MDS Genie Privacy Policy

HIPAA Compliant
Healthcare Grade Security
Effective Date: July 1, 2025
Last Updated: July 1, 2025
Version: 1.0

Quick Navigation

🏥 Healthcare Data Protection Commitment

MDS Genie is committed to the highest standards of healthcare data protection. As a healthcare technology service that may process Protected Health Information (PHI), we comply with HIPAA, state privacy laws, and industry best practices to safeguard your data.

1. Data Collection and Use

1.1 Personal Information We Collect

Data Type Purpose Retention Period
Account Information User registration, authentication, service delivery Until account deletion + 7 years
Payment Information Billing, transaction processing, compliance 7 years from last transaction
Usage Analytics Basic service usage counts only (no assessment details) 2 years from collection
Clinical Notes (PHI) MDS code generation, immediate processing only Never stored - processed and discarded immediately
System Logs Security monitoring, troubleshooting 90 days

1.2 Protected Health Information (PHI)

Zero PHI Storage Policy: Clinical notes and patient information you input for MDS analysis are processed through our AI service but are never stored on our systems. The data is processed immediately and discarded, ensuring zero PHI retention and minimal compliance burden.

1.3 Legal Basis for Processing

2. HIPAA Compliance

2.1 Business Associate Relationship

MDS Genie acts as a Business Associate under HIPAA when processing PHI on behalf of covered entities (healthcare providers). Key points:

2.2 HIPAA Safeguards Implementation

Technical Safeguards:

Administrative Safeguards:

Physical Safeguards:

3. Security Measures

3.1 Data Protection

3.2 Data Processing Security

4. Data Sharing and Third-Party Processors

4.1 Third-Party Service Providers

We work with carefully vetted service providers who sign Business Associate Agreements:

4.2 International Data Transfers

If data is transferred internationally, we ensure adequate protection through:

4.3 We Do NOT Share Data For:

5. Your Privacy Rights

5.1 HIPAA Rights

5.2 State Privacy Law Rights (CCPA, CDPA, etc.)

5.3 How to Exercise Your Rights

To exercise any privacy rights:

6. Data Breach Procedures

6.1 Our Response

In the event of a data breach involving PHI:

6.2 Prevention

7. Regulatory Compliance

7.1 Healthcare Regulations

7.2 General Privacy Regulations

8. Data Retention and Deletion

8.1 Retention Schedules

8.2 Secure Deletion

All data deletion follows NIST guidelines for secure data destruction, including:

9. Children's Privacy

MDS Genie is not intended for use by individuals under 13 years of age. We do not knowingly collect personal information from children under 13. If we become aware that we have inadvertently collected such information, we will delete it immediately.

10. Policy Changes

We may update this Privacy Policy to reflect changes in our practices or for legal compliance. We will:

11. Contact Information

Privacy Officer

Email: privacy@mdsgenie.ai
Response Time: Within 48 hours for privacy inquiries
Address: Verisight Analytics
100 Illinois Street Ste 200
St Charles, Illinois 60174

HIPAA Compliance Officer

Email: hipaa@mdsgenie.ai
For: BAA requests, HIPAA compliance questions, breach reports

Data Protection Officer (if applicable)

Email: dpo@mdsgenie.ai
For: GDPR-related inquiries, EU data subject requests

12. Regulatory Contacts

If you believe your privacy rights have been violated, you may file a complaint with:

🔒 Your Privacy Matters

This policy demonstrates our commitment to protecting your privacy and maintaining the highest standards of data security in healthcare technology. We continuously review and improve our practices to ensure compliance with evolving regulations.

← Back to MDS Genie | Contact Us | About