Privacy Policy

Version 3.0
We are committed to protecting your privacy and complying with HIPAA, CCPA, and other applicable privacy laws.

PRIVACY POLICY

Effective Date: July 28, 2025
Version: 3.0

QUICK REFERENCE GUIDE

Data Controller: Verisight Analytics, LLC
Location: 342 N Water St Suite 600, Milwaukee, WI 53202
Privacy Officer: privacy@mdsgenie.ai
Data Protection Officer: dpo@mdsgenie.ai
HIPAA Compliance: hipaa@mdsgenie.ai

Your Rights: - Access your personal data - Correct inaccurate data - Delete your data (with exceptions) - Port your data - Object to processing - Restrict processing - Withdraw consent

Key Facts: - We do NOT sell personal data - We do NOT store PHI - only ephemeral processing - We use encryption for all data - We comply with HIPAA, CCPA, and other privacy laws


1. INTRODUCTION

Verisight Analytics, LLC ("Company," "we," "us," or "our") provides MDS Genie, a clinical decision support platform for healthcare facilities. This Privacy Policy explains how we collect, use, disclose, and protect information when you use our Service.

This Policy applies to: - MDS Genie platform (the "Service") - Our marketing website (www.mdsgenie.ai) - Communications between you and Verisight Analytics - Data processing under our Business Associate Agreement

By using MDS Genie, you consent to the data practices described in this Policy.

2. INFORMATION WE COLLECT

2.1 Account Information

What We Collect: - Full name - Professional credentials and license numbers - Email address (business) - Phone number (business) - Facility name and NPI number - Job title and role - Username and password

How We Collect: Directly from you during registration and account management

Purpose: Account creation, authentication, communication, compliance verification

2.2 Usage Information

What We Collect: - Login times and frequency - Features accessed - Assessment types generated - System performance metrics - Error logs (no PHI included)

How We Collect: Automatically through system monitoring

Purpose: Service improvement, troubleshooting, security monitoring

2.3 Clinical Processing Data (Ephemeral)

What We Process (NOT Store): - Clinical notes submitted for analysis - MDS assessment context - Generated recommendations

How We Handle: - Processed in volatile memory only - Immediately discarded after processing - Never stored in databases or logs - No retention whatsoever

Purpose: Generate MDS coding suggestions

2.4 Payment Information

What We Collect: - Billing name and address - Last 4 digits of payment card - Transaction history

How We Collect: Through Stripe (PCI-DSS compliant)

Note: We do NOT store full payment card numbers

2.5 Marketing Website Analytics

What We Collect: - Pages visited - Time on site - General geographic location (city level) - Browser and device type - Referral source

How We Collect: Google Analytics (marketing site only)

Purpose: Improve website experience, marketing effectiveness

2.6 Communications

What We Collect: - Support tickets and inquiries - Training completion records - Feedback and surveys

How We Collect: Directly from you

Purpose: Customer service, compliance tracking, service improvement

3. LEGAL BASIS FOR PROCESSING

We process your information based on:

3.1 Contract Performance

  • Providing MDS Genie services
  • Account management
  • Billing and payments

3.2 Legal Obligations

  • HIPAA compliance
  • State healthcare regulations
  • Tax and financial reporting
  • Legal proceedings

3.3 Legitimate Interests

  • Service improvement
  • Security and fraud prevention
  • Marketing (to existing customers)
  • Aggregated analytics

3.4 Consent

  • Marketing to prospects
  • Optional features
  • Cookies (marketing website)

3.5 Vital Interests

  • Emergency situations affecting health/safety

4. HOW WE USE INFORMATION

4.1 Service Delivery

  • Provide MDS coding suggestions
  • Process clinical documentation
  • Manage user accounts
  • Provide customer support
  • Send service updates

4.2 Compliance and Legal

  • Comply with HIPAA requirements
  • Meet state regulatory obligations
  • Respond to legal requests
  • Enforce our Terms of Service
  • Protect against fraud

4.3 Analytics and Improvement

  • Monitor system performance
  • Improve algorithms (de-identified data only)
  • Develop new features
  • Create industry benchmarks (aggregated)
  • Conduct research (de-identified)

4.4 Marketing and Communication

  • Send service announcements
  • Provide training materials
  • Share industry insights
  • Marketing (with consent)

5. INFORMATION SHARING

5.1 We DO NOT Sell Personal Information

We never sell, rent, or trade your personal information to third parties.

