Jane's Guide

Here's all the help you need to use Jane.


Cloud Security White Paper

We've built Jane with security and privacy as our main focus. It's what drives our culture, training, and hiring processes. It also shapes how we've used technology to protect and secure data.

This white paper outlines Jane's approach to security and how we've ensured that securing Jane data has always been and will continue to be our top priority.


                              


Data Hosting

Amazon Web Services Jane's physical infrastructure is hosted and managed within Amazon Web Services' secure data centers. We utilize their built-in security, privacy, and redundancy features, including AWS's ability to perform regular backups. Amazon Web Services complies with leading security policies and frameworks, including ISO 27001, SOC 1 and SOC 2.

AWS follows industry best practices and has strict physical access policies for the data centre building. For more information see Amazon's documentation on their physical access controls: AWS Data Layer
Data Storage All Jane accounts are individually stored within their own database schema.
Data Storage Location The location of Jane data storage depends on the location you choose for your Jane account when you sign up:
  • Canada: Montreal, Quebec, and Calgary, Alberta
  • United States and Cayman Islands: Portland, Oregon
  • Australia, New Zealand, and Singapore: Sydney, Australia
  • UK and Europe: London, England
  • Rest of world: Montreal, Quebec, and Calgary, Alberta
If you're using any integrated services, these services may have different regional data processing and storage practices. You may wish to reach out to individual service providers with any questions about this.
Resiliency Hosting on AWS allows Jane to remain resilient, even if one location goes down. AWS spans across multiple data centres within a particular region (called availability zones), which allows Jane servers to remain resilient in the event of a failure, including natural disasters or system failures.
Defense In Depth Protections are in place at the host, network, cloud, and policy levels.
Encrypting Data Data that passes through Jane is encrypted, both at transit and at rest. We also encrypt all volumes where customer data is stored, and we also individually encrypt all backups. Data in transit is encrypted using TLS 1.2, ECDHE_RSA with P-256, and AES_128_GCM and at rest using AES 256 encryption.
Continuous Monitoring Jane has continuous and automated monitoring and vulnerability scanning on the AWS infrastructure so that we are proactive and have an awareness of any potential vulnerabilities, incidents, and threats.
Customer Backups We back up customer data daily, weekly, monthly, and yearly to our primary environment using multiple availability zones. All backups are encrypted in transit and at rest. We also regularly test the recovery of these backups. And we store an encrypted copy of the backups at a separate data centre environment on a weekly basis.
Data Deletion When it comes to deleting data, we do so in a way that does not allow for reconstruction by using NIST 800-88 guidelines to destroy data. For more information on how to manage deletion requests and record retention, please see our Deleting Patient Data guide.


Application Security

Account Ownership As per Terms of Use, all data is owned by the Account Owner. This person acts as Jane's sole point of contact for decisions about the account and facilitates access to other users in the account. For more information, see our Account Ownership in Jane guide.
Access Control and Account Security Access to Jane is managed by username and password, with 2-Step Verification available (and enforceable) to add an additional layer of security. Jane secures your credentials by using leading industry standards to salt and hash your credentials before it is stored.

Each user is assigned an "access level" and chart privacy settings so that users have access only to what they need. For more information, see the following guides:
Activity Logging The Account Owner has access to the Activity Log that gives them a detailed breakdown of all Staff activity. This can be filtered by date range, staff member, and the type of data that they access. In addition to this, each user has their own Sessions Log to see activity and additional details associated with any of their past or current sessions.
AI-Powered Features Jane takes a careful and transparent approach to AI, which you can read more about in our AI Principles Guide. All of Jane's AI-powered features, both current and future, are designed to be safe and secure, with Account Owners having control over staff access. Our first AI-powered feature, AI Scribe, along with all associated data and outputs, is securely hosted and managed within secure data centers where the other data processing and storage activities are located.

If you are located in Canada and using AI Scribe, please note that we use a US-based service provider for some of our AI Scribe features, which require temporary data processing in the U.S., for example, to enable the translation of text conversations into structured clinical notes. No information is stored or logged during transmission or processing. After processing, all data and outputs are stored in the clinic's home region, as determined when setting up your Jane account.

As part of our commitment to continuously upgrading the user experience, Jane may adopt and experiment with new large language models (LLMs) as they become available, always keeping security and privacy as our top priorities.
Data Protection Jane will continue to secure and protect your data so long as you have a Jane account and unless instructed otherwise by the Account Owner. If the Account Owner decides to close their Jane account, we can export your data, free of charge, or we can place the account on hold at a lesser fee.
Development Lifecycle Jane developers follow a strict policy to ensure that Jane features and updates are secure by design, in development, and after deployment. Jane releases frequent updates that are heavily tested before deployment. All updates do not require downtime.
Third-Party Integration Jane's optional third-party services are assessed thoroughly before implementation to ensure that they meet our security requirements. No medical data or patient health information is sent to our third-party services. View our optional third-party integrations here: Jane's Integrations


Compliance

Regulatory Compliance Jane complies with applicable legal and regulatory requirements while enabling you to do the same. This includes Jane's compliance with all Canadian Privacy laws, GDPR, HIPAA, and Standard Codes of Practice across multiple health professions.
Self-Regulatory and PCI Compliance Jane is SOC 2 Type 2 compliant, in addition to being PCI compliant. Regarding PCI, Jane never stores or processes credit card information. This is completed by an optional integration by Stripe or Payfirma, which are PCI compliant. Additional information can be found here: Is Jane PCI-Compliant?
Dedicated Teams We have dedicated Security and Privacy teams that regularly review our policies, update training, and ensure that Jane is one of the top EMR companies to secure data.
Security Culture and Training At Jane, security and privacy are at the forefront of every decision we make, so they're embedded deep in our company's culture. On the training side specifically, our teams undergo training during onboarding and annually, at minimum, with a strong focus on best practices and privacy principles.
Confidentiality Jane employees sign strict confidentiality agreements upon hire, and we access your data only as allowed by our Terms of Use. Our trainings focus heavily on privacy and confidentiality best practices.
Background Check All Jane employees undergo a multi-step background check prior to employment.
Recovery Plan Jane maintains a Business Continuity and Disaster Recovery Plan, which is regularly reviewed, updated, and tested.
Incident Response Program Jane maintains a robust incident response program with procedures and training in place to manage any kind of incident, including security or privacy incidents. These procedures ensure that remediation and mitigation actions are established. As part of our incident response program, we have established procedures for privacy breach response.


Resources

Here are additional resources that you might find helpful:

If you have any questions for our team, please contact us at [email protected].