Nextvisit uses several AI providers across clinical documentation, AriaMD chat, voice, and internal services. This page describes those providers and our data practices as of the date above. Read it alongside our Privacy Policy, Terms of Service, and your organization's applicable agreements.
- Training on patient or provider information requires explicit opt-in.
- Internal quality evaluations are enabled by default and include transcripts and AI traces.
- We use zero data retention where supported; most other AI processing has 30-day provider retention.
- Support handles provider restrictions, RUM opt-outs, and agreement-specific evaluation exclusions.
1. Providers and agreements
We maintain Business Associate Agreements (BAAs) and contractual agreements covering our providers and their applicable services. Our signed BAAs include OpenAI, Anthropic, Google Cloud, Google Workspace, AWS, Microsoft Azure, DigitalOcean, Deepgram, OpenRouter, Cloudflare, Helicone, Sentry's hosted services, Datadog's HIPAA-compliant services, Laravel Cloud, Telnyx, Twilio, Claim.MD, Stedi, Neon, and Backblaze. Processing of protected health information (PHI) is subject to the applicable BAA and its covered services.
SpaceX/xAI is covered through OpenRouter's subprocessor arrangements. A direct agreement with xAI is in progress. Our Sentry BAA covers Sentry's hosted services, used by Nextvisit GO and our Help Center. Nextvisit-maintained Sentry instances run on our own infrastructure.
We primarily connect to models using our own API keys and connections through Cloudflare AI Gateway and OpenRouter. The gateway and the model provider both participate in the processing path. Provider selection depends on the feature, task, and available routing configuration.
| Service | Providers and purpose |
|---|---|
| AI gateways | Cloudflare AI Gateway and OpenRouter route model requests. |
| Legacy gateway failover | Helicone is retired from routine use and retained as a fourth-level AI gateway failover. |
| Language models | OpenAI, Anthropic, Google, and xAI process text and generate responses. Perplexity supports searches using information without PII. |
| Voice and transcription | Deepgram is our primary provider. SpaceX/xAI provides fallback text-to-speech (TTS) and speech-to-text (STT). |
| Cloud platforms | Amazon Web Services (AWS), Google Cloud, Microsoft Azure, and DigitalOcean provide cloud infrastructure and storage. |
| Backup and storage | Backblaze provides encrypted backup and storage. |
| Claims and insurance | Claim.MD and Stedi provide claims and insurance services. |
| Phone and fax | Telnyx provides phone and fax services. |
| Hosted diagnostics | Sentry's US hosted services support Nextvisit GO and our Help Center. Datadog provides HIPAA-compliant diagnostic services in the US. |
| Support infrastructure | Neon supports some Help Center and support services. Laravel Cloud provides application infrastructure. |
| Internal collaboration | Google Workspace supports internal email and documents. |
| Internal help and documentation | Nextvisit hosts these services. Their AI features primarily use OpenAI and Anthropic through OpenRouter. |
| Planned provider | Twilio has a signed BAA but is not used by any current service. |
Google Workspace, Neon, and Laravel Cloud are not intended to receive patient information. We maintain BAAs with these providers as a precaution against incidental exposure.
We store sensitive data with partners covered by a BAA or another appropriate agreement for the data and service involved. PHI storage requires the applicable BAA. Other service providers are listed in our Privacy Policy; this page describes the providers relevant to AI, patient data, support, and diagnostics.
Processing locations
Requests and storage containing patient information or other PII are restricted to the United States, including AI prompts, responses, audio, gateway routing, and fallback processing. Tasks without patient information or other PII can use providers globally, including medication research and insurance remittance-address searches.
2. Models by feature
Model selection and versions change as we evaluate quality, speed, and task requirements. "Latest" refers to the model version selected for the workflow at the time of processing. A feature can use several models within one request.
