Privacy Policy
Last updated: January 28, 2026
Our Commitment to Privacy
InnovateMed Solutions ("we", "our", or "us") is committed to protecting your privacy and the privacy of your patients. As a healthcare technology provider, we understand the critical importance of data security and comply with all applicable healthcare privacy regulations, including HIPAA.
1. Information We Collect
Account Information
- Name and professional credentials
- Email address
- Healthcare facility/practice information
- Billing and payment information
Protected Health Information (PHI)
- Patient encounter audio recordings (temporarily processed)
- Generated clinical documentation (SOAP notes, HPIs)
- Patient demographic information entered by providers
All PHI is handled in strict accordance with HIPAA regulations. See our HIPAA Compliance page for details.
Usage Data
- Feature usage patterns (anonymized)
- Error logs and performance data
- Device and browser information
2. How We Use Your Information
- Service Delivery: Process audio recordings and generate clinical documentation
- Account Management: Manage your subscription, billing, and support requests
- Service Improvement: Analyze anonymized usage patterns to improve our AI models and features
- Communication: Send important service updates, security alerts, and (with consent) product news
- Compliance: Meet legal and regulatory obligations
3. Data Retention
| Data Type | Retention Period |
|---|---|
| Audio recordings | Deleted within 24 hours after processing |
| Generated documentation | Retained until you delete or close your account |
| Account information | Duration of account + 30 days after closure |
| Billing records | 7 years (legal requirement) |
| Anonymized analytics | Indefinitely (no personal data) |
4. Data Security
We implement industry-leading security measures:
- AES-256 encryption for data at rest
- TLS 1.3 encryption for data in transit
- AWS HIPAA-compliant infrastructure
- Regular security audits and penetration testing
- Role-based access controls
- Multi-factor authentication options
5. Third-Party Services
We use the following third-party services, all of which maintain HIPAA compliance:
- Amazon Web Services (AWS): HIPAA-compliant cloud infrastructure
- AWS Transcribe Medical: Speech-to-text processing
- Stripe: Payment processing (does not receive PHI)
We have Business Associate Agreements (BAAs) with all vendors who may access PHI.
6. Your Rights
You have the right to:
- Access: Request a copy of your data
- Correction: Request corrections to inaccurate data
- Deletion: Request deletion of your data (subject to legal retention requirements)
- Portability: Export your data in a standard format
- Opt-out: Unsubscribe from marketing communications
To exercise these rights, contact us at privacy@innovatemedsolutions.com
7. Children's Privacy
Our service is designed for healthcare professionals and is not intended for use by individuals under 18 years of age. We do not knowingly collect personal information from children.
8. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of material changes via email and/or a prominent notice on our service. Continued use after changes constitutes acceptance.
9. Contact Us
For privacy-related questions or concerns: