Legal
Privacy Policy
1. About this Privacy Policy
Sefton Health, Inc. operates the Sefton platform ("Sefton," "we," "us," or "our"). This Privacy Policy explains how we handle information across the Service, including how we handle Protected Health Information (PHI) on behalf of healthcare providers.
This is not a Notice of Privacy Practices (NPP). Under 45 CFR 164.520, the NPP is issued by your healthcare provider (the Covered Entity), not by Sefton. For PHI, Sefton acts as a Business Associate of the provider: the provider's own Notice of Privacy Practices governs the provider–patient relationship, and our Business Associate Agreement governs how we handle PHI. This document is (a) our corporate privacy policy for account-holders and website visitors, and (b) a description of how we handle PHI as a Business Associate.
2. Scope and roles
- Providers/practices ("Customers") are the Covered Entities (or their Business Associates). They control patient PHI in the Service.
- Sefton is the Business Associate that processes PHI to provide the Service. We use and disclose PHI only as permitted by the Business Associate Agreement, HIPAA, and this Policy.
- Patients interact with the patient portal and telehealth at the direction of their provider.
3. Information we handle
- Account & profile data: names, work email, role, practice, credentials, and authentication data (including passkeys/WebAuthn and OAuth identity metadata).
- Protected Health Information (PHI): patient demographics, clinical notes, telehealth recordings/transcripts, scheduling, messages, claims and billing data, and related records that providers create or upload.
- Billing/subscription data: plan, seats, and payment-processor tokens. We keep subscription/payment payloads PHI-free; card data is handled by our payment processor (Stripe), not stored by us.
- Technical/usage data: logs, device/app data, IP address, and diagnostics used to operate, secure, and improve the Service. We avoid placing PHI in URLs, analytics, or non-PHI logs.
4. How we use information
- To provide and support the Service for your provider (the treatment, payment, and healthcare-operations purposes the provider directs);
- To secure the Service (authentication, abuse/fraud prevention, audit logging, incident response);
- To operate and improve the Service (reliability, performance, support);
- To communicate about the Service (service notices, security, billing);
- To comply with law and respond to lawful requests.
We do not sell personal information or PHI. We do not use PHI to train, fine-tune, or improve any AI/ML model (first-party or third-party, general-purpose or special-purpose), other than solely to deliver the contracted feature to the provider whose patient supplied the PHI. We also do not use de-identified data derived from PHI to train models offered to other customers. Automated documentation, transcription, and translation features process PHI only to deliver those features to your provider, under signed Business Associate Agreements with HIPAA-eligible vendors.
5. How PHI may be used and disclosed
Consistent with HIPAA and the Business Associate Agreement, PHI may be used or disclosed:
- For treatment — to support the care your provider delivers;
- For payment — eligibility, claims, ERA/remittance, and billing workflows;
- For healthcare operations — quality, documentation, and administration the provider directs;
- To sub-processors under Business Associate Agreements (e.g., AWS for hosting and HIPAA-eligible processing; Claim.MD for clearinghouse/ERA), bound to protect PHI;
- As required by law, and for required breach notification.
Other uses or disclosures require authorization as provided by HIPAA. Patients should consult their provider's Notice of Privacy Practices for the full description of their rights and the provider's practices.
6. Patient rights (exercised through the provider)
Patients generally have the right to: access and obtain a copy of their records; request corrections/amendments; request restrictions; receive an accounting of certain disclosures; and request confidential communications — as provided by HIPAA and state law. Because the provider is the Covered Entity, patients exercise these rights through their provider; we support providers in fulfilling them.
7. Telehealth, recording, and automated documentation
Where enabled and consented to, telehealth sessions may be recorded, transcribed, and processed by automated documentation tools, and real-time translation/subtitles may be provided. See the Telehealth Recording, Transcription & Automated Documentation Consent for details. Recordings, transcripts, and notes are PHI and protected accordingly.
8. Security
We apply administrative, physical, and technical safeguards appropriate for PHI, including: encryption in transit and at rest; access controls and least-privilege; multi-factor and passkey authentication options; tenant isolation; PHI-aware audit logging; secrets management; and security headers and origin controls. No system is perfectly secure, but we work to protect your information and to detect and respond to incidents.
9. Data retention and deletion
We retain PHI and account data for as long as needed to provide the Service and as required by the provider's instructions, the Business Associate Agreement, and applicable retention law. On termination, Customer data is made available for export for a reasonable period, then deleted or de-identified consistent with the Business Associate Agreement and law. Backups are retained on a defined cycle and then aged out.
10. Sub-processors
We use vetted sub-processors to operate the Service. PHI-bearing sub-processors operate under signed Business Associate Agreements (currently AWS and Claim.MD). Payment, push-notification, identity, and source-control vendors are kept out of PHI scope. We will update this Policy and provide notice by reasonable means before adding a new PHI-bearing sub-processor.
11. International processing
The Service is operated in the United States and intended for U.S. healthcare use. Do not use the Service to send data subject to data-localization requirements that the Service is not configured to meet.
