Introduction

Medocs is a sophisticated AI-powered medical scribe and electronic health record (EHR) platform designed to streamline clinical documentation, billing, and practice management for healthcare providers. We are committed to safeguarding the privacy and security of every individual who uses our platform, visits our website, or interacts with our services.

This Privacy Policy describes how MEDOCS LLC ("Medocs," "we," "us," or "our") collects, uses, discloses, and protects your personal information when you access or use our website at medocs.ai, our mobile applications, and all related services (collectively, the "Services"). By using the Services, you agree to the practices described in this Privacy Policy.

We comply with all applicable data protection and privacy laws, including but not limited to the Health Insurance Portability and Accountability Act (HIPAA), the California Consumer Privacy Act (CCPA), and the General Data Protection Regulation (GDPR) where applicable.

Information We Collect

Personal Information

When you register for an account, request a demo, or contact us, we may collect the following personal information:

  • Full name, professional title, and credentials
  • Email address and phone number
  • Practice or organization name and address
  • National Provider Identifier (NPI) and license information
  • Login credentials (passwords are encrypted and never stored in plaintext)

Usage Data

We automatically collect certain information when you interact with our Services, including:

  • Device type, operating system, and browser information
  • IP address and approximate geographic location
  • Pages visited, features used, and session duration
  • Referring URLs and search terms used to find our website
  • Interaction patterns within the application (clicks, navigation paths)

Payment Information

When you subscribe to a paid plan, we collect billing information including your name, billing address, and payment method details. Payment card information is processed directly by our PCI-DSS-compliant payment processor and is never stored on our servers.

Sensitive Health Data

In the course of providing our AI Scribe, EHR, and related clinical documentation services, our platform may process Protected Health Information (PHI) as defined under HIPAA. This data may include:

  • Patient names, dates of birth, and contact information
  • Medical records, diagnoses, treatment plans, and clinical notes
  • Audio recordings of clinical encounters (used for transcription)
  • Prescription and medication data
  • Insurance and billing codes (CPT, ICD-10)

All PHI is handled in strict accordance with HIPAA regulations. We enter into Business Associate Agreements (BAAs) with covered entities and implement administrative, technical, and physical safeguards to protect this data.

How We Use Your Information

We use the information we collect for the following purposes:

  • To provide, operate, maintain, and improve the Services
  • To process transactions and manage your subscription
  • To generate AI-powered clinical documentation, coding suggestions, and billing recommendations
  • To personalize your experience and deliver specialty-specific features
  • To communicate with you about updates, support requests, and promotional offers (with your consent)
  • To monitor and analyze usage trends to improve performance and reliability
  • To detect, investigate, and prevent fraudulent, unauthorized, or illegal activity
  • To comply with legal obligations, including HIPAA, and respond to lawful requests
  • To train and improve our AI models using de-identified and aggregated data only, unless you explicitly opt in to contribute identifiable data for model improvement

How We Share Your Information

We do not sell your personal information. We may share your information only in the following circumstances:

  • Service Providers: We share data with trusted third-party vendors who assist us in operating the Services, such as cloud hosting providers, payment processors, analytics platforms, and customer support tools. These providers are contractually obligated to protect your data.
  • Business Associates: For PHI, we only share data with entities that have executed a BAA with us, as required by HIPAA.
  • Legal Compliance: We may disclose information if required by law, regulation, legal process, or governmental request.
  • Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of the transaction. We will notify you of any such change in ownership or control.
  • With Your Consent: We may share information for other purposes with your explicit consent.

Data Retention

We retain your personal information for as long as your account is active or as needed to provide you with the Services. Specific retention periods are determined by:

  • The nature of the data and the purpose for which it was collected
  • Legal and regulatory requirements (e.g., medical records retention laws, HIPAA requirements)
  • Our legitimate business interests, such as fraud prevention and dispute resolution

Audio recordings used for transcription are automatically deleted after processing unless you choose to retain them. De-identified and aggregated data may be retained indefinitely for research and analytics purposes.

When your account is terminated, we will delete or de-identify your personal information within a reasonable timeframe, subject to legal retention requirements.

Your Rights and Choices

Depending on your jurisdiction, you may have the following rights regarding your personal information:

  • Access: Request a copy of the personal information we hold about you.
  • Correction: Request correction of inaccurate or incomplete information.
  • Deletion: Request deletion of your personal information, subject to legal retention obligations.
  • Portability: Request your data in a structured, machine-readable format.
  • Opt-Out: Opt out of marketing communications at any time by clicking the unsubscribe link or contacting us.
  • Restriction: Request that we restrict the processing of your personal information in certain circumstances.
  • Objection: Object to the processing of your personal information for specific purposes.

To exercise any of these rights, please contact us at contact@medocs.ai. We will respond to your request within the timeframe required by applicable law.

For HIPAA-related data rights, patients should contact their healthcare provider directly. Medocs acts as a Business Associate and processes PHI on behalf of covered entities.

Data Security

We implement comprehensive security measures designed to protect your information from unauthorized access, alteration, disclosure, or destruction. These measures include:

  • AES-256 encryption of data at rest and TLS 1.2+ encryption for data in transit
  • Role-based access controls with multi-factor authentication
  • Regular security audits, penetration testing, and vulnerability assessments
  • Comprehensive audit logging and real-time monitoring
  • Employee security awareness training and background checks
  • Physical security controls at our data center facilities
  • Incident response procedures and breach notification protocols

While we strive to use commercially acceptable means to protect your data, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee absolute security.

International Transfers

Medocs is headquartered in the United States. If you access the Services from outside the United States, your information may be transferred to, stored, and processed in the United States or other countries where our service providers operate.

For users in the European Economic Area (EEA), United Kingdom, or other jurisdictions with data transfer restrictions, we use appropriate safeguards such as Standard Contractual Clauses (SCCs) approved by the European Commission to ensure your data receives an adequate level of protection.

By using the Services, you consent to the transfer of your information to the United States and other jurisdictions as described in this Privacy Policy.

Cookies and Tracking Technologies

We use cookies and similar tracking technologies to enhance your experience, analyze usage patterns, and deliver relevant content. The types of technologies we use include:

  • Essential Cookies: Required for the Services to function properly, such as authentication and session management.
  • Analytics Cookies: Help us understand how users interact with the Services so we can improve performance and usability.
  • Preference Cookies: Remember your settings and preferences for a personalized experience.
  • Marketing Cookies: Used to deliver relevant advertisements and measure campaign effectiveness (only with your consent where required by law).

You can manage cookie preferences through your browser settings. Please note that disabling certain cookies may limit the functionality of the Services.

We may also use web beacons, pixel tags, and similar technologies in emails and on our website to track engagement and improve our communications.

Children's Privacy

The Services are not intended for individuals under the age of 18, and we do not knowingly collect personal information from children. If we become aware that we have inadvertently collected personal information from a child under 18, we will take prompt steps to delete that information.

If you are a parent or guardian and believe your child has provided personal information to us, please contact us at contact@medocs.ai so we can take appropriate action.

Note: Medocs may process the health information of minor patients on behalf of their healthcare providers as part of our clinical documentation services, in which case the healthcare provider serves as the covered entity responsible for obtaining the necessary consents.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this page
  • Notify you via email or through an in-app notification
  • Provide a summary of the key changes when appropriate

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information. Your continued use of the Services after any changes constitutes your acceptance of the updated Privacy Policy.

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

For HIPAA-related inquiries or to report a potential data breach, please email us at contact@medocs.ai with the subject line "HIPAA Inquiry" and we will respond promptly.