In Re. · The Handling of Personal & Health Information
Privacy
Policy
Ultradoc Technologies LLC ("Ultradoc," "we," "us," or "our") builds the clinical workflow platform your medical practice uses, including the Ultradoc patient app. This Privacy Policy describes what information we collect in connection with the patient app and our patient-facing services, why we collect it, who can see it, how long we keep it, and the choices you have.
The short version: your health information belongs to your care, not to us. We process it only on behalf of your practice, under contract, as a HIPAA business associate. We show no ads, we sell nothing about you, and the app collects no location, no contacts, no photos, and no payment card numbers.
Article I
Scope
This Policy applies to the Ultradoc patient app (distributed through the Apple App Store and Google Play), the patient-facing services of the Ultradoc platform, and the ultradoc.net website.
It does not replace your practice's own Notice of Privacy Practices, which governs how your practice — the HIPAA covered entity responsible for your care — uses and discloses your health information. If you use the Ultradoc platform as a member of a practice's workforce, the practice's Customer Agreement with Ultradoc governs that use.
Article II
Two Kinds of Information, Two Roles
Understanding this Policy requires one distinction.
Protected Health Information (PHI). Your appointments, messages with your care team, billing records, and the fact of your relationship with a practice are PHI. For PHI, your practice is the covered entity and Ultradoc is its business associate: we process this information only as permitted by the Business Associate Agreement with your practice and by HIPAA, and your practice's Notice of Privacy Practices governs its use. Our safeguards are described in our Statement of HIPAA Compliance.
Account and technical information. Your app account, device information, and usage analytics are information Ultradoc handles to operate the service itself. This Policy is the primary document governing that information.
Article III
Information We Collect
- § 3.01
- § 3.02
- § 3.03
- § 3.04
- § 3.05
Account & profile information.
When you create an account in the Patient App, we collect your name, email address, phone number, date of birth, and sex, together with a password. Passwords are stored only as cryptographic hashes; Ultradoc cannot read your password. This information identifies you to your Practice and protects your account.
Health information handled for your Practice.
The Patient App transmits and displays health information on behalf of your Practice: your connections to practices, appointment requests and confirmed visits, secure messages exchanged with your care team, and billing balances and payment history drawn from your Practice's billing systems. This is Protected Health Information under HIPAA. Ultradoc processes it solely as a business associate of your Practice — it is your Practice's data about your care, not Ultradoc's.
Device & technical information.
We collect the technical minimum needed to run the app reliably: device model and operating system version, app version, language and region settings, network reachability, push-notification tokens for your device, and diagnostic information about errors and update installs.
Usage analytics.
We collect limited product analytics — screen views, app lifecycle events, and feature-usage events — to understand reliability and improve the app. Analytics never carry your name, email address, phone number, or date of birth, and never the contents of your messages or records. They are grouped by a randomly generated device identifier rather than by your account. Because a screen view records which screen you opened, and the address of some screens contains the identifier of the record being shown, we treat analytics as information about your care rather than as anonymous data. Article X explains this precisely.
Family & caregiver connections.
If you manage care for a family member — a child under thirteen (13), or another person who has granted you access — we collect that person's profile information (name, date of birth, sex, and their connections to practices) and the record of who is permitted to act for whom. A managed profile is created by you or by the practice, never by the child.
Article IV
What the App Does Not Collect
- (i)Your precise or approximate location. The Patient App never requests location access.
- (ii)Your contacts, photos, camera, or microphone. The app requests none of these permissions.
- (iii)Advertising identifiers (IDFA / AAID). The app contains no advertising SDKs and displays no ads.
- (iv)Payment card numbers. When you pay a balance, the app opens your Practice's own payment portal in your device browser; card entry happens there, with your Practice's payment provider, never inside the app.
- (v)Biometric data. If you protect the app with Face ID or a fingerprint, that biometric check is performed entirely by your device's operating system; biometric information never reaches Ultradoc.
Article V
Device Permissions & On-Device Features
The patient app asks for three optional permissions. Each is explained in the app before your device prompts you, each is refusable, and the app remains usable without any of them. You can withdraw any of them later in your device settings.
Push notifications. With your permission, the app registers your device to receive notifications — a reply from your care team, a confirmed appointment. Notifications are written to signal that something happened without putting the substance of your health information on your lock screen.
Calendar. If you turn on calendar sync, the app writes your confirmed visits to the calendar you choose on your device, and updates or removes those entries when a visit is rescheduled or cancelled. This is a one-way write: the app never uploads your calendar, and Ultradoc never reads, receives, or stores your calendar events or any other appointment on it. Nothing about your calendar leaves your device to us. Note that a calendar you sync with another provider — iCloud, Google, or your employer's server — is governed by that provider, so consider which calendar you pick.
