Legal
Privacy Policy
Effective date: January 1, 2026 · Last updated: January 1, 2026
Our Privacy Commitment
- ✓ We never sell your data or patient data to third parties
- ✓ Protected Health Information (PHI) is handled under our HIPAA Business Associate Agreement
- ✓ California residents have full CCPA/CPRA rights over their personal data
- ✓ You own your data and can export or delete it at any time
1. Overview
CareOps Technologies, Inc. ("CareOps," "we," "us," or "our") operates the CareOps platform, a HIPAA-compliant medication management and care operations solution for licensed California healthcare facilities. This Privacy Policy explains how we collect, use, disclose, and protect information about our customers, their employees, and where applicable, the residents in their care.
This policy applies to: (a) information collected through our website (careops.ai and subdomains); (b) information collected through the CareOps web application; and (c) information processed on behalf of healthcare facilities as their Business Associate under HIPAA.
This Privacy Policy does not apply to third-party websites or services linked from our platform. We encourage you to review the privacy policies of any third-party services you access through CareOps.
2. Information We Collect
We collect the following categories of information:
| Category | Examples | Source |
|---|---|---|
| Account Data | Name, email, phone, role, job title | You, during registration |
| Organization Data | Facility name, address, license number, NPI, subscription tier | You, during onboarding |
| Payment Data | Billing address, last 4 digits of card (stored by Stripe) | You, via Stripe |
| Usage Data | Feature usage, login events, error logs, API calls | Automatically collected |
| Device/Technical Data | IP address, browser type, OS, session duration | Automatically collected |
| PHI (on behalf of facilities) | Resident names, diagnoses, medications, care notes | Entered by facility staff |
3. Protected Health Information (PHI) and HIPAA
When healthcare facilities use CareOps to manage resident health records, medications, and care documentation, CareOps acts as a Business Associate under HIPAA (45 CFR Parts 160 and 164). This means:
- We process PHI only as directed by and on behalf of the healthcare facility (the Covered Entity)
- We do not use PHI for our own commercial purposes
- We do not sell PHI or use it for targeted advertising
- We maintain appropriate safeguards required under the HIPAA Security Rule
- We report suspected breaches of PHI to the relevant facility within 60 days of discovery, in accordance with the HIPAA Breach Notification Rule
A Business Associate Agreement (BAA) is required for all CareOps customers and is incorporated into the CareOps Terms of Service. The full BAA text is available at careops.ai/hipaa.
Residents' rights to access and control their PHI are managed through the healthcare facility, which serves as the Covered Entity under HIPAA. Residents should contact their care facility directly to exercise HIPAA rights.
4. How We Use Information
We use account, organization, and usage data for:
- Service delivery: Providing, operating, and maintaining the CareOps platform
- Account management: Managing your subscription, authentication, and access controls
- Customer support: Responding to inquiries, troubleshooting, and providing technical assistance
- Billing: Processing payments and managing subscriptions through Stripe
- Communications: Sending service notifications, security alerts, product updates, and transactional emails
- Compliance: Maintaining audit logs required by HIPAA and applicable regulations
- Product improvement: Analyzing aggregated, de-identified usage patterns to improve features and performance
- Security: Detecting fraud, unauthorized access, and security threats
- Legal obligations: Complying with applicable laws, court orders, and regulatory requirements
We will not use your information for purposes materially different from those listed above without providing advance notice and, where required, obtaining your consent.
6. Data Security
CareOps implements security safeguards aligned with HIPAA Security Rule requirements and industry best practices:
- Encryption: AES-256 encryption for data at rest; TLS 1.2 or higher for all data in transit
- Access Controls: Role-based access control (RBAC) with principle of least privilege; MFA support
- Audit Logging: Comprehensive audit trails for all data access and modifications
- Backups: Automated daily backups with point-in-time recovery capability
- Vulnerability Management: Regular security assessments and dependency updates
- Incident Response: Documented breach response procedures with notification timelines
Despite our safeguards, no system is 100% secure. If you suspect unauthorized access to your account, contact us immediately at security@careops.ai.
7. Data Retention
We retain information for as long as necessary to provide the Service and comply with legal obligations:
- Account data: Retained for the duration of the subscription plus 30 days after termination
- PHI (clinical records): Retained as required by California law (minimum 7 years for adult records; 7 years after age 18 for minors) or as directed by the facility
- Audit logs: Retained for 6 years per HIPAA requirements
- Payment records: Retained for 7 years per financial regulations
- Usage/analytics data: Retained in aggregated form for up to 3 years
After the retention period, data is securely deleted using industry-standard data sanitization methods.
8. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to Know: Request disclosure of personal information we have collected about you and the categories, sources, and purposes of collection
- Right to Delete: Request deletion of personal information we hold about you (subject to legal exceptions)
- Right to Correct: Request correction of inaccurate personal information
- Right to Opt-Out of Sale: We do not sell personal information. No opt-out is necessary.
- Right to Limit Use of Sensitive Data: Request that we limit our use of sensitive personal information
- Right to Non-Discrimination: You will not be discriminated against for exercising your privacy rights
To exercise these rights, contact us at privacy@careops.ai. We will respond within 45 days and may verify your identity before processing the request.
Note: CCPA rights apply to personal information about California consumers in their individual capacity. PHI about facility residents is governed by HIPAA, not CCPA. Residents should contact their care facility directly.
10. Children's Privacy
CareOps is designed for licensed healthcare professionals and organizations. We do not knowingly collect personal information directly from children under 13. If you believe we have inadvertently collected such information, contact us at privacy@careops.ai and we will delete it promptly.
Note: CareOps may process health records for minor residents in care facilities (e.g., ARF). Such processing is performed on behalf of the licensed care facility and is governed by the BAA and applicable healthcare privacy laws.
11. International Data Transfers
CareOps is headquartered in California and processes data primarily within the United States. Our infrastructure is hosted in US-based data centers. If any data processing occurs outside the United States, we will ensure appropriate safeguards are in place (such as Standard Contractual Clauses) to protect your information.
12. Changes to This Policy
We may update this Privacy Policy from time to time. For material changes, we will provide notice via email and in-app notification at least 30 days before the changes take effect. The "Last updated" date at the top of this page reflects the most recent revision.
Continued use of the Service after the effective date of any changes constitutes acceptance of the updated policy.
13. Contact Us
For privacy inquiries, data requests, or to report a security concern:
CareOps Technologies, Inc.Attn: Privacy Officer
Email: privacy@careops.ai
Security incidents: security@careops.ai
Response time: Within 45 days for CCPA requests; within 30 days for general inquiries