EN / ES
Sign In Start Free Trial

Privacy Policy

Last Updated: July 3, 2026 · Effective Date: June 14, 2026

1. About this Privacy Policy

Sefton Health, Inc. operates the Sefton platform ("Sefton," "we," "us," or "our"). This Privacy Policy explains how we handle information across the Service, including how we handle Protected Health Information (PHI) on behalf of healthcare providers.

This is not a Notice of Privacy Practices (NPP). Under 45 CFR 164.520, the NPP is issued by your healthcare provider (the Covered Entity), not by Sefton. For PHI, Sefton acts as a Business Associate of the provider: the provider's own Notice of Privacy Practices governs the provider–patient relationship, and our Business Associate Agreement governs how we handle PHI. This document is (a) our corporate privacy policy for account-holders and website visitors, and (b) a description of how we handle PHI as a Business Associate.

2. Scope and roles

  • Providers/practices ("Customers") are the Covered Entities (or their Business Associates). They control patient PHI in the Service.
  • Sefton is the Business Associate that processes PHI to provide the Service. We use and disclose PHI only as permitted by the Business Associate Agreement, HIPAA, and this Policy.
  • Patients interact with the patient portal and telehealth at the direction of their provider.

3. Information we handle

  • Account & profile data: names, work email, role, practice, credentials, and authentication data (including passkeys/WebAuthn and OAuth identity metadata).
  • Protected Health Information (PHI): patient demographics, clinical notes, telehealth recordings/transcripts, scheduling, messages, claims and billing data, and related records that providers create or upload.
  • Billing/subscription data: plan, seats, and payment-processor tokens. We keep subscription/payment payloads PHI-free; card data is handled by our payment processor (Stripe), not stored by us.
  • Technical/usage data: logs, device/app data, IP address, and diagnostics used to operate, secure, and improve the Service. We avoid placing PHI in URLs, analytics, or non-PHI logs.

4. How we use information

  • To provide and support the Service for your provider (the treatment, payment, and healthcare-operations purposes the provider directs);
  • To secure the Service (authentication, abuse/fraud prevention, audit logging, incident response);
  • To operate and improve the Service (reliability, performance, support);
  • To communicate about the Service (service notices, security, billing);
  • To comply with law and respond to lawful requests.

We do not sell personal information or PHI. We do not use PHI to train, fine-tune, or improve any AI/ML model (first-party or third-party, general-purpose or special-purpose), other than solely to deliver the contracted feature to the provider whose patient supplied the PHI. We also do not use de-identified data derived from PHI to train models offered to other customers. Automated documentation, transcription, and translation features process PHI only to deliver those features to your provider, under signed Business Associate Agreements with HIPAA-eligible vendors.

5. How PHI may be used and disclosed

Consistent with HIPAA and the Business Associate Agreement, PHI may be used or disclosed:

  • For treatment — to support the care your provider delivers;
  • For payment — eligibility, claims, ERA/remittance, and billing workflows;
  • For healthcare operations — quality, documentation, and administration the provider directs;
  • To sub-processors under Business Associate Agreements (e.g., AWS for hosting and HIPAA-eligible processing; Optum for clearinghouse/ERA), bound to protect PHI;
  • As required by law, and for required breach notification.

Other uses or disclosures require authorization as provided by HIPAA. Patients should consult their provider's Notice of Privacy Practices for the full description of their rights and the provider's practices.

6. Patient rights (exercised through the provider)

Patients generally have the right to: access and obtain a copy of their records; request corrections/amendments; request restrictions; receive an accounting of certain disclosures; and request confidential communications — as provided by HIPAA and state law. Because the provider is the Covered Entity, patients exercise these rights through their provider; we support providers in fulfilling them.

7. Telehealth, recording, and automated documentation

Where enabled and consented to, telehealth sessions may be recorded, transcribed, and processed by automated documentation tools, and real-time translation/subtitles may be provided. See the Telehealth Recording, Transcription & Automated Documentation Consent for details. Recordings, transcripts, and notes are PHI and protected accordingly.

8. Security

We apply administrative, physical, and technical safeguards appropriate for PHI, including: encryption in transit and at rest; access controls and least-privilege; multi-factor and passkey authentication options; tenant isolation; PHI-aware audit logging; secrets management; and security headers and origin controls. No system is perfectly secure, but we work to protect your information and to detect and respond to incidents.

9. Data retention and deletion

We retain PHI and account data for as long as needed to provide the Service and as required by the provider's instructions, the Business Associate Agreement, and applicable retention law. On termination, Customer data is made available for export for a reasonable period, then deleted or de-identified consistent with the Business Associate Agreement and law. Backups are retained on a defined cycle and then aged out.

10. Sub-processors

We use vetted sub-processors to operate the Service. PHI-bearing sub-processors operate under signed Business Associate Agreements (currently AWS and Optum). Payment, push-notification, identity, and source-control vendors are kept out of PHI scope. We will update this Policy and provide notice by reasonable means before adding a new PHI-bearing sub-processor.

11. International processing

The Service is operated in the United States and intended for U.S. healthcare use. Do not use the Service to send data subject to data-localization requirements that the Service is not configured to meet.

12. Children

The Service is used by providers, who may maintain records of pediatric patients as part of treatment. Patient minors' information is handled as PHI under the provider's direction and HIPAA, not as consumer data collected directly from children.

13. Changes to this Policy

We may update this Policy. Material changes will be communicated by reasonable means before they take effect. The "Effective date" above reflects the current version.

14. Contact

Questions or privacy requests:

Sefton Health, Inc. (operating the Sefton platform)

Email: privacy@sefton.health

Patients should also contact their provider, who is the Covered Entity for their records. If you believe your privacy rights have been violated, you may file a complaint with the U.S. Department of Health and Human Services, Office for Civil Rights, at www.hhs.gov/ocr/privacy/. We will not retaliate against you for filing a complaint.

© 2026 Sefton Health, Inc. All rights reserved.

sefton

Bilingual to the core — care, documentation, and billing in one platform.

Product

  • Features
  • Pricing
  • FAQ
  • Sign in
  • Start free trial

Legal

  • Privacy policy
  • Terms of service
  • Cookie policy
  • Accessibility

Compliance

  • Security
  • Business Associate Agreement
  • Legal center

Company

  • Contact
© Sefton — bilingual, billing-first practice management for allied health.