MedSynthea

Privacy Policy

Effective Date: January 1, 2026

Last Updated: January 1, 2026

Introduction

MedSynthea is committed to protecting the privacy and security of your personal information. This Privacy Policy describes how we collect, use, store, disclose, and protect personal information and protected health information ("PHI") in connection with our website at medsynthea, our autonomous revenue cycle management platform (the "Platform"), and our related services (collectively, the "Services").

By accessing our Website or using our Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with the practices described in this Privacy Policy, please do not use our Website or Services.

This Privacy Policy does not apply to third-party websites, services, or applications that may be linked from our Website. We encourage you to review the privacy policies of any third-party services you access.

1. Information We Collect

1.1 Information You Provide Directly

We collect personal information that you voluntarily provide to us, including when you:

  • Request a demo or contact us: Name, email address, phone number, organization name, job title, and any additional information you include in your message.
  • Create an account or sign in: Name, email address, organization affiliation, role, and authentication credentials.
  • Subscribe to communications: Email address and communication preferences.
  • Submit support requests: Name, email address, organization name, and details of your support inquiry.
  • Engage with sales or partnerships: Contact information, organizational details, and information relevant to evaluating our Services.

1.2 Information Collected Automatically

When you visit our Website, we may automatically collect certain information, including:

  • Device and browser information: Browser type, operating system, device type, screen resolution, and language preferences.
  • Usage data: Pages visited, time spent on pages, links clicked, and navigation patterns.
  • Network information: IP address, approximate geographic location (city/region level), and referring URL.
  • Cookies and similar technologies: We use cookies, web beacons, and similar technologies to collect usage data, remember preferences, and improve our Website experience. See Section 7 (Cookies and Tracking Technologies) for details.

1.3 Protected Health Information (PHI)

In the course of providing our Platform Services to healthcare organizations ("Customers"), MedSynthea may process protected health information (PHI) as defined under the Health Insurance Portability and Accountability Act of 1996, as amended ("HIPAA"), and its implementing regulations.

Important: MedSynthea processes PHI solely on behalf of our Customers and under the terms of a Business Associate Agreement ("BAA") executed with each Customer. We do not collect PHI directly from patients through our Website. PHI processed through our Platform is governed by the applicable BAA and HIPAA requirements, not solely by this Privacy Policy.

MedSynthea's Platform is designed with a zero-trust security architecture that de-identifies PHI before any AI reasoning occurs:

  • PHI Scrubber: All HIPAA-defined identifiers are stripped from patient data before it reaches the AI processing layer.
  • Token Vault: De-identified data elements are replaced with encrypted tokens that expire automatically after 15 minutes (15-minute TTL).
  • 0% PHI in system logs: No protected health information appears in MedSynthea's system logs. System logs capture agent activity and workflow decisions—never patient-identifiable information.

2. How We Use Your Information

2.1 Personal Information

We use the personal information we collect for the following purposes:

  • Providing and improving our Services: To operate, maintain, and improve the Website and Platform, including responding to your inquiries and support requests.
  • Communications: To send you information about our Services, including product updates, security notifications, and administrative messages. If you have opted in to marketing communications, we may also send you newsletters, industry insights, and promotional content.
  • Demo and sales engagement: To schedule and personalize product demonstrations, respond to pricing inquiries, and manage the sales process.
  • Analytics and improvement: To understand how our Website is used, identify trends, diagnose technical issues, and improve the user experience.
  • Security and fraud prevention: To protect the security and integrity of our Website, Platform, and Services, and to detect and prevent fraudulent or unauthorized activity.
  • Legal compliance: To comply with applicable laws, regulations, legal processes, or governmental requests.

2.2 Protected Health Information

MedSynthea uses PHI solely as permitted and required under the applicable BAA and HIPAA regulations. PHI is used exclusively for the purposes of performing revenue cycle management services on behalf of our Customers, including:

  • Insurance eligibility verification and benefits analysis
  • Clinical documentation processing and structuring
  • Medical coding (ICD-10, CPT, HCPCS)
  • Claims validation, submission, and follow-up
  • Denial risk assessment and management
  • Payment posting and financial reconciliation

MedSynthea does not use PHI for marketing, advertising, or any purpose not authorized by the applicable BAA and HIPAA.

3. How We Share Your Information

3.1 Personal Information

We do not sell your personal information. We may share personal information in the following circumstances:

  • Service providers: We may share personal information with third-party service providers who perform services on our behalf, such as website hosting, analytics, email delivery, and customer support. These providers are contractually obligated to use your information only for the purposes of providing services to us and to protect your information in accordance with this Privacy Policy.
  • Business transfers: If MedSynthea is involved in a merger, acquisition, reorganization, or sale of assets, your personal information may be transferred as part of that transaction. We will notify you of any such change in ownership or control of your personal information.
  • Legal requirements: We may disclose personal information if required to do so by law, regulation, legal process, or governmental request, or if we believe disclosure is necessary to protect the rights, property, or safety of MedSynthea, our Customers, or others.
  • With your consent: We may share your personal information for other purposes with your explicit consent.

3.2 Protected Health Information

MedSynthea discloses PHI only as permitted or required under the applicable BAA and HIPAA regulations. We do not share, sell, or otherwise disclose PHI to third parties except as follows:

  • To the Customer: PHI is returned to the Customer organization through approved integration channels (SMART on FHIR write-back to the Customer's EHR system).
  • Subcontractors: If MedSynthea engages subcontractors that access PHI, we require those subcontractors to execute agreements with data protection obligations at least as stringent as our BAA commitments.
  • As required by law: We may disclose PHI as required by applicable federal or state law, including HIPAA-mandated disclosures.

