MIHP EMR PRIVACY POLICY
Effective Date: September 8, 2026
Company: MIHP EMR, LLC
Service: MIHP EMR
1. Introduction
MIHP EMR, LLC (“MIHP EMR,” “we,” “us,” or “our”) provides electronic medical record, healthcare administration, clinical documentation, billing, data management, and related software services to healthcare providers and other authorized organizations.
Protecting the privacy, confidentiality, integrity, and security of health information is a fundamental part of the MIHP EMR platform.
MIHP EMR does not sell, rent, trade, monetize, or use patient information for advertising or marketing purposes.
MIHP EMR does not operate a data brokerage business and does not use Protected Health Information (“PHI”) to create advertising profiles or otherwise commercially exploit patient information.
When MIHP EMR creates, receives, maintains, or transmits PHI on behalf of a healthcare provider or other entity regulated by the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), MIHP EMR generally acts as a Business Associate of that organization and handles PHI in accordance with applicable HIPAA requirements, the Health Information Technology for Economic and Clinical Health Act (“HITECH”), applicable regulations, and the applicable Business Associate Agreement (“BAA”).
2. Information We May Process
Depending upon how a customer uses MIHP EMR, the platform may process information including:
• Patient names;
• Addresses and contact information;
• Dates of birth;
• Demographic information;
• Medical record numbers;
• Medicaid, Medicare, insurance, or payer-related identifiers;
• Health insurance information;
• Diagnoses;
• Treatment information;
• Care plans;
• Clinical notes;
• Encounter information;
• Medications;
• Referrals;
• provider information;
• Claims and billing information;
• healthcare authorization information;
• appointment or scheduling information;
• electronic healthcare transaction information;
• documents uploaded by authorized users; and
• other information entered into the platform by authorized healthcare organizations and their users.
Some of this information constitutes PHI under HIPAA.
MIHP EMR may also process limited information concerning authorized users of the platform, including names, professional contact information, usernames, authentication information, organizational affiliation, system activity, device information, IP address, and security or audit-log information.
3. How Information Is Obtained
Information may be provided to MIHP EMR through:
• authorized healthcare providers and healthcare organizations;
• authorized employees, contractors, and workforce members of those organizations;
• patients or authorized representatives when the platform provides patient-facing functionality;
• healthcare payers;
• clearinghouses;
• authorized healthcare integrations;
• APIs;
• electronic healthcare transactions;
• uploaded documentation; and
• normal operation of the MIHP EMR software and security systems.
MIHP EMR does not collect patient health information for advertising, consumer profiling, or data-brokerage purposes.
4. How MIHP EMR Uses Protected Health Information
MIHP EMR uses or processes PHI only as permitted by applicable law, applicable Business Associate Agreements, agreements with our customers, and instructions from authorized customers.
Permitted activities may include operating the EMR platform and performing functions such as:
• storing and maintaining electronic medical records;
• displaying patient records to authorized users;
• processing clinical documentation;
• facilitating treatment, payment, and healthcare operations as authorized by the customer;
• processing claims and related transactions;
• supporting healthcare interoperability;
• facilitating authorized communication between healthcare organizations;
• maintaining system security;
• creating system backups;
• troubleshooting software;
• investigating technical problems;
• preventing fraud, misuse, or unauthorized access;
• providing customer support;
• performing system maintenance; and
• improving the reliability, functionality, usability, performance, or security of the MIHP EMR platform.
MIHP EMR does not use PHI for independent commercial purposes unrelated to providing the MIHP EMR service.
5. No Sale or Marketing of Patient Information
MIHP EMR does not:
• sell PHI or patient information;
• rent PHI or patient information;
• trade PHI or patient information;
• provide patient information to data brokers;
• use PHI for targeted advertising;
• use PHI to build advertising profiles;
• permit advertising networks to use PHI;
• use PHI to market unrelated products or services;
• provide PHI to third parties for their independent marketing purposes; or
• monetize identifiable patient information.
MIHP EMR does not permit patient medical information maintained within the EMR platform to be used for behavioral advertising.
6. Limited Review of Medical Records
MIHP EMR personnel do not routinely review patient medical records.
In limited circumstances, authorized MIHP EMR personnel may need to access information contained within the platform when reasonably necessary to:
• diagnose a technical problem;
• investigate a reported software error;
• respond to an authorized customer-support request;
• investigate security events;
• validate data integrity;
• troubleshoot an interface or electronic transaction;
• improve the reliability or functionality of the platform;
• test or verify correction of a software issue; or
• perform another activity permitted under an applicable Business Associate Agreement.
Any such access will be limited to personnel whose responsibilities reasonably require the access.
Whenever applicable, MIHP EMR will limit access, use, and disclosure of PHI to the minimum necessary information reasonably required to accomplish the authorized purpose.
Access to PHI for troubleshooting, support, diagnostics, or platform improvement does not authorize MIHP EMR personnel to browse patient records for unrelated purposes.
