Privacy Policy

How EHR360 collects, uses, protects, and safeguardspersonal and protected health information.

Effective Date: August 18, 2026

Last Updated: August 18, 2026

1. Introduction

EHR360 (“EHR360,” “we,” “us,” or “our”) is committed to protecting the privacy and security of personal information and protected health information (“PHI”).

This Privacy Policy explains how we collect, use, disclose, retain, and protect information when you:

  • Visit the EHR360 website;
  • Request information or a demonstration of our Services;
  • Use the EHR360 platform or related services;
  • Access EHR360 as an authorized healthcare professional, staff member, administrator, or other user; or
  • Interact with services made available through a healthcare provider using EHR360.

This Privacy Policy applies to EHR360’s website, electronic health record platform, practice management capabilities, AI-enabled features, and related services collectively referred to as the “Services.”

2. EHR360's Role Under HIPAA

When EHR360 creates, receives, maintains, or transmits PHI on behalf of a healthcare provider or other HIPAA-covered entity, EHR360 generally acts as a Business Associate.

In these circumstances, EHR360 processes PHI in accordance with applicable law, the applicable Business Associate Agreement (“BAA”), and instructions from the healthcare organization we serve.

Healthcare providers remain responsible for their relationships with patients, their own HIPAA compliance obligations, and their Notices of Privacy Practices.

If you are a patient seeking access to, correction of, or other rights regarding your medical record, you should generally contact your healthcare provider directly.

This Privacy Policy is not intended to replace a healthcare provider's HIPAA Notice of Privacy Practices.

3. Information We Collect

The information we collect depends on how you interact with EHR360.

Personal and Business Information

We may collect information such as:

  • Name
  • Email address
  • Phone number
  • Organization or medical practice name
  • Job title or professional role
  • Account credentials
  • Professional information
  • Billing and payment-related information
  • Information submitted through contact, demo, or support forms

Protected Health Information

When EHR360 provides Services to healthcare organizations, the platform may process PHI on their behalf, including:

  • Patient demographic information
  • Contact information
  • Medical histories
  • Diagnoses
  • Clinical notes
  • Treatment information
  • Medications and prescriptions
  • Laboratory and diagnostic results
  • Appointment information
  • Insurance information
  • Billing information
  • Communications related to patient care
  • Other information maintained as part of a healthcare record

The healthcare organization using EHR360 generally determines what patient information is entered into and processed through the platform.

Usage and Technical Information

When you access our website or Services, we may automatically collect certain information, such as:

  • IP address
  • Browser type
  • Device information
  • Operating system
  • Pages or features accessed
  • Date and time of access
  • Log and diagnostic information
  • Cookie and similar technology data
  • Information about interactions with our Services

4. How We Use Information

We may use personal information to:

  • Provide, operate, maintain, and support EHR360;
  • Create and manage user accounts;
  • Authenticate users and manage access;
  • Respond to inquiries and demo requests;
  • Provide customer support;
  • Process payments and manage customer accounts;
  • Configure and improve platform functionality;
  • Maintain the security and reliability of our Services;
  • Analyze how our website and Services are used;
  • Communicate administrative or service-related information;
  • Comply with applicable legal and regulatory requirements; and
  • Protect our users, customers, Services, and organization.

When processing PHI as a Business Associate, EHR360 uses and discloses PHI only as permitted by applicable law, the relevant BAA, and our contractual relationship with the healthcare organization.

5. AI-Enabled Features and the EHR360 AI Workforce

EHR360 includes AI-enabled functionality designed to assist with healthcare and practice workflows.

Depending on the features used, AI-enabled functionality may process information to support activities such as:

  • Patient communication
  • Appointment and front-desk workflows
  • Patient intake
  • Clinical documentation
  • Chart summarization and information retrieval
  • Administrative document processing
  • Clinical workflow support
  • Coding and billing workflows
  • Practice analytics and operational insights

When these features process PHI on behalf of a healthcare organization, the information remains subject to applicable HIPAA requirements, contractual obligations, and the applicable BAA.

