InPractice
InPractice does one thing: it reads medical records and turns them into chronologies and narrative summaries for legal and medical professionals. Records are uploaded to a case and processed at a stated three seconds a page, so a thousand-page file completes in under an hour. Chronologies are organised by date with an outline view that jumps straight to the underlying source document, and a side-by-side view puts the generated summary next to the original record for verification. Users can edit individual entries, search across records with OCR, filter by date range, provider, facility, document type, medicine type and body part, and export to Word, Excel or PDF with a choice of fields and layouts and the original records optionally attached. Duplicate documents are detected and automatically, and a per-case cost statement reports pages used and total spend for internal tracking or case billing. A Case Chat feature answers questions against the record set. The company sells to personal injury, workers' compensation, medical malpractice and mass tort practices, to qualified and independent medical examiners, and to insurers handling workers' compensation claims, in the United States only. Pricing is published and pay-as-you-go with no subscription and no per-user fee, starting at 100 dollars for a thousand page credits and falling with volume, and credits do not expire. There is a free trial of 500 pages over seven days with no credit card. InPractice states that it does not use customer information to train AI models, and describes itself as HIPAA compliant. InPractice, Inc. is based in Goleta, California.
Capability grades
All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The models are the mechanism and the unit of charge at once. Every function is model output: chronology construction, narrative summarisation, OCR-enabled search, duplicate detection and the Case Chat feature that answers questions against the record set. The product is billed per page processed, so a customer is paying for inference directly and nothing else, with no seat fee and no subscription. The vendor states its own scope in the same terms, describing itself as specialising exclusively in medical record review rather than offering a broad legal AI platform. Remove the models and there is a file store with a search box. Checked 4 September 2026.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Grounding is real, documented and built into the interface rather than asserted. Chronology entries carry an outline view that jumps directly to the underlying source document, and a side-by-side review places each generated summary and chronology entry alongside the original medical record specifically to support verification and editing. Export can optionally include the original records, so the chain from output back to source survives outside the platform. The vendor also publishes its own limitations, stating that the product requires human oversight for final verification and that AI-generated content needs review, which is an unusually direct acknowledgment for a marketing surface. What is missing is measurement. No accuracy figure is published, no test set is described and no evaluation is linked. The one published number, three seconds per page, is throughput rather than accuracy and should not be read as one.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
A written commitment that the product works alongside a supervising professional, with a real review surface behind it. The side-by-side view is the mechanism: generated summaries and chronology entries sit next to the original records, and every entry is individually editable before export so the user controls what leaves the system. The vendor states in its published limitations that human oversight is required for final verification and strategic decision-making, which locates the review point rather than merely recommending care. Duplicate detection operates unattended and is described as hiding exact duplicates only. What is absent is the rest of the control structure: no threshold is published at which the system defers or flags low confidence, nothing describes what happens when an error survives review, and there is no terms of service in which a supervision obligation would ordinarily sit.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Real deployment evidence with named sources, short of measurement. Five testimonials carry both an individual and an organisation: Wayne Winders of Williams and Swee, Dylan Barket of Barket Lawyers, Simone Sacks of Orthopedic Expert Services, George Gluck MD of the Hand Center of Nevada, and Jaclyn Meeks of AmarilloMD, which spans the legal and medical examiner segments the product sells to. One carries a figure attached to the named firm, with Winders reporting that case preparation time was cut by half and that demand letters improved because detail buried in hundreds of pages was no longer missed. The vendor separately claims use by hundreds of firms and organisations nationwide. What holds this at B is that the single figure is a self-reported proportion with no matter volume, no period and no method, nothing is dated, and no case study is published anywhere on the site.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
The commitment covering the material this product actually holds cannot be read in advance, which is what decides this. The privacy policy states in its second paragraph that it does not apply to protected health information processed on behalf of customers, and that such processing is governed by the business associate agreements InPractice has in place with its customers. Those agreements are not published anywhere. Since the entire input to the product is medical records, the published policy governs account and marketing data while the instrument governing the case material is unavailable to a buyer before contracting. What is published is real but partial: the security page states that customer information is never used to train AI models or shared with third parties, and describes 256-bit AES at rest, AES encryption in transit and multi-factor authentication by SMS or TOTP. Nothing addresses privilege or work product, nothing describes segregation between customers or matters, no retention or deletion position exists on any surface, and no model provider is identified, so what any underlying provider may retain is unstated.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
