1. Introduction
Essence Health ("we," "our," or "us") operates the Essence EMR platform (essence-health.com). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our electronic medical records service.
We are committed to protecting the privacy and security of your personal and health-related information. By using Essence EMR, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
Account Information
- Name, email address, and professional credentials
- Practice or organization name
- Billing information (processed securely through our payment provider)
Patient Health Information (PHI)
- Patient demographics (name, date of birth, contact information)
- Clinical documentation including SOAP notes
- Treatment plans and medical records
- Voice recordings processed for AI transcription (not stored after processing)
Usage Data
- Log data (IP address, browser type, pages visited)
- Device information
- Feature usage analytics (anonymized)
3. How We Use Your Information
- To provide and maintain the Essence EMR service
- To process AI-powered documentation and transcription
- To manage your account and subscription
- To communicate service updates and support
- To improve our platform and develop new features
- To comply with legal obligations
4. Data Security
We implement industry-standard security measures to protect your data:
- Encryption in transit (TLS 1.3) and at rest (AES-256)
- Role-based access controls
- Regular security audits and vulnerability assessments
- Multi-tenant data isolation — your data is never accessible to other organizations
- Automatic session management and token expiration
5. Data Sharing and Disclosure
We do not sell your personal information or patient health data. We may share information only in the following circumstances:
- Service Providers: Third-party services that help us operate (e.g., cloud hosting, AI processing), bound by data processing agreements
- Legal Requirements: When required by law, subpoena, or legal process
- Business Transfers: In connection with a merger, acquisition, or sale of assets (with prior notice)
6. AI and Data Processing
Essence EMR uses artificial intelligence to assist with clinical documentation. Important details about our AI processing:
- Voice recordings are processed in real-time and are not stored after transcription
- AI-generated content is always presented for clinician review before saving
- Your clinical data is not used to train AI models
- AI processing occurs on secure, HIPAA-compliant infrastructure
7. Your Rights
You have the right to:
- Access and export your data at any time
- Request correction of inaccurate information
- Request deletion of your account and associated data
- Opt out of non-essential communications
- Withdraw consent for data processing
8. Data Retention
We retain your data for as long as your account is active or as needed to provide services. Clinical records are retained in accordance with applicable healthcare record retention laws. Upon account deletion, personal data is removed within 30 days, except where retention is required by law.
9. Cookies and Tracking
We use essential cookies for authentication and session management. We may use analytics cookies to understand how users interact with our platform. You can control cookie preferences through your browser settings.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the platform. Continued use of the service after changes constitutes acceptance of the updated policy.
11. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at:
Email: support@essence-health.com