Legal

Privacy Policy

Effective date: July 1, 2026  ·  Last updated: August 18, 2026

HIPAA notice: ClariteNote is a tool for licensed healthcare providers. We process Protected Health Information (PHI) on behalf of a covered entity only under an applicable Business Associate Agreement (BAA). This privacy policy describes ClariteNote's practices; it does not replace a covered entity's own Notice of Privacy Practices or other HIPAA obligations.

Privacy Policy

1. Who We Are

ClariteNote ("we," "us," or "our") provides an AI-powered clinical documentation platform for licensed therapists and mental health professionals. We are a Business Associate as defined under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and its implementing regulations.

2. Information We Collect

We collect only the information necessary to provide the service:

3. How We Use Information

4. How We Share Information

We do not sell, rent, or share PHI with any third party for marketing purposes. PHI is shared only as permitted or required by law, or with service providers operating under signed BAAs:

5. Data Retention

Medical-record retention periods are generally determined by applicable state law, professional rules, payer requirements, contracts, and your organization's policies; HIPAA does not establish a universal medical-record retention period. You are responsible for selecting and following the retention period that applies to your practice. ClariteNote provides record download and deletion controls to support that responsibility.

6. Security Safeguards

7. Your Rights

As a provider using this platform, you retain full ownership of your clinical records. You may:

8. Analytics

We do not use third-party analytics, tracking pixels, or advertising SDKs. No PHI is ever transmitted to analytics platforms.

9. Children

ClariteNote is intended solely for use by licensed clinical professionals. It is not directed at individuals under 18.

10. Changes to This Policy

We will notify users via email of any material changes to this policy at least 30 days before they take effect.


HIPAA Roles and Requests

This section summarizes how ClariteNote supports customers when PHI is processed under a BAA. The healthcare provider remains responsible for its own Notice of Privacy Practices and for responding to individuals as required by law.

Our Obligations as a Business Associate

ClariteNote operates as a Business Associate (BA) under HIPAA. We are required to:

Permitted Uses and Disclosures

We may use or disclose PHI only as follows:

Uses and Disclosures Requiring Authorization

We will not use or disclose PHI for any purpose not listed above without your prior written authorization.

Individual Rights

Your clients may have rights regarding their PHI that you, as the covered entity, are responsible for honoring. ClariteNote supports customer responses by providing:

Breach Notification

In the event of a breach of unsecured PHI, we will notify affected Covered Entities without unreasonable delay and no later than 60 days after discovery, as required by 45 CFR § 164.410.

Complaints

If you believe your privacy rights have been violated, you may file a complaint with us using the contact information below, or with the U.S. Department of Health and Human Services Office for Civil Rights at www.hhs.gov/ocr. We will not retaliate against you for filing a complaint.

Contact & Privacy Officer

ClariteNote Privacy

Email: admin@claritenote.com

This policy was last reviewed by our Privacy Officer on July 26, 2026.