Smart Clinic
Features
Aesthetic clinicsDental clinicsSkin clinicsAll clinic types
AboutFAQContact

Privacy Policy

Last updated: September 20, 2026

Contents

1. Introduction2. Information We Collect3. How We Use Your Information4. Data Storage and Security5. Data Sharing and Disclosure6. AI-Assisted Features7. HIPAA-Inspired Architecture8. Data Retention9. Your Rights10. Cookies and Tracking11. Children's Privacy12. International Data Transfers13. Changes to This Policy14. Contact Us

Data questions?

[email protected]

1. Introduction

SmartClinic ("we", "our", or "the Platform") is a cloud-based clinic management platform designed for healthcare providers. We are committed to protecting the privacy and security of your personal and health-related information in compliance with applicable data protection laws, including the Health Insurance Portability and Accountability Act (HIPAA), the General Data Protection Regulation (GDPR), and the Israeli Privacy Protection Law.

This Privacy Policy explains what information we collect, how we use it, who we share it with, and what rights you have regarding your data.

2. Information We Collect

2.1 Information Provided by Clinic Staff

  • Account details: name, email address, phone number, job title, license number
  • Authentication credentials (securely hashed passwords)
  • Role and permission assignments
  • Work schedules and availability

2.2 Patient Information (Entered by Clinic Staff)

  • Demographics: name, date of birth, gender, contact information, identification number
  • Medical history, diagnoses, and clinical notes
  • Appointment records and treatment plans
  • Prescriptions and medication history
  • Laboratory orders and results
  • Billing and payment records
  • Uploaded documents, images, and dental charts

2.3 Automatically Collected Information

  • IP addresses and browser/user-agent data (for security and audit logs)
  • Login timestamps and session activity
  • Device and browser type

3. How We Use Your Information

We process personal data for the following purposes:

  • Providing and operating the clinic management platform
  • Managing user accounts, roles, and access permissions
  • Scheduling appointments and managing patient care workflows
  • Generating invoices, processing payments, and financial reporting
  • Sending transactional emails (appointment confirmations, verification emails, invoices)
  • Maintaining audit logs aligned with HIPAA Security Rule principles for all system actions
  • Ensuring platform security through login monitoring and account lockout protections
  • Improving platform performance and fixing bugs
  • Providing AI-assisted features, such as clinical note drafting and intake summaries, as described in Section 6

4. Data Storage and Security

We implement industry-standard technical and organizational measures to protect your data:

  • All data is encrypted in transit using TLS/SSL
  • Passwords are hashed using bcrypt with appropriate salt rounds
  • Sensitive configuration data is encrypted at rest using AES-256
  • Access is controlled through role-based permissions (RBAC) with the principle of least privilege
  • Comprehensive, immutable audit logs record all data access and modifications
  • JWT-based authentication with token expiration and refresh token rotation
  • Account lockout after repeated failed login attempts
  • Session inactivity timeouts for unattended terminals

Data is hosted on secure, access-controlled cloud infrastructure with encryption in transit and at rest, supported by regular backups and disaster recovery procedures.

5. Data Sharing and Disclosure

We do not sell, rent, or trade personal or patient information. Data may be shared only in the following circumstances:

  • Within your clinic: Staff members with appropriate permissions can view and manage patient data according to their assigned role
  • Service providers: We use trusted third-party services for email delivery (SMTP), cloud hosting, and file storage (S3-compatible), all bound by data processing agreements
  • Legal requirements: When required by law, court order, or regulatory authority
  • Emergency access: Under HIPAA Break-the-Glass provisions, authorized personnel may access patient data in emergencies with full audit trail logging
  • AI processing: Anthropic, PBC processes clinical content, with patient identifiers removed as described in Section 6, to provide our AI-assisted features
  • Payments: Freemius, our merchant of record, processes subscription payments and receives the clinic's billing contact details. It does not receive patient information

6. AI-Assisted Features

SmartClinic includes AI-assisted features that help clinic staff: drafting and improving clinical notes, summarizing a patient's intake answers before treatment, drafting follow-up messages, and an assistant that answers questions about clinic operations and can send clinic owners a daily briefing. These features use Claude, a language model provided by Anthropic, PBC, a company based in the United States, which processes the data as our service provider. On-premise installations can run these features on a locally hosted model instead, in which case no data is sent to Anthropic.

