The consultation stays in the pharmacy.
RxScribe is a desktop application, so most of what protects a patient record happens on the machine in front of you rather than in someone else's data centre. This page describes the mechanism, not the reassurance.
Where the audio goes, and where it stops
One boundary, two hard stops. This is the part worth reading before anything else on the page.
On your workstation
The audio stops here
The speech engine and its language model are installed with RxScribe, not reached over the internet. The consultation is turned into text on the machine in front of you.
- Audio is held in memory only, for as long as transcription takes
- It is never written to disk, on the workstation or anywhere else
- No copy survives the session
- Pausing releases the microphone outright
Audio never
crosses this line
What leaves the workstation
A transcript with the identifiers already removed
Drafting the note is the one step that does not run locally. What crosses the boundary is text, not speech — and identifiers are stripped from it before the drafting model reads a word.
- Names, health numbers and contact details are removed first
- Identifier removal fails closed — if it is unavailable, the scribe is switched off and you are told before you record, not after
- The transcript is destroyed the moment you save or discard
- Only the note you reviewed and approved is kept
One precision worth stating plainly. Drafting the note is the only step that does not run on your machine — and what crosses that boundary is text with identifiers already removed, never the recording. On-device transcription is the default on the Windows build we ship and sign. The in-app Privacy & Trust Statement sets out, in full, the one case where it is not available and what happens instead.
On the workstation
RxScribe is a desktop application, so most of its security lives on the machine rather than in a browser tab.
The window is blank to screen capture
Screenshots, screen recorders and video-conferencing tools see a black rectangle where the RxScribe window is. A shared screen cannot leak a patient record by accident.
Credentials are held by Windows, not by us
Sign-in tokens go into the operating system's own credential store. They are never written to a file on disk, and when you choose not to be remembered they exist only in memory until the app closes.
A tampered install refuses to open
The application's contents are hash-verified every time it starts. Change a single byte of the installed program and it will not run.
Nothing loads from outside
The app talks to a short, fixed list of OneRx hosts that is compiled into the program itself. It cannot be pointed somewhere else by a settings file or a registry key.
In transit
Clinical information is protected in the request body itself, not only by the transport underneath it.
Request bodies are encrypted end to end
Clinical payloads are encrypted before they are sent and decrypted only by the service that is meant to read them.
Logs are scrubbed
Tokens, passwords and clinical information are removed from diagnostic output before anything is written down.
Installation and updates
The pharmacy should never have to judge whether a download is genuine. RxScribe checks on your behalf.
Signed by OneRx Inc.
Windows installers carry an Extended Validation code-signing certificate issued to OneRx Inc. The install prompt names us instead of reading “unknown publisher”.
Updates are verified twice before they run
Every update is checked against its published hash and against the publisher signature. An installer that fails either check is not run.
Updates arrive on their own
New versions install in the background and a plain-language summary explains what changed. Nobody at the pharmacy has to go looking for a download.
Do you want to allow this app to make changes?
- Program
- RxScribe Setup
- Publisher
- OneRx Inc.
What Windows shows when the installer runs
The shorter list is the one that matters
Any vendor can publish a long list of safeguards. These are the four things RxScribe does not do at all.
- No consultation audio is stored — not on the workstation, not on our servers
- No transcript is kept once the note is saved or discarded
- No patient name or health-card number is held inside the app
- No advertising, no analytics resale, no third-party trackers
Built against Canadian health-privacy law
RxScribe is designed for the statutes a Canadian pharmacy custodian actually answers to, not a generic international standard.
Canada
PIPEDA
Alberta
Health Information Act (HIA)
Ontario
PHIPA
British Columbia
PIPA
Quebec
Act respecting the protection of personal information in the private sector
Who is responsible for what
- The pharmacy and its pharmacists are the custodians of the personal health information handled through RxScribe.
- OneRx acts as an information manager, service provider or agent — processing information only on the custodian's instructions and only to deliver the service.
- Ownership and control of everything documented in RxScribe stay with the pharmacy at all times.
- Whether to use the optional features — Ambient Scribe, reading from an image or screen region, screenshots attached to support reports — is the custodian's decision, and so is the consent each one requires.
The full Privacy & Trust Statement sets all of this out section by section, including data residency, retention and the diagnostics the app sends. Read the Privacy Policy or the Terms of Service.
Questions your privacy officer needs answered?
We would rather have that conversation before you buy than after. Book a walkthrough and bring the hard questions.
Ready to Experience the OneRx Difference?
Book a personalized demo and see how OneRx can help your pharmacy thrive.