AI-generated information is intended to support healthcare professionals and practice staff. Appropriate human review and professional judgment remain important, particularly for clinical decisions and patient care.

6. How We Share Information

We may disclose information only as reasonably necessary for legitimate business, operational, contractual, or legal purposes.

Healthcare Organizations and Authorized Users

Information may be accessible to authorized healthcare providers, staff members, administrators, and other users based on their roles and permissions within the organization.

Service Providers and Subcontractors

We may use third-party companies to help provide infrastructure, hosting, communications, payment processing, support, security, analytics, and other services.

Where a service provider or subcontractor creates, receives, maintains, or transmits PHI on our behalf and is subject to HIPAA Business Associate requirements, we require appropriate contractual safeguards, including a BAA where required.

Legal and Regulatory Requirements

We may disclose information when necessary or required to:

  • Comply with applicable law or regulation;
  • Respond to valid legal processes;
  • Cooperate with regulatory authorities;
  • Protect the rights, safety, or security of EHR360, our customers, users, or others;
  • Investigate fraud or security incidents; or
  • Establish, exercise, or defend legal claims.

Business Transactions

If EHR360 is involved in a merger, acquisition, financing, restructuring, sale of assets, or similar corporate transaction, information may be transferred as part of that transaction subject to applicable privacy and legal requirements.

With Authorization or Direction

We may disclose information when you, or the applicable healthcare organization, directs or authorizes us to do so.

7. We Do Not Sell PHI

EHR360 does not sell, rent, or trade PHI to third parties for marketing purposes.

We also do not sell personal information collected through our Services in exchange for monetary payment.

Any use or disclosure of PHI is governed by applicable law, contractual requirements, and the applicable BAA.

8. Cookies and Similar Technologies

Our website and Services may use cookies and similar technologies to support functionality, security, preferences, analytics, and website performance.

These technologies may help us:

  • Maintain user sessions;
  • Remember preferences;
  • Understand how visitors use our website;
  • Improve website and platform performance;
  • Detect fraud or suspicious activity; and
  • Maintain security.

You may be able to control cookies through your browser or device settings. Disabling certain cookies may affect website or platform functionality.

9. Data Security

EHR360 maintains administrative, technical, and physical safeguards designed to protect the confidentiality, integrity, and availability of information.

Depending on the applicable environment and Services, safeguards may include:

  • Encryption of information in transit and at rest;
  • Authentication controls;
  • Multi-factor authentication;
  • Role-based access controls;
  • Logging and monitoring;
  • Security assessments;
  • Workforce privacy and security training;
  • Backup and recovery procedures;
  • Incident response processes; and
  • Risk-management procedures.

Access to PHI is limited based on appropriate roles, responsibilities, and authorized purposes.

However, no electronic transmission, storage system, or security measure can guarantee absolute security.

10. Data Retention

We retain personal information for as long as reasonably necessary to:

  • Provide and maintain the Services;
  • Fulfill the purposes described in this Privacy Policy;
  • Meet contractual obligations;
  • Comply with applicable legal and regulatory requirements;
  • Maintain appropriate business and security records;
  • Resolve disputes; and
  • Enforce our agreements.

When EHR360 processes PHI on behalf of a healthcare organization, retention and disposition may also be governed by the applicable BAA, customer instructions, and the healthcare organization's legal and regulatory obligations.

Different types of information may therefore have different retention periods.

11. Your Privacy Rights

Your privacy rights depend on the type of information involved, your relationship with EHR360, and applicable law.

Patient Rights Regarding PHI

If you are a patient whose healthcare provider uses EHR360, you may have rights under HIPAA regarding your PHI, including rights relating to:

  • Access to health information;
  • Requests for amendments;
  • Certain restrictions on uses or disclosures;
  • Confidential communications; and
  • An accounting of certain disclosures.

Healthcare providers generally remain responsible for responding to patient requests regarding these rights.

If you contact EHR360 regarding PHI maintained on behalf of a healthcare provider, we may direct you to that provider or assist the provider as required by our contractual and legal obligations.

