AI1Health

Privacy Policy

Effective Date: July 27, 2026

Last Updated: July 27, 2026

About AI1Health

AI1Health is a healthcare workflow platform for clinics and organizations that manage patient demographics, immunization workflows, vaccine inventory, storage and handling records, patient portal access, imports, role-based staff access, Smart MA guidance, and audit logs.

Scope of this Privacy Policy

This Privacy Policy describes how [Company Legal Name] collects, uses, shares, and protects information when AI1Health is used by clinic customers, authorized staff users, patient portal users, and other permitted users.

Customer contracts, Business Associate Agreements, and applicable law may provide additional terms for specific uses of the service.

Information We Collect

Account and contact information, such as names, email addresses, roles, authentication details, and support contact information.

Clinic and organization information, such as clinic names, locations, staff roles, workflow settings, inventory and storage configuration, and related operational records.

Patient and health-related information entered by authorized users, including patient demographics, immunization-related records, vaccine administration details, patient portal access records, and clinic workflow notes where enabled.

Import and upload information processed during patient demographic import, including CSV or Excel rows used to preview, validate, and create demographic records. Raw import files are not intended to be stored server-side; import job history is designed to be PHI-light.

Usage, device, and log information, including sign-in events, security events, audit activity, browser or device details, and diagnostic information needed to operate and secure the service.

Communications and support requests, including messages submitted to AI1Health for support, onboarding, feedback, or service questions.

How We Use Information

Provide, operate, maintain, and support the AI1Health service.

Support clinic workflows, including patient directory, immunization, vaccine inventory, storage and handling, scheduling, task, import, and patient portal workflows.

Authenticate users, manage role-based access, and help clinics administer authorized staff and patient portal access.

Maintain security records, audit logs, access logs, and compliance-supporting records.

Improve reliability, troubleshoot service issues, respond to support requests, and communicate service updates.

Comply with legal obligations, enforce agreements, and protect the rights, safety, and security of AI1Health, customers, patients, and users.

Protected Health Information and HIPAA

When AI1Health is used by covered entities or business associates for healthcare operations, AI1Health may process Protected Health Information (PHI) on behalf of those organizations.

Where required, that use may be governed by a Business Associate Agreement (BAA). If a BAA applies, the BAA controls where it conflicts with this Privacy Policy regarding PHI.

AI1Health uses reasonable administrative, technical, and organizational safeguards, but this Privacy Policy does not claim that any product or process is HIPAA certified or guarantees compliance for every customer use case.

How We Share Information

With authorized clinic users and patient portal users according to configured roles, permissions, and clinic settings.

With service providers and subprocessors that help us host, secure, monitor, support, or operate the service, subject to appropriate contractual obligations where applicable.

For legal, compliance, safety, security, or enforcement purposes when required by law or reasonably necessary to protect the service and its users.

In connection with a merger, acquisition, financing, reorganization, or business transfer, subject to appropriate protections for covered information.

With consent, direction, or authorization from the customer, user, patient, guardian, or other legally authorized person, as applicable.

Data Security

AI1Health uses reasonable administrative, technical, and organizational safeguards designed to protect information, including role-based access controls, authentication, MFA where applicable, audit logging, and operational security practices.

No method of transmission, storage, or processing can be guaranteed to be completely secure. Customers and users are responsible for using the service appropriately, managing authorized access, and promptly reporting suspected unauthorized activity.

Data Retention

We retain information as needed to provide the service, comply with legal obligations, resolve disputes, enforce agreements, maintain audit records, and support customer operations.

Customer configuration, clinic controls, legal requirements, and contractual terms may affect retention periods and deletion options.

Patient Portal

Where enabled, patients and guardians may receive limited portal access to view or interact with records made available by their clinic.

Patient portal users should contact their clinic for corrections, clinical questions, medical advice, access changes, or urgent health concerns.

Imports and Files

AI1Health supports CSV and Excel imports for patient demographic onboarding. Import previews and validations are intended to help authorized clinic users review data before confirming creation.

Raw import files are not intended to be stored server-side. Import job history is designed to record operational counts and PHI-light status information rather than full row-level file contents.

Cookies and Similar Technologies

AI1Health may use cookies, local storage, session storage, and similar technologies to support authentication, security, preferences, analytics, diagnostics, and reliable service operation.

Children's Privacy

AI1Health is not intended for direct use by children without an authorized clinic, guardian, or legally permitted context. Clinics and authorized users are responsible for using the service in accordance with applicable consent, access, and privacy requirements.

California and Other Privacy Rights

Depending on your location and relationship to AI1Health or a clinic customer, you may have privacy rights under applicable law. To exercise rights that apply to AI1Health directly, contact us using the information below.

If your information is maintained by a clinic customer or appears in your patient record, AI1Health may direct you to the applicable clinic because the clinic may control that information.

Changes to this Policy

We may update this Privacy Policy from time to time. Updates will be posted on this page with a revised effective date or otherwise communicated as required by law or contract.

Contact Us

For privacy questions, please visit our Contact Us page.