5.2 Service Providers

We share information with vendors who help us provide services:

Provider Purpose Data Shared Safeguards
Microsoft Azure Infrastructure/AI Processing data (ephemeral) BAA, SOC 2, HIPAA compliant
Stripe Payment processing Payment information PCI-DSS Level 1
Google Analytics Website analytics Anonymous usage data No PHI, marketing site only
[Email Provider] Communications Email addresses Encryption, no PHI

5.3 Legal Disclosures

We may disclose information when required by: - Court orders or subpoenas - Government investigations - HIPAA-permitted disclosures - Emergency situations

5.4 Business Transfers

If we merge, sell, or reorganize, information may transfer to successors who agree to protect it similarly.

5.5 Aggregated/De-identified Data

We may share aggregated or de-identified data that cannot identify individuals for: - Industry reports - Research - Public health purposes - Quality improvement initiatives

6. DATA SECURITY

6.1 Technical Safeguards

Encryption: - At Rest: AES-256 encryption - In Transit: TLS 1.3 minimum - Key Management: Automated rotation

Access Controls: - Multi-factor authentication required - Role-based access control - Principle of least privilege - Automatic session timeout (15 minutes) - Account lockout after 5 failed attempts

Monitoring: - 24/7 security monitoring - Intrusion detection systems - Audit logs (7-year retention) - Monthly vulnerability scanning - Annual penetration testing

6.2 Administrative Safeguards

  • Designated Security and Privacy Officers
  • Employee background checks
  • HIPAA training (initial and annual)
  • Confidentiality agreements
  • Incident response plan
  • Business continuity planning

6.3 Physical Safeguards

  • Secure data centers (SOC 2 certified)
  • Access controls and monitoring
  • Environmental controls
  • Media disposal procedures (NIST 800-88)

6.4 Compliance Certifications

  • HIPAA compliant infrastructure
  • SOC 2 Type II (in progress)
  • Annual third-party audits
  • State regulatory compliance

7. DATA RETENTION

Data Type Retention Period Reason
Account information Active + 7 years Legal/tax requirements
Clinical processing 0 (ephemeral only) Privacy by design
Audit logs 7 years HIPAA requirement
Payment records 7 years Tax/financial regulations
Support tickets 3 years Service improvement
Marketing analytics 2 years Analytics purposes
Training records Active + 3 years Compliance tracking

Deletion: Upon expiration, data is securely deleted using NIST 800-88 standards.

8. YOUR PRIVACY RIGHTS

8.1 Rights for All Users

Right to Access: Request a copy of your personal data

Right to Correct: Request correction of inaccurate data

Right to Delete: Request deletion (subject to legal requirements)

Right to Restrict: Limit how we process your data

Right to Object: Object to certain processing activities

Right to Portability: Receive data in machine-readable format

Right to Withdraw Consent: Withdraw previously given consent

8.2 CCPA/CPRA Rights (California Residents)

Additional rights under California law: - Right to know categories and specific pieces of personal information - Right to know purposes of collection and use - Right to know if information is sold or disclosed (we don't sell) - Right to opt-out of sale (not applicable - we don't sell) - Right to non-discrimination - Right to correct inaccurate information - Right to limit use of sensitive personal information

To Exercise Rights: - Email: privacy@mdsgenie.ai - Toll-free: [To be provided] - Online form: [To be provided]

Verification: We verify identity before processing requests

Response Time: Within 45 days (may extend additional 45 days with notice)

8.3 State-Specific Rights

Virginia (VCDPA): Similar rights to CCPA plus right to appeal

Colorado (CPA): Similar rights plus right to opt-out of profiling

Connecticut (CTDPA): Similar comprehensive rights

Illinois: Rights under BIPA for biometric data (if applicable)

Nevada: Right to opt-out of sale (not applicable)