Rights Regarding Personal Information

Depending on applicable law, you may also have rights regarding personal information EHR360 controls directly, which may include the right to:

  • Request access to personal information;
  • Request correction of inaccurate personal information;
  • Request deletion of certain personal information;
  • Receive information about how personal information is processed; and
  • Opt out of certain marketing communications.

Some requests may be limited by legal, regulatory, security, record-retention, or contractual requirements.

12. State Privacy Rights

Residents of certain U.S. states may have additional privacy rights under applicable state consumer privacy laws.

Depending on the applicable law and EHR360's relationship with you, these rights may include requests to know, access, correct, or delete certain personal information or obtain information about how personal information is disclosed.

Certain information regulated by HIPAA or other healthcare privacy laws may be exempt from some state consumer privacy requirements.

These exemptions do not necessarily apply to all information EHR360 collects, such as information collected directly from website visitors or business contacts.

To submit an applicable privacy request, contact us using the information provided below.

13. Marketing Communications

If you receive marketing communications from EHR360, you may opt out by using the unsubscribe instructions included in the communication or by contacting us.

Opting out of marketing communications does not prevent us from sending necessary service-related, security, account, or transactional communications.

14. Children's Privacy

The EHR360 public website and business Services are not directed to children under the age of 13, and we do not knowingly solicit personal information directly from children under 13 through our public website.

EHR360 may process information relating to minors when providing Services to healthcare organizations. In such cases, EHR360 processes the information on behalf of the healthcare provider and in accordance with applicable law and contractual requirements.

Access to health information relating to minors may also depend on applicable law, parental or guardian authority, and the policies of the healthcare provider.

15. Third-Party Services and Links

Our website or Services may contain links to, or integrate with, third-party websites, applications, or services.

Those third parties may have their own privacy practices and policies. EHR360 is not responsible for the privacy practices of third-party services that operate independently from EHR360.

We encourage users to review the applicable privacy policies before providing information directly to third parties.

16. International Users

EHR360 is primarily intended to provide Services within the United States.

If you access our website or Services from outside the United States, your information may be transferred to and processed in the United States or other locations where EHR360 or its service providers operate.

Applicable privacy protections may differ from those in your country of residence.

17. Security Incidents and Breach Notification

EHR360 maintains processes designed to identify, investigate, and respond to security incidents.

Where an incident involves PHI or other protected information, EHR360 will provide notifications and cooperate with affected healthcare organizations as required by applicable law and contractual obligations, including applicable BAAs.

18. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in:

  • Our Services;
  • Technology;
  • Privacy practices;
  • Legal or regulatory requirements; or
  • Business operations.

When we update this Privacy Policy, we will revise the “Last Updated” date at the top of this page.

Where appropriate or required, we may also provide additional notice of material changes.

We encourage users to review this Privacy Policy periodically.

19. Contact Us

If you have questions about this Privacy Policy, EHR360's privacy practices, or a privacy request involving information controlled directly by EHR360, please contact:

EHR360
Attn: Privacy Officer
Email: support@ehr360.ai
Phone: 865-474-7559

Mailing Address:
[Insert Complete Legal Mailing Address]

If your request concerns medical records or PHI maintained by your healthcare provider, please contact the healthcare provider directly first.

20. HIPAA Privacy Complaints

If you believe your healthcare privacy rights have been violated, you may contact your healthcare provider or submit a complaint to the appropriate government authority, including the U.S. Department of Health and Human Services Office for Civil Rights, where applicable.

EHR360 will not retaliate against an individual for making a good-faith privacy or security complaint to EHR360.

21. Business Associate Responsibilities

When acting as a Business Associate, EHR360 maintains appropriate safeguards for PHI and performs its obligations in accordance with applicable HIPAA requirements and the relevant BAA.

EHR360 also requires applicable subcontractors that handle PHI on its behalf to agree to appropriate privacy and security protections as required by law.

Healthcare organizations using EHR360 remain responsible for their own legal and regulatory obligations, including appropriately configuring access, managing authorized users, maintaining their Notice of Privacy Practices, and responding to patient privacy requests.