7. HIPAA Minimum Necessary Standard
MIHP EMR maintains policies and procedures intended to limit uses, disclosures, requests for, and workforce access to PHI consistent with the HIPAA Minimum Necessary Standard when that standard applies.
Access to PHI is based upon legitimate job responsibilities and authorized operational requirements.
MIHP EMR seeks to avoid accessing identifiable patient information where an issue can reasonably be investigated using non-identifiable information, test information, technical logs, or other information that does not expose PHI.
8. Disclosure of Information
MIHP EMR does not disclose PHI except as permitted or required to operate the service and comply with applicable law.
Information may be disclosed:
To the MIHP EMR Customer
Information may be made available to the healthcare provider or organization that maintains the information through MIHP EMR and to users authorized by that organization.
At the Customer's Direction
Information may be transmitted to healthcare providers, payers, clearinghouses, governmental healthcare programs, laboratories, health information exchanges, or other organizations when requested or authorized by the MIHP EMR customer.
To HIPAA-Compliant Service Providers and Subcontractors
MIHP EMR may use carefully selected service providers or subcontractors that provide infrastructure or services necessary to operate MIHP EMR.
Where a service provider creates, receives, maintains, or transmits PHI on behalf of MIHP EMR and is considered a Business Associate or subcontractor Business Associate under HIPAA, MIHP EMR requires appropriate contractual protections, including a Business Associate Agreement when required by law.
Such providers may use PHI only as necessary to perform authorized services and may not use PHI for their independent advertising or marketing purposes.
When Required by Law
MIHP EMR may disclose information where disclosure is required by applicable federal or state law, regulation, court order, subpoena, administrative requirement, or other legally enforceable process.
Where legally permitted, MIHP EMR will seek to limit such disclosure to information legally required to be produced.
Security and Legal Protection
Information may be used or disclosed when legally permissible and reasonably necessary to investigate or address fraud, security threats, unlawful activity, misuse of the platform, or threats to the safety or security of individuals, systems, or information.
9. Security of Electronic Protected Health Information
MIHP EMR maintains administrative, physical, and technical safeguards designed to protect the confidentiality, integrity, and availability of electronic Protected Health Information (“ePHI”).
These safeguards may include, as appropriate:
• authentication and access controls;
• role-based access restrictions;
• individual user accounts;
• audit logging;
• encryption;
• secure transmission protocols;
• system monitoring;
• backups;
• security procedures;
• workforce confidentiality requirements;
• security training;
• vulnerability and risk management;
• incident-response procedures; and
• restrictions on workforce access to PHI.
No electronic system can guarantee absolute security. MIHP EMR nevertheless maintains safeguards designed to comply with applicable HIPAA Security Rule requirements and contractual obligations.
10. Security Incidents and Breach Notification
MIHP EMR maintains procedures for investigating suspected unauthorized access, acquisition, use, or disclosure of PHI.
If MIHP EMR discovers a breach of unsecured PHI for which notification is required under HIPAA, MIHP EMR will provide notification to the affected Covered Entity or Business Associate as required by applicable law and the applicable Business Associate Agreement.
MIHP EMR will cooperate with affected customers in investigating, mitigating, documenting, and responding to reportable incidents.
11. Data Ownership
As between MIHP EMR and its healthcare customers, patient records and customer-entered healthcare information remain under the control of the applicable healthcare customer, subject to applicable law and contractual terms.
MIHP EMR does not claim ownership of a patient's medical information merely because the information is stored or processed using the MIHP EMR platform.
12. Patient Rights and Healthcare Provider Responsibilities
In most circumstances, MIHP EMR operates as a Business Associate rather than the healthcare provider responsible for the patient's medical record.
Requests concerning:
• access to medical records;
• amendment of medical records;
• restrictions on disclosure;
• accounting of disclosures;
• copies of medical records;
• correction of clinical information; or
• other rights provided under HIPAA
should generally be submitted to the healthcare provider or organization responsible for the individual's care or medical record.
When required by an applicable Business Associate Agreement or applicable law, MIHP EMR will assist its healthcare customers in responding to such requests.
13. Data Retention
MIHP EMR retains information only for periods reasonably necessary to:
• provide contracted services;
• maintain healthcare records on behalf of customers;
• satisfy customer instructions;
• comply with contractual requirements;
• meet applicable healthcare, billing, tax, security, litigation-hold, backup, or legal requirements; and
• maintain necessary audit and security records.
Because medical records may be subject to federal and state retention requirements, a request to delete an individual user account does not necessarily permit deletion of medical records that a healthcare provider or MIHP EMR is legally or contractually required to maintain.
When information is no longer required to be retained, MIHP EMR may delete, destroy, anonymize, or return information in accordance with applicable agreements, policies, and law.
14. Account Deletion
Where the MIHP EMR mobile application permits an individual to create an account, an account holder may request deletion of the account through the method provided within the application or through the account-deletion process identified by MIHP EMR.
