ClinicalSim

Trust, data handling, and what we haven't certified yet

Last updated: August 2026

Hospital privacy offices, IRBs, and procurement teams all ask the same handful of questions before a pilot starts. This page answers them in one place, including the one answer that is a no.

Key takeaway: every patient in every ClinicalSim case is synthetic, authored from the clinical literature rather than from patient records, so no protected health information enters the platform and there is nothing to de-identify. SOC 2 and HIPAA certification are on our funded roadmap and are not yet in place.

1. What ClinicalSim is, in regulatory terms

ClinicalSim is a training and assessment tool for clinician communication, not a diagnostic device, so no FDA clearance is required. The platform produces no patient-facing output, makes no diagnostic or treatment recommendation, and is not a clinical documentation tool.

What it produces is a rubric-scored record of how a clinician handled a simulated conversation, mapped to a published competency framework such as the ACGME Milestones 2.0.

2. Every patient is synthetic

Every patient in every ClinicalSim case is authored from the clinical literature, not adapted from a real chart. There is no de-identification step in our pipeline because there is nothing to de-identify.

That decision predates any compliance argument. A case written from the literature can be versioned, reviewed, and reasoned about by the physicians who authored it, and a case derived from a real encounter cannot. How cases get built is documented on our methodology page.

3. Cases, rubrics, and scoring prompts are versioned and locked

Once a case is published, its case text, its rubric, and its scoring prompts are versioned and locked. A program can point to the exact version a learner was assessed against, and a score from six months ago can be reproduced rather than re-litigated. Nothing about a published assessment changes underneath a learner after the fact, which matters most in remediation, where a score may end up in a due process file.

4. Learner voice data

Learners speak their side of the conversation out loud, which makes their voice data the one genuinely sensitive thing the platform holds. Collection is consent-gated, learners can request erasure, and our AI vendors are contractually barred from training on the data.

A learner's recording exists to generate that learner's feedback. Our privacy policy covers visitors to this website; learner data inside the product is governed by the institutional agreement and by the practices on this page.

5. What we haven't certified

SOC 2 and HIPAA certification are on our funded roadmap and are not in place today. We would rather write that here than let a vendor security questionnaire assume otherwise, and the reason it matters less than it usually would is section 2: the platform holds no protected health information, because every patient is synthetic.

Two other things we don't claim. ClinicalSim does not price malpractice risk and does not benchmark one institution against another, and both are later phases of our roadmap rather than features you can buy. And ClinicalSim does not replace a standardized patient program, it extends one.

We also don't claim our scoring is more accurate or more valid than a faculty member's read. We don't have the validation data to say that, and we won't claim it until we do.

6. Questions we get from privacy and procurement reviewers

Does ClinicalSim need FDA clearance?

No. ClinicalSim is a training and assessment tool for clinician communication, not a diagnostic device, so no FDA clearance is required. The platform produces no patient-facing output and makes no diagnostic or treatment recommendation, and it is not a clinical documentation tool.

Does any protected health information enter the platform?

No. Every patient in every ClinicalSim case is synthetic, authored from the clinical literature rather than from patient records, so no protected health information enters the platform and there is nothing to de-identify.

Is ClinicalSim SOC 2 or HIPAA certified?

Not yet. SOC 2 and HIPAA certification are on our funded roadmap and are not in place today. The reason that matters less than it usually would is that the platform holds no protected health information, because every patient in every case is synthetic.

What happens to a learner's voice recording?

Learner voice data is consent-gated, learners can request erasure, and our AI vendors are contractually barred from training on the data. A recording exists to generate that learner's feedback.

Can a program reproduce a score after the fact?

Yes. Published cases, rubrics, and scoring prompts are versioned and locked, so a program can point to the exact version a learner was assessed against and a score from months ago can be reproduced rather than reconstructed.

Does ClinicalSim price malpractice risk or benchmark our institution against others?

No. Risk pricing and cross-institution benchmarking are later phases of our roadmap, not features available today. What the platform produces now is per-learner, timestamped, rubric-scored practice records.

If your security review needs something this page doesn't cover, ask us.

We'll tell you what exists and what doesn't. You can also read how cases get built on our methodology page, or how we handle website data in our privacy policy.