Privacy Policy

Kintah LLC · Version 1.0 · Dr Practice OS
Template — not yet legal advice. This document is a standard-form starting point and must be reviewed and finalized by Kintah LLC's legal counsel before production use.

This Privacy Policy explains how Kintah LLC handles information in connection with the Dr Practice OS Service. Handling of patient protected health information ("PHI") is governed primarily by HIPAA and the Business Associate Agreement between Kintah LLC and your practice; where this Policy and the BAA conflict as to PHI, the BAA controls.

1. Information we process

Account data (names, work emails, roles) about your users; practice data (practice name, billing contact); PHI your practice inputs (patients, appointments, documents); and usage/audit logs (access records, IP address, device info) used for security and compliance.

2. How we use information

To provide, secure, and support the Service; to maintain HIPAA-required audit trails; to process subscription billing; and to comply with law. We do not sell personal information or PHI, and we do not use PHI for advertising.

3. Service providers (sub-processors)

Every provider that processes PHI on our behalf operates under a Business Associate Agreement and within a HIPAA-eligible venue. We use Amazon Web Services (compute, database, storage, email, notifications, and AI via Amazon Bedrock) as our BAA-covered infrastructure. Our payment processor (Stripe) handles subscription billing only and never receives PHI.

4. AI processing

AI features are provided exclusively through Amazon Bedrock under our AWS Business Associate Agreement. We do not send data to any other AI provider. AI output is advisory and reviewed by your licensed providers.

5. Security

We apply administrative, physical, and technical safeguards including tenant isolation, role/capability-based access control, encryption in transit and at rest, automatic session timeout, append-only audit logging, and break-glass controls for emergency access.

6. Data retention

We retain PHI for as long as your practice's account is active and as directed by the BAA. Audit records are retained for at least six (6) years as required by HIPAA. On termination, data is exported and then deleted per the BAA and applicable law.

7. Your rights and patient rights

Your practice, as covered entity, is responsible for honoring individual rights under HIPAA (access, amendment, accounting of disclosures). We provide tooling to support these requests. Individuals should contact the practice directly regarding their records.

8. Breach notification

We will notify your practice of any breach of unsecured PHI without unreasonable delay and within the timeframes required by the BAA and HIPAA.

9. Changes and contact

We may update this Policy and will require re-acceptance of material changes. Contact Kintah LLC for privacy inquiries.