Legal

Privacy Policy

Last updated: August 2, 2026

HDN Works LLC, operator of the MedChartMax platform ("MedChartMax," "we," "us," or "our"), operates an AI-powered medical documentation platform designed to assist individual healthcare providers with clinical documentation. This Privacy Policy describes how we collect, use, disclose, and safeguard Protected Health Information (PHI) and other personal information when you use our services.

As a healthcare technology platform subject to HIPAA (Health Insurance Portability and Accountability Act), we take the privacy and security of your information extremely seriously. This Privacy Policy should be read in conjunction with our Business Associate Agreement, which governs our handling of Protected Health Information.

1. Information We Collect

1.1 Protected Health Information (PHI)

When you use MedChartMax to generate medical notes, you may provide patient encounter summaries that constitute Protected Health Information under HIPAA. This includes:

  • Patient demographics (name, date of birth, medical record numbers)
  • Clinical information (symptoms, diagnoses, treatment plans, medications)
  • Vital signs and physical examination findings
  • Medical history and encounter summaries

Important: PHI is processed in real-time for note generation and is not permanently stored in our databases. Patient data exists only during your active session and is cleared upon session termination.

1.2 Account Information

  • Name and professional credentials
  • Email address
  • License number and state of licensure
  • Professional title and specialty
  • Password (encrypted)

1.3 Billing Information

  • Payment method details (processed by Stripe, our payment processor)
  • Billing address
  • Subscription plan and payment history

1.4 User-Generated Content

  • Custom templates for medical note generation
  • Clinical rules and preferences
  • Perfect example notes for training
  • User-specific configuration settings

1.5 Usage Data

  • Log data (IP address, browser type, access times)
  • Device information (operating system, device type)
  • Feature usage patterns (number of notes generated, specialty selections)
  • Performance metrics (response times, error rates)

2. How We Use Your Information

2.1 PHI Processing

Protected Health Information is used exclusively for:

  • Medical Note Generation: Processing patient encounter summaries through AWS Bedrock foundation models to generate structured medical documentation
  • Template Retrieval: Matching patient context with your custom templates stored in AWS S3 using Knowledge Base retrieval
  • Real-Time Processing Only: PHI is transmitted securely to AWS Bedrock via encrypted channels and is not stored in our databases or logs

2.2 Account Management

  • Creating and maintaining your MedChartMax account
  • Authenticating your identity and managing access
  • Processing subscription payments
  • Providing customer support
  • Communicating service updates and changes

2.3 Service Improvement

  • Analyzing usage patterns to improve platform performance
  • Monitoring system health and reliability
  • Troubleshooting technical issues
  • Developing new features based on user needs

Note: We do not use PHI to train AI models. AWS Bedrock's no-training policy ensures your patient data is never used for model improvement.

3. Information Sharing and Disclosure

3.1 Business Associate - AWS

We have executed a Business Associate Agreement with Amazon Web Services (AWS) for:

  • AWS Bedrock: PHI is transmitted to AWS Bedrock for real-time AI processing using foundation models. AWS maintains HIPAA-compliant infrastructure and does not store or use your data for training purposes.
  • AWS S3: User templates, clinical rules, and configuration data are stored in encrypted S3 buckets with customer-managed KMS keys.
  • AWS OpenSearch Serverless: Vector embeddings of templates (not containing PHI) are stored for intelligent retrieval.

3.2 Payment Processor - Stripe

We use Stripe, Inc. as our payment processor. Stripe receives your payment information (credit card details, billing address) to process subscription payments. Stripe maintains PCI DSS compliance and does not receive or process PHI.

3.3 Legal Requirements

We may disclose information, including PHI, if required by law, such as:

  • In response to valid subpoenas or court orders
  • To comply with HIPAA breach notification requirements
  • To prevent or address fraud, security, or technical issues
  • To protect the rights, property, or safety of MedChartMax, our users, or the public

3.4 No Sale of Data

We do not sell, rent, or trade your personal information or PHI to third parties for marketing purposes. We do not receive compensation for PHI disclosure.

