CODAVIA HEALTH AI-NATIVE EMR
Book A Demo
PRIVACY POLICY

How we handle patient data, and yours.

PHI is processed as a HIPAA business associate under a signed BAA. The ambient scribe does not store patient audio.

LAST UPDATED: [ effective date ]
Read this first

This is a working draft prepared from the practices already described across this site. It has not been reviewed by counsel. Do not publish it as a binding policy until a qualified healthcare privacy attorney has reviewed it against your actual data flows, subprocessors and state-law obligations.

Codavia Health provides an electronic health record platform to healthcare organizations in the United States. This policy explains what we collect, how we use it, and the distinct roles we play with respect to two very different categories of information.

1. Two kinds of data, two different roles

Protected Health Information (PHI)

When a healthcare provider uses Codavia Health, that provider is the covered entity and Codavia Health acts as a business associate under HIPAA. We process PHI solely to provide the service, on the provider’s instructions, under a signed Business Associate Agreement (BAA). We do not own that PHI, we do not sell it, and we do not use it for advertising.

Website and account information

When you browse this website, request a demo, or administer an account, we act as the controller of that limited business-contact information. It is separate from PHI and is handled as described below.

2. Information we collect

  • Information you give us. Name, work email, organization, role, and anything you include in a demo request or support message.
  • PHI processed on behalf of a provider. Patient demographics, clinical documentation, orders, results, prescriptions, and billing data entered into or generated by the platform.
  • Technical and usage data. Log data, IP address, browser and device information, and platform usage events used to operate, secure and improve the service.

3. Ambient scribe and audio

The ambient scribe does not store patient audio. Audio is processed to produce a draft clinical note and is not retained as a recording. The resulting note becomes part of the patient record under the provider’s control, and the provider reviews and signs it.

4. How we use information

  • To provide, secure, maintain and support the platform.
  • To generate clinical documentation, decision support and coding suggestions requested by the provider.
  • To communicate about your account, respond to enquiries, and provide support.
  • To meet legal, regulatory and contractual obligations.

We do not sell personal information or PHI. We do not use PHI to train general-purpose models outside the scope permitted by the applicable BAA.

5. Sharing and subprocessors

We share information only with service providers who help us run the platform (for example hosting and infrastructure), each bound by written obligations at least as protective as those we accept, including BAAs where PHI is involved. Current subprocessors: [ list subprocessors ]

We may also disclose information where required by law, or to protect the rights, safety and security of patients, customers or the platform.

6. Security

Security measures are described in detail on our security and compliance page and include encryption in transit and at rest, role-based access control, PHI audit logging, US-based hosting, and a completed SOC 2 audit. No system is perfectly secure, but PHI protection is designed in rather than added on.

7. Retention

PHI is retained according to the provider’s instructions and the terms of the BAA, and returned or destroyed on termination as that agreement requires. Business-contact and technical data is retained only as long as needed for the purposes above. Standard retention periods: [ specify retention periods ]

8. Your rights

Patients: your rights of access, amendment and accounting of disclosures run through your healthcare provider, who controls your record. Please contact them directly — we will support them in responding.

Website visitors and account users: you may request access to, correction of, or deletion of the business-contact information we hold about you by emailing info@codavia.health. State-specific rights (including under applicable US state privacy laws): [ confirm applicable state laws ]

9. Cookies

This site uses only what is necessary to serve and secure the pages. Cookie and analytics detail: [ confirm current cookie/analytics use ]

10. Children

This website is not directed at children. PHI relating to pediatric patients is processed solely on the instruction of the treating provider under the BAA.

11. Changes

We will post any changes on this page and update the date above. Material changes affecting PHI handling will be communicated to affected customers directly.

12. Contact

Privacy questions, BAA requests and data enquiries: info@codavia.health. Privacy officer: [ name privacy officer ]

SEE IT ON YOUR OWN WORKFLOW

Give your clinicians their evenings back.

A 30-minute walkthrough on a live chart — ambient scribe, decision support, coding and the patient portal, end to end.

Book A Demo
No implementation fee for pilot practices · BAA signed before any PHI