MEDICALSYSTEMS.appHIPAA READY
HomeAboutPrivacyTerms
Contact us

LEGAL

Privacy Policy

EFFECTIVE DATE: AUGUST 4, 2026 · LAST UPDATED: AUGUST 4, 2026

This document is provided as a working draft for the MEDICALSYSTEMS.app website. Have qualified legal counsel review it for your jurisdictions and business practices before publishing.

1. Introduction

MEDICALSYSTEMS.app (“we,” “us,” or “our”) provides an AI-powered practice management platform for private practices and medical centers (the “Service”). This Privacy Policy explains what information we collect, how we use it, and the choices you have. It applies to this website and to the Service. Where the Service processes patient records, we act as a service provider or processor on behalf of the healthcare organization that holds the relationship with the patient.

2. Information We Collect

Information you provide. Contact details when you request a demo or email us (name, work email, organization, phone). Account details when your organization provisions users (name, role, phone number for one-time-password sign-in).

Information processed for healthcare organizations. Patient registration details, appointments, clinical records, prescriptions, lab results, billing records, and referral documents, including faxed referrals and the text our AI extracts from them. This information belongs to the healthcare organization and its patients; we process it under our agreement with that organization.

Information collected automatically. Log and device data such as IP address, device identifiers, timestamps, and the actions taken in the Service. This data also powers the Service's audit trail, which records who did what, and why.

3. How We Use Information

We use information to provide and operate the Service; to authenticate users and enforce role-based permissions; to maintain append-only audit logs, including logs of every read of a clinical record; to send transactional messages such as appointment confirmations and reminders; to respond to inquiries and provide support; to maintain security, prevent fraud, and enforce our terms; and to comply with legal obligations. We do not sell personal information. We do not use patient records to train AI models. AI extraction of faxed referrals is stored verbatim as evidence, validated against existing records, and never acted on without the checks described on our website.

4. Protected Health Information

Where the Service processes protected health information (“PHI”) for a covered entity or its business associates, we do so under a Business Associate Agreement (“BAA”) on eligible plans, and we support the vendor BAA chain for the infrastructure the deployment uses. HIPAA does not offer certification. The Service provides technical safeguards designed to support a covered entity's compliance program; compliance also requires the administrative and physical safeguards your organization operates. Questions about a specific deployment's posture can be sent to sales@medicalsystems.app.

5. How We Protect Information

Controls that exist in the product today include: row-level security on every tenant-scoped table, enabled and forced, so one organization can never read another's rows; an application database role with no DELETE grant on any table, so records are retired rather than erased; append-only audit logging of every state-changing action; logging of every read of a clinical record; break-glass emergency access that requires a typed reason, notifies the treating clinician, and reports to the organization owner; Argon2id password hashing; TOTP multi-factor authentication that an organization can make compulsory per role; shared-terminal idle lock; and server-side session revocation within 60 seconds. No system can be guaranteed 100% secure, and we do not make that claim.

6. Data Retention

Clinical records are retained for at least 10 years, or longer where the healthcare organization's legal obligations require it, including legal holds. Website inquiry data is kept only as long as needed to respond and follow up. Because the application role holds no DELETE privilege, removal from active systems is implemented as retirement with a preserved audit history, subject to applicable law.

7. Your Rights

Depending on your jurisdiction (including PDPA in Sri Lanka, DPDP in India, GDPR in the European Union, and applicable US state laws), you may have rights to access, correct, export, restrict, or delete personal information, and to withdraw consent. Patients using the portal can exercise several of these directly: view visit history, see who accessed their record, update contact details, raise correction requests, manage consent and communication preferences per purpose, and export their data. Requests concerning patient records held by a healthcare organization should be directed to that organization; we support the organization in fulfilling them. Other requests can be sent to sales@medicalsystems.app.

8. Cookies and Similar Technologies

This website uses only the cookies and local storage needed for it to function and for basic, privacy-respecting analytics of page performance. The Service uses session storage strictly for authentication and operation, not for advertising. We do not use third-party advertising cookies.

9. Service Providers and Disclosures

We share information with infrastructure providers that host and operate the Service (for example, edge compute, database, SMS delivery, and fax providers such as Documo, Phaxio, Sinch, and Updox where your organization connects them), under contracts that limit their use of the information to providing the service. We may disclose information when required by law, to protect rights and safety, or as part of a merger or acquisition, in which case this policy will continue to apply until updated.

10. International Transfers

Deployments are configured per jurisdiction. Our posture is built to the strictest of the regimes we operate in and configured per deployment. Where information crosses borders, we use lawful transfer mechanisms appropriate to the jurisdictions involved.

11. Children's Privacy

The portal supports dependent records managed by a parent or guardian under one login. When a dependent reaches the age of majority, the guardian retains the history they lawfully managed and loses access to everything after; the Service states this on every page of the portal. This website is not directed to children, and we do not knowingly collect information from children outside the dependent-record feature operated by healthcare organizations.

12. Changes to This Policy

We will post any changes on this page with an updated effective date. Material changes will be communicated to account owners.

13. Contact

MEDICALSYSTEMS.app · sales@medicalsystems.app · medicalsystems.app

MEDICALSYSTEMS.app

HomeAboutTerms & Conditionssales@medicalsystems.app

© 2026 MEDICALSYSTEMS.app · medicalsystems.app · HIPAA-READY ARCHITECTURE · PDPA · DPDP · GDPR