Privacy Policy for emrXAI
Last Updated: 6/11/2025
1. Introduction
emrXAI ("Company", "we", "our", "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information, including Protected Health Information (PHI), when you use our home health electronic medical record (EMR) software and services ("Service"). This policy is compliant with the Health Insurance Portability and Accountability Act (HIPAA) and other relevant privacy laws.
2. Information We Collect
We may collect information about you in a variety of ways. The information we may collect via the Service includes:
- Personal Data: Personally identifiable information, such as your name, shipping address, email address, and telephone number, and demographic information, such as your age, gender, hometown, and interests, that you voluntarily give to us when you register with the Service or when you choose to participate in various activities related to the Service.
- Protected Health Information (PHI): As a Business Associate to healthcare providers (Covered Entities), we may handle PHI as defined under HIPAA. This includes patient demographic information, medical history, treatment information, insurance information, and other data necessary for the provision of home health care services.
- Derivative Data: Information our servers automatically collect when you access the Service, such as your IP address, your browser type, your operating system, your access times, and the pages you have viewed directly before and after accessing the Service.
- Usage Data: Information about how you use the Service, such as features utilized, frequency of access, and actions taken within the application. This data is typically anonymized or aggregated.
3. Use of Your Information
Having accurate information permits us to provide you with a smooth, efficient, and customized experience. Specifically, we may use information collected about you via the Service to:
- Create and manage your account.
- Provide, operate, and maintain our Service.
- Process transactions and send related information, including confirmations and invoices.
- Improve, personalize, and expand our Service.
- Understand and analyze how you use our Service.
- Develop new products, services, features, and functionality.
- Communicate with you, either directly or through one of our partners, including for customer service, to provide you with updates and other information relating to the Service, and for marketing and promotional purposes (with your consent, where required).
- Ensure compliance with HIPAA, HITECH, and other applicable laws and regulations.
- Prevent fraudulent transactions, monitor against theft, and protect against criminal activity.
- Comply with legal obligations and assist law enforcement.
4. Disclosure of Your Information
We may share information we have collected about you in certain situations. Your information may be disclosed as follows:
- By Law or to Protect Rights: If we believe the release of information about you is necessary to respond to legal process, to investigate or remedy potential violations of our policies, or to protect the rights, property, and safety of others, we may share your information as permitted or required by any applicable law, rule, or regulation. This includes exchanging information with other entities for fraud protection and credit risk reduction.
- Third-Party Service Providers: We may share your information with third parties that perform services for us or on our behalf, including data storage, data analysis, payment processing, email delivery, hosting services, customer service, and marketing assistance. These third parties are obligated to protect your information and are typically bound by Business Associate Agreements (BAAs) if they handle PHI.
- Business Transfers: We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.
- With Your Consent: We may disclose your personal information for any other purpose with your consent.
- De-identified or Aggregated Data: We may share de-identified or aggregated data, which cannot reasonably be used to identify you, for research, analytics, or other purposes.
We will not sell, rent, or lease your PHI to third parties for marketing purposes.
5. Security of Your Information
We use administrative, technical, and physical security measures to help protect your personal information and PHI. These measures include encryption, access controls, audit logs, and regular security assessments. While we have taken reasonable steps to secure the information you provide to us, please be aware that despite our efforts, no security measures are perfect or impenetrable, and no method of data transmission can be guaranteed against any interception or other type of misuse.
6. Your Rights Regarding PHI
As a patient whose PHI may be processed by our Service on behalf of a Covered Entity (your healthcare provider), you have certain rights under HIPAA, including the right to access, amend, and request an accounting of disclosures of your PHI. Please direct such requests to your healthcare provider. We will assist Covered Entities in fulfilling these requests as required.
7. Data Retention
We will retain your personal information and PHI only for as long as necessary for the purposes set out in this Privacy Policy, as required by our contractual obligations with Covered Entities, and as necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies.
8. Children's Privacy
Our Service is not intended for use by children under the age of 13. We do not knowingly collect personally identifiable information from children under 13. If we become aware that a child under 13 has provided us with Personal Information, we will take steps to delete such information.
9. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
10. Contact Us
If you have any questions or concerns about this Privacy Policy or our data practices, please contact our Privacy Officer at:
Email: privacy@emrxai.com