6.1 What We Send to Anthropic

  • Clinical information the task needs, such as symptoms, diagnoses, treatments, vital signs, allergies, medications, medical history, intake-form answers, dental chart findings and visit notes
  • The patient's age and gender, but never their date of birth
  • Text that staff type into an AI feature, such as a note to improve or a question for the assistant
  • Clinic context, such as the clinic's specialty and name, and aggregated figures for operational summaries, such as appointment counts and payment totals

6.2 How We Protect Patient Identity

  • Before a request about a patient leaves our servers, we remove the patient's name, ID number, phone number and email address, using the identifiers stored in the patient's record. The name is replaced with a placeholder and restored only after the response returns to our servers
  • We never send identity fields from intake forms: name, ID number, date of birth, address, contact details, signature or photo
  • If we cannot load the patient's record to run these checks, we do not send the request
  • Follow-up message drafts are written around a placeholder, and we add the patient's name on our servers
  • Questions for the assistant, and other free text that is not about one specific patient, are checked against the names of your clinic's patients, and any match is replaced with a placeholder before it is sent
  • Every request also passes an automated filter that removes email addresses, Israeli ID numbers, and phone numbers in Israeli or international format

Automated checks cannot catch every identifying detail in free text. A name is sent to Anthropic as written if it is misspelled, if it belongs to someone who is not a patient of the clinic, such as a relative, or if it appears in a note about a different patient. Staff should include only the details a task needs.

6.3 Safeguards

  • Anthropic processes the data only to provide the service, under its Commercial Terms and Data Processing Addendum
  • We have an executed Business Associate Agreement with Anthropic, and our Anthropic organization is configured to process health information under it
  • Anthropic's terms do not allow it to train its models on the data we send
  • Anthropic deletes API inputs and outputs within 30 days, unless it must keep them longer by law or to investigate a violation of its Usage Policy
  • Data is encrypted in transit
  • Only signed-in clinic staff with the right permissions can use AI features, and usage is rate-limited
  • AI output is a suggestion for staff to review. Nothing is saved to a patient's record unless a staff member saves it

7. HIPAA-Inspired Architecture

SmartClinic is architected following HIPAA security and privacy guidelines to support healthcare providers who require compliance. While SmartClinic has not undergone formal HIPAA certification, our platform incorporates many of the technical safeguards described in the HIPAA Security Rule:

  • Protected Health Information (PHI) access is restricted to authorized users only
  • All PHI access is logged in immutable audit trails
  • Emergency access (Break-the-Glass) procedures are available with mandatory justification and review
  • User accounts are deactivated (soft-deleted) to preserve audit history
  • Credential retrieval and offboarding procedures are tracked
  • Data retention policies comply with applicable healthcare record retention requirements

8. Data Retention

Patient records and clinical data are retained in accordance with applicable healthcare regulations and the retention policies configured by each clinic. When a staff account is deactivated, the account is soft-deleted (marked inactive) rather than permanently removed, to preserve audit trail integrity.

Permanent deletion of user accounts without clinical records is available to super administrators upon request.

9. Your Rights

Depending on your jurisdiction, you may have the following rights:

  • Access: Request a copy of the personal data we hold about you
  • Rectification: Request correction of inaccurate or incomplete data
  • Erasure: Request deletion of your data, subject to legal retention obligations
  • Restriction: Request restriction of processing in certain circumstances
  • Portability: Request your data in a structured, machine-readable format
  • Objection: Object to processing based on legitimate interests

To exercise any of these rights, please contact your clinic administrator or email us at [email protected].

10. Cookies and Tracking

SmartClinic uses cookies and similar browser storage for these purposes:

  • Essential: secure, HttpOnly cookies that keep you signed in, and a cookie that protects forms against cross-site request forgery
  • Preferences: settings such as your theme, sidebar layout and selected clinic, kept in your browser
  • Bot protection: Cloudflare Turnstile on some public forms
  • Analytics, only if you accept them in the cookie banner: PostHog and Google Analytics measure how visitors use our public website

Analytics tools do not run in the clinic dashboard and never receive patient names or contact details. For the full list of cookies and how to change your choice, see our Cookie Policy.

11. Children's Privacy

SmartClinic is a business-to-business platform intended for use by healthcare professionals. We do not knowingly collect personal information directly from individuals under the age of 16. Patient records for minors are entered and managed by authorized clinic staff.

12. International Data Transfers

Your data is processed on secure, access-controlled cloud infrastructure. If you access the platform from a different country or region, your data may be transferred to and processed in the location where our infrastructure operates. AI-assisted features send the data described in Section 6 to Anthropic, which may process it in the United States. We ensure appropriate safeguards are in place for any cross-border data transfers.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify registered users by email and update the "Last updated" date at the top of this page. Continued use of the platform after changes constitutes acceptance of the updated policy.

14. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us:

Smart Clinic

Email: [email protected]

Website: smartclinic.biz

© 2026 SmartClinic. All rights reserved.

Smart Clinic

Smart clinic management for modern healthcare.

Download SmartClinic on the App StoreGet SmartClinic on Google Play

Product

  • Features
  • Security
  • Integrations
  • Compare alternatives

Company

  • About
  • Blog
  • Contact
  • Partners

Resources

  • Help Center
  • HIPAA Compliance

Legal

  • Privacy Policy
  • Terms of Service
  • Refund Policy
  • Cookie Policy

© 2026 Smart Clinic. All rights reserved.

Dr Shuster Irena

v1.1.0