No position on the advice line was located, and there is no document in which one would sit. The site publishes no terms of service, no customer agreement and no acceptable use policy: the navigation carries Product, Industries, Security, Pricing and Company, and the footer carries a privacy policy alone. Nothing anywhere states that output is not legal advice or not medical advice, and no attorney-client or clinician-patient boundary is addressed. That matters more than usual because the same product is sold to attorneys, to qualified and independent medical examiners who write expert reports, and to insurers adjusting claims, and its output is a medical chronology used to argue causation. What is published is adjacent but different: a limitations statement that human oversight is required for final verification and strategic decision-making, which speaks to output quality rather than to the advice boundary. Checked home page, security page, pricing page, privacy policy, navigation and footer on 4 September 2026.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
No governance position is published for a system that decides which clinical facts reach a case file. There is no responsible AI statement, no governance framework, no named owner accountable for model behaviour, no description of pre-release evaluation and no published testing results. Nothing addresses bias, which has a specific edge here: a chronology tool that summarises treatment history determines which diagnoses, gaps and pre-existing conditions surface, and uneven performance across record types, providers or handwriting quality would change what a reader concludes about causation. The Vanta partnership named on the security page automates compliance monitoring for HIPAA and answers a security question rather than a governance one. Searched the home page, the security page, the pricing page, the privacy policy and the AI information page on 4 September 2026.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
A privacy policy covers the company without addressing what happens to the records after processing, and the gap is explicit rather than accidental: the policy states that it does not apply to customer protected health information at all. Access control is the strongest published element, with 256-bit AES at rest, AES encryption in transit and multi-factor authentication supporting both SMS and TOTP. Infrastructure suppliers are named as AWS, Google Cloud Platform and Microsoft Azure, and Google Analytics and Google Ads are named in the privacy policy. Three elements of the set are missing entirely. No retention period is published for uploaded records, summaries or chat content anywhere on any surface. No deletion commitment or route exists. And no incident or breach notification practice was located. One published statement cuts against the rest: the privacy policy provides that personal information may be transferred, processed and stored anywhere in the world.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
Nothing is published on who bears the loss when the system is wrong. There is no terms of service, no master subscription agreement, no customer agreement and no order form template anywhere on the site; the navigation has no legal section and the footer's only legal link is the privacy policy. No indemnity, no liability cap, no warranty of any kind, no service level and no insurance position was located on any surface. A buyer purchasing page credits self-serve with a credit card, as the pricing page invites, does so without any published allocation of loss to read. The business associate agreements referenced in the privacy policy govern data protection rather than liability for output, and are in any event unpublished. Searched the home page, the security page, the pricing page, the privacy policy, the AI information page, the navigation and the footer on 4 September 2026.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
No integration into practice systems was located. No case management system, document management system, medical record retrieval service, intake platform or e-signature product is named anywhere on the surfaces read, and there is no integrations page, API reference or developer documentation in the navigation or footer. What exists is export rather than integration, and it is well specified: chronologies and summaries export to Word, Excel or PDF with a choice of fields, filters and layouts and the original records optionally included. That moves a finished document out of the platform; it does not connect the platform to the systems a personal injury firm already runs, and records still arrive by upload. The vendor's own published boundary confirms the position, stating that the product is not an EHR or EMR system. Checked 4 September 2026.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Neither the tenancy model nor the region is stated. Three cloud providers are named on the security page, AWS, Google Cloud Platform and Microsoft Azure, but naming a provider is not naming a location and no region, country or data centre appears anywhere. Nothing describes whether the platform is single or multi-tenant, and no dedicated, private or isolated option is offered at any tier. The one residency statement located runs the other way: the privacy policy provides that all personal information processed may be transferred, processed and stored anywhere in the world, including but not limited to the United States or other countries with different privacy laws. For a platform whose stated market is the United States only and whose content is protected health information, an express worldwide processing permission with no residency commitment is the material fact and is recorded as such.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
No independent security attestation was located. HIPAA compliance is claimed, but HIPAA has no certification scheme, and what the security page actually describes is a partnership with Vanta, a compliance automation vendor whose product monitors controls; a Vanta HIPAA badge evidences a monitoring subscription rather than an audit, and Vanta is not a certifying body or an auditor. No SOC 2 of any type is claimed, which is a notable absence for a platform whose entire content is protected health information. No ISO certification, no auditor, no report date, no scope statement and no penetration testing appears anywhere, there is no trust centre, and no report is offered at any access tier including on request. Applying the third-party verifiability test, a buyer has nothing to check against any register. Checked home page, security page, pricing page, privacy policy and footer on 4 September 2026.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
