Privacy Policy
Last Updated: September 6, 2026
Pre-Release Notice
PracticeCore AI is a product in development, scheduled for general availability in June 2027. This policy describes how the product is designed to handle information and how this website handles the information you give us today (a demo request or a feature request). No practice runs on PracticeCore AI in production before general availability.
HIPAA
PracticeCore AI is designed to the HIPAA Privacy Rule and Security Rule requirements for Protected Health Information (PHI). A Business Associate Agreement (BAA) is part of every customer agreement at general availability. PracticeCore AI does not claim any third-party certification.
Information We Collect
Patient Information:
- Name, date of birth, contact information
- Appointment scheduling information
- Insurance and billing information
- Clinical treatment information
- Communication preferences (SMS opt-in status)
Practice Information:
- Practice name and contact details
- Provider credentials and licensing
- Billing and payment information
- Usage analytics and system logs
How We Use Your Information
- Provide practice management services
- Send appointment reminders via SMS/email (with consent)
- Process insurance claims and billing
- Maintain patient records
- Facilitate patient-practice communication
- Improve our services and user experience
- Comply with legal and regulatory requirements
SMS Appointment Reminders
Opt-In Required: We only send SMS messages to patients who explicitly opt in via:
- Online booking checkbox
- Verbal phone consent (documented)
- Written intake forms
- Patient portal settings
Minimal PHI: SMS messages contain only minimal PHI (appointment date/time). You can opt-out anytime by replying STOP.
See our SMS Terms for full details.
We DO NOT Sell Your Information
We never sell, rent, or trade patient health information. Your PHI is protected under HIPAA and is only used for treatment, payment, and healthcare operations as permitted by law.
Data Security
The product is built with these security measures:
- Encryption: AES-256 encryption at rest, TLS 1.3 in transit
- Access Control: Role-based access with multi-factor authentication
- Monitoring: 24/7 security monitoring and intrusion detection
- Auditing: Security review and penetration testing before launch, and on a schedule after it
- Backups: Encrypted backups with disaster recovery
- Compliance: SOC 2 is on the roadmap for launch. No certification is claimed today.
Your Rights
Under HIPAA and applicable privacy laws, you have the right to:
- Access: Request copies of your health information
- Amendment: Request corrections to your records
- Restriction: Request limits on use or disclosure
- Accounting: Receive a list of disclosures we have made
- Opt-Out: Unsubscribe from SMS/email communications
- Complaint: File a complaint if you believe your rights have been violated
Data Retention
We retain patient health information in accordance with HIPAA requirements and state regulations. Typically, records are retained for a minimum of 6 years from the date of last service, or longer as required by law. You may request deletion of your data subject to legal retention requirements.
Third-Party Services
We use third-party services to provide our platform. Before any PHI is processed at general availability, every third party with access to it will have signed a Business Associate Agreement:
- Cloud infrastructure providers (data hosting)
- Payment processors (billing)
- Communication providers (SMS/email)
- Analytics services (anonymized usage data only)
Cookies and Tracking
Our website uses essential cookies for functionality and security. We use analytics cookies to understand how visitors use our site (no PHI is collected through cookies). You can control cookie preferences through your browser settings.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the “Last Updated” date. We encourage you to review this policy periodically.
Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us:
PracticeCore AI
Privacy Officer
Email: privacy@practice-core-ai.com
HIPAA Compliance: hipaa@practice-core-ai.com