06/03/2026
Ambient AI captures live clinical conversations. Those conversations contain PHI. Before your CISO approves Dragon Copilot, four questions will come up. Where does the data go? Who controls access? How long is it retained? What happens if something goes wrong? Here are the answers. Dragon Copilot deployments are contractually bound to U.S.-only Microsoft Azure data centers under the Microsoft BAA. Audio is processed to generate the clinical note and then permanently deleted. It is not stored, indexed, or used for model training. Access runs on role-based controls, MFA, and audit logging through a centralized admin console. The security review package, including architecture diagrams and PHI workflow documentation, goes to your CISO before integration work begins. Not after.