Effective: August 31, 2026 · Last updated: August 31, 2026
HyperClinic AI LLC (“HyperClinic,” “we,” “us”) provides software to medical practices: Patient Check‑In, Provider Scribe, and Website & SEO management. This policy explains what information we collect, how we use it, and the choices you have. It covers our website at hyperclinic.ai, our platform at admin.hyperclinic.ai, and the text messages our software sends on behalf of the practices that use it.
Our Patient Check‑In product sends text messages to patients on behalf of the medical practice they have an appointment with. The practice is the sender; HyperClinic is the software that delivers the message.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt‑in data and consent are not shared with any third party.
Information may be disclosed to subcontractors who support the messaging service itself — for example our SMS carrier — solely so the message can be delivered. Those subcontractors may not use the information for their own purposes.
The medical practice collects a patient’s mobile number and their agreement to receive appointment messages, as part of registration or scheduling. HyperClinic does not buy, rent, or import phone lists, and we do not message anyone whose number was not given to their own practice by the patient.
Message frequency varies and depends on your appointments. In normal use our software sends at most one message per appointment — a single arrival message shortly before the visit. No further message is sent for that appointment once it has been sent, once the patient has arrived or checked in, or if the appointment is cancelled. Messages are suppressed during the practice’s configured quiet hours. A practice’s staff may separately send a patient a link to complete intake forms.
Message and data rates may apply. HyperClinic and the practice do not charge you for these messages; your mobile carrier may.
Reply STOP to any message to stop receiving texts. STOP, QUIT, END, CANCEL, REVOKE, OPT OUT and UNSUBSCRIBE are all recognised, and you may also withdraw consent by any other reasonable means — including simply telling the practice’s front desk or calling them. Reply START if you later want messages again.
We record an opt‑out immediately, which is sooner than the ten business days the Federal Communications Commission allows. An opt‑out applies to all appointment messages from that practice, not only the one you replied to. Reply HELP for help, or contact the practice directly.
Appointment messages are deliberately minimal. They contain only the practice’s name and a secure link. They do not contain a patient name, a provider name, an appointment time, a location, a reason for visit, or any clinical information — so a message seen on a lock screen by someone else discloses nothing about the patient’s care. This restriction is enforced by the software, not by convention.
Carriers may filter or delay messages; delivery is not guaranteed.
If you visit our website or contact us, we may collect your name, business email address, phone number, practice name, and what you told us you were interested in. We collect standard server and analytics information such as IP address, browser type, and pages viewed.
Accounts are created through Google Sign‑In. We receive your name, email address, and Google account identifier — never your Google password. We record your role, the practice you belong to, and an audit record of security‑relevant actions you take, including when you open patient information.
When a practice uses our software, we process information about its patients on that practice’s behalf: name, date of birth, chart or medical record number, mobile number, appointment details, the answers a patient gives on intake forms, uploaded insurance cards and identification, and clinical documentation produced by Provider Scribe.
We do not use patient information to advertise or market anything, to ourselves or to anyone else. We do not sell personal information, and we do not share it for cross‑context behavioural advertising.
Provider Scribe uses Google Vertex AI to draft clinical notes from a visit. The draft is a starting point: a clinician reviews and signs the note, and nothing enters a patient’s chart without that. Content sent to the model is processed under Google Cloud’s enterprise terms and is not used to train general‑purpose models.
We share information only as described here.
| Who | Why |
|---|---|
| The practice whose patients they are | It is their information; we hold it for them. |
| Google Cloud / Firebase | Hosting, database, file storage, and sign‑in. Data is stored in the United States. |
| Google Vertex AI | Drafting clinical notes for Provider Scribe. |
| Twilio | Delivering text messages. |
| Our email delivery provider | Sending notifications and completed documents where a practice has asked us to. |
| Google Business Profile | Only for Website & SEO, and only with the practice’s explicit authorisation, to publish replies to reviews. |
| Professional advisers, or authorities | Where the law requires it, or to protect rights and safety. |
| A successor | If the business is sold or merged, subject to this policy. |
Where a service provider may handle protected health information, we require a written agreement with it, including a HIPAA business associate agreement where one applies. Mobile phone numbers and SMS opt‑in consent are excluded from every sharing arrangement above except delivery of the message itself.
No system is perfectly secure. If a breach of unsecured protected health information occurs, we notify the affected practice without unreasonable delay and in no case later than 60 calendar days after discovery, as 45 CFR §164.410(b) and our business associate agreement require. The practice, as the covered entity, decides what notice goes to patients.
We keep it for as long as our agreement with the practice requires, and no longer. The retention period itself is the practice’s to set, not ours — the legal duty to keep medical records falls on the physician and the practice, not on their software vendor. In Texas, for example, a physician must keep an adequate medical record for at least seven years from the last treatment, and for a patient who was a minor, until the patient turns 21 or seven years from the last treatment, whichever is longer (Texas Medical Board Rule 22 TAC §165.1(b)). We hold information for the practice so that it can meet obligations like that one; we do not decide them.
When our agreement with a practice ends, we return or destroy the protected health information we still hold and keep no copies. Where returning or destroying it is not feasible — encrypted backups on a fixed expiry cycle, and audit records that are deliberately immutable — we continue to protect it under the same terms and stop using it for anything else, which is what 45 CFR §164.504(e)(2)(ii)(J) requires.
We keep them for at least six years. To be precise about why: HIPAA requires that the documentation the Security Rule calls for be retained for six years from creation or from the date it was last in effect (45 CFR §164.316(b)(2)(i)). The rule requiring audit controls (§164.312(b)) sets no retention period of its own. Six years for the logs themselves is our choice, applied to match the documentation standard.
Website enquiry and account information is kept only as long as it is useful, and you can ask us to delete it. An SMS opt‑out is kept indefinitely and deliberately — deleting it is how a number gets messaged again by mistake.
State privacy laws generally do not reach the patient information we hold. The Texas Data Privacy and Security Act exempts HIPAA business associates at the entity level, and exempts protected health information at the data level; that information is governed by HIPAA and by our agreement with the practice instead. Comparable laws in other states exempt it on the same basis.
We would rather not lean on that. For the information we hold in our own right — a website enquiry, a contact record, a platform user account — we will honour a request to see it, correct it, or delete it whether or not a statute compels us to, and we will answer within 45 days. We do not sell personal information and we do not use it for targeted advertising, so there is nothing to opt out of on that front. We will not treat you differently for exercising a privacy right.
For patient records, the request belongs with your practice: HIPAA gives you a right of access to your own records from the covered entity that holds them, and we would only be able to act on the practice’s instruction anyway.
Our platform is for medical practices and their staff; it is not directed at children and we do not knowingly collect information from a child through our website. Where a practice’s patient is a minor, that information is handled for the practice under the same business associate terms as any other patient information, in line with the practice’s own policies and applicable law.
Your practice’s use of the platform is governed by our Terms of Service, and our handling of protected health information is governed by the Business Associate Agreement between us. Where any of them conflict on protected health information, the Business Associate Agreement controls.
If we change this policy we will update the date at the top and post the new version at this address. If a change materially affects how we handle personal information we will tell the practices we work with directly.
HyperClinic AI LLC
A Texas limited liability company
Email: support@hyperclinic.ai
Phone: (726) 253‑1503
Web: hyperclinic.ai
Patients: for questions about your own medical records, please contact your medical practice directly. They are the holder of your health information.
© 2026 HyperClinic AI LLC. All rights reserved.