Contents
1. Scope & who we are
MedCRM (the "Platform") is a healthcare customer-relationship-management application operated by Cardio AI ("Cardio AI," "we," "us") and offered under the Cardio AI brand. This Privacy Statement explains how we handle information when a healthcare organization ("Customer") and its authorized users access the Platform.
For most health information processed in the Platform, the Customer is the data controller / HIPAA covered entity and Cardio AI acts as a data processor / business associate that processes such data only under the Customer's instructions and any executed Business Associate Agreement ("BAA").
2. Information we collect
Account & organization data
Names, work email addresses, roles, organization name and email domain, and authentication data (passwords are stored only as salted Argon2 hashes; we never store them in plaintext).
Health & operational data entered by users
Patient records, appointments, care-management enrollments and activities, care gaps, telehealth session metadata, messages, quality measures, and related clinical/operational content the Customer chooses to store.
Usage & device data
Log data such as IP address, timestamps, actions taken (audit logs), browser type, and security events used to operate, secure, and troubleshoot the Platform.
Billing data
Subscription tier and status. Card payments are processed by our payment provider (Stripe); we do not store full card numbers.
3. Protected Health Information (PHI)
When the Platform is used with real PHI under a signed BAA, we process PHI solely to provide the contracted services, safeguard it with administrative, physical, and technical measures, and do not sell it or use it for advertising. Until a BAA and compliance review are complete, the Platform must be used only with test or de-identified data.
4. How we use information
- Provide, maintain, and secure the Platform and its features.
- Authenticate users and enforce role-based access and approvals.
- Operate care-management, telehealth, reporting, analytics, and interoperability features at the Customer's direction.
- Detect, investigate, and prevent security incidents, fraud, and misuse.
- Provide support and communicate service and security notices.
- Comply with legal obligations.
We do not sell personal information or PHI, and we do not use PHI for targeted advertising.
5. Legal bases
Where applicable law (such as the GDPR) requires a legal basis, we rely on: performance of our contract with the Customer; compliance with legal obligations; our legitimate interests in securing and improving the Platform; and, where required, consent. For PHI, processing is governed by HIPAA and the applicable BAA.
6. Sharing & disclosure
| Recipient | Purpose |
|---|---|
| Subprocessors (hosting, database, email, payments, video) | Operate the Platform under contract and, where relevant, a BAA. |
| The Customer's own authorized users | Access governed by the Customer's role and approval settings. |
| Legal / regulatory authorities | When required by law or to protect rights, safety, and security. |
| Successor entity | In a merger, acquisition, or asset transfer, subject to this Statement. |
7. Third-party integrations
The Platform can connect, at the Customer's configuration, to external systems including FHIR servers, HL7 gateways, and DICOM/PACS imaging systems, as well as payment (Stripe) and telehealth video (Jitsi/WebRTC) services. When enabled, data is exchanged with those systems under the Customer's direction and the third party's own terms. Public telehealth video servers are not HIPAA-compliant and must be replaced with a self-hosted or BAA-covered deployment before use with PHI.
8. Data security
We apply layered safeguards including encrypted transport (TLS), hashed credentials, role-based and permission-based access control, account-approval workflows, session expiration, and audit logging. No method of transmission or storage is perfectly secure; we work to protect information but cannot guarantee absolute security.
9. Data retention
We retain data for as long as the Customer's account is active or as needed to provide the Platform, then delete or de-identify it in accordance with the Customer's instructions, the BAA, and applicable law. Customers may request export or deletion of their data as described in their agreement.
10. Your privacy rights
Depending on your jurisdiction (e.g., GDPR, UK GDPR, CCPA/CPRA and other US state laws), individuals may have rights to access, correct, delete, restrict, or port personal information, and to object to certain processing. Because the Customer controls most data in the Platform, please direct requests to your organization; we assist Customers in fulfilling verified requests as required by law and the BAA.
11. Cookies & analytics
The Platform uses strictly necessary cookies and local storage to keep you signed in and maintain your session. It does not use third-party advertising cookies. Any product analytics are limited to operating and improving the service.
12. Children's privacy
The Platform is intended for use by healthcare organizations and their staff, not by children, and is not directed to individuals under 16. Pediatric patient records entered by a Customer are handled as PHI under the applicable agreement.
13. International transfers
If information is processed in a country other than where it was collected, we use appropriate safeguards (such as standard contractual clauses) where required by law.
14. Changes to this Statement
We may update this Statement to reflect changes to the Platform or the law. Material changes will be communicated through the Platform or to the Customer's administrator, and the "Last updated" date above will change.
15. Contact us
Cardio AI — Privacy & Support
Email: support@cardioailive.com
Product: MedCRM Healthcare Suite (Cardio AI)
For data-subject or HIPAA requests about records in your organization's account, contact your organization's administrator or Privacy Officer.