carelinkMD Privacy Policy
Last Updated: June 2, 2026
carelinkMD ("we," "us," or "our") provides the carelinkMD platform (the "Service"). Our principal place of business is 1200 Riverplace Blvd, Suite 105, Jacksonville, FL 32207. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our Service, including through our website and patient intake portals.
Scope of This Policy
This Privacy Policy applies to:
- Healthcare providers and organizations ("Clients") using carelinkMD
- Patients and individuals submitting information through Client-branded intake forms
- Visitors to our website
Important: When we process Protected Health Information ("PHI"), we act as a Business Associate under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), pursuant to a Business Associate Agreement ("BAA") with our Clients.
Information We Collect
### 2.1 Information Provided by Clients
- Account registration details (name, email, organization, billing info)
- Uploaded forms and configuration data
### 2.2 Patient Information (Submitted via Clients)
- Personal identifiers (name, date of birth, contact details)
- Health and medical information (PHI)
- Insurance and demographic information
- Digital signatures and uploaded documents
### 2.3 Automatically Collected Information
- Device and browser information
- IP address and approximate location
- Usage data (pages visited, session activity)
- Cookies and tracking technologies
How We Use Information
### 3.1 To Provide the Service
- Process and store patient intake data
- Render digital forms and manage submissions
- Enable Client workflows and analytics
### 3.2 For Platform Operations
- Maintain system security and integrity
- Monitor performance and usage
- Improve functionality and user experience
### 3.3 Legal and Compliance
- Comply with legal obligations
- Enforce our Terms and agreements
We do NOT:
- Sell personal data or PHI
- Use PHI for advertising or marketing
- Train AI models using PHI
HIPAA and Protected Health Information (PHI)
When acting as a Business Associate:
- We use and disclose PHI only as permitted by our BAA and HIPAA
- We implement administrative, technical, and physical safeguards
- We follow the "minimum necessary" standard
Patients should contact their healthcare provider (the Client) for:
- Access, correction, or deletion of PHI
- Privacy rights under HIPAA
Cookies and Tracking Technologies
We use cookies and similar technologies to:
- Maintain sessions and authentication
- Analyze usage and improve performance
You may control cookies through your browser settings. Disabling cookies may affect functionality.
How We Share Information
We may share information:
### 6.1 With Service Providers (Subprocessors)
- Cloud hosting providers (e.g., Microsoft Azure)
- Analytics and infrastructure providers
All subprocessors are contractually required to safeguard data.
### 6.2 With Clients (Healthcare Providers)
Patient data is shared with the healthcare provider who owns the intake process.
### 6.3 For Legal Reasons
- To comply with laws, regulations, or legal processes
- To protect rights, safety, and security
Data Security
We implement industry-standard safeguards, including:
- Encryption in transit and at rest
- Role-based access controls
- Secure cloud infrastructure
- Monitoring and incident response procedures
Despite these measures, no system is completely secure.
Data Retention
- Data is retained as long as necessary to provide the Service
- Upon termination, data is retained for 30 days for export, then securely deleted unless required by law
Retention for PHI may also be governed by the Client's policies.
Your Privacy Rights
### 9.1 Clients (Healthcare Organizations)
Clients may:
- Access, update, or delete account information
- Request data export
### 9.2 Patients
Patients should contact their healthcare provider for:
- Access to their records
- Corrections or restrictions
### 9.3 U.S. State Privacy Rights
Depending on your state (e.g., California, Virginia), you may have rights to:
- Access personal data
- Request deletion
- Opt out of certain data uses
We will honor applicable legal requirements.
Children's Privacy
The Service is not directed to children under 13.
However, patient data involving minors may be processed on behalf of healthcare providers in accordance with HIPAA and applicable laws.
International Users
The Service is intended for use within the United States.
If accessed internationally, data may be transferred and processed in the U.S.
Changes to This Privacy Policy
We may update this Privacy Policy periodically.
Changes will be posted with an updated "Last Updated" date.
Contact Us
For questions about this Privacy Policy or our data practices:
carelinkMD
1200 Riverplace Blvd, Suite 105
Jacksonville, FL 32207
Email: legal@carelinkmd.com
<small>carelinkMD is a product of Expert Business Consulting LLC, a Florida limited liability company.</small>