Account deletion will delete or deactivate information that MIHP EMR is permitted to delete.
Certain information may nevertheless be retained where necessary to:
• preserve an official medical record;
• satisfy healthcare record-retention obligations;
• comply with HIPAA or other applicable law;
• maintain legally required audit records;
• comply with instructions from the healthcare provider responsible for the record;
• prevent fraud or security abuse; or
• satisfy another lawful retention obligation.
Deleting an application account therefore may not result in deletion of medical information that a healthcare provider is legally required to retain.
Individuals seeking deletion, amendment, or correction of their medical record should contact the healthcare provider responsible for that record.
15. Mobile Application Data
The MIHP EMR mobile application may access information necessary to provide the functions requested by an authorized user.
Depending upon features enabled in a particular version of the application, this may include:
• account information;
• healthcare information;
• documents or files selected by the user;
• photographs or images when an authorized feature requires them;
• camera access when requested for an authorized application function;
• device identifiers necessary for security or application operation;
• IP address;
• authentication information;
• application diagnostics;
• crash information; and
• security logs.
MIHP EMR does not use mobile application information for targeted advertising or unrelated marketing.
Device permissions are requested only where needed for an enabled feature of the application.
16. Analytics and Diagnostics
MIHP EMR may collect or generate technical information concerning application operation, reliability, security, crashes, performance, and errors.
Where reasonably possible, diagnostic and analytics processes are designed to avoid including PHI.
MIHP EMR does not permit PHI to be used by advertising analytics providers.
Technical or diagnostic information will be used for purposes such as:
• detecting software problems;
• improving application performance;
• identifying crashes;
• maintaining security;
• detecting unauthorized activity; and
• improving MIHP EMR functionality.
17. No Advertising-Based Business Model
The MIHP EMR platform is not funded through the commercialization of patient information.
MIHP EMR does not provide patient information to advertising networks and does not permit third-party advertising companies to use PHI obtained through the MIHP EMR platform.
18. Cookies and Website Technologies
MIHP EMR websites or web applications may use cookies, session identifiers, or similar technologies when reasonably necessary for:
• authentication;
• maintaining secure sessions;
• application functionality;
• security;
• fraud prevention;
• user preferences; and
• performance monitoring.
MIHP EMR does not use PHI obtained through the EMR for targeted advertising.
19. Children's Information
MIHP EMR may contain healthcare records concerning minors when such information is entered or maintained by an authorized healthcare provider.
MIHP EMR processes such records on behalf of the applicable healthcare organization and does not independently collect children's medical information for advertising or commercial profiling.
Rights regarding a minor's medical record are governed by applicable healthcare privacy laws and the policies of the healthcare provider responsible for the record.
20. Business Associate Agreements
Where required by HIPAA, MIHP EMR enters into Business Associate Agreements with Covered Entities or other Business Associates for which MIHP EMR performs services involving PHI.
These agreements define permitted uses and disclosures of PHI and impose appropriate privacy and security obligations.
Where MIHP EMR uses a subcontractor that creates, receives, maintains, or transmits PHI on MIHP EMR's behalf, MIHP EMR requires the subcontractor to accept applicable HIPAA privacy and security obligations.
If this Privacy Policy conflicts with an applicable Business Associate Agreement regarding PHI, the Business Associate Agreement will govern to the extent required by applicable law.
21. Changes to This Privacy Policy
MIHP EMR may periodically update this Privacy Policy to reflect changes in:
• law or regulation;
• MIHP EMR functionality;
• security practices;
• application-store requirements; or
• MIHP EMR's data-processing practices.
The effective date shown at the top of this policy identifies the most recent revision.
Material changes will be published through an appropriate MIHP EMR website, application, or other notice mechanism.
22. Contacting MIHP EMR
Questions concerning this Privacy Policy or MIHP EMR's privacy practices may be directed to:
MIHP EMR, LLC
Privacy / HIPAA Compliance
[MAILING ADDRESS]
Email: [PRIVACY EMAIL ADDRESS]
Telephone: [PHONE NUMBER]
Patients seeking access to, amendment of, or other action concerning an official medical record should generally contact the healthcare provider or healthcare organization responsible for that record.
23. HIPAA Compliance Statement
MIHP EMR is committed to handling PHI entrusted to the MIHP EMR platform in accordance with applicable HIPAA Privacy, Security, and Breach Notification requirements.
MIHP EMR's core privacy principles are:
We do not sell patient information.
We do not use patient information for advertising.
We do not use patient information for unrelated marketing.
We limit access to PHI to authorized purposes.
When MIHP EMR personnel must access PHI for support, diagnostics, security, or authorized platform improvement, access is restricted to authorized personnel and, where applicable, to the minimum information reasonably necessary to accomplish that purpose.
We require appropriate privacy and security protections from subcontractors that handle PHI on our behalf.
Patient information exists within MIHP EMR to support healthcare—not to create an advertising or data-monetization business.
|