Skip to main content

Clinix AI | Population Health Management

Privacy Policy

Effective Date: June 1, 2026

Clinix LLC, doing business as Clinix AI ("Clinix," "we," "us," or "our"), provides a population health management platform that supports Advanced Primary Care Management ("APCM"), Behavioral Health Integration ("BHI"), care-plan development, patient outreach, consent documentation, care coordination, communications, reporting, and related services (collectively, the "Services").

This Privacy Policy explains how Clinix collects, uses, discloses, and protects personal information through the Services, including our websites, the Clinix platform, patient-facing consent or communication experiences, and related support interactions. It also explains the choices and rights that may be available to you.

1. Scope and Clinix's Role

This Privacy Policy applies to personal information that Clinix collects in connection with the Services. It does not replace a healthcare provider's Notice of Privacy Practices or describe every way a provider may use or disclose protected health information ("PHI").

Clinix often provides the Services to physician practices, healthcare organizations, care-management companies, and other customers ("Customers"). When Clinix creates, receives, maintains, or transmits PHI on behalf of a Customer that is a HIPAA covered entity or business associate, Clinix generally acts as a business associate or subcontractor business associate. In those circumstances:

  • the applicable Customer agreement and Business Associate Agreement ("BAA") govern Clinix's use and disclosure of PHI;
  • the Customer remains responsible for its Notice of Privacy Practices and for responding to patient requests involving access, amendment, restrictions, or an accounting of disclosures, except to the extent the Customer has authorized Clinix to assist; and
  • if this Privacy Policy conflicts with an applicable BAA concerning PHI, the BAA controls.

Some Customers or records may also be subject to 42 CFR Part 2, which provides additional protections for certain substance use disorder patient records. Where Part 2 applies, Clinix processes those records only as permitted by applicable law, Customer instructions, and the governing agreement. The applicable Part 2 program, covered entity, or lawful holder remains responsible for providing any required patient notice and obtaining any required consent.

Clinix is a technology and workflow provider, not your healthcare provider. Questions about diagnosis, treatment, billing, program eligibility, or a healthcare provider's privacy practices should be directed to the applicable provider or practice.

2. Personal Information We Collect

The information we collect depends on how you interact with the Services and the features used by the applicable Customer.

A. Account and Professional Information

We may collect:

  • name, title, organization, department, and professional role;
  • work email address, telephone number, business address, and other contact information;
  • username, account identifiers, authentication information, and account preferences;
  • provider identifiers, such as National Provider Identifier information, when entered by a Customer or authorized user; and
  • Customer, practice, provider, care-team, and coordinator assignments.

B. Patient, Care-Management, and Health Information

When submitted by or on behalf of a Customer, we may process information such as:

  • patient name, date of birth, contact information, demographic information, and patient or medical-record identifiers;
  • diagnoses, conditions, allergies, medications, clinical history, encounters, assessments, screening results, functional status, social needs, goals, interventions, treatment-planning information, referrals, transitions of care, and follow-up information;
  • care plans, care-plan revisions, provider review status, coordinator notes, communications, task history, and longitudinal care records;
  • information received from electronic health records, clinical documents, customer files, patient submissions, or authorized integrations; and
  • information needed to support APCM, BHI, care coordination, patient outreach, quality activities, and related documentation.

Depending on the circumstances, this information may be PHI under HIPAA or health information protected by other federal or state laws.

We may collect and maintain:

  • the program or service to which a patient was asked to consent;
  • consent method, including verbal, written, or electronic signature;
  • required disclosures and the version of the consent script or document presented;
  • patient response, signature, initials, affirmation, refusal, or withdrawal;
  • date, time, channel, delivery status, failed-contact status, and outreach history;
  • identity-verification and authentication information;
  • staff member, provider, practice, or organization associated with the consent;
  • electronic-signature evidence, such as document version, timestamps, internet protocol address, device or browser information, and audit history; and
  • a reference to a consent maintained in a Customer's electronic health record or other system.

D. Communications Information

We may process communications sent through or in connection with the Services, including email, text messages, secure messages, call outcomes, support requests, and patient or caregiver responses. If a Customer uses a lawful call-recording feature, the recording or related verification information may be processed subject to applicable consent and notice requirements.

