Kipu EMR

Privacy Policy

Last Updated: October 8, 2025

1. Introduction

Welcome to Kipu ("we," "us," or "our"). We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application.

2. Information We Collect

2.1 Personal Information

• Account Information: Name, email address, professional credentials
• Authentication Data: Login credentials, authentication tokens
• Professional Information: Role, department, healthcare organization affiliation

2.2 Health Information

As a HIPAA-compliant healthcare application, we handle Protected Health Information (PHI):
• Patient records accessed through the App
• Clinical notes and documentation
• Treatment and medication information

2.3 Technical Information

• Device Information: Device type, operating system, unique device identifiers
• Usage Data: Features accessed, session duration, interaction patterns
• Log Data: IP addresses, access times, error logs

2.4 Location Information

We may collect location data to ensure compliance with geographic access restrictions. Location services can be disabled in your device settings.

3. How We Use Your Information

3.1 Service Delivery

• Authenticating users and managing access
• Providing healthcare management features
• Synchronizing data across devices

3.2 Security and Compliance

• Ensuring HIPAA compliance
• Detecting and preventing unauthorized access
• Maintaining audit logs as required by healthcare regulations

3.3 Service Improvement

• Analyzing usage patterns to improve functionality
• Troubleshooting technical issues
• Developing new features

4. How We Share Your Information

4.1 We DO Share Information With:

• Your Healthcare Organization: For authorized healthcare operations
• Business Associates: HIPAA-compliant service providers who assist in operations
• Legal Authorities: When required by law or to protect rights and safety

4.2 We DO NOT Share Information For:

• Marketing purposes
• Third-party advertising
• Sale to data brokers

5. HIPAA Compliance

5.1 Protected Health Information (PHI)

• We handle PHI in accordance with HIPAA Privacy and Security Rules
• We maintain appropriate administrative, physical, and technical safeguards
• We conduct regular security risk assessments

5.2 Your HIPAA Rights

• Right to access your PHI
• Right to request amendments
• Right to receive accounting of disclosures
• Right to request restrictions on use and disclosure

5.3 Breach Notification

In the event of a breach of unsecured PHI, we will notify affected individuals and the Secretary of the Department of Health and Human Services as required by law.

6. Data Security

We implement industry-standard security measures:

Technical Safeguards:
• End-to-end encryption for data transmission
• Encrypted data storage
• Multi-factor authentication
• Secure session management

Physical Safeguards:
• Secure data centers with restricted access
• Environmental controls and monitoring
• Backup and disaster recovery systems

Administrative Safeguards:
• Security training for all personnel
• Access controls and user authentication
• Regular security audits and assessments

7. Data Retention

• Active User Data: Retained while your account is active
• Audit Logs: Retained for 6 years as required by HIPAA
• Inactive Accounts: Data may be deleted after 90 days of inactivity
• Legal Requirements: Some data may be retained longer to comply with legal obligations

8. Your Privacy Rights

8.1 Access and Correction

You can access and update your account information through the App. You can request copies of your PHI.

8.2 Data Deletion

You can request deletion of your account. Note: Some information must be retained for legal compliance.

8.3 Opt-Out Rights

You can opt out of non-essential communications. You cannot opt out of essential service notifications.

9. Children's Privacy

This App is not intended for use by individuals under 18 years of age. We do not knowingly collect information from children.

10. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place for such transfers.

11. California Privacy Rights

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
• Right to know what personal information is collected
• Right to know if personal information is sold or disclosed
• Right to opt out of sale (Note: We do not sell your information)
• Right to deletion
• Right to non-discrimination

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy in the App, sending an email notification, or displaying a prominent notice. Your continued use of the App after changes constitutes acceptance of the updated policy.

13. Contact Us

For questions, concerns, or to exercise your privacy rights, please contact:

Privacy Officer
Kipu EMR
Email: privacy@kipuhealth.com
Phone: 1-800-KIPU-HELP

HIPAA Privacy Officer
Email: hipaa@kipuhealth.com

14. Dispute Resolution

If you have concerns about our privacy practices, please contact us first. We will investigate and attempt to resolve any complaints.

For HIPAA-related complaints, you may also file a complaint with:

U.S. Department of Health and Human Services
Office for Civil Rights
Website: www.hhs.gov/ocr/privacy/hipaa/complaints/