Privacy Policy
Effective date:
1. Scope and Roles
This Privacy Policy explains how PracticeFront("PracticeFront," "we," "us," or "our") collects, uses, and shares information in connection with our website, dashboard, desktop companion, connector, and related services (the "Service").
For account and operational data about users and organizations, PracticeFront determines how that information is processed to operate the Service. For practice protected health information (PHI) and other PMS-derived practice data processed on behalf of customer practices, PracticeFront acts as a business associate (or service provider) to those practices, subject to HIPAA and any applicable business associate agreement (BAA).
2. Information We Collect
Depending on how you use the Service, we may collect:
- Account identity — name, email address, profile image URL (for example via Gravatar), and similar account fields
- Organization and practice metadata — organization name, practice identifiers, membership roles, and configuration
- Authentication and security data — credentials (hashed), session data, multi-factor authentication status, and security event metadata
- Connector and sync operational telemetry — non-PHI status such as connector health, job state, and sync timing
- PMS and PHI sync payloads — practice data synced from the PMS (which may include PHI) for normalization and authorized use
- Audit metadata — records of who accessed what practice data, when, and in what context (without unnecessarily storing raw PHI in logs)
- Approximate location derived from IP at signup — coarse location string resolved from IP (for example via IPInfo)
- Cookies or similar technologies - used for authentication, preferences, site functionality, and product analytics
- Product analytics - page views, in-app usage, and device/browser metadata sent to PostHog so we can understand how the Service is used. We identify analytics to the account user id, not to practice PHI
Sources include you, your organization, the on-premises connector and PMS, authorized partners (for example write-intent submissions where enabled), and our service providers.
3. How We Use Information
We use information to:
- Provide, operate, and secure the Service
- Sync, normalize, store, and display practice data for authorized users
- Deliver data to partners only as authorized by the practice
- Calculate practice-health and partner-performance insights
- Communicate about the Service, support, and security
- Improve reliability and product quality
- Comply with law and enforce our Terms
4. How We Share Information
We may share information with:
- Service providers / subprocessors that help us run the Service, including cloud hosting such as AWS and Vercel, email delivery providers, realtime infrastructure (for example Pusher-compatible services), and product analytics (PostHog), under contractual obligations appropriate to their role
- Practice-authorized partners — partners receive only data the practice has permitted through the Service
- Legal and safety — when required by law, to protect rights and safety, or in connection with a corporate transaction subject to appropriate safeguards
We do not sell personal information for money.
5. Retention
We retain account and operational data for as long as needed to provide the Service and for legitimate business or legal purposes. PHI access audit logs are retained for seven (7) years (or longer if required by law or the applicable BAA). Practice data retention and deletion after account closure follow our customer agreements, the applicable BAA, and law.
6. Security
We use administrative, technical, and physical safeguards designed to protect information, including encryption in transit, encryption at rest as implemented for relevant systems, role-based access controls, tenant isolation (including database row-level security for practice data), and audit logging of PHI access. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
7. Your Rights and Choices
Depending on your role and applicable law, you may request access, correction, or deletion of personal information we hold about you as an account user. For practice PHI and other practice-controlled data, requests are generally mediated by the customer practice (the covered entity or controlling organization), and we will assist that practice as required by the BAA and law.
You may update certain account profile settings in the product. You may revoke partner connections in the dashboard where that control is available.
8. Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13 as account users. Patient data about minors that appears in PMS sync is processed on behalf of the practice under the applicable BAA and practice instructions, not as a consumer child account.
9. Changes and Contact
We may update this Privacy Policy from time to time. We will post the updated policy with a new effective date. Material changes will be communicated as required by law.
This policy is intended for a U.S.-focused service. Privacy questions: privacy@practicefront.com.