Data Privacy & Security
Privacy Policy
Last Updated: August 9, 2026 • Effective Date: January 1, 2026
1. Introduction & Overview
Medsy Inc. ("Medsy", "we", "our", or "us") operates the Medsy clinic and hospital management platform at medsy.me and associated services. We are committed to maintaining the highest standards of data privacy, confidentiality, and security for healthcare providers, medical professionals, and their patients.
2. HIPAA & HITECH Compliance Statement
Medsy is engineered to comply with the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the Health Information Technology for Economic and Clinical Health (HITECH) Act.
- Protected Health Information (PHI): All patient health information is encrypted at rest using AES-256 and in transit using TLS 1.3 protocols.
- Business Associate Agreements (BAAs): Medsy executes standard Business Associate Agreements (BAAs) with eligible healthcare organization clients.
3. Information We Collect
We collect information to provide, improve, and secure our clinical software operations:
- Account & Profile Information: Doctor name, medical specialty, NPI / license numbers, clinic address, work email, and billing details.
- Clinical & EHR Data: Patient health records, medical histories, prescriptions, laboratory orders, and clinical notes uploaded by authorized staff.
- Usage & Diagnostic Data: IP addresses, browser types, interaction telemetry, and error logs for system performance and security auditing.
4. AI Copilot Data Boundary & Privacy
Medsy includes an AI clinical copilot designed to assist doctors with charting and clinical decision support.
- No Public Model Training: Your clinical notes, patient details, and proprietary medical data are NEVER used to train public foundation models.
- Zero Retention AI Processing: AI processing requests are executed within isolated, enterprise-encrypted environments with zero data retention by model vendors.
5. Data Sharing & Third Parties
We do not sell, rent, or monetize personal health information or clinical data. We only share data with trusted infrastructure providers (such as encrypted cloud hosting and SMS/email gateway services) strictly to deliver the Medsy platform.
6. Contact Us
For privacy inquiries, BAA requests, or security reports, please contact our Data Protection Officer at: