Privacy Policy

Last updated: March 17, 2026

1. Introduction

Docnostix ("we," "our," or "us") operates an AI-powered Revenue Cycle Management platform for healthcare providers. This Privacy Policy describes how we collect, use, disclose, and protect your information — including your health information — when you use our services. We encourage you to read this policy carefully before authorizing Docnostix to access your health information.

2. Your Consent

Docnostix will never access, use, or share your health information without your express consent. Before we access any of your health information, you will be asked to review this Privacy Policy and take an affirmative action (such as clicking a consent button or checking a box) to confirm that you have read and agree to its terms.

You may withdraw your consent at any time. See Section 9 ("Withdrawing Consent & Data Disposal") for details on how to do this and what happens to your data afterward.

3. Information We Collect

We may collect the following types of information:

  • Account Information: Name, email address, organization details, and login credentials.
  • Health Information: Claims data, patient demographic information, insurance details, eligibility records, and clinical data as provided by your organization or accessed through authorized payer and EHR integrations.
  • Usage Data: Log data, device information, and analytics about how you interact with our platform.

Device Access: Docnostix does not access contacts, photos, location data, or any other personal information from your device beyond what is necessary to operate the web application (such as browser type and screen size for rendering purposes).

4. How Your Health Information May Be Accessed, Exchanged, or Used

Your health information may be accessed, exchanged, or used in the following ways:

  • To submit, track, and manage insurance claims on your behalf
  • To verify eligibility and obtain prior authorizations from payers
  • To analyze claim denials and generate appeals
  • To produce AI-powered coding suggestions and revenue insights
  • To generate reports and analytics for your organization
  • To exchange data with payers and clearinghouses (such as TriZetto/Availity) as necessary to process claims

Health information processed by our AI services is handled through HIPAA-compliant providers with zero data retention agreements in place. Your health data is not used to train AI models.

5. Sharing and Sale of Health Information

We do not sell your health information. We will never sell your health information to any third party, now or in the future.

We may share your health information only in the following circumstances, and only with your express consent (unless otherwise noted):

  • Service Providers: With trusted third-party service providers who help us operate the platform (e.g., cloud hosting, AI processing, clearinghouse partners), subject to data protection agreements and Business Associate Agreements (BAAs).
  • Payers & Clearinghouses: To submit and process claims, check eligibility, and handle remittance on your behalf.
  • Legal Requirements: When required by law, regulation, or legal process (e.g., court order, subpoena). This is the only circumstance where sharing may occur without your separate express consent.
  • Business Transfers: In connection with a merger, acquisition, or sale of all or a portion of our business. In such an event, we will notify you and obtain your express consent before your health information is transferred to the new entity.

6. HIPAA Compliance

Docnostix acts as a Business Associate under HIPAA when processing Protected Health Information (PHI) on behalf of Covered Entities. We maintain appropriate administrative, physical, and technical safeguards to protect PHI. We enter into Business Associate Agreements (BAAs) with our customers and subcontractors as required by HIPAA.

7. Data Security Safeguards

We maintain safeguards consistent with responsible stewardship of personal and health data to protect against loss, unauthorized access, use, alteration, destruction, unauthorized annotation, or disclosure. These safeguards include:

  • TLS 1.2+ encryption for all data in transit
  • Encryption at rest for all stored data
  • Role-based access controls with field-level PHI protection
  • AI services configured with zero data retention (HIPAA BAA in place)
  • Comprehensive audit logging of all data access
  • Regular security assessments and vulnerability testing
  • Token-based authentication with automatic session expiration
  • Circuit breakers and rate limiting to prevent unauthorized bulk access

8. Data Retention

We retain your data for as long as necessary to provide our services and comply with legal obligations. Healthcare data retention periods comply with applicable federal and state regulations. When data is no longer needed and no legal retention requirement applies, it is securely deleted using industry-standard methods.

9. Withdrawing Consent & Data Disposal

You may withdraw your consent and discontinue Docnostix's access to your health information at any time by:

What happens when you withdraw consent:

  • We will act on your request in accordance with applicable law and our data-retention obligations, and will cease accessing and processing your health information as promptly as reasonably practicable.
  • Active integrations and data connections associated with your account will be disconnected as part of processing your request.
  • Your health information will be securely deleted once any legally required retention period has elapsed; where the law requires a longer retention period, the data is retained only as long as legally required and then deleted.
  • We will confirm completion of your request.

10. Your Rights

Depending on your jurisdiction, you may have rights to access, correct, delete, or port your data. To exercise these rights, contact us using the information below. We will respond to all verified requests within 30 days.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes through the platform or via email at least 30 days before they take effect. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.

12. Contact Us

For questions about this Privacy Policy or our data practices, please contact our Privacy Officer at privacy@docnostix.com.

© 2026 Docnostix. All rights reserved.