Nothing is published about the model supply chain a customer inherits. No model is named, no model provider is identified, no subprocessor list exists, no location is given for inference, and no commitment to notify customers of a change was located. AWS, Google Cloud Platform and Microsoft Azure are named on the security page, but as the cloud platforms the product runs on: naming where a model executes is not naming whose model it is, and infrastructure never answers this axis. The security page's statement that customer information is never shared with third parties sits in tension with the fact that some model must process the records, and nothing reconciles the two or identifies whether inference happens on a proprietary model or a third-party one. Searched the home page, the security page, the pricing page, the privacy policy and the AI information page on 4 September 2026.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
Amended 4 September 2026 from A to B on operator ruling R73(e); surfaces as originally checked on 4 September 2026, no re-research. Real pricing is published for part of the range and a buyer cannot determine from it what they will actually pay. The pricing page carries two schedules that do not reconcile. The volume table gives 1,000 pages at 0.10 dollars a page for 100 dollars, 5,000 at 0.09 for 450, 20,000 at 0.07 for 1,400, 100,000 at 0.06 for 6,000 and 200,000 at 0.05 for 10,000. The four purchase cards immediately below give Starter at 100 dollars for 1,000 pages at 0.10, Pro at 400 dollars for 5,000 at 0.08, Growth at 1,500 dollars for 25,000 at 0.06 and Scale at 5,000 dollars for 100,000 at 0.05. Three of the four overlapping tiers disagree on both total and per-page rate, the cards offer a 25,000-page tier the table does not contain, and the vendor's separate AI information page gives a third variant whose 200,000-page row reads 0.10 a page against a 10,000 dollar total, which does not compute. Only the 1,000-page entry tier at 100 dollars is stated consistently across all three. Everything else the band asks for is present: the unit of charge is published, what is included at every tier is itemised as unlimited users, medical chronologies, customisable AI summaries, one-click export, OCR and support, nothing is charged for implementation, and a 500-page seven-day trial requires no credit card. The axis asks whether a buyer can learn what this costs without entering a sales process. A page that returns three different answers does not let them, so publication alone does not carry the top band.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Coverage is documented with real precision at both ends, and the outer limits are stated more plainly than almost any record in this corpus. Three buyer segments each carry their own page: legal, medical examiners, and insurance. Practice areas are named specifically as personal injury, workers' compensation, medical malpractice and mass tort, and the medical examiner audience is identified as qualified and independent medical examiners scaling their practices. Unusually, the vendor publishes what it does not do, stating that it specialises exclusively in medical record review rather than general legal AI, that it is not an EHR or EMR system, and that it serves the United States market only. What is missing from the top band is the segment dimension: no firm size is addressed, in-house legal departments and government use are not mentioned at all, and nothing states a record volume ceiling or the document types the system cannot process.
Legal Signals
What each signal meansA signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
A public policy or trust page states no training on customer content, with no matching term located in the published agreement.
The security page states without qualification that InPractice never uses customer information to train AI models or shares it with third parties, and that the data belongs to the customer. The statement is unambiguous and carries no de-identification or aggregation carve-out. It sits on a marketing surface rather than in an agreement, and the search for a matching term was run and came back empty: the site publishes no terms of service, no customer agreement and no data processing agreement, and the privacy policy expressly states that it does not apply to customer protected health information, which is the material this question is really about. The privacy policy points instead to business associate agreements that are not published. So the commitment is real and readable but cannot be verified as contractual by a buyer before signing.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
No located public material states how long prompts and outputs are retained.
No located public material states how long uploaded records, generated summaries, chronologies or Case Chat content are retained. There is no retention section in the privacy policy, no retention statement on the security page, and no terms of service in which one would sit. No deletion commitment, deletion route or end-of-engagement position appears anywhere, and nothing states what happens to a case file once page credits are exhausted or an account goes dormant. The one adjacent published fact concerns commercial credits rather than data, namely that page credits never expire. Searched the home page, the security page, the pricing page, the privacy policy, the AI information page and the footer on 4 September 2026.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
No located public material addresses walls or matter level segregation.
No located public material addresses walls or matter level segregation. Nothing states whether the platform is single or multi-tenant or how one customer's records are separated from another's. Within a customer account the published position runs toward openness rather than separation: credits can be shared across team members and used across cases, users are unlimited at every tier, and the privacy policy records that a customer may access information associated with a user's use of the Services including the contents of files associated with that account. No role model, permission structure or per-matter access control is described, and multi-factor authentication is the only access control published. Searched the home page, the security page, the pricing page and the privacy policy on 4 September 2026.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Published terms or policy address disclosure to authorities or in response to legal process, and no commitment or reservation regarding customer notice is located anywhere. The vendor has told the customer that data can leave and has said nothing about whether the customer hears of it.