Encounter and note generation
Note generation uses multiple steps for reviewing context, drafting, extraction, and checking the result. The following model families handle the primary tasks.
| Model | Primary uses |
|---|---|
| Anthropic Opus / Fable (latest) | Large-context review and matching; custom note templates; adversarial review; diagnosis suggestion triage; insurance coding and suggestion verification; statement checks; and current medical information. |
| OpenAI GPT Sol (latest) | Primary note generation; medication extraction; diagnosis suggestion triage; encounter summaries; transcription and context compaction; insurance coding; chart reviews; adversarial review; and inline note editing. |
| OpenAI GPT Astra (latest) | Extensive chart review and complex cases. A classifier escalates cases to this model, and note generation also escalates cases when an in-depth review is needed. |
| OpenAI GPT Luna / Terra | Information tagging, metadata, other suggestions, and web search tools. |
| Google Flash (latest) | Web, medical, and reference searches. |
AriaMD chat
Our in-house heuristic router selects models for Auto, High, and Fast modes. Mode selection determines the available model pool; the router selects the model for each task.
| Model or provider | Modes or restriction |
|---|---|
| OpenAI o3 | Auto, High, Fast |
| OpenAI GPT Sol (latest) | Auto, High, Fast |
| OpenAI GPT Terra | Auto, Fast |
| OpenAI GPT Astra | High |
| Google Flash (latest) | Auto, Fast |
| Perplexity | Search requests using information without PII |
| xAI Grok (latest) | Auto, Fast |
| Anthropic Sonnet (latest) | Auto, Fast |
| Anthropic Opus | Auto, High |
| Anthropic Fable | High |
We also test other models, including open source models, subject to the compliance and contractual requirements of the workflow. Clinicians remain responsible for reviewing AI-generated documentation and suggestions before clinical use.
3. Data retention
We use zero data retention (ZDR) with AI providers when it is available for the model, endpoint, and configuration used. Where ZDR is unavailable, provider retention is 30 days in most cases. Processes using Anthropic Fable 5.1 are one example of a path with retained data. The applicable provider agreement and processing path determine the actual period.
ZDR describes the provider's handling of request and response content. The 30-day period is not a universal deletion deadline for clinical records, evaluation data, traces, diagnostics, or backups held by Nextvisit. Those records have separate retention needs. See our Privacy Policy and contact support for the retention terms that apply to your service.
RUM data is retained for 30 days. Retention for traces and evaluation data varies by workflow. These records are used internally; external reporting is limited to aggregate performance metrics. After an evaluation, our usual practice is to retain results and calculations without PII. The handling and retention of identifiable evaluation material varies by workflow.
4. PII redaction
Some workflows replace personally identifiable information (PII) with bracketed tags.
For example, a first name becomes [First Name]. We use three levels according
to the purpose of the workflow. Review steps check for and correct identifiers missed by
earlier steps.
Full PII redaction
This process targets patient, provider, and other identifying information. It is used for eligible training data when both the provider and patient opt in, and for workflows such as diagnostic traces, analytics, safety review, internal performance measurement, and evaluations.
- A non-LLM filter removes identifiers and replaces them with tags.
- OpenAI GPT 5.6 Terra reviews the result with High reasoning.
- Google 3.8 Flash reviews the result.
- Anthropic Sonnet 5 reviews the result with High reasoning.
- OpenAI GPT 5.6 Sol reviews the result with Extra High reasoning.
- A final pattern-matching filter checks the output.
- Human review is added according to the use case.
Partial PII redaction
This process keeps provider information and removes selected patient identifiers, such as names. Clinically relevant information, including location, sex, and birth month or year, can be retained or adjusted to preserve its diagnostic relevance for the task. The information retained depends on the process.
Filter-only redaction
Some diagnostics use a non-LLM filter to remove or replace identifiers, without the model review sequence described above.
Redaction is a data-minimization measure. Replacing names with tags does not by itself establish that a record meets HIPAA's de-identification standard, particularly when demographic or clinical details remain. The standard requires Safe Harbor or Expert Determination, as described in HHS de-identification guidance.
Internal comparison of redacted and full-PII inputs
Between October 2022 and April 2025, we compared notes generated from full-PII inputs with notes generated from fully redacted inputs using data from the same period. The dataset covered 27,500 patient visits, diagnoses, and medications, with at least six months of each patient's visit timeline. Models varied over the study period; the paired inputs differed in redaction. Providers reviewed both versions without knowing which version they were judging.
| Input version | Selections | Share of selections |
|---|---|---|
| Full PII | 19,250 | 70% |
| Fully redacted PII | 8,250 | 30% |
These are provider-selection rates across 27,500 comparisons, with a difference of 40 percentage points. They describe this internal comparison and do not establish a clinical accuracy rate or isolate the effect of individual identifiers such as names.