8.4 HIPAA Rights

For Protected Health Information: - Right to access PHI - Right to amend PHI - Right to accounting of disclosures - Right to restrict uses/disclosures - Right to confidential communications - Right to file complaints with HHS

8.5 International Users (GDPR)

If GDPR applies: - All rights listed in Section 8.1 - Right to lodge complaint with supervisory authority - Right to withdraw consent - Right to object to automated decision-making

9. COOKIES AND TRACKING

9.1 Marketing Website

Our marketing website uses cookies for:

Essential Cookies: Required for site functionality - Session management - Security features - Load balancing

Analytics Cookies: Understand site usage - Google Analytics - Page views and paths - Time on site

Preference Cookies: Remember your choices - Language preferences - Cookie consent choices

9.2 MDS Genie Platform

The MDS Genie platform does NOT use cookies or tracking technologies

9.3 Managing Cookies

Browser Controls: Set preferences in your browser

Cookie Banner: Use our consent tool on marketing website

Google Analytics Opt-out: https://tools.google.com/dlpage/gaoptout

9.4 Do Not Track

We honor Do Not Track signals on our marketing website.

10. CHILDREN'S PRIVACY

MDS Genie is not intended for individuals under 18. We do not knowingly collect information from children. If we discover we have collected information from a child, we will promptly delete it.

To Report: Contact privacy@mdsgenie.ai

11. INTERNATIONAL DATA TRANSFERS

11.1 Location of Processing

Primary Processing: United States

Safeguards for International Transfers: - Standard Contractual Clauses (EU) - Appropriate safeguards per GDPR - Encryption for all transfers

11.2 Your Rights

Regardless of location, you maintain all privacy rights described in this Policy.

12. THIRD-PARTY LINKS

Our Service may contain links to third-party sites. We are not responsible for their privacy practices. Please review their policies.

13. BIOMETRIC DATA (If Applicable)

If we collect biometric data (e.g., for authentication):

13.1 Illinois BIPA Compliance

  • Written consent before collection
  • Disclosure of purpose and retention period
  • No sale or disclosure without consent
  • Destruction within 3 years of last interaction
  • Published retention and destruction guidelines

13.2 Other State Laws

We comply with all applicable state biometric privacy laws.

14. DATA BREACH NOTIFICATION

14.1 Our Commitment

In the event of a breach affecting your personal information, we will:

Notification Timeline: - HIPAA Covered Entities: Within 10 business days - Individuals: As required by law (typically 30-60 days) - Regulators: As required by law

Notification Content: - What happened - Information involved - Steps we're taking - Steps you can take - Contact information for questions

14.2 Your Responsibilities

  • Maintain account security
  • Report suspected breaches immediately
  • Cooperate with investigations

15. CALIFORNIA PRIVACY DISCLOSURE

15.1 Categories of Information Collected

Category Examples Sources Purpose Shared With
Identifiers Name, email You directly Service delivery Service providers
Professional Info License, credentials You directly Compliance Verification services
Commercial Info Transaction history Service use Billing Payment processor
Internet Activity Usage data Automatic Analytics None
Geolocation City-level only IP address Analytics None

15.2 "Sale" of Personal Information

We DO NOT sell personal information as defined by CCPA

15.3 Sensitive Personal Information

We limit use of sensitive personal information to purposes permitted by CCPA.

15.4 Retention

See Section 7 for retention periods.

15.5 Rights

See Section 8.2 for CCPA rights.

16. AUTOMATED DECISION-MAKING

16.1 How We Use Automation

MDS Genie uses AI to analyze clinical notes and suggest codes. However: - All outputs are suggestions only - Human review is always required - No automated decisions affect legal rights - You can request human review of any output

16.2 Your Rights

You have the right to: - Understand the logic involved - Request human intervention - Express your point of view - Contest any suggestions

17. CHANGES TO THIS POLICY

17.1 How We Notify You

Material Changes: - 30 days advance notice via email - Banner notice on platform - Ability to review changes before effective date

Minor Changes: - Updated policy posted on website - Effective date updated

17.2 Your Choices

If you disagree with changes: - Download your data - Close your account - Continue under existing policy until renewal