Biometric app lock. You can require Face ID, Touch ID, or your device passcode to open the app. This check is performed entirely by your device's operating system, and the result never leaves the device. Ultradoc neither receives nor stores your fingerprint, face data, or passcode.
Article VI
How We Use Information
- § 5.01
- § 5.02
- § 5.03
- § 5.04
- § 5.05
To provide the service.
Operating the Patient App on behalf of your Practice: authenticating you, displaying your appointments, delivering your messages, showing your balances, and keeping the app updated and secure.
To secure the platform.
Verifying sign-ins, detecting unauthorized access, enforcing access controls, and maintaining the audit trails required of a HIPAA business associate.
To notify you.
Sending push notifications you have enabled — such as when your care team replies — and service emails such as verification codes and security notices. Notifications are designed to signal that activity occurred without exposing the substance of your health information on your lock screen.
To support and improve the app.
Responding to support requests, diagnosing errors, and analyzing aggregate usage patterns to improve reliability and usability.
To comply with law.
Meeting our obligations under HIPAA, our Business Associate Agreements, and other applicable laws, and responding to lawful requests where required.
Article VII
What We Never Do
- (i)We never sell your information — health-related or otherwise — to anyone.
- (ii)We never use or disclose your health information for advertising or marketing.
- (iii)We never share your information with data brokers, ad networks, or analytics platforms for their own use.
- (iv)We never use your health information to train models or build products unrelated to the service your Practice engaged us to provide.
Article VIII
When Information Is Shared
- § 7.01
- § 7.02
- § 7.03
- § 7.04
With your Practice.
Sharing your information with your own Practice is the product: your profile, messages, appointment requests, and payments are visible to the Practice(s) you are connected to, exactly as a patient portal requires.
With subprocessors under Business Associate Agreements.
Ultradoc uses a small number of infrastructure providers — cloud hosting, database, analytics, and communications services — each of which processes data under a signed Business Associate Agreement and only on Ultradoc's instructions. A current subprocessor list is available to Practices on request via compliance@ultradoc.net.
For legal reasons.
We may disclose information where required by law, subpoena, or court order, or where necessary to protect the rights, safety, or property of patients, Practices, Ultradoc, or the public — always to the minimum extent required and as permitted by HIPAA.
In a business transition.
If Ultradoc is involved in a merger, acquisition, or sale of assets, information may transfer to the successor entity subject to the same HIPAA and Business Associate Agreement obligations that bind Ultradoc.
Article IX
Text Messaging & Opt-In Data
Ultradoc operates a text message program that sends appointment notifications, reminders to open a message or book a follow-up, task notifications to practice staff who have enabled them, and one-time sign-in verification codes. It carries no marketing or promotional content. The complete program terms are published at ultradoc.net/sms.
Two pieces of information make that program work: your mobile number, and the record that consent to text it was given — when, through which channel, and against which language. We call these together your text messaging opt-in data and consent. Patients give consent to their practice at the point of care; practice staff enable text notifications themselves in their Ultradoc account and verify the number with a one-time code.
Text messaging opt-in data and consent status are never sold, rented, or shared with any third party for marketing purposes. They are used to run the program described above and for nothing else, and they are disclosed only to the messaging provider that delivers the messages, which acts on Ultradoc's instructions under contract.
To state the point in the form the mobile carriers require: All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
You may withdraw consent at any time by replying STOP to any message, which stops the messages without affecting your account, your care, or anything else in this Policy. Ultradoc retains a record that a number opted out for as long as the number would otherwise be eligible to be texted, because honoring an opt-out requires remembering it.
Article X
Analytics, Advertising & Tracking
The patient app uses a single analytics service, PostHog, operating under a signed Business Associate Agreement, to measure reliability and product usage. It receives three things: screen views, app lifecycle events (such as the app being opened), and crash and diagnostic reports when something goes wrong.
PostHog is never told who you are. The app does not identify you to it: your account identifier is never sent, no event is associated with your identity, and your name, email address, phone number, date of birth, message contents, and records never reach PostHog. Events are grouped by a randomly generated device identifier rather than by your account. Automatic capture of screen taps is switched off, so what you tap on a screen — including a family member's name on a card — is never recorded, and events are scrubbed on-device to strip tokens and sensitive links before transmission.
One qualification, stated plainly. A screen view records the address of the screen you opened, and the address of some screens inside the app contains the identifier of the record you were looking at — a practice, an appointment, a conversation. Those identifiers are meaningless to PostHog and to anyone else, but Ultradoc holds the records they point to and could match them up. So although analytics carry no direct identifiers, we do not claim they are anonymous. We treat them as information about your care: covered by the Business Associate Agreement, never sold, never used for advertising, and never shared for anyone else's purposes.
The app contains no advertising, no advertising SDKs, and no social media trackers. We do not track you across other companies' apps or websites, and the app never requests the ability to do so. Your health information is never used for advertising of any kind.
