Scope
This policy applies to information collected through acuityhealth.io, business inquiries, and Acuity Health services. It does not replace the privacy notice of a medical practice, healthcare provider, or other customer that determines how patient information is used.
Our services support administrative patient access and practice operations. They do not provide medical advice, diagnose conditions, independently provide clinical triage, or replace emergency services.
Information we collect
The information we receive depends on how you interact with us and how a customer configures its service. We collect information you provide directly and limited technical or operational information generated when the website or service is used.
- Business and website information, such as your name, organization, business email, phone number, and the details included in an inquiry.
- User identity and authorization information used to identify Users and control access to a Practice, Location, or role.
- Patient-access information needed for an authorized workflow, which may include contact details, call audio or transcripts when configured, appointment information, and practice-provided rules.
- Technical and operational information, such as device or browser data, IP address, session identifiers, service requests, integration outcomes, errors, and security events.
How we use information
We use information for the purposes described when it is collected, to perform our agreements, to operate and protect our business, and as otherwise permitted or required by law.
- Respond to inquiries, evaluate potential engagements, and communicate about requested services.
- Provide, configure, support, and improve authorized patient-access and practice workflows.
- Authenticate users, limit access, protect service integrity, investigate failures, and respond to security concerns.
- Maintain operational evidence, meet contractual obligations, and comply with applicable legal requirements.
HIPAA and customer-directed services
When Acuity Health acts as a business associate under the Health Insurance Portability and Accountability Act (HIPAA), we use and disclose protected health information as permitted by the applicable Business Associate Agreement, customer instructions, and law.
The customer remains responsible for its clinical decisions, patient notices, authorized users, workflows, disclosures, and system-of-record obligations. This public policy is not a Business Associate Agreement, certification, or legal opinion.
Security and retention
We use administrative, technical, and contractual safeguards designed for the information and services in scope. No internet transmission, software, or storage system can guarantee absolute security.
We retain information according to customer agreements, service needs, security requirements, and applicable legal obligations, then delete or return it as required. Retention can vary by data type and deployment.
Your choices and third-party services
You may ask us to update or delete information submitted directly through our website, or opt out of marketing messages through the instructions in those messages. We evaluate requests based on our relationship with you and applicable obligations.
Our website or services may link to or connect with third-party services. Their own privacy terms apply to information they control. Patients should direct medical-record or patient-rights requests to the medical practice responsible for the record.
Changes to this policy
We may update this policy as our services or practices change. We will post the revised policy here and update the date above. Material contractual requirements remain governed by the applicable signed agreement.
Questions about privacy?
Contact Data Buddies Solutions LLC d/b/a Acuity Health about this policy or our general privacy practices. Patients seeking access to, correction of, or information about a medical record should contact the medical practice that controls that record.
chase@acuityhealth.io