generated inside the MednBot doctor portal. Pairing creates a device token that the clinician can revoke at any time from the portal, and that expires on its own. The device token is kept in the browser's extension storage on that computer. It is the only thing the extension stores, besides a per-visit checklist of which note sections have already been inserted.

Your finished notes

The extension requests the text of a completed visit note from MednBot only when the clinician selects it. Note text is held in memory for that action and is never written to extension storage or to disk by the extension.

What the extension reads from the EHR page

The extension runs on an EHR site only after the clinician allows that site, the first time they insert there. It is injected on demand — never when a page merely loads. On allowed sites it reads exactly two kinds of things, each only when the clinician presses the button that needs it:

  • The form's structure, for Fill form. When the clinician presses Fill form, the extension reads the form's field labels, field names, and choice options — never values typed into the form — and sends that structure to MednBot once per form layout, so MednBot can learn which field takes which note section. MednBot keeps only the resulting field-to-section map and an anonymous fingerprint of the layout; the labels themselves are not stored.
  • Patient name and date-of-birth candidates, for matching. On allowed sites, the extension looks for a patient name and date of birth visible on the page and sends those candidates to MednBot solely to check them against the clinician's own recent visits, so the matching visit can be highlighted in the side panel. They are used for that comparison and are not stored.

What the extension does not do

  • It does not track browsing, collect analytics, or show advertising.
  • It does not sell, share, or transfer data to third parties.
  • It does not submit, save, or sign anything in the EHR — the clinician reviews every outlined field and saves in the EHR themselves.
  • It does not read EHR pages on sites the clinician has not allowed, and it never runs at page load.

What MednBot records

Each insert or form fill is logged on MednBot's servers as an audit event: which clinician, which paired device, which visit, the hostname of the EHR site, whether the whole note, a section, or a form fill was used, how many fields were filled, and the time. The audit log never contains the note text or any page content.

HIPAA

Note content is processed by the MednBot platform, which operates as a HIPAA Business Associate under agreements with the practices it serves. This policy covers the extension; the platform's handling of patient information is governed by those agreements.

Security

All communication with MednBot uses HTTPS. Device tokens are stored hashed on MednBot's servers and expire automatically.

Contact

Questions about this policy: hello@mednbot.com