Effective Date: March 2, 2026

ConversaCare (“we”, “our”, or “us”) provides conversational AI solutions to healthcare, senior care, and service providers.

Where applicable, we support HIPAA-aligned handling of Protected Health Information (PHI).

1. HIPAA Role

When ConversaCare processes health-related information on behalf of healthcare clients:

  • The client is the Covered Entity
  • ConversaCare operates as a Business Associate

A Business Associate Agreement (BAA) may be executed upon request.

2. Information We Collect

A. General Information

  • Name
  • Email
  • Phone
  • Organization
  • Interaction history

B. Health-Related Information (When Provided by Users)

May include:

  • Appointment requests
  • Care inquiries
  • Symptoms voluntarily disclosed
  • Treatment interest
  • Insurance information

This may qualify as PHI under HIPAA.

3. Permitted Use of PHI

We use PHI only to:

  • Facilitate appointment scheduling
  • Support care intake workflows
  • Enable communication automation
  • Deliver requested services
  • Provide analytics to Covered Entities

We do not use PHI for marketing.

4. Safeguards

We implement administrative, technical, and physical safeguards including:

  • Encryption in transit
  • Access controls
  • Role-based permissions
  • Secure cloud infrastructure
  • Audit logging

5. Minimum Necessary Rule

We limit access to PHI based on:

  • Operational need
  • Service delivery requirement

6. Data Storage

PHI is stored only:

  • For operational purposes
  • For service functionality

Clients control retention policies.

7. Disclosure of PHI

PHI is only disclosed:

  • To the Covered Entity
  • To subcontractors supporting service delivery (who are HIPAA-aligned)

Never sold. Never shared for advertising.

8. User Rights

End-users interacting with clients may exercise HIPAA rights through the Covered Entity, including:

  • Access
  • Correction
  • Deletion

Requests should be directed to the healthcare provider.

9. Breach Notification

In case of a confirmed PHI breach:

ConversaCare will notify the Covered Entity without unreasonable delay.

10. Subprocessors

Any subprocessors handling PHI are contractually required to maintain HIPAA safeguards.

11. Client Responsibility

Covered Entities must:

  • Obtain patient consent
  • Use platform in HIPAA-compliant manner

12. Business Associate Agreement

A BAA is available upon request and must be executed for HIPAA-regulated deployments.

Contact: [email protected]

HIPAA TERMS ADDENDUM

(To be added to Terms of Use)

PHI Handling

ConversaCare does not independently determine medical necessity, treatment decisions, or clinical outcomes.

The platform is a communication and workflow automation tool, not a medical system of record.

Customer Obligations

Clients must:

  • Ensure lawful PHI collection
  • Obtain patient authorization
  • Avoid transmitting unnecessary PHI

No Medical Advice

ConversaCare does not provide diagnosis or treatment.

Security Responsibility Model

ConversaCare provides:

  • Infrastructure safeguards
  • Platform-level controls

Clients are responsible for:

  • Workflow design
  • Consent capture
  • Downstream compliance

BAA Requirement

Use involving PHI requires a signed BAA.

Absent a BAA:

The platform must not be used for PHI processing.

Limitation of Use

Clients may not:

  • Use platform as EMR replacement
  • Store medical records
  • Conduct clinical decision automation