Privacy Policy
Effective June 2026
This Privacy Policy explains how MediCRM collects, uses, and protects information, including protected health information (PHI), when your organization uses the Service.
1. Information We Collect
We collect: (a) account information such as your name, email, organization, and role; (b) protected health information you enter about your clients — including contact details, medical history, appointments, session notes, consents, and disclosures; and (c) usage and audit data such as logins and PHI-access events.
2. How We Use Information
We use information solely to provide and secure the Service: authenticating users, isolating each organization's data, sending transactional emails (such as appointment reminders and team invitations), processing subscription payments, and maintaining audit trails. We do not sell personal information or PHI.
3. HIPAA & Your Role
Your organization is the covered entity or business associate that controls the PHI it enters. MediCRM acts as a business associate and processes PHI under a Business Associate Agreement. We only use and disclose PHI as permitted by that agreement and applicable law.
4. Data Isolation & Security
Every record is tagged to your organization and access is scoped so one practice cannot view another's data. We apply encryption in transit, role-based access control, and access logging. Access to PHI is limited to authorized users within your organization.
5. Sub-processors
We rely on vetted service providers for infrastructure, transactional email delivery, and payment processing. These providers are bound by confidentiality and data-protection obligations consistent with this Policy and the BAA.
6. Data Retention
We retain organization and PHI data for as long as your account is active or as needed to provide the Service and comply with legal obligations. On termination, data is handled per the BAA and applicable law.
7. Your Choices & Rights
Administrators can manage team access, export client disclosure records, and request account closure. Individuals seeking to exercise rights over their PHI should contact the treating practice, which controls that data.
8. Contact
For privacy questions, contact your practice administrator or MediCRM support. We may update this Policy and will notify you of material changes in-app or by email.
