Privacy Policy
Last updated: August 5, 2026
FusioMed ("FusioMed", "we", "us") provides a practice management platform that doctors, clinics, and hospitals ("Customers") use to manage patients, visits, billing, and related operations. This policy explains what information we collect, how we use it, and the choices available to you. It applies to our marketing site, application, and any communications we send.
1. Two kinds of data we handle
Because FusioMed is software that clinics use to run their practice, we handle two distinct categories of information, and our role is different for each:
- Account Data: information about the people who sign up for and use FusioMed directly (clinic owners, practitioners, and staff), such as name, email, phone number, role, and authentication activity. For this data, FusioMed is the data controller.
- Patient Data: health and demographic information a Customer enters into the platform about their own patients (medical history, visit notes, insurance details, documents, billing records). For this data, the Customer is the data controller and, where HIPAA applies, the covered entity. FusioMedprocesses this information solely on the Customer's behalf and instructions, acting as a data processor / business associate under agreement with that Customer. We do not use Patient Data for our own independent purposes.
If you are a patient of a clinic using FusioMed, that clinic, not FusioMed, is responsible for your medical records and for honoring your rights under HIPAA or other applicable law. Please contact your clinic directly with requests about your own health information.
2. Information we collect
- Account information: name, email address, phone number, role/permissions, and organization details you or your Customer provide when creating and managing an account.
- Patient Data: demographics, medical history, insurance, visit notes, documents, and billing records entered by Customer staff in the course of using the platform.
- Contact form submissions: name, email, phone number, and message content you submit through our public contact form.
- Technical data: IP address, browser/device information, and log data, used for security, fraud prevention, and abuse protection (for example, rate-limiting the contact form).
- Cookies: a small number of strictly necessary cookies used to keep you signed in and remember your selected workspace (see Section 7).
3. How we use information
- Operate, maintain, and secure the FusioMed platform.
- Authenticate users and enforce role-based access to each organization's data.
- Send transactional communications you or your Customer's clinic have requested, for example, password reset and verification emails, appointment/follow-up reminders, and phone verification codes.
- Respond to inquiries submitted through our contact form.
- Detect, investigate, and prevent fraud, abuse, and security incidents.
- Comply with legal obligations and enforce our agreements.
- Improve and develop the platform, including through aggregated, de-identified usage analysis.
We do not sell personal information, and we do not use Patient Data to train AI models or for any purpose outside operating the platform on the Customer's behalf.
4. How we share information
We share information only as necessary to provide the service, and never sell it. We rely on a small number of trusted third-party service providers to operate the platform, including for secure hosting, database storage, email and SMS delivery, and bot/abuse protection on our public contact form. Each provider is bound by contract to protect the data they handle and may only use it to provide their service to us.
We may also disclose information if required by law, to protect the rights, safety, or property of FusioMed, our Customers, or others, or in connection with a merger, acquisition, or sale of assets, subject to the same confidentiality commitments described here.
5. Data security
We apply security controls appropriate to the sensitivity of the data we handle, including:
- Encryption in transit (TLS) for every connection, and encryption at rest for all stored data.
- Field-level encryption for particularly sensitive fields (such as names, phone numbers, and emails), using dedicated encryption keys managed separately for each organization.
- Tenant isolation: every request is scoped to the requesting organization, so one Customer's data is never visible to another.
- Role-based access control, so staff only see the data their role permits.
- Multi-factor authentication for user accounts.
No system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a security incident affecting your information, we will notify affected Customers as required by law and our agreements.
6. Data retention
We retain Account Data for as long as the associated account is active, and Patient Data for as long as the Customer's subscription is active, plus a limited period afterward to allow for account recovery, backups, and legal or regulatory recordkeeping requirements. Customers may request deletion of their data, subject to any retention obligations we or they are legally required to observe.
7. Cookies
We use only strictly necessary cookies: a session cookie that keeps you signed in, and a workspace-selection cookie that remembers which organization you're currently working in. We do not use third-party advertising or tracking cookies.
8. SMS and email communications
Where a Customer enables phone or email-based reminders and verification, messages are sent only to numbers and addresses provided through the platform for that purpose (for example, staff opting in to two-factor phone verification, or a clinic recording a patient's preferred contact details for recall reminders). Message and data rates may apply. Recipients of SMS messages can reply STOP to opt out at any time, or contact the sending clinic directly.
9. Your rights and choices
If you are Customer staff with an FusioMed account, you can access and update your account information from your profile settings, or contact us using the details below for assistance with access, correction, or deletion requests. If you are a patient of a clinic using FusioMed, please direct requests about your health information to that clinic, who controls your Patient Data.
10. International data transfers
Our infrastructure is currently hosted in data centers located in Europe. Where information is transferred internationally, we rely on our service providers' standard contractual safeguards to protect it in transit and at rest.
11. Children's privacy
FusioMedis not directed at children, and we do not knowingly collect Account Data from anyone under 16. Patient Data may include information about minors only where a Customer clinic enters it as part of providing care to that minor patient, under the clinic's own legal basis for doing so.
12. Changes to this policy
We may update this policy from time to time. If we make material changes, we will update the "Last updated" date above and, where appropriate, notify Customers directly.
13. Contact us
Questions about this policy or how we handle information can be sent to [email protected], or through our contact form.