4. Data Security

MedSynthea implements administrative, technical, and physical safeguards designed to protect personal information and PHI from unauthorized access, use, alteration, and destruction.

4.1 Technical Safeguards

  • Encryption: All data is encrypted in transit using TLS 1.2+ and at rest using AES-256 encryption.
  • Access controls: Role-based access control (RBAC) governs access to all Platform functions and data. User authentication is required for all Platform access.
  • Audit logging: Agent activity, access events, and workflow decisions are logged for security monitoring and compliance review.
  • Token Vault: PHI is replaced with encrypted tokens with 15-minute TTL before any AI processing occurs, limiting the window of potential exposure.
  • PHI Scrubber: All HIPAA-defined identifiers are removed from data before it reaches the AI reasoning layer.

4.2 Administrative Safeguards

  • Security policies and procedures: Documented policies governing data handling, access management, incident response, and workforce training.
  • Incident response: Established procedures for detecting, responding to, and reporting security incidents, including breach notification in accordance with HIPAA requirements.
  • Workforce training: Personnel with access to personal information or PHI receive training on data protection and privacy obligations.

4.3 Physical Safeguards

  • Cloud infrastructure: MedSynthea's Platform is hosted in cloud environments with physical access controls, surveillance, environmental protections, and redundancy measures.
  • Device security: Administrative access to MedSynthea systems is subject to device security policies and multi-factor authentication.

While we implement comprehensive security measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security, but we are committed to protecting your information using industry-standard practices.

5. Data Retention

5.1 Personal Information

We retain personal information for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required by law. When personal information is no longer needed, we securely delete or anonymize it.

  • Account information: Retained for the duration of the account relationship and for a reasonable period thereafter to fulfill legal and operational obligations.
  • Contact and inquiry information: Retained for as long as necessary to respond to your inquiry and for reasonable follow-up.
  • Usage and analytics data: Retained in aggregated or anonymized form for product improvement purposes.

5.2 Protected Health Information

PHI is retained in accordance with the applicable BAA and Customer-specific data retention agreements. Upon termination of the BAA, PHI is returned or securely destroyed in accordance with the BAA terms and HIPAA requirements.

Token Vault entries expire automatically after 15-minute TTL.

6. Your Rights and Choices

6.1 Cookies

You can manage your cookie preferences through your browser settings. Please note that disabling certain cookies may affect the functionality of our Website. See Section 7 for details.

6.2 PHI Rights

Individuals seeking to exercise their rights with respect to PHI (access, amendment, accounting of disclosures, and other rights under HIPAA) should contact the healthcare organization (MedSynthea's Customer) that is the covered entity for their health information. MedSynthea will assist Customers in fulfilling these requests as required under the applicable BAA and HIPAA.

7. Cookies and Tracking Technologies

7.1 What We Use

MedSynthea uses the following types of cookies and tracking technologies on our Website:

  • Essential cookies: Required for the Website to function properly, including session management and security features. These cookies cannot be disabled.
  • Analytics cookies: Used to understand how visitors interact with our Website, including pages visited, time on site, and navigation patterns. We use Google Analytics (via Google Tag Manager) to collect this data.
  • Functional cookies: Used to remember your preferences and improve your experience on subsequent visits.

7.2 Google Tag Manager

Our Website uses Google Tag Manager to manage analytics and tracking scripts. Google Tag Manager may set cookies and collect usage data in accordance with Google's Privacy Policy. For more information on how Google uses data, visit: https://policies.google.com/privacy

7.3 Managing Cookies

You can control cookies through your browser settings. Most browsers allow you to block or delete cookies. However, blocking essential cookies may prevent you from accessing certain features of our Website.

8. Children's Privacy

MedSynthea's Website and Services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child under 18, we will take steps to delete that information promptly. If you believe that a child has provided us with personal information, please contact us so we can take appropriate action.

9. International Users

MedSynthea is headquartered in the United States. If you access our Website or Services from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your jurisdiction. By using our Website or Services, you consent to the transfer of your information to the United States.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will post the updated Privacy Policy on this page with a revised "Last Updated" date. If the changes are significant, we will provide additional notice through our Website or by email to registered users.

We encourage you to review this Privacy Policy periodically for the latest information on our privacy practices.

12. HIPAA-Specific Disclosures

MedSynthea operates as a Business Associate under HIPAA when processing PHI on behalf of covered entity Customers. The following disclosures apply specifically to our handling of PHI:

  • Business Associate Agreement: MedSynthea executes a BAA with each Customer that is a covered entity or business associate under HIPAA. The BAA defines the permitted uses and disclosures of PHI, required safeguards, breach notification obligations, subcontractor requirements, and PHI return or destruction upon termination.
  • Minimum Necessary Standard: MedSynthea's Platform is designed to access and process only the minimum PHI necessary to perform the authorized revenue cycle management services.
  • Breach Notification: In the event of a breach of unsecured PHI, MedSynthea will notify the affected Customer in accordance with the timeframes and requirements specified in the BAA and HIPAA Breach Notification Rule.
  • Subcontractor Management: If MedSynthea engages subcontractors that access PHI, we require those subcontractors to execute agreements with data protection obligations at least as stringent as our BAA commitments, in accordance with the HIPAA subcontractor flow-down requirement.
  • No Sale of PHI: MedSynthea does not sell PHI under any circumstances.
  • No Use of PHI for Marketing: MedSynthea does not use PHI for marketing or advertising purposes.
  • De-Identification: MedSynthea's Platform de-identifies PHI before AI processing using the PHI Scrubber and Token Vault architecture. De-identified data is not subject to HIPAA restrictions, but MedSynthea maintains its protective controls regardless.