Privacy Policy
Effective Date: January 1, 2026
Last Updated: January 1, 2026
Introduction
MedSynthea is committed to protecting the privacy and security of your personal information. This Privacy Policy describes how we collect, use, store, disclose, and protect personal information and protected health information ("PHI") in connection with our website at medsynthea, our autonomous revenue cycle management platform (the "Platform"), and our related services (collectively, the "Services").
By accessing our Website or using our Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with the practices described in this Privacy Policy, please do not use our Website or Services.
This Privacy Policy does not apply to third-party websites, services, or applications that may be linked from our Website. We encourage you to review the privacy policies of any third-party services you access.
1. Information We Collect
1.1 Information You Provide Directly
We collect personal information that you voluntarily provide to us, including when you:
- Request a demo or contact us: Name, email address, phone number, organization name, job title, and any additional information you include in your message.
- Create an account or sign in: Name, email address, organization affiliation, role, and authentication credentials.
- Subscribe to communications: Email address and communication preferences.
- Submit support requests: Name, email address, organization name, and details of your support inquiry.
- Engage with sales or partnerships: Contact information, organizational details, and information relevant to evaluating our Services.
1.2 Information Collected Automatically
When you visit our Website, we may automatically collect certain information, including:
- Device and browser information: Browser type, operating system, device type, screen resolution, and language preferences.
- Usage data: Pages visited, time spent on pages, links clicked, and navigation patterns.
- Network information: IP address, approximate geographic location (city/region level), and referring URL.
- Cookies and similar technologies: We use cookies, web beacons, and similar technologies to collect usage data, remember preferences, and improve our Website experience. See Section 7 (Cookies and Tracking Technologies) for details.
1.3 Protected Health Information (PHI)
In the course of providing our Platform Services to healthcare organizations ("Customers"), MedSynthea may process protected health information (PHI) as defined under the Health Insurance Portability and Accountability Act of 1996, as amended ("HIPAA"), and its implementing regulations.
Important: MedSynthea processes PHI solely on behalf of our Customers and under the terms of a Business Associate Agreement ("BAA") executed with each Customer. We do not collect PHI directly from patients through our Website. PHI processed through our Platform is governed by the applicable BAA and HIPAA requirements, not solely by this Privacy Policy.
MedSynthea's Platform is designed with a zero-trust security architecture that de-identifies PHI before any AI reasoning occurs:
- PHI Scrubber: All HIPAA-defined identifiers are stripped from patient data before it reaches the AI processing layer.
- Token Vault: De-identified data elements are replaced with encrypted tokens that expire automatically after 15 minutes (15-minute TTL).
- 0% PHI in system logs: No protected health information appears in MedSynthea's system logs. System logs capture agent activity and workflow decisions—never patient-identifiable information.
2. How We Use Your Information
2.1 Personal Information
We use the personal information we collect for the following purposes:
- Providing and improving our Services: To operate, maintain, and improve the Website and Platform, including responding to your inquiries and support requests.
- Communications: To send you information about our Services, including product updates, security notifications, and administrative messages. If you have opted in to marketing communications, we may also send you newsletters, industry insights, and promotional content.
- Demo and sales engagement: To schedule and personalize product demonstrations, respond to pricing inquiries, and manage the sales process.
- Analytics and improvement: To understand how our Website is used, identify trends, diagnose technical issues, and improve the user experience.
- Security and fraud prevention: To protect the security and integrity of our Website, Platform, and Services, and to detect and prevent fraudulent or unauthorized activity.
- Legal compliance: To comply with applicable laws, regulations, legal processes, or governmental requests.
2.2 Protected Health Information
MedSynthea uses PHI solely as permitted and required under the applicable BAA and HIPAA regulations. PHI is used exclusively for the purposes of performing revenue cycle management services on behalf of our Customers, including:
- Insurance eligibility verification and benefits analysis
- Clinical documentation processing and structuring
- Medical coding (ICD-10, CPT, HCPCS)
- Claims validation, submission, and follow-up
- Denial risk assessment and management
- Payment posting and financial reconciliation
MedSynthea does not use PHI for marketing, advertising, or any purpose not authorized by the applicable BAA and HIPAA.
4. Data Security
MedSynthea implements administrative, technical, and physical safeguards designed to protect personal information and PHI from unauthorized access, use, alteration, and destruction.
4.1 Technical Safeguards
- Encryption: All data is encrypted in transit using TLS 1.2+ and at rest using AES-256 encryption.
