Skip to main content
Memry Logo

Privacy Policy

MemryHealth LLC
Effective Date: 07/01/2026
Version 1.0

1.  Introduction and Scope

MemryHealth LLC (“MemryHealth,” “we,” “us,” or “our”) provides a Software-as-a-Service post-acute electronic health record platform (the “Services”) to healthcare provider organizations and their affiliates (each, a “Customer”). This Privacy Policy describes how MemryHealth collects, uses, discloses, and protects information in connection with the Services.

This Privacy Policy is incorporated into and forms part of the Subscription Agreement between MemryHealth and each Customer (the “Agreement”). Capitalized terms used but not defined in this Privacy Policy have the meanings given in the Agreement.

1.1  Order of Precedence

MemryHealth processes Protected Health Information (“PHI”) on behalf of Customers as a Business Associate under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations, as amended by the HITECH Act (collectively, “HIPAA”). The Business Associate Agreement (“BAA”) attached as Exhibit C to the Agreement governs all Use and Disclosure of PHI. In the event of any conflict between this Privacy Policy and the BAA with respect to PHI, the BAA controls.

1.2  Who This Policy Covers

This Privacy Policy addresses information collected through the Services in connection with a

Customer’s subscription. It does not govern:

•       Information collected through MemryHealth’s public-facing marketing website, which is governed by a separate website privacy notice.

•       A patient’s rights with respect to their PHI maintained by a Customer, which are addressed by the Customer’s HIPAA Notice of Privacy Practices.

•       Information processed by Customer’s own systems or third-party services not provided

by MemryHealth.

 

2.  Information We Process

In connection with delivering the Services, MemryHealth processes the following categories of information.

2.1  Customer Data, Including PHI

“Customer Data” means information, data, and other content, in any form or medium, that is collected, downloaded, or otherwise received, directly or indirectly, from Customer or an Authorized User by or through the Services. Customer Data includes PHI uploaded to or generated within the Services in the course of patient care, scheduling, documentation, billing, claims, and related post-acute workflows.

PHI within Customer Data is handled exclusively as set forth in the BAA. MemryHealth uses and discloses PHI only as necessary to perform the Services, as required by law, or as otherwise permitted by the BAA.

2.2  Authorized User and Account Information

To provision and administer the Services, MemryHealth processes information identifying each Authorized User, including:

•       Name, business email address, role or job title, and organizational affiliation.

•       Access Credentials, multi-factor authentication factors, and session identifiers.

•       Authentication and authorization events, including sign-in attempts and credential changes.

2.3  Service Usage and Log Data

MemryHealth automatically collects information generated by the operation of the Services, including:

•       Application logs, audit trails, error reports, and diagnostic telemetry.

•       Device, browser, operating system, IP address, and approximate location derived from IP.

•       Pages and features accessed, transactions performed, performance metrics, and

integration events.

MemryHealth maintains audit logs sufficient to comply with the HIPAA Security Rule and

applicable certified electronic health record technology (“CEHRT”) requirements.

 

2.4  Support Communications

When Customer or an Authorized User contacts MemryHealth for support, MemryHealth processes the contents of the request, contact information, and any attachments, screenshots, or reproduction data provided. Authorized Users are instructed not to include PHI in support tickets except where reasonably necessary to diagnose an issue, and any such PHI is handled in accordance with the BAA.

2.5  Resultant Data

“Resultant Data” means data and information related to Customer’s use of the Services that is used by MemryHealth in an aggregate and anonymized manner, including to compile statistical and performance information related to the provision and operation of the Services. Resultant Data is de-identified consistent with 45 C.F.R. § 164.514, does not identify Customer, any Authorized User, or any individual, and is owned by MemryHealth as set forth in the Agreement.

 

3.  How We Use Information

MemryHealth uses the information described in Section 2 for the following purposes.

3.1  Providing and Operating the Services

•       Authenticating Authorized Users and managing access.

•       Hosting, displaying, processing, transmitting, and storing Customer Data.

•       Performing integrations with third-party services authorized under an Order.

•       Generating Customer Reports and other outputs of the Services.

3.2  Securing, Monitoring, and Maintaining the Services

•       Detecting, investigating, and responding to Security Incidents and unauthorized activity.

•       Performing audit logging, intrusion detection, vulnerability management, and incident response.

•       Performing backups, disaster recovery, capacity planning, and infrastructure maintenance.

3.3  Customer Support

•       Responding to support tickets, troubleshooting issues, and communicating service-related notices.

•       Validating service levels and tracking issue resolution under the Support Policy.

3.4  Service Improvement Through Resultant Data

MemryHealth uses Resultant Data — in aggregate, de-identified form only — to operate, analyze, improve, and develop the Services and new features. Resultant Data is not used in a manner that identifies Customer, any Authorized User, or any individual, and de-identification of PHI for this purpose is performed only with Customer’s express written permission as required by the BAA.

3.5  Legal, Regulatory, and Contractual Compliance

•       Complying with applicable law, regulation, subpoena, court order, or governmental request.

•       Enforcing the Agreement, including the BAA, and protecting the rights, property, and safety of MemryHealth, its Customers, and Authorized Users.

•       Cooperating with audits requested by the U.S. Department of Health and Human

Services or other regulators with jurisdiction.

3.6  No Sale of PHI; No Marketing Use of PHI

MemryHealth does not sell PHI and does not use PHI for Marketing, in each case as those terms are defined in 45 C.F.R. § 164.501 and § 164.502(a)(5)(ii)(B).

 

4.  Use of Artificial Intelligence and Machine Learning

Where MemryHealth uses artificial intelligence or machine-learning technologies (“AI Technologies”) within the Services, it does so subject to the following commitments, consistent with the BAA:

•       AI Technologies do not disclose, transfer, or store Customer personal information, including PHI, outside of MemryHealth’s controlled environment without Customer’s prior written consent.