12. Children
The Service is used by providers, who may maintain records of pediatric patients as part of treatment. Patient minors' information is handled as PHI under the provider's direction and HIPAA, not as consumer data collected directly from children.
13. Changes to this Policy
We may update this Policy. Material changes will be communicated by reasonable means before they take effect. The "Effective date" above reflects the current version.
14. How you use the portal
If your provider gives you access to the patient portal, we record which parts of the portal you use and when — for example that you opened an appointment, completed an assigned exercise, read a message from your care team, or switched the portal to another language. We record this as counts and categories only.
- We do not record what your messages say, the names of your documents, or anything you type.
- We do not record whether you use accessibility features such as a screen reader.
We use this for three purposes:
- So your care team can follow up with you — for example if an intake form was left unfinished before your visit, or if you have not been able to join a video visit.
- To improve the portal itself, such as fixing a step where many people get stuck.
- For research, in de-identified and combined form — for example whether people who receive care in their own language have a different experience.
There are limits we hold ourselves to. This information is never used to deny, delay, or limit your care, and it is never used to score or rank patients. It is never sold, and never shared with an employer or an insurance company. Information about payments — such as viewing a bill or asking about a payment plan — is used only in combined form and is not shown to your clinician as a judgement about you. Whether you read your own visit notes is likewise only ever used in combined form.
If you would rather your information not be included in research, tell your provider and we will exclude it. This does not affect your care, and your care team can still see what they need to support you.
15. Measurement and analytics
Section 14 describes how we measure use of the patient portal. This section describes the other ways we measure use of the Service. Every measurement below is recorded by our own servers into our own database. We do not load a third-party analytics or session-replay script on the Service or on this website.
First-use milestones and account setup (providers). When a provider account uses a feature for the first time — for example the first voice command, the first translated session, or the first transcript that completes — and as a provider reaches each step of account setup, we record that milestone once. Each record holds the milestone name; a keyed one-way hash of the account and practice identifiers rather than the identifiers themselves; the role, workflow, platform (web, iOS, or server) and outcome; and a short list of permitted descriptive values such as the language pair or the setup step number. There is no field for names, notes, messages, or other content. Setup steps are recorded by our server as you move through setup, not by a script in your browser. These records are read as counts per milestone, by Sefton administrators only, to see which features are adopted and where setup is abandoned.
Language and workflow timing. For interpreted or translated encounters we record the encounter type, the languages involved, the number of utterances, the duration, and the outcome, together with hashed practice, clinician, and patient identifiers. For the time it takes to move from a visit to a signed note and a submitted claim we record timestamps and durations for each stage; that record keeps the internal visit, patient, and clinician record identifiers so the stages can be tied together. Neither record holds transcript, note, or message text. Timing is shown to a provider for that provider's own visits, and to anyone else only as totals and averages.
Weekly rollups and the research page. Once a week we compute, for each practice, totals such as claims filed, notes signed, active clinicians, multilingual sessions, and languages used, and per-language totals in which patients appear only as a count of distinct hashed identifiers. Figures on our public research page come either from snapshots we publish deliberately, each with a sample size of at least five, or from live totals that are withheld until at least five records exist.
Network benchmarks (providers). A practice's adjudicated claims can contribute to cross-practice benchmarks. The automatic contribution computes three rates — denial rate, clean-claim rate, and average days to payment — and the pool accepts at most six named rates in total and nothing else. Each contributed rate is stored with a keyed one-way hash of the provider identifier, the specialty and provider type, and the month (never the day) it relates to. Contribution runs automatically, at most once per month per provider, for providers who have not turned it off, and does not run at all if the hashing key is not configured. Benchmarks are shown only when at least fifty distinct contributors are in the pool, and peer patterns only when they are drawn from at least ten practices. Contribution is on by default; the Service keeps a per-provider preference that turns it off.
Website attribution. When you first arrive at our website or the Service, a first-party cookie named sef_ft stores, for 90 days, the referring site, the first page you landed on, and any campaign tags in the address (utm_source, utm_medium, utm_campaign, utm_term, utm_content). If you then register a provider account, those values are saved with the new account together with the registration request's referer, IP address, and browser user agent, so we can see how practices find us. The cookie is set for the sefton.health domain only.
Who sees what, and for how long. Milestone counts, rollups, and benchmark inputs are read by Sefton administrators in the administration console. Practices see benchmarks only as pooled figures, and workflow timing only for their own visits. The public research page shows only the published and threshold-protected figures described above. We keep these measurement records under section 9; no separate, shorter retention period is currently applied to them.
16. Contact
Questions or privacy requests:
Sefton Health, Inc. (operating the Sefton platform)
Email: privacy@sefton.health
Patients should also contact their provider, who is the Covered Entity for their records. If you believe your privacy rights have been violated, you may file a complaint with the U.S. Department of Health and Human Services, Office for Civil Rights, at www.hhs.gov/ocr/privacy/. We will not retaliate against you for filing a complaint.