Neurise ("Neurise," "we," "our," or "us") is committed to protecting the privacy and security of your personal and health-related information. This Privacy Policy describes how we collect, use, disclose, and safeguard information when you access or use the Neurise healthcare management platform ("Platform"). Please read this policy carefully. By using the Platform, you agree to the practices described herein.
1. Information We Collect
We collect the following categories of information:
- Account Information: Name, email address, role (admin, staff, or resident), and authentication credentials.
- Protected Health Information (PHI): Health status, wellness data, voice interactions, and other health-related data submitted through the Platform, as applicable to your role.
- Facility Information: Details about healthcare facilities, including addresses, operational data, and staff assignments.
- Usage Data: Log data, IP addresses, browser type, pages visited, actions taken within the Platform, and timestamps, used for security and operational purposes.
- Communications: Messages, support requests, and other communications you send to us.
2. How We Use Your Information
We use collected information to:
- Provide, operate, and maintain the Platform and its features.
- Deliver healthcare management and wellness services to residents and facilities.
- Authenticate users and enforce role-based access controls.
- Monitor and improve Platform performance, security, and reliability.
- Comply with applicable legal and regulatory obligations, including HIPAA.
- Respond to support inquiries and communicate service updates.
- Generate de-identified or aggregated analytics to improve our services.
3. HIPAA Compliance
Neurise operates as a Business Associate under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and its implementing regulations, including the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule.
- We enter into Business Associate Agreements (BAAs) with Covered Entities as required by HIPAA.
- We implement administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of PHI.
- PHI is used and disclosed only as permitted under applicable BAAs and HIPAA regulations.
- We maintain breach notification procedures consistent with HIPAA requirements.
4. Disclosure of Information
We do not sell your personal information. We may share information in the following circumstances:
- With your Facility: Information is shared with authorized personnel within your healthcare facility as necessary to provide care and manage operations.
- Service Providers: We engage trusted third-party vendors (e.g., cloud hosting, authentication providers) under confidentiality obligations and, where applicable, BAAs.
- Legal Requirements: We may disclose information when required by law, court order, or governmental authority.
- Business Transfers: In connection with a merger, acquisition, or sale of assets, information may be transferred subject to appropriate confidentiality protections.
- With Your Consent: We may share information for other purposes with your explicit consent.
5. Data Retention
We retain personal information and PHI for as long as necessary to fulfill the purposes outlined in this policy, satisfy legal and regulatory obligations, resolve disputes, and enforce our agreements. Retention periods for PHI are governed by applicable HIPAA requirements and our BAAs with Covered Entities.
6. Security
We implement industry-standard security measures including encryption in transit (TLS) and at rest, role-based access controls, multi-factor authentication options, audit logging, and regular security assessments. While we take reasonable steps to protect your information, no system is completely secure, and we cannot guarantee absolute security.
7. Your Rights
Depending on your jurisdiction and role, you may have the following rights:
- Access: Request access to personal information we hold about you.
- Correction: Request correction of inaccurate or incomplete information.
- Deletion: Request deletion of your information, subject to legal and contractual obligations.
- PHI Rights: Residents may exercise applicable HIPAA rights (access, amendment, accounting of disclosures) through their healthcare facility.
- California Residents: California residents may have additional rights under the California Consumer Privacy Act (CCPA).
To exercise your rights, please contact your facility administrator or reach out to us at the contact information below.
8. Cookies and Tracking
We use session cookies and similar technologies solely to authenticate users and maintain secure sessions on the Platform. We do not use third-party advertising cookies or behavioral tracking technologies.
9. Children's Privacy
The Platform is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from minors. If we become aware that we have inadvertently collected such information, we will take steps to delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify users of material changes by updating the "Last Updated" date and, where appropriate, providing in-app or email notification. Continued use of the Platform after changes take effect constitutes acceptance of the revised policy.
11. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact us at: