Legal

Privacy Policy

How we collect, use, disclose, and safeguard your information, including Protected Health Information (PHI). Last updated 7/21/2026.

Important: When EMRxAI handles Protected Health Information (PHI) on behalf of a healthcare provider, our handling of that PHI is governed primarily by HIPAA and a separate Business Associate Agreement (BAA), which controls over this Privacy Policy with respect to PHI. This document is provided for informational purposes and is not legal advice.

1. Introduction

EMRxAI ("Company", "we", "our", "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information, including Protected Health Information (PHI), when you use our home health electronic medical record (EMR) software and services ("Service"). We aim to handle information consistent with the Health Insurance Portability and Accountability Act (HIPAA), the HITECH Act, applicable U.S. state privacy laws (such as the California Consumer Privacy Act as amended by the CPRA), and other relevant privacy laws. This Privacy Policy does not modify or limit any Business Associate Agreement; where a BAA applies to PHI, the BAA controls.

2. Information We Collect

We may collect information about you in a variety of ways. The information we may collect via the Service includes:

  • Personal Data: Personally identifiable information, such as your name, shipping address, email address, and telephone number, and demographic information, such as your age, gender, hometown, and interests, that you voluntarily give to us when you register with the Service or when you choose to participate in various activities related to the Service.
  • Protected Health Information (PHI): As a Business Associate to healthcare providers (Covered Entities), we may handle PHI as defined under HIPAA. This includes patient demographic information, medical history, treatment information, insurance information, and other data necessary for the provision of home health care services.
  • Derivative Data: Information our servers automatically collect when you access the Service, such as your IP address, your browser type, your operating system, your access times, and the pages you have viewed directly before and after accessing the Service.
  • Usage Data: Information about how you use the Service, such as features utilized, frequency of access, and actions taken within the application. This data is typically anonymized or aggregated.

3. Use of Your Information

Having accurate information permits us to provide you with a smooth, efficient, and customized experience. Specifically, we may use information collected about you via the Service to:

  • Create and manage your account.
  • Provide, operate, and maintain our Service.
  • Process transactions and send related information, including confirmations and invoices.
  • Improve, personalize, and expand our Service.
  • Understand and analyze how you use our Service.
  • Develop new products, services, features, and functionality.
  • Communicate with you, either directly or through one of our partners, including for customer service, to provide you with updates and other information relating to the Service, and for marketing and promotional purposes (with your consent, where required).
  • Ensure compliance with HIPAA, HITECH, and other applicable laws and regulations.
  • Prevent fraudulent transactions, monitor against theft, and protect against criminal activity.
  • Comply with legal obligations and assist law enforcement.

4. Disclosure of Your Information

We may share information we have collected about you in certain situations. Your information may be disclosed as follows:

  • By Law or to Protect Rights: If we believe the release of information about you is necessary to respond to legal process, to investigate or remedy potential violations of our policies, or to protect the rights, property, and safety of others, we may share your information as permitted or required by any applicable law, rule, or regulation. This includes exchanging information with other entities for fraud protection and credit risk reduction.
  • Third-Party Service Providers: We may share your information with third parties that perform services for us or on our behalf, including data storage, data analysis, payment processing, email delivery, hosting services, customer service, and marketing assistance. These third parties are obligated to protect your information and are typically bound by Business Associate Agreements (BAAs) if they handle PHI.
  • Business Transfers: We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.
  • With Your Consent: We may disclose your personal information for any other purpose with your consent.
  • De-identified or Aggregated Data: We may share de-identified or aggregated data, which cannot reasonably be used to identify you, for research, analytics, or other purposes.

We will not sell, rent, or lease your PHI to third parties for marketing purposes.

5. Security of Your Information

We use administrative, technical, and physical security measures to help protect your personal information and PHI. These measures include encryption, access controls, audit logs, and regular security assessments. While we have taken reasonable steps to secure the information you provide to us, please be aware that despite our efforts, no security measures are perfect or impenetrable, and no method of data transmission can be guaranteed against any interception or other type of misuse.

6. Your Rights Regarding PHI

As a patient whose PHI may be processed by our Service on behalf of a Covered Entity (your healthcare provider), you have certain rights under HIPAA, including the right to access, amend, and request an accounting of disclosures of your PHI. Please direct such requests to your healthcare provider. We will assist Covered Entities in fulfilling these requests as required.

7. Data Retention

We will retain your personal information and PHI only for as long as necessary for the purposes set out in this Privacy Policy, as required by our contractual obligations with Covered Entities, and as necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies.

8. Cookies and Tracking Technologies

Our website and Service may use cookies, web beacons, and similar technologies to operate the site, remember preferences, analyze usage, and improve performance. You can control cookies through your browser settings; disabling them may affect site functionality. We do not use these technologies to collect PHI for advertising, and we do not place advertising trackers within the authenticated EMR application.

9. Your State Privacy Rights (e.g., California / CPRA)

Depending on where you reside, you may have rights regarding personal information that is not PHI governed by HIPAA, including the right to know what personal information we collect, the right to access or delete it, the right to correct inaccuracies, and the right to opt out of certain processing. PHI handled on behalf of a healthcare provider is generally exempt from these state laws and is instead governed by HIPAA and the applicable BAA. To exercise rights regarding non-PHI personal information, contact us using the details below. We will not discriminate against you for exercising these rights.

10. No Sale or Sharing of Personal Information for Advertising

We do not sell your personal information or PHI, and we do not share PHI for cross-context behavioral advertising. We will not sell, rent, or lease PHI to third parties for marketing purposes.

11. International Data Transfers

The Service is operated in the United States and intended for use by U.S.-based home health agencies. If you access the Service from outside the United States, you understand that your information may be processed and stored in the United States, where data protection laws may differ from those in your jurisdiction.

12. Breach Notification

In the event of a breach of unsecured PHI, we will notify affected Covered Entities in accordance with the HIPAA Breach Notification Rule and the terms of the applicable Business Associate Agreement, and will cooperate with the Covered Entity's notification obligations. For other personal information, we will provide notice as required by applicable law.

13. Children's Privacy

Our Service is not intended for use by children under the age of 13. We do not knowingly collect personally identifiable information from children under 13. If we become aware that a child under 13 has provided us with Personal Information, we will take steps to delete such information.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.

15. Information You Provide Through Demo Requests and Contact Forms

When you request a demo or contact us through our website, we collect the information you submit, which may include your name, business email, agency name, phone number, number of clinicians, patient census, and any message you provide. We use this information to respond to your inquiry, schedule and conduct your demo, understand your agency's needs, and follow up about the Service. This business-contact information is not PHI and is handled under this Privacy Policy rather than a BAA.

16. Marketing Communications and Your Choices

With your consent where required, we may send you marketing emails, calls, or text messages about the Service. You can opt out of marketing emails at any time by using the unsubscribe link in any message, reply STOP to opt out of text messages, or contact us using the details below; we will honor opt-out requests as required by the CAN-SPAM Act, TCPA, and other applicable laws. We will still send necessary transactional or account-related communications. Because no uniform standard for recognizing "Do Not Track" browser signals has been adopted, our Service does not currently respond to such signals.

17. Contact Us

If you have any questions or concerns about this Privacy Policy or our data practices, please contact our Privacy Officer at:
Email: contact@emrxai.com