E. Device, Usage, and Log Information

We may automatically collect:

  • internet protocol address, device type, operating system, browser type, language, and approximate location derived from an internet protocol address;
  • dates and times of access, pages or features viewed, referring pages, session activity, and interaction events;
  • authentication events, permissions, audit events, changes to records, exports, and administrative actions;
  • crash, performance, diagnostic, and security information; and
  • cookies, local storage, and similar technologies used to operate, secure, remember, and improve the Services.

F. Business, Billing, and Support Information

We may collect Customer contract information, subscription and invoice records, payment status, implementation information, training records, support communications, feedback, and other information needed to administer the Customer relationship. Payment-card details may be collected directly by a payment processor rather than stored by Clinix.

G. Website and Marketing Information

When you visit our public website, request information, book a demonstration, or communicate with our team, we may collect your contact information, organization, role, areas of interest, referral source, and the content of your request. Do not submit PHI through a public website form unless the form expressly states that it is approved for that purpose.

3. Sources of Personal Information

We may receive personal information:

  • directly from you;
  • from Customers, healthcare providers, care-management organizations, authorized users, patients, caregivers, and personal representatives;
  • from electronic health records, authorized integrations, uploaded files, clinical documents, and other Customer-directed data sources;
  • from communications, electronic-signature, hosting, security, identity, analytics, and support service providers;
  • from publicly available professional or business sources; and
  • automatically from devices and use of the Services.

4. How We Use Personal Information

Subject to applicable law, Customer instructions, and applicable agreements, we may use personal information to:

  • provide, configure, operate, maintain, support, and secure the Services;
  • create and maintain accounts, roles, permissions, and practice or care-team assignments;
  • support patient enrollment, outreach, consent capture, electronic signatures, care-plan development, care coordination, communications, revisions, reporting, and exports;
  • process information on behalf of Customers under Customer agreements and BAAs;
  • facilitate access to care-plan or consent records by authorized persons;
  • authenticate users, prevent fraud, investigate misuse, and maintain audit history;
  • communicate about accounts, service notices, security, support, implementation, training, and Customer relationships;
  • respond to requests, complaints, questions, and legal or regulatory inquiries;
  • monitor performance, troubleshoot, conduct testing, improve usability, and develop features;
  • create aggregated or de-identified information in accordance with applicable law and contractual restrictions;
  • comply with legal obligations, enforce agreements, protect rights and safety, and establish or defend legal claims; and
  • send marketing communications where permitted by law and consistent with your choices.

Clinix does not use PHI for targeted advertising. Clinix does not sell PHI. Clinix also does not sell personal information for money. If a state law defines "sale," "sharing," or "targeted advertising" more broadly, you may have the rights described in Section 12.

5. HIPAA, PHI, and Healthcare Records

When Clinix handles PHI as a business associate or subcontractor business associate, we use and disclose PHI only as permitted by the applicable BAA, Customer agreement, Customer instructions, and applicable law. Clinix maintains safeguards designed to protect the confidentiality, integrity, and availability of electronic PHI.

Patients generally should direct requests to access, correct, amend, restrict, or obtain an accounting of disclosures of PHI to the healthcare provider or practice responsible for the record. Clinix will assist Customers with those requests as required by the applicable BAA and law. A Customer may authorize Clinix to provide a copy of a consent record, care plan, or other record directly to a patient or caregiver.

This Privacy Policy is not a healthcare provider's Notice of Privacy Practices. A provider's Notice of Privacy Practices describes the provider's uses and disclosures of PHI and the patient's HIPAA rights.

Part 2 records may carry protections in addition to HIPAA, including restrictions on use or disclosure in legal proceedings against a patient. Clinix and Customers must handle those records according to the applicable consent, agreement, and law.

6. Artificial Intelligence and Automated Features

The Services may use artificial intelligence, machine learning, rules-based automation, or similar technology to organize information, assist with draft care-plan content, identify potential workflow actions, summarize records, support documentation, or provide other features.

