Privacy Policy
1. About this Privacy Policy
Sefton Health, Inc. operates the Sefton platform ("Sefton," "we," "us," or "our"). This Privacy Policy explains how we handle information across the Service, including how we handle Protected Health Information (PHI) on behalf of healthcare providers.
This is not a Notice of Privacy Practices (NPP). Under 45 CFR 164.520, the NPP is issued by your healthcare provider (the Covered Entity), not by Sefton. For PHI, Sefton acts as a Business Associate of the provider: the provider's own Notice of Privacy Practices governs the provider–patient relationship, and our Business Associate Agreement governs how we handle PHI. This document is (a) our corporate privacy policy for account-holders and website visitors, and (b) a description of how we handle PHI as a Business Associate.
2. Scope and roles
- Providers/practices ("Customers") are the Covered Entities (or their Business Associates). They control patient PHI in the Service.
- Sefton is the Business Associate that processes PHI to provide the Service. We use and disclose PHI only as permitted by the Business Associate Agreement, HIPAA, and this Policy.
- Patients interact with the patient portal and telehealth at the direction of their provider.
3. Information we handle
- Account & profile data: names, work email, role, practice, credentials, and authentication data (including passkeys/WebAuthn and OAuth identity metadata).
- Protected Health Information (PHI): patient demographics, clinical notes, telehealth recordings/transcripts, scheduling, messages, claims and billing data, and related records that providers create or upload.
- Billing/subscription data: plan, seats, and payment-processor tokens. We keep subscription/payment payloads PHI-free; card data is handled by our payment processor (Stripe), not stored by us.
- Technical/usage data: logs, device/app data, IP address, and diagnostics used to operate, secure, and improve the Service. We avoid placing PHI in URLs, analytics, or non-PHI logs.
4. How we use information
- To provide and support the Service for your provider (the treatment, payment, and healthcare-operations purposes the provider directs);
- To secure the Service (authentication, abuse/fraud prevention, audit logging, incident response);
- To operate and improve the Service (reliability, performance, support);
- To communicate about the Service (service notices, security, billing);
- To comply with law and respond to lawful requests.
We do not sell personal information or PHI. We do not use PHI to train, fine-tune, or improve any AI/ML model (first-party or third-party, general-purpose or special-purpose), other than solely to deliver the contracted feature to the provider whose patient supplied the PHI. We also do not use de-identified data derived from PHI to train models offered to other customers. Automated documentation, transcription, and translation features process PHI only to deliver those features to your provider, under signed Business Associate Agreements with HIPAA-eligible vendors.
5. How PHI may be used and disclosed
Consistent with HIPAA and the Business Associate Agreement, PHI may be used or disclosed:
- For treatment — to support the care your provider delivers;
- For payment — eligibility, claims, ERA/remittance, and billing workflows;
- For healthcare operations — quality, documentation, and administration the provider directs;
- To sub-processors under Business Associate Agreements (e.g., AWS for hosting and HIPAA-eligible processing; Optum for clearinghouse/ERA), bound to protect PHI;
- As required by law, and for required breach notification.
Other uses or disclosures require authorization as provided by HIPAA. Patients should consult their provider's Notice of Privacy Practices for the full description of their rights and the provider's practices.
6. Patient rights (exercised through the provider)
Patients generally have the right to: access and obtain a copy of their records; request corrections/amendments; request restrictions; receive an accounting of certain disclosures; and request confidential communications — as provided by HIPAA and state law. Because the provider is the Covered Entity, patients exercise these rights through their provider; we support providers in fulfilling them.
7. Telehealth, recording, and automated documentation
Where enabled and consented to, telehealth sessions may be recorded, transcribed, and processed by automated documentation tools, and real-time translation/subtitles may be provided. See the Telehealth Recording, Transcription & Automated Documentation Consent for details. Recordings, transcripts, and notes are PHI and protected accordingly.
8. Security
We apply administrative, physical, and technical safeguards appropriate for PHI, including: encryption in transit and at rest; access controls and least-privilege; multi-factor and passkey authentication options; tenant isolation; PHI-aware audit logging; secrets management; and security headers and origin controls. No system is perfectly secure, but we work to protect your information and to detect and respond to incidents.
9. Data retention and deletion
We retain PHI and account data for as long as needed to provide the Service and as required by the provider's instructions, the Business Associate Agreement, and applicable retention law. On termination, Customer data is made available for export for a reasonable period, then deleted or de-identified consistent with the Business Associate Agreement and law. Backups are retained on a defined cycle and then aged out.
10. Sub-processors
We use vetted sub-processors to operate the Service. PHI-bearing sub-processors operate under signed Business Associate Agreements (currently AWS and Optum). Payment, push-notification, identity, and source-control vendors are kept out of PHI scope. We will update this Policy and provide notice by reasonable means before adding a new PHI-bearing sub-processor.
11. International processing
The Service is operated in the United States and intended for U.S. healthcare use. Do not use the Service to send data subject to data-localization requirements that the Service is not configured to meet.
12. Children
The Service is used by providers, who may maintain records of pediatric patients as part of treatment. Patient minors' information is handled as PHI under the provider's direction and HIPAA, not as consumer data collected directly from children.
13. Changes to this Policy
We may update this Policy. Material changes will be communicated by reasonable means before they take effect. The "Effective date" above reflects the current version.
14. Contact
Questions or privacy requests:
Sefton Health, Inc. (operating the Sefton platform)
Email: privacy@sefton.health
Patients should also contact their provider, who is the Covered Entity for their records. If you believe your privacy rights have been violated, you may file a complaint with the U.S. Department of Health and Human Services, Office for Civil Rights, at www.hhs.gov/ocr/privacy/. We will not retaliate against you for filing a complaint.
© 2026 Sefton Health, Inc. All rights reserved.