•       MemryHealth maintains technical and administrative safeguards in connection with AI Technologies, including encryption standards, secure data transmission protocols, and access control measures.

•       MemryHealth maintains business associate agreements, data use agreements, or other

regulatory or legally required contracts with any subcontractor or vendor whose AI Technologies process Customer information.

•       MemryHealth does not deploy tracking technologies (such as pixel trackers) on any Customer-branded portal, application, or digital property without Customer’s prior written consent.

 

5.  Disclosures of Information

5.1  To Subcontractors

MemryHealth engages third-party subcontractors (“Subcontractors”) to host, operate, secure, and support the Services, including cloud infrastructure, data center, monitoring, security, communications, and integration providers. MemryHealth requires each Subcontractor that may access PHI to enter into a written agreement imposing privacy and security obligations no less protective than those imposed on MemryHealth under the BAA. A current list of categories of Subcontractors is available to Customer upon written request.

5.2  To Customer

MemryHealth makes Customer Data available to Customer through the Services and, on request and as required by the BAA, makes PHI available to Customer for inspection, copying, amendment, and accounting of disclosures.

5.3  As Required by Law

MemryHealth may disclose information when compelled by valid legal process, including subpoena, court order, or law enforcement request. Where permitted, MemryHealth will promptly notify Customer of any such request affecting PHI so that Customer may seek a protective order or other appropriate remedy.

5.4  In Connection With a Corporate Transaction

In the event of a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred to the successor or acquiring entity, subject to confidentiality obligations consistent with this Privacy Policy and the BAA.

5.5  No Other Sale or Disclosure

MemryHealth does not sell Customer Data or Authorized User information to third parties and does not share it with third parties for their own marketing purposes.

 

6.  Data Location and Transfers

MemryHealth processes and stores Customer Data on infrastructure located in the United States. MemryHealth does not transfer Customer Data outside the United States without Customer’s prior written consent, except to the extent required by applicable law.

 

7.  Information Security

MemryHealth implements and maintains administrative, physical, and technical safeguards designed to protect the confidentiality, integrity, and availability of Customer Data, in accordance with 45 C.F.R. § 164.308, § 164.310, § 164.312, and § 164.316. These safeguards include, at a minimum:

•       Encryption of Customer Data in transit using current industry-standard protocols and at rest using current industry-standard algorithms.

•       Role-based access controls, least-privilege provisioning, multi-factor authentication for privileged access, and periodic access reviews.

•       Audit logging, log monitoring, and alerting on anomalous activity.

•       Vulnerability management, secure development practices, change management, and periodic third-party security assessments.

•       Workforce security policies, background checks for personnel with access to PHI, and mandatory privacy and security training.

•       Documented incident response and disaster recovery procedures, with periodic testing. Notwithstanding these safeguards, no system can be guaranteed secure. MemryHealth’s

breach notification obligations are set forth in the BAA.

 

8.  Data Retention and Deletion

MemryHealth retains Customer Data, including PHI, for the duration of the Subscription Term and for such additional period as may be required by applicable law, the BAA, or the Agreement. Following expiration or termination, the parties shall discuss in good faith the extent to which MemryHealth will return or delete Customer Data, as further described in the Agreement. MemryHealth may retain copies of Customer Data in backups, archives, and disaster recovery systems until deleted in the ordinary course, and may retain Resultant Data indefinitely.

Audit logs and other records required to evidence regulatory compliance are retained for the period required by applicable law, including the six-year retention requirement applicable to certain HIPAA records.

 

9.  Individual Rights and Requests

MemryHealth processes PHI on behalf of Customer. Customer is the Covered Entity (or, where applicable, the Business Associate of a Covered Entity) responsible for responding to individuals’ requests under HIPAA, including requests for access, amendment, accounting of disclosures, restriction, and confidential communications.

If MemryHealth receives a request directly from an individual concerning PHI, MemryHealth will, within the timeframes set forth in the BAA, notify Customer and direct the individual to Customer. Approval or denial of any such request remains the responsibility of Customer.

To the extent applicable U.S. state privacy laws (including the California Consumer Privacy Act, as amended by the CPRA, and the Washington My Health My Data Act) apply to information processed by MemryHealth that is not otherwise governed by HIPAA, MemryHealth will support Customer in responding to consumer requests in its capacity as a service provider, processor, or analogous role under such laws.

 

10.  Information Concerning Minors

The Services are not directed to children under 13 and MemryHealth does not knowingly market the Services to children. Customer Data may include PHI relating to minor patients, which is handled exclusively in accordance with HIPAA and the BAA.

 

11.  Breach Notification

MemryHealth notifies Customer of a Breach of Unsecured PHI without unreasonable delay and in no case later than 48 hours after discovery, in accordance with the BAA. Notification includes the information required by the BAA and applicable law and is supplemented as additional information becomes available.

 

12.  Changes to this Privacy Policy

MemryHealth may update this Privacy Policy from time to time. The updated Privacy Policy will be posted at the Privacy Policy URL referenced in the Agreement, and the “Effective Date” above will be revised. For material changes that adversely affect the privacy or security of PHI, MemryHealth will provide reasonable advance notice to Customer through the Services or by email to the Customer notice contact on file.

 

13.  Contact Us

Privacy questions or requests concerning this Privacy Policy or MemryHealth’s privacy practices

should be directed to: MemryHealth LLC Attn: Privacy Officer

445 Hutchinson Ave

Suite 300

Columbus OH 43235

 

Email: privacy@MemryHealth.com

Notices required under the Agreement must be delivered as provided in the Notice section of the Agreement.