A separate Nextvisit review, supervised by medical professionals, assessed the percentage of accurate content within categories including diagnosis, condition, mental status exam, and review of systems. The first visit contributed 50% of the timeline weighting; later visits shared the remaining weight equally. Non-applicable items were excluded and weights adjusted. The table reports the original provider selections; a separate numerical result from the supervised review is not published here.
5. Model training
As of 2026, we do not train models on patient or provider information without explicit opt-in. Our default requires consent from both the provider and patient; consent requirements depend on the applicable state, region, and locality. Eligible training data goes through the full PII redaction process above. Participation in internal evaluations does not constitute training opt-in.
When training is enabled, eligible data is limited to information created directly on Nextvisit. Data from third-party authentication services and connected data sources is excluded, including Google Accounts, Google Calendar, and EHRs. Opting in does not remove these exclusions.
Contact our Help Center for consent, training information, opt-in, or withdrawal requests. Withdrawal excludes the information from future training. It does not reverse training already completed or remove the information's effects from a Nextvisit model that has already been trained on it.
6. Internal evaluations
Users participate in internal evaluations by default. We evaluate system performance and quality using data that includes transcripts and large language model (LLM) traces. These evaluations measure accuracy, quality, and progress toward our service goals.
Evaluation records remain for internal use. We share aggregate performance metrics when reporting results externally. Trace and evaluation retention varies by workflow.
Access follows least-privilege and need-to-know controls under the CTO's oversight. Support agents receive access to detailed information after explicit provider confirmation in a request initiated by the user. Senior engineers with higher levels of trace access are based in the United States.
Evaluations are separate from model training. Trace and evaluation exclusions are available through enterprise or custom agreements. Some services cannot be provided with those exclusions. Contact support to discuss your requirements.
7. Diagnostics and support
Traces, diagnostics, and real user monitoring (RUM) data are stored in US data centers. The destination depends on the service and diagnostic configuration:
- Nextvisit-hosted or support-managed Sentry, a storage bucket, or a database.
- Sentry's US hosted services for Nextvisit GO and the Help Center, covered by our Sentry BAA.
- Datadog's HIPAA-compliant services in US data centers.
- Laravel Nightwatch for diagnostics that do not contain PII.
Support can enable or disable a user's RUM or other diagnostic service according to the issue being investigated or the user's request. RUM data is retained for 30 days. Some diagnostic workflows use the filter-only redaction level; others use the full review process described above.
Our internal help center and documentation services are hosted by Nextvisit. Their AI features primarily use OpenAI and Anthropic through OpenRouter.
8. Provider traffic
The figures below describe provider shares measured in tokens for AI generations with text input and output. They exclude voice and audio traffic. The September snapshot and the earlier period average show how our provider mix changes over time.
| Provider | Snapshot reported September 20, 2026 | Average, January to August 2026 |
|---|---|---|
| OpenAI | 38% | 9% |
| Anthropic | 46% | 71% |
| 10% | 17% | |
| xAI | 4% | 0% |
| Others | 2% | 3% |
"Others" includes models hosted on AWS, Google Cloud, or Azure, usually fine-tuned open source models. These figures describe historical usage and do not fix the provider mix for future requests.
9. Requests and opt-outs
Submit a request at help.nextvisit.ai to discuss a specific provider or subprocessor restriction, RUM opt-out, trace and evaluation exclusion, or training consent and withdrawal request.
- We try to accommodate provider and subprocessor restrictions when feasible.
- Users can request a RUM opt-out through support.
- Trace and evaluation opt-outs require an enterprise or custom agreement and can limit available services.
Provider availability, model versions, routing, and traffic shares are subject to change. We notify users of subprocessor changes through a Terms of Service notification at login and aim to give 30 days' advance notice when possible. This target is subject to operational circumstances. The notice requirements for material changes to the Terms and applicable customer agreements continue to apply.
Changes to our policies follow the notice provisions in the Privacy Policy, Terms of Service, and applicable customer agreements.