Medsy LogoMedsy

Data Privacy & Security

Privacy Policy

Last Updated: August 9, 2026 • Effective Date: January 1, 2026

1. Introduction & Overview

Medsy Inc. ("Medsy", "we", "our", or "us") operates the Medsy clinic and hospital management platform at medsy.me and associated services. We are committed to maintaining the highest standards of data privacy, confidentiality, and security for healthcare providers, medical professionals, and their patients.

2. HIPAA & HITECH Compliance Statement

Medsy is engineered to comply with the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the Health Information Technology for Economic and Clinical Health (HITECH) Act.

  • Protected Health Information (PHI): All patient health information is encrypted at rest using AES-256 and in transit using TLS 1.3 protocols.
  • Business Associate Agreements (BAAs): Medsy executes standard Business Associate Agreements (BAAs) with eligible healthcare organization clients.

3. Information We Collect

We collect information to provide, improve, and secure our clinical software operations:

  • Account & Profile Information: Doctor name, medical specialty, NPI / license numbers, clinic address, work email, and billing details.
  • Clinical & EHR Data: Patient health records, medical histories, prescriptions, laboratory orders, and clinical notes uploaded by authorized staff.
  • Usage & Diagnostic Data: IP addresses, browser types, interaction telemetry, and error logs for system performance and security auditing.

4. AI Copilot Data Boundary & Privacy

Medsy includes an AI clinical copilot designed to assist doctors with charting and clinical decision support.

  • No Public Model Training: Your clinical notes, patient details, and proprietary medical data are NEVER used to train public foundation models.
  • Zero Retention AI Processing: AI processing requests are executed within isolated, enterprise-encrypted environments with zero data retention by model vendors.

5. Data Sharing & Third Parties

We do not sell, rent, or monetize personal health information or clinical data. We only share data with trusted infrastructure providers (such as encrypted cloud hosting and SMS/email gateway services) strictly to deliver the Medsy platform.

6. Contact Us

For privacy inquiries, BAA requests, or security reports, please contact our Data Protection Officer at:

Medsy Privacy & Compliance Office

Email: hello@medsy.me

Website: https://medsy.me