Privacy Policy

Effective date: March 29, 2026

This Privacy Policy explains how Harmonize Health collects, uses, and protects information in connection with our services, software, and websites. We work with independent healthcare practices and handle operational data related to appointment scheduling, urgent provider communications, and basic patient information.

Covered data

  • Practice account information (contact details, user credentials).
  • Scheduling data, urgent call routing details, and basic patient information provided by a practice.
  • Usage data (logs, device and browser details, and service performance data).
  • If you submit our SMS opt-in form, your first name, last name, mobile number, consent, and related request metadata.

Patient information that we handle for a healthcare practice may be protected health information (PHI) under HIPAA.

How we use information

  • Provide and operate the Services.
  • Secure, maintain, and improve the Services.
  • Respond to requests and provide support.
  • Send appointment reminders and care updates to enrolled patients.
  • Comply with legal obligations.

We do not sell PHI or practice data.

SMS opt-in information

When you submit an SMS opt-in form on our website, we collect the name and phone number you provide, your consent to receive SMS messages related to your care and/or appointment schedule, and basic technical details about the request. We use this information to manage enrollment, send care updates, respond to support requests, and maintain records of consent.

Msg & data rates may apply. Msg frequency varies but should be a dozen messages a week. You can opt out by replying STOP or using our unsubscribe page. You can reply HELP for help.

HIPAA and BAA

When we handle PHI on behalf of a healthcare practice, we act as a business associate under HIPAA. Our use and disclosure of PHI are governed by our Business Associate Agreement (BAA) with that practice and applicable HIPAA regulations. Practices are responsible for providing their own HIPAA notices to patients.

Sharing and disclosures

  • Service providers who help us operate the Services (subject to contract).
  • To comply with law or legal process.
  • To protect the rights, safety, and security of Harmonize Health, our customers, or others.

We may also share information as otherwise authorized by the practice and the BAA.

Mobile Messaging Disclosure

Mobile numbers, text messaging originator opt-in data, and consent records are not shared with third parties or affiliates for marketing or promotional purposes. We may share this information only with service providers that support delivery and operation of the Services on our behalf, subject to contractual safeguards.

Security

We use reasonable administrative, technical, and physical safeguards designed to protect information. No system is completely secure, and we cannot guarantee absolute security.

Data retention

We retain information for as long as needed to provide the Services, meet legal obligations, resolve disputes, and enforce our agreements. Retention of PHI is handled consistent with the BAA.

Your choices

Practices may request access, correction, or deletion of their account data by contacting us. Patient requests related to PHI should be directed to the patient's practice, which is the HIPAA- covered entity responsible for patient rights.

Changes

We may update this Privacy Policy by posting an updated version. Material changes will take effect on the effective date shown above.

Contact

Questions? Email info@harmonize.health.