Notice: This policy has been updated to reflect AI EHR's FHIR-native data ownership model and AI WFM integration. All AI model training data is de-identified and cannot be used to re-identify patients.
1. Overview
TheMadHacker LLC ("we," "our," or "us") operates AI EHR, an AI-native Electronic Health Records platform. This Privacy Policy describes how we collect, use, store, and protect your information when you use our platform, website, and services.
As an AI-native platform handling sensitive protected health information (PHI), we hold ourselves to the highest privacy standards — exceeding HIPAA requirements even for non-healthcare customers.
2. Data We Collect
2.1 Information You Provide Directly
- Account creation details (name, email, organization, NPI)
- Patient demographic and clinical data (names, diagnoses, medications, lab results)
- Organizational settings (sites, departments, shift templates, CDS rules)
- MIPS reporting configuration and measure scoring data
- Support communications and feedback
2.2 Information Collected Automatically
- Usage analytics (feature adoption, documentation patterns, API calls)
- System logs (error reports, performance metrics, FHIR search queries)
- Device information (browser, OS, IP address for security)
- Cookies and similar technologies (see Section 7)
2.3 Data From Integrations
- Patient data from connected EHRs, labs, and imaging systems via HL7/FHIR
- Clinical documentation and SOAP notes from AI Scribe ambient recording
- Workforce scheduling data from AI WFM integration
3. How We Use Your Data
- Core Platform: To provide EHR, clinical documentation, MIPS reporting, and interoperability features
- AI Training: De-identified, aggregated clinical patterns to improve NLP and AI Scribe models (never individual patient data)
- Compliance: To validate schedules against MIPS, ONC, and ePrescribing requirements in real-time
- Security: To detect unauthorized access, prevent fraud, and maintain platform integrity
- Improvement: To identify bugs, optimize performance, and develop new features
- Communication: To send platform updates, security notices, and support responses (with opt-out for marketing)
4. Data Sharing
We do not sell your patient data. Ever. Period. Our business model is one-time licensing — we have no incentive to monetize your clinical data.
We may share data only in these limited circumstances:
- Service Providers: AWS, Cloudflare, Surescripts, and other infrastructure partners bound by strict data processing agreements
- Integrations: Data shared with connected platforms (labs, imaging, AI WFM) only as directed by your organization
- Legal Requirements: When required by law, court order, or government authority
- Business Transfers: In connection with a merger or acquisition, with notice and continued privacy protections
5. Security
We employ enterprise-grade security measures including AES-256 encryption at rest, TLS 1.3 in transit, RBAC with 25+ predefined roles, immutable audit trails, and annual third-party penetration testing. Our SOC 2 Type II and ONC Certification are maintained annually with zero material exceptions.
For on-premise deployments, security controls are managed entirely within your infrastructure. We follow a strict zero-trust architecture for our SaaS offering.
6. Your Rights
Under applicable data protection laws (HIPAA, GDPR, CCPA, etc.), you have the right to:
- Access your patient data at any time via the platform or FHIR API
- Correct inaccurate data through the platform
- Delete your data via platform controls or by contacting us
- Export your data in FHIR Bundle, CSV, or C-CDA format at any time
- Opt out of marketing communications
- Lodge a complaint with a supervisory authority
7. Cookies & Tracking
We use essential cookies for platform authentication and security. Analytics cookies (Google Analytics, Plausible) are used only for aggregate platform usage metrics and are configured for privacy compliance. No advertising or tracking cookies are used.
8. Children's Privacy
AI EHR is not designed for or directed at children under 16. We do not knowingly collect personal information from children. If we become aware of unauthorized collection, we will delete such data immediately.
9. Policy Changes
We will notify customers of material changes to this policy via email and in-platform notification at least 30 days before changes take effect. Continued use of AI EHR after the effective date constitutes acceptance of the updated policy.
For privacy inquiries, data subject requests, or to exercise your rights, contact our Data Protection Officer:
- Email: [email protected]
- Mail: TheMadHacker LLC, 1200 Commerce St, Suite 4500, Nashville, TN 37211
- Phone: 615 461 0768
- Response Time: We will respond to all privacy requests within 30 days.