Repertoire is a template-management tool. It is not an electronic medical record (EMR), and it is not intended to receive, store, or process protected health information (PHI).
The rule for using Repertoire is simple: do not enter PHI or patient-specific information anywhere in the tool. Use Repertoire to build, organize, and manipulate reusable clinical templates. Add details about an individual patient only in your organization-approved EMR.
Obtain approval from your organization’s IT, privacy, security, or compliance team before using Repertoire in a clinical workflow. Product design choices do not replace organizational review, policy, access controls, or other requirements. If your team has questions, please contact Repertoire.
Do not use patient identifiers in Repertoire
Do not type, paste, import, save, or otherwise use any of the identifiers addressed by the HIPAA Safe Harbor method in Repertoire. This includes obvious identifiers such as names and medical record numbers, as well as less obvious categories such as dates linked to an individual, contact information, device or account identifiers, IP addresses, biometric identifiers, and full-face photographs.
Refer to the official HHS guidance on the HIPAA Safe Harbor method and its identifier categories. If there is any possibility that text could identify a patient, keep it out of Repertoire.
De-identification can be context-dependent. Do not treat removing a name as sufficient, and do not use Repertoire to perform or validate de-identification.
What belongs in Repertoire
Repertoire is designed for reusable, patient-independent material, such as:
- Generic template structures and section headings
- Reusable assessment and plan language
- Selectable template options and default states
- Generic counseling or instruction language
- Recognition aliases for finding templates
- Non-patient test phrases used to verify template behavior
Think of it as an easier way to manage a large, interlocking template library—not as a place to maintain a patient record. A traditional document containing dozens of dot phrases can be difficult to search, update, and keep internally consistent. Repertoire gives those reusable building blocks structure, controls, recognition, and a normal writing surface.
What belongs only in the EMR
Keep all encounter-specific information in the approved medical record, including:
- Patient demographics and identifiers
- Dates, locations, contact details, and record numbers
- History, findings, results, diagnoses, medications, or plans tied to an individual
- Any free text copied from a chart, message, referral, or patient conversation
- The completed patient-specific clinical note
A suitable workflow is to assemble generic template language in Repertoire, copy that reusable structure into the approved EMR, and add or verify all patient-specific details there.
What the browser does and does not retain
The live writing area is session-only. Its contents are not included in a Repertoire workspace export. Reloading the page clears the active writing area and restores the selected reusable starting template.
Repertoire can store reusable configuration in the current browser profile, including custom templates, template reminders, timestamped notepad entries, starting-note presets, and preferences. Workspace exports likewise contain that reusable configuration. Those locations must remain free of PHI. A reminder or half-formed idea is not an exception: use only generic, patient-independent language.
External services and telemetry
The production deployment uses Vercel for hosting, Web Analytics for aggregate page-use measurement, and Speed Insights for performance measurement. Public About and Blog pages also load an EmailOctopus form script, and a published guide may include a privacy-enhanced YouTube embed. Repertoire does not configure custom analytics events and does not intentionally place active writing or reusable template content in URLs.
These services still require organization-specific privacy and security review. The published privacy and data-practices notice describes the current product behavior and providers, but it is not a substitute for legal or security approval of the actual organizational deployment. Do not treat the absence of an application database as the absence of hosting, network, browser, endpoint, clipboard, download, or third-party data flows.
Get IT approval before use
Before using Repertoire at work, discuss within your organization:
- This data-boundary guide.
- The intended workflow: reusable template management in Repertoire, patient-specific completion in the EMR.
- The fact that the live writing area resets on reload and is excluded from local storage and exports.
- The reusable information that does remain in browser storage.
- The production hosting, analytics, contact-form, and optional video services.
- The user agreement that prohibits PHI and requires appropriate IT approval.
Your organization may decide that additional review, configuration, training, or restrictions are needed. Follow that decision and all applicable policies. If your team has questions, please contact Repertoire.
For a broader explanation of the product model, read why Repertoire is more than a dot phrase library.