18. ACCESSIBILITY

We strive to make our Privacy Policy accessible to all: - Plain language where possible - Screen reader compatible - Available in alternative formats upon request

Contact: accessibility@mdsgenie.ai

19. CONTACT US

19.1 Privacy Inquiries

Email: privacy@mdsgenie.ai
Phone: [To be provided]
Mail: Verisight Analytics, LLC
Attn: Privacy Officer
342 N Water St Suite 600
Milwaukee, WI 53202

Response Time: Within 30 days

19.2 HIPAA Compliance

Email: hipaa@mdsgenie.ai
Phone: [To be provided]

19.3 Data Protection Officer

Email: dpo@mdsgenie.ai
Phone: [To be provided]

19.4 Supervisory Authorities

You may also contact:

HHS Office for Civil Rights (HIPAA)
https://www.hhs.gov/ocr

California Privacy Protection Agency (CCPA)
https://cppa.ca.gov

Illinois Attorney General (BIPA)
https://www.illinoisattorneygeneral.gov

20. STATE-SPECIFIC PROVISIONS

20.1 Illinois

Personal Information Protection Act: - Breach notification within 5 business days - Notice to AG if 500+ residents affected

Biometric Information Privacy Act: - See Section 13 for biometric data handling

20.2 Wisconsin

Medical Records: - Retained per state requirements (5+ years) - Patient access within 30 days

20.3 Other States

We comply with all applicable state privacy laws. Contact us for state-specific information.

21. PRIVACY PRINCIPLES

We adhere to the following principles:

1. Minimization: Collect only what's necessary

2. Purpose Limitation: Use only for stated purposes

3. Transparency: Clear about our practices

4. Security: Protect with appropriate measures

5. Accountability: Take responsibility for compliance

6. Privacy by Design: Build privacy into our systems

7. User Control: Provide choices and rights

22. DEFINITIONS

"De-identified Data": Data that cannot reasonably identify an individual

"Personal Information": Information that identifies or could identify you

"PHI": Protected Health Information under HIPAA

"Processing": Any operation performed on data

"Service": MDS Genie platform

"Service Provider": Third party that processes data for us


APPENDIX A: DATA PROCESSING DETAILS

Categories of Data Subjects

  • Healthcare professionals
  • Facility administrators
  • Support staff

Types of Processing Activities

  • Storage (except PHI)
  • Analysis
  • Transmission
  • Deletion

Technical and Organizational Measures

  • See Section 6 for detailed security measures

Cross-Border Transfer Mechanisms

  • Standard Contractual Clauses
  • Adequacy decisions where applicable
  • Appropriate safeguards per Article 46 GDPR

APPENDIX B: COOKIE POLICY DETAILS

Cookie Categories and Purposes

Cookie Name Provider Purpose Expiry Type
_ga Google Analytics 2 years Analytics
_gid Google Analytics 24 hours Analytics
sessionid Verisight Session Session Essential
consent Verisight Consent tracking 1 year Essential

How to Control Cookies

Browser Settings: - Chrome: Settings > Privacy > Cookies - Firefox: Options > Privacy > Cookies - Safari: Preferences > Privacy - Edge: Settings > Privacy > Cookies

Mobile Devices: - iOS: Settings > Safari > Block Cookies - Android: Chrome > Settings > Site Settings > Cookies


APPENDIX C: LAWFUL BASIS REFERENCE

GDPR Article 6 Basis

Processing Activity Lawful Basis Article 6 Reference
Account management Contract 6(1)(b)
Compliance Legal obligation 6(1)(c)
Security Legitimate interest 6(1)(f)
Marketing Consent 6(1)(a)
Analytics Legitimate interest 6(1)(f)

Legitimate Interests Assessment

We have conducted assessments confirming our legitimate interests don't override your rights for: - Security monitoring - Service improvement - Fraud prevention - Direct marketing (existing customers)


ACCEPTANCE

BY USING MDS GENIE, YOU ACKNOWLEDGE THAT YOU HAVE READ AND UNDERSTOOD THIS PRIVACY POLICY.

Last Updated: July 28, 2025
Version: 3.0

© 2025 Verisight Analytics, LLC. All rights reserved.

← Back to Dashboard Login →