Article XI
How We Protect Information
All communication between the patient app and the Ultradoc platform is encrypted in transit using TLS 1.2 or higher. Information at rest is encrypted with AES-256 on HIPAA-eligible cloud infrastructure operated under Business Associate Agreements. Session credentials on your device are stored in your device's secure storage, and you can additionally protect them with Face ID or fingerprint unlock.
Access to production systems is role-based, least-privilege, and fully audited. The complete control set — administrative, physical, and technical — is published in our Statement of HIPAA Compliance. Suspected vulnerabilities may be reported to security@ultradoc.net under our vulnerability disclosure policy.
If a breach of unsecured health information occurs, Ultradoc will notify affected practices without unreasonable delay, as HIPAA requires, so that patients receive the notifications they are entitled to.
Article XII
Retention & Deletion
- § 11.01
- § 11.02
- § 11.03
- § 11.04
Account information.
Retained while your account is active. When you delete your account — in the app via Settings, or by request per ultradoc.net/delete-account — your account, sign-in credentials, profile, practice connections, and push-notification registrations are deleted.
Health information.
Your medical record is maintained by your Practice, which is legally required to retain it. Health information Ultradoc holds as a business associate is retained and returned or destroyed as directed by the governing Business Associate Agreement, not by your app account's existence.
Audit logs.
Access and security audit records are retained for a minimum of six (6) years, as required of HIPAA business associates (45 CFR § 164.316(b)).
Analytics.
Product analytics are retained under our agreement with our analytics subprocessor, protected by the same Business Associate Agreement as the rest of your information. Deleting your account does not by itself erase analytics events already collected; to ask us to delete those as well, write to privacy@ultradoc.net.
Article XIII
Your Choices & Rights
- § 12.01
- § 12.02
- § 12.03
- § 12.04
- § 12.05
Review and update your profile.
Your name, contact details, and demographic information can be reviewed and updated in the app under Settings → Edit profile.
Delete your account.
Delete your account at any time in the app (Settings → Delete account) or by following the instructions at ultradoc.net/delete-account. Deletion is permanent.
Control notifications.
Enable or disable push notifications at any time in your device settings.
Exercise your HIPAA rights.
Your rights to access, amend, restrict, and receive an accounting of disclosures of your medical record run against your Practice, the covered entity that maintains it. Contact your Practice, whose Notice of Privacy Practices explains the process. Ultradoc supports Practices in honoring every such request.
State privacy rights.
Depending on your state of residence, you may have additional rights over personal information not covered by HIPAA (which most information handled by the Patient App is). To exercise them, or to ask which apply, contact privacy@ultradoc.net. We do not discriminate against you for exercising any privacy right.
Article XIV
Children, Teens & Family Profiles
Families are part of how care works, so the patient app draws a line at thirteen (13) and treats each side of it differently.
Children under 13 do not get an account. The app will not create one: an attempted sign-up with a date of birth under thirteen is refused, and no account is made. A child under thirteen is instead cared for through a managed profile that a parent or legal guardian holds inside their own adult account. The parent creates and controls that profile, sees the child's appointments and messages, and can remove it at any time. Ultradoc collects the child's information from the parent or from the practice — never from the child, who has no way to sign in and no way to give us anything directly. We do not knowingly collect personal information from a child under thirteen in any other way; if you believe we have, contact privacy@ultradoc.net and we will delete it.
Teens aged 13 to 17 may hold their own account. A teen who is at least thirteen can create an account, sign in, and use the app for their own care. A teen's account is subject to this Policy in full and gets the same protections as an adult's: the same limits on analytics, the same absence of advertising, the same right to delete. Where state law gives a minor the right to consent to a category of care on their own, or gives a parent the right to see it, that determination is made by the practice, which is the custodian of the record; the app displays what the practice makes available.
When a teen with a managed profile turns thirteen, they may take over with their own account. The parent's ability to see that care afterward is set by the practice, consistent with applicable law.
No part of the patient app is directed to children under thirteen, and it shows no advertising to anyone. We do not use any information about a minor for advertising, marketing, profiling, or model training, and we do not sell it.
Article XV
Changes to This Policy
When we change this Policy, we will update the effective date above and, for material changes, provide notice in the app or by email before the change takes effect. Prior versions are available on request. Continued use of the patient app after a change takes effect constitutes acceptance of the revised Policy.
Article XVI
Contact
Questions, requests, or complaints about this Policy or Ultradoc's privacy practices may be directed to:
You also have the right to file a complaint with the U.S. Department of Health and Human Services, Office for Civil Rights, if you believe your rights under the HIPAA Privacy Rule have been violated. Filing instructions are available at hhs.gov/ocr/complaints. Complaints never affect your care or your access to the app.
Entered into the records of
Ultradoc Technologies LLC
— End of Document · UD-PRIV-01 —