Privacy Policy
Effective Date: 7/25/2026
Last Updated: 7/25/2026
1. Introduction
Copper Digital ("Company," "we," "us," or "our") is committed to protecting the privacy and security of personal information, including Protected Health Information (PHI), that we collect, use, and disclose in connection with our healthcare AI voice solution services. This Privacy Policy explains how we collect, use, protect, and disclose information when you use our services.
Company Information:
Copper Digital
4100 Spring Valley Rd, STE 525
Dallas, TX 75244
Email: privacy@copperdigital.com
2. HIPAA Compliance and PHI Protection
2.1 Protected Health Information (PHI)
As a healthcare technology provider, we understand that our services may involve the collection, processing, and storage of Protected Health Information as defined under the Health Insurance Portability and Accountability Act (HIPAA). We are committed to maintaining the highest standards of data protection and HIPAA compliance.
2.2 Business Associate Relationship
When providing services to covered entities, we operate as a Business Associate under HIPAA. We enter into Business Associate Agreements (BAAs) with all covered entity clients that outline our responsibilities and commitments regarding PHI protection. Our BAA template is available on our HIPAA Compliance page.
2.3 PHI Security Measures
- End-to-end encryption for all PHI in transit and at rest
- Multi-factor authentication for system access
- Regular security audits and vulnerability assessments
- Role-based access controls limiting PHI access to authorized personnel only
- Comprehensive audit logging of all PHI access and modifications
- Employee training on HIPAA compliance and data security
3. Information We Collect
3.1 Protected Health Information
Through our AI voice solutions, we may collect and process the following types of PHI:
- Voice recordings and transcriptions of patient interactions
- Patient demographic information
- Medical history and treatment information
- Medication information and care plans
- Insurance and billing information
- Healthcare provider notes and assessments
3.2 Technical Information
- Device identifiers and system information
- Usage data and service performance metrics
- Network information and IP addresses
- Application logs and error reports
3.3 Account Information
- User account credentials and authentication data
- Organization and facility information
- Contact information for administrative purposes
4. How We Use Information
4.1 PHI Usage
We use PHI solely for the following purposes:
- Providing healthcare AI voice services as requested by covered entities
- Processing and analyzing voice data to generate clinical documentation
- Facilitating communication between healthcare providers and patients
- Maintaining and improving service quality and accuracy
- Complying with legal obligations and regulatory requirements
4.2 Service Improvement
We may use de-identified data (with all PHI removed) to improve our AI algorithms and service performance. All de-identification processes comply with HIPAA standards.
5. Third-Party Integrations
5.1 Healthcare System Integrations
Our services integrate with various healthcare management systems, including but not limited to:
- WellSky (Kinnser): Home health management system integration
- Electronic Health Records (EHR) systems
- Practice management systems
- Billing and revenue cycle management systems
5.2 Third-Party Data Sharing
We only share PHI with third parties under the following circumstances:
- As directed by the covered entity or healthcare provider
- With authorized integration partners under signed BAAs
- When required by law or legal process
- In emergency situations to prevent harm to individuals
- For HIPAA-compliant auditing and compliance purposes
6. Data Retention and Deletion
6.1 Retention Periods
We retain PHI according to the following schedule:
- Active Patient Records: Retained for the duration of the BAA and active service period
- Voice Recordings: Retained for 30 days after transcription, unless longer retention is specified in the BAA
- Clinical Documentation: Retained according to healthcare provider's record retention policies
- Audit Logs: Retained for 6 years as required by HIPAA
- Backup Data: Retained for 90 days with encrypted storage
6.2 Secure Deletion
Upon expiration of retention periods or termination of services, we securely delete all PHI using NIST-approved methods that ensure data cannot be recovered. We provide certificates of destruction upon request.
7. Patient Rights
Under HIPAA, patients have specific rights regarding their PHI. While we are a Business Associate and do not directly interact with patients, we support covered entities in fulfilling these rights:
7.1 Right to Access
Patients have the right to access their PHI. We will cooperate with covered entities to provide requested information within the timeframes required by HIPAA.
7.2 Right to Amendment
Patients may request amendments to their PHI. We will implement amendments as directed by the covered entity.
7.3 Right to Restriction
Patients may request restrictions on the use or disclosure of their PHI. We will honor such restrictions as communicated by the covered entity.
7.4 Right to Accounting of Disclosures
We maintain detailed logs of all PHI disclosures and will provide accounting information to covered entities upon request.
8. Data Security
8.1 Technical Safeguards
- AES-256 encryption for data at rest
- TLS 1.3 encryption for data in transit
- Multi-factor authentication and single sign-on (SSO)
- Regular security updates and patch management
- Intrusion detection and prevention systems
- 24/7 security monitoring and incident response
8.2 Physical Safeguards
- SOC 2 Type II certified data centers
- Biometric access controls and 24/7 security personnel
- Environmental monitoring and fire suppression systems
- Secure destruction of physical media containing PHI
8.3 Administrative Safeguards
- Designated Privacy and Security Officers
- Regular HIPAA training for all employees
- Background checks for personnel with PHI access
- Incident response and breach notification procedures
- Regular risk assessments and security audits
9. Breach Notification
In the event of a security incident involving PHI, we will:
- Immediately investigate and contain the incident
- Notify the covered entity within 24 hours of discovery
- Provide detailed incident reports and remediation plans
- Cooperate with covered entities in their breach notification obligations
- Implement additional safeguards to prevent future incidents
10. International Data Transfers
All PHI processing and storage occurs within the United States in HIPAA-compliant facilities. We do not transfer PHI to countries outside the United States without explicit written authorization from the covered entity and appropriate safeguards.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify covered entities of material changes at least 30 days before they take effect. The current version will always be available on our website with the effective date clearly marked.
12. Contact Information
Privacy Officer
Copper Digital
4100 Spring Valley Rd, STE 525
Dallas, TX 75244
Email: privacy@copperdigital.com
Phone: (214) 555-0100
HIPAA Hotline: (214) 555-0101
For HIPAA-related inquiries:
If you have questions about our HIPAA compliance, need to report a potential breach, or require assistance with patient rights requests, please contact our Privacy Officer using the information above. We respond to all privacy inquiries within 48 hours.
13. Effective Date and Acknowledgment
This Privacy Policy is effective as of 7/25/2026 and supersedes all previous versions. By using our services, covered entities acknowledge that they have read, understood, and agree to be bound by this Privacy Policy.
