Every ambient scribe, copilot, and clinical assistant on the market today sends PHI to somebody else's cloud. DPLYD doesn't.
The same generative AI productivity your clinicians want — running on an appliance inside your own perimeter, HIPAA-compliant by construction, not by BAA.
Abridge, Nuance DAX, Suki, Nabla, Ambience, Epic's own AI Charting — the entire ambient-documentation market runs the same way: audio leaves the exam room, a vendor transcribes it, structures it, indexes it, and hands you a signed BAA as the compliance answer.
That's a legal instrument, not an architecture. The BAA tells you who's liable if something goes wrong. It says nothing about whether PHI ever left your walls in the first place. For most health systems, it never had to.
The ambient-scribe category matured fast — real KLAS-ranked winners, real time-back-to-clinicians, real revenue lift. That's not in dispute. What's in dispute is where the data lives while it happens.
| Abridge / Nuance DAX / Suki / Nabla / Ambience | Epic AI Charting (bundled) | DPLYD Healthcare | |
|---|---|---|---|
| Where PHI processes | Vendor cloud | Epic's cloud / MSFT Azure | Your perimeter |
| Compliance model | BAA + trust-us | BAA, bundled with EHR contract | Architectural — PHI never transmitted |
| Index/embeddings location | Vendor-side, queryable off-site | Vendor-side | On-prem, same side of the boundary as the source |
| Pricing | Per-seat / per-visit, scales with volume | "Free" — bundled into EHR spend | Fixed monthly, zero metering |
| Best fit | Ambient documentation at the point of care | Existing Epic shops wanting zero incremental spend | Any workload touching PHI you can't ship off-site — documentation, intake, coding, record search |
The independents compete on note quality and specialty depth. Epic competes on being free. Neither one answers the question a compliance officer actually asks: where does the data go? DPLYD is the only entry in the category where the honest answer is "nowhere."
Most "privacy-preserving" healthcare AI stops at de-identifying content before it leaves your network — stripping the eighteen HIPAA identifiers, then shipping the rest to a cloud model. But clinical narrative re-identifies easily: rare diagnoses, unusual drug combinations, visit timing, and free-text notes can fingerprint a patient even with names removed.
An index built from de-identified notes is still a second copy of your patients' clinical reality, sitting outside your walls.
DPLYD skips the trade entirely — the model and the index stay on your hardware, so there's no de-identification pipeline to get wrong.
A fully managed appliance, deployed inside your data center or colo, running the clinical workflows your staff already wants:
Same category of workflow as the incumbents. Different side of the boundary.
Every DPLYD healthcare deployment inherits Lighthouse, the platform's standing trust substrate — zero-trust identity, workload isolation, signed supply chain, continuous policy enforcement — and Sentinel, which turns "we're compliant" into an exportable, immutable audit log.
You're not buying a scribe with a compliance page. You're buying compliance as the platform underneath the scribe.
See the appliance running against a sample of your own clinical documentation — 30 minutes, on your data, not a sales deck.