Where AI features are enabled:

  • information may be processed by Clinix and contracted service providers subject to applicable agreements and safeguards;
  • PHI is processed only as permitted by the applicable Customer agreement, BAA, Customer instructions, and law;
  • outputs may be incomplete, inaccurate, or inappropriate for a particular patient or circumstance and require review by an authorized healthcare professional; and
  • Clinix does not use PHI for targeted advertising or to train publicly available models for unrelated purposes.

AI-generated or AI-assisted content is not a diagnosis, treatment recommendation, billing determination, legal opinion, or substitute for professional judgment.

7. How We Disclose Personal Information

We may disclose personal information in the following circumstances.

A. Customers and Authorized Users

We disclose information to the applicable Customer and its authorized workforce, providers, care teams, coordinators, contractors, and administrators according to configured permissions, Customer instructions, and applicable agreements.

B. Service Providers and Subcontractors

We may disclose information to vendors that provide hosting, data storage, security, identity management, communications, electronic signatures, customer support, analytics, implementation, payment processing, and other services. These providers are permitted to process information only for authorized purposes and are subject to contractual privacy and security obligations. Where required, Clinix enters into BAAs with subcontractors that create, receive, maintain, or transmit PHI.

C. Patient-Directed and Customer-Directed Disclosures

We may provide or transmit information at the direction of a patient, authorized representative, Customer, or authorized user, including by exporting a care plan, consent record, communication history, or related documentation.

We may disclose information when we reasonably believe disclosure is required by law, subpoena, court order, regulatory request, or legal process, or is necessary to protect the rights, security, or safety of Clinix, our Customers, users, patients, or others. Where applicable, disclosures of PHI remain subject to HIPAA, the applicable BAA, and other legal requirements.

E. Corporate Transactions

We may disclose information in connection with an actual or proposed merger, acquisition, financing, reorganization, sale of assets, bankruptcy, or similar transaction, subject to applicable law and contractual restrictions. Any successor will remain subject to applicable privacy, BAA, and Customer obligations.

We may disclose information for other purposes with valid consent, authorization, or direction.

G. Aggregated or De-Identified Information

We may use and disclose information that has been aggregated or de-identified in accordance with applicable law and contractual requirements so that it is not reasonably identifiable to an individual. We do not attempt to re-identify information that has been de-identified under HIPAA, except as permitted by law to test whether de-identification is effective.

8. Cookies and Similar Technologies

Clinix uses cookies and similar technologies to operate and secure the Services, remember preferences, understand performance, and improve user experience. These technologies may include:

  • strictly necessary technologies for authentication, security, session management, and core functions;
  • preference technologies that remember settings; and
  • limited analytics technologies used to understand website and product performance.

We do not use PHI for advertising and do not permit advertising technologies to use PHI. Browser settings may allow you to block or delete cookies, but some Services may not function properly without necessary technologies. Where required by law, we provide additional cookie choices.

9. Email, Text Messages, Calls, and Electronic Communications

Clinix may send transactional or care-related communications on behalf of a Customer, as well as account, security, support, and service notices. Message frequency varies. Message and data rates may apply to text messages. You may reply STOP to an eligible text-message program to stop future messages from that program and HELP for help, or contact the applicable provider or Clinix.

Opting out of text messages does not by itself withdraw consent to participate in a healthcare program or stop communications through other channels. Contact the applicable provider or practice to change program participation, care preferences, or clinical communications.

You may unsubscribe from Clinix marketing emails using the link in the message. We may continue to send non-promotional communications regarding an account, security, support request, contract, or transaction.

Text messages and ordinary email may not be encrypted. Customers and patients should use secure messaging options where available and should avoid sending sensitive information through an insecure channel unless they accept the associated risk.

If calls are recorded, Clinix or the applicable Customer will provide notice or obtain consent as required by applicable law. Call recording is not enabled or lawful in every jurisdiction.

10. Data Security

Clinix maintains administrative, physical, and technical safeguards designed to protect personal information against unauthorized access, use, alteration, disclosure, or destruction. These safeguards may include access controls, role-based permissions, authentication, encryption, logging, monitoring, backups, workforce training, incident-response processes, and vendor-management controls, as appropriate to the information and risk.