4. Data Security

We implement comprehensive technical, administrative, and physical safeguards to protect your information:

4.1 Technical Safeguards

  • Encryption: All PHI is encrypted in transit using TLS 1.2+ and at rest using AES-256-GCM encryption
  • Customer-Managed Keys: AWS KMS customer-managed keys provide you with audit control over encryption operations
  • Multi-Factor Authentication: Optional MFA for account access
  • Automatic Session Timeout: Inactive sessions are automatically terminated to prevent unauthorized access
  • Access Controls: Role-based access controls limit system access to authorized personnel only

4.2 Administrative Safeguards

  • Designated HIPAA Security Officer responsible for compliance
  • Workforce training on HIPAA requirements and PHI handling
  • Regular security risk assessments and management
  • Incident response procedures for security breaches
  • Business Associate Agreements with all subcontractors

4.3 Audit Controls

  • Comprehensive audit trails of all system access and PHI handling
  • AWS CloudTrail logging for all API activities
  • S3 Server Access Logging for document operations
  • Audit logs retained for 7 years as required by HIPAA

5. Your Rights

5.1 HIPAA Rights

As a healthcare provider using MedChartMax, you have the following rights regarding PHI:

  • Access: Request access to PHI in a Designated Record Set within 30 days
  • Amendment: Request amendments to PHI within 60 days
  • Accounting of Disclosures: Request an accounting of PHI disclosures within 60 days
  • Restriction Requests: Request restrictions on uses and disclosures of PHI

5.2 California Privacy Rights

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  • Right to Know: Request disclosure of personal information collected
  • Right to Delete: Request deletion of personal information
  • Right to Opt-Out: Opt-out of sale of personal information (we do not sell personal information)
  • Right to Non-Discrimination: Exercise privacy rights without discriminatory treatment

5.3 Account Management

  • Update Information: Update your account information through account settings
  • Delete Account: Request account deletion by contacting support@medchartmax.com
  • Export Data: Request export of your templates and configuration data

To exercise any of these rights, contact us at compliance@medchartmax.com.

6. HIPAA Compliance

MedChartMax operates as your Business Associate under HIPAA. Our Business Associate Agreement governs our responsibilities regarding PHI handling.

6.1 Individual Practitioner Model

MedChartMax is designed for individual healthcare providers (Covered Entities) who use our platform independently. Each provider is responsible for:

  • Determining what PHI is minimum necessary for documentation purposes
  • Providing appropriate patient notice regarding PHI disclosure to MedChartMax
  • Obtaining necessary patient authorizations where required
  • Ensuring compliance with their own HIPAA obligations as Covered Entities

6.2 Breach Notification

In the event of a breach of unsecured PHI, we will notify you without unreasonable delay and no later than 60 calendar days after discovery, as required by 45 CFR § 164.410.

7. Data Retention

7.1 PHI Retention

Patient encounter data (PHI) is not permanently stored. PHI exists only during your active session for the purpose of generating medical notes and is cleared upon session termination. This design minimizes risk and ensures compliance with HIPAA minimum necessary standards.

7.2 Template and Configuration Data

User-specific templates, clinical rules, and configuration data are stored in AWS S3 with enterprise-grade encryption and retained to provide personalized documentation services. This data is retained for the duration of your subscription and for a reasonable period thereafter.

7.3 Audit Logs

Audit logs are retained for 7 years as required by HIPAA regulations (45 CFR § 164.316(b)(2)(i)).

7.4 Account Data

Upon account deletion, we will delete or de-identify your personal information within 90 days, except where retention is required by law or for legitimate business purposes (e.g., audit compliance, legal defense).

8. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to:

  • Essential Cookies: Maintain your session and authentication state
  • Preference Cookies: Remember your settings and preferences
  • Analytics Cookies: Understand usage patterns and improve service performance

You can control cookies through your browser settings. Disabling essential cookies may affect platform functionality.

9. Third-Party Links

Our platform may contain links to third-party websites or services not operated by us. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party sites you visit.

10. Children's Privacy

MedChartMax is designed for use by licensed healthcare providers only. Our services are not directed to individuals under the age of 18, and we do not knowingly collect personal information from minors.

11. International Data Transfers

MedChartMax operates in the United States and stores data on AWS infrastructure located in the US East (N. Virginia) region. If you access our services from outside the United States, your information will be transferred to, stored, and processed in the United States in accordance with this Privacy Policy and applicable laws.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by:

  • Posting the updated Privacy Policy on our website with a new "Last Updated" date
  • Sending email notification to your registered email address
  • Displaying a prominent notice within the platform

Your continued use of MedChartMax after changes are posted constitutes acceptance of the updated Privacy Policy.

13. Contact Information

For questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact:

HDN Works LLC, operator of the MedChartMax platform

HIPAA Compliance Officer

Email: compliance@medchartmax.com

Product Support: support@medchartmax.com

For general inquiries, visit our Contact Us page.

By using MedChartMax, you acknowledge that you have read and understood this Privacy Policy and agree to the collection, use, and disclosure of your information as described herein.