- Access controls: Role-based access control (RBAC) governs access to all Platform functions and data. User authentication is required for all Platform access.
- Audit logging: Agent activity, access events, and workflow decisions are logged for security monitoring and compliance review.
- Token Vault: PHI is replaced with encrypted tokens with 15-minute TTL before any AI processing occurs, limiting the window of potential exposure.
- PHI Scrubber: All HIPAA-defined identifiers are removed from data before it reaches the AI reasoning layer.
4.2 Administrative Safeguards
- Security policies and procedures: Documented policies governing data handling, access management, incident response, and workforce training.
- Incident response: Established procedures for detecting, responding to, and reporting security incidents, including breach notification in accordance with HIPAA requirements.
- Workforce training: Personnel with access to personal information or PHI receive training on data protection and privacy obligations.
4.3 Physical Safeguards
- Cloud infrastructure: MedSynthea's Platform is hosted in cloud environments with physical access controls, surveillance, environmental protections, and redundancy measures.
- Device security: Administrative access to MedSynthea systems is subject to device security policies and multi-factor authentication.
While we implement comprehensive security measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security, but we are committed to protecting your information using industry-standard practices.
5. Data Retention
5.1 Personal Information
We retain personal information for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required by law. When personal information is no longer needed, we securely delete or anonymize it.
- Account information: Retained for the duration of the account relationship and for a reasonable period thereafter to fulfill legal and operational obligations.
- Contact and inquiry information: Retained for as long as necessary to respond to your inquiry and for reasonable follow-up.
- Usage and analytics data: Retained in aggregated or anonymized form for product improvement purposes.
5.2 Protected Health Information
PHI is retained in accordance with the applicable BAA and Customer-specific data retention agreements. Upon termination of the BAA, PHI is returned or securely destroyed in accordance with the BAA terms and HIPAA requirements.
Token Vault entries expire automatically after 15-minute TTL.
6. Your Rights and Choices
6.1 Cookies
You can manage your cookie preferences through your browser settings. Please note that disabling certain cookies may affect the functionality of our Website. See Section 7 for details.
6.2 PHI Rights
Individuals seeking to exercise their rights with respect to PHI (access, amendment, accounting of disclosures, and other rights under HIPAA) should contact the healthcare organization (MedSynthea's Customer) that is the covered entity for their health information. MedSynthea will assist Customers in fulfilling these requests as required under the applicable BAA and HIPAA.
8. Children's Privacy
MedSynthea's Website and Services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child under 18, we will take steps to delete that information promptly. If you believe that a child has provided us with personal information, please contact us so we can take appropriate action.
9. International Users
MedSynthea is headquartered in the United States. If you access our Website or Services from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your jurisdiction. By using our Website or Services, you consent to the transfer of your information to the United States.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will post the updated Privacy Policy on this page with a revised "Last Updated" date. If the changes are significant, we will provide additional notice through our Website or by email to registered users.
We encourage you to review this Privacy Policy periodically for the latest information on our privacy practices.
12. HIPAA-Specific Disclosures
MedSynthea operates as a Business Associate under HIPAA when processing PHI on behalf of covered entity Customers. The following disclosures apply specifically to our handling of PHI:
- Business Associate Agreement: MedSynthea executes a BAA with each Customer that is a covered entity or business associate under HIPAA. The BAA defines the permitted uses and disclosures of PHI, required safeguards, breach notification obligations, subcontractor requirements, and PHI return or destruction upon termination.
- Minimum Necessary Standard: MedSynthea's Platform is designed to access and process only the minimum PHI necessary to perform the authorized revenue cycle management services.
- Breach Notification: In the event of a breach of unsecured PHI, MedSynthea will notify the affected Customer in accordance with the timeframes and requirements specified in the BAA and HIPAA Breach Notification Rule.
- Subcontractor Management: If MedSynthea engages subcontractors that access PHI, we require those subcontractors to execute agreements with data protection obligations at least as stringent as our BAA commitments, in accordance with the HIPAA subcontractor flow-down requirement.
- No Sale of PHI: MedSynthea does not sell PHI under any circumstances.
- No Use of PHI for Marketing: MedSynthea does not use PHI for marketing or advertising purposes.
- De-Identification: MedSynthea's Platform de-identifies PHI before AI processing using the PHI Scrubber and Token Vault architecture. De-identified data is not subject to HIPAA restrictions, but MedSynthea maintains its protective controls regardless.