No system is completely secure, and Clinix cannot guarantee that unauthorized access, loss, or misuse will never occur. Users are responsible for protecting credentials, using appropriate devices and networks, promptly reporting suspected compromise, and following Customer security requirements.

If a security incident or breach occurs, Clinix will investigate and provide notices as required by applicable law, the applicable BAA, and Customer agreements.

11. Data Retention

Clinix retains personal information for as long as reasonably necessary to provide the Services, fulfill Customer instructions, comply with contractual and legal obligations, resolve disputes, maintain security and audit records, and enforce agreements.

Retention periods vary based on the type of information, the applicable Customer agreement or BAA, legal and regulatory requirements, patient-record obligations, the status of the Customer relationship, and technical backup cycles. At the end of the applicable period, Clinix will delete, return, de-identify, or securely dispose of information as required by applicable agreements and law. Information may remain in protected backups until overwritten through ordinary retention cycles.

12. Your Choices and Privacy Rights

Depending on your relationship with Clinix and where you live, you may have rights regarding personal information, including the right to:

  • request access to or a copy of personal information;
  • request correction of inaccurate information;
  • request deletion, subject to legal and contractual exceptions;
  • receive certain information in a portable format;
  • opt out of certain sales, sharing, targeted advertising, or profiling;
  • limit or withdraw consent for certain processing of sensitive information;
  • object to or restrict certain processing; and
  • appeal a decision concerning a privacy request.

These rights do not apply in all circumstances. Applicable exemptions may include PHI governed by HIPAA, information processed solely on behalf of a Customer, business-to-business information, and information Clinix must retain for legal, security, contractual, or patient-record purposes.

A. Requests Concerning PHI

If your request concerns a medical record, care plan, consent, PHI, or Part 2 record maintained for a provider or practice, contact that provider or practice first. The provider, Part 2 program, or other regulated entity is generally responsible for verifying and responding to the request. Clinix will assist as required by the applicable agreement and law.

B. Requests to Clinix

For personal information Clinix controls directly, submit a request to hello@tryclinixai.com. Describe the request and the relevant Clinix account, practice, or interaction. We may need to verify your identity and authority before acting. An authorized agent may submit a request where permitted by law, subject to verification.

We will not discriminate against you for exercising an applicable privacy right.

C. Communication Choices

  • Marketing email: use the unsubscribe link or contact us.
  • Text messages: reply STOP to an eligible program or contact the sender.
  • Cookies: use available cookie controls or browser settings.
  • Electronic records: follow the withdrawal process presented with the applicable consent or contact the provider or Clinix.

13. Children and Minors

Our public website and business-facing Services are not directed to children under 13, and we do not knowingly collect personal information directly from children under 13 through the public website without appropriate authorization.

Healthcare providers may use the Services in connection with care involving minors. In those circumstances, the provider or Customer is responsible for obtaining any required parental, guardian, or minor consent and for determining the authority of a personal representative. Clinix processes the information on behalf of the Customer under applicable agreements and law.

14. United States Services

The Services are intended primarily for use in the United States. If you access the Services from another jurisdiction, information may be transferred to and processed in the United States, where privacy laws may differ from those in your location. Any international use is subject to applicable Customer agreements and legal requirements.

15. Third-Party Services and Links

The Services may integrate with or link to electronic health records, communications providers, electronic-signature services, payment processors, or other third-party services. This Privacy Policy does not govern a third party's independent privacy practices. Review the privacy terms of third-party services you choose to use.

16. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in the Services, our practices, or legal requirements. We will post the updated policy and revise its effective or last-updated date. Where required by law or contract, we will provide additional notice or obtain consent before a material change takes effect.

17. Contact Us

Questions, concerns, and privacy requests may be directed to:

Clinix LLC d/b/a Clinix AI

3455 Peachtree Road NE, Suite 500

Atlanta, Georgia 30326

hello@tryclinixai.com

If your question concerns medical care, billing, eligibility, a patient record, or a provider's privacy practices, contact the applicable healthcare provider or practice.