The privacy policy addresses compelled disclosure directly, reserving the right to disclose personal information as required by law and where InPractice believes disclosure is necessary or appropriate to protect rights, property or safety, enforce policies or contracts, assist an investigation, or comply with a judicial proceeding, court order or legal process served on it. No commitment to notify the customer of such a request appears anywhere, and no discretion over notice is reserved either. One limit on the clause is recorded because it matters: the policy states at the outset that it does not apply to customer protected health information, so this provision governs account and marketing data rather than the medical records themselves, and nothing published addresses compelled disclosure of those. No transparency report was located.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
No located public material identifies the corpus behind the product’s answers.
No located public material identifies a corpus behind the product's output, and the product's design makes the question narrow: InPractice reads the medical records the customer uploads to a case and produces chronologies and summaries from them, rather than retrieving external content. No external database, publisher, clinical coding set or reference source is named anywhere, and no licence basis is stated. Searched the home page, the security page, the pricing page, the privacy policy and the AI information page on 4 September 2026.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No located public material addresses whether authority is checked for subsequent history.
Nothing on any located surface addresses whether authority is checked for subsequent history. The product does not retrieve or present primary law at all: it summarises and sequences the medical records supplied for a case. The question does not bite on this product class and the honest value is the absence rather than a penalty. Searched the home page, the security page, the pricing page and the AI information page on 4 September 2026.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
No located public material addresses what the product does when it cannot ground an answer.
No located public material describes what the product does when it cannot ground an output. The vendor states in its published limitations that AI-generated content needs review and that human oversight is required for final verification, which places the check on the user rather than describing a system behaviour. No abstention path, no no-answer state and no confidence or grounding score surfaced to the reviewer is described, and nothing states how the system handles illegible handwriting, poor scans or gaps in a record set, which are the ordinary failure conditions for this product class. Searched the home page, the security page, the pricing page and the AI information page on 4 September 2026.
Fabricated Citation Record
Does a public court record exist involving output from this product?
No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.
The AI Hallucination Cases database maintained by Damien Charlotin was searched on 4 September 2026 on both the product name InPractice and the corporate name InPractice, Inc. No court order, opinion or disciplinary record naming the product was located. This records the state of the public record on that date and is not a finding about the product.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
No located public material engages with bar or ethics guidance.
No located public material engages with bar or ethics guidance. No bar association, regulator, rule of professional conduct or ethics opinion is named on any surface, and there is no terms of service or acceptable use policy in which such a reference would ordinarily sit. One published item comes close to the subject without engaging it: a blog post referencing American Bar Association survey data on the rate of AI adoption among legal professionals, which cites the ABA as a source of statistics rather than as a source of conduct guidance. Searched the home page, the security page, the pricing page, the privacy policy and the AI information page on 4 September 2026.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
A usable record of AI assisted work exists with no published fee guidance.
The product generates a per-matter record of AI-assisted work and publishes no guidance on how to treat it. Case Cost Statements are described as clear reporting of page usage and total spend per case, exportable to PDF to support internal tracking or case billing. Because the entire product is AI processing charged per page, every figure on that statement is a record of AI-assisted work on that specific matter, which distinguishes it from generic software cost allocation: the pages counted are the pages the model read. What is absent is the second half. Nothing addresses how that cost should be disclosed to a client or characterised on an invoice, no guidance on fee treatment is published, and nothing addresses what happens to a billable-hours entry when review time collapses from days to minutes.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
No located public material supports a client side disclosure obligation.
No located public material supports a client-side disclosure obligation. No subprocessor list is published, no model provider is identified anywhere, and no data processing agreement, consent pack or notification template exists at any access tier. The three cloud platforms named on the security page, AWS, Google Cloud Platform and Microsoft Azure, are infrastructure and say where the product runs rather than whose models see the records, which does not answer what a client's AI clause asks. Business associate agreements are referenced in the privacy policy as governing customer protected health information but are not published and no route to obtain one before contracting is described. Searched the home page, the security page, the pricing page, the privacy policy and the AI information page on 4 September 2026.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Some elements of the record are available, short of a document level export.
Substantial elements of a record are produced, short of anything covering the model. The sources side is well evidenced: chronology entries link to the underlying source document, the side-by-side view pairs each generated entry with the original record, and export can optionally include the original records alongside the chronology so the chain from output to source travels with the document. Case Cost Statements add a per-matter record of pages processed and spend. What is absent is the model dimension and the verification trail: nothing states that the model behind a given entry is recorded or disclosed, no log of which entries a human edited or approved is described as exportable, and no disclosure guidance or template for a court or an opposing party was located.