Clinapse Privacy Policy

Effective Date: May 20, 2026
Last Updated: May 20, 2026

1. Introduction & Scope

Clinapse, Inc. ("Clinapse," "we," "us," or "our") operates a multi-tenant coordination and reporting layer for healthcare practices that is built to support HIPAA compliance. The Platform connects to a practice's existing systems — such as its EHR — to bring scheduling coordination, denial tracking, and financial reporting into one view; it augments rather than replaces the EHR, practice-management, or billing platform. The Platform includes the website located at clinapse.com, the web application at app.clinapse.com, and all associated tools, services, and integrations (collectively, the "Platform").

This Privacy Policy explains how we collect, use, disclose, and secure information when you visit our website, register for an account, or use the Platform.

HIPAA & Protected Health Information (PHI) Statement

Clinapse acts as a Business Associate to the healthcare practice(s) it serves and executes a Business Associate Agreement (BAA) where one is required. The practices we serve are Covered Entities under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA").

2. Information We Collect

We collect several categories of information depending on how you interact with Clinapse:

A. Information You Provide Directly to Us

B. Information Collected Automatically

C. Information from Third-Party Integrations

Clinapse enables healthcare practices to integrate with leading medical, operations, and advertising platforms. Depending on the integrations enabled by your practice, we may ingest:

3. How We Use Your Information

We process personal data (excluding PHI, which is strictly limited by BAAs) for the following business purposes:

Purpose Description Legal Basis / Governance
Service Provisioning Managing practice signups, setting up dedicated tenant databases, executing onboarding wizards, and providing coordination and reporting tools. Contractual Obligation
Integrations Management Securing OAuth credentials, synchronizing schedules, and fetching external practice metrics (e.g., athenahealth, Square, Google). Consent / Client-Initiated
System Security Rate limiting to help mitigate brute-force attacks, validating file uploads (MIME/size filtering), and enforcing multi-factor authentication (MFA). Legitimate Interest / Compliance
HIPAA Compliance Maintaining append-only, immutable audit trails of Platform activities for a minimum of seven (7) years. Federal Legal Mandate
Communications & Support Sending system updates, security advisories, billing invoices, and responding to customer support inquiries. Contractual / Legitimate Interest

4. How We Share & Disclose Information

We respect your privacy and enforce strict isolation protocols. We do not sell, rent, or trade any personal information, and we never share Patient PHI except as permitted under a signed BAA or required by law.

We may disclose Platform data under the following circumstances:

5. Data Security, Isolation & Retention

Clinapse implements a security program designed to align with HIPAA requirements and the principles of the HITRUST and SOC 2 frameworks:

A. Hybrid Multi-Tenancy & Data Isolation

B. Session and Access Controls

C. Data Retention & Soft Deletes

6. Your Rights & Choices

A. For Practice Administrative Users

As a Clinapse account holder, you have control over your administrative data:

B. For Patients of Clinapse Clients

C. Jurisdictional & State-Specific Rights

Depending on your jurisdiction, state-specific privacy laws (such as the California Consumer Privacy Act/CCPA or state healthcare privacy statutes) may grant you additional rights regarding your business data. These rights generally include the right to know what personal information is collected, request its deletion, and opt out of certain disclosures. Clinapse will honor these rights in accordance with applicable state laws.

7. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our operational workflows, security systems, or legal requirements. When updates occur, we will post the revised version on this page and update the "Effective Date" at the top of this document. We encourage you to review this policy periodically to stay informed about how we protect your information.

8. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy, our data practices, or our security frameworks, please contact our Security & Compliance Officer: