Privacy Policy
PRIVACY POLICY
Effective Date: January 3, 2022
Company: AMG Health AI Solutions, Inc.
1. Introduction
AMG Health AI Solutions, Inc respects your privacy and is committed to protecting your personal data and health information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you interact with our websites, mobile applications, and artificial intelligence-powered health solutions (collectively, the "Services").
2. Information We Collect
We collect several types of information from and about users of our Services:
- Personal Identifiable Information (PII): Name, email address, phone number, postal address, and account credentials.
- Protected Health Information (PHI) & Health Data: Symptoms, health histories, medical records, diagnostic inputs, physiological data, and health parameters submitted by you or transmitted via an integrated healthcare provider system.
- Technical & Usage Data: IP addresses, browser types, device identifiers, operating systems, and usage metrics regarding how you interact with our AI tools.
- AI Training Inputs & Feedback: Query logs, prompt history, and explicit feedback provided to refine model responses.
3. How We Use Your Information
We use the collected data for the following essential purposes:
- To Provide and Maintain Services: Generating health insights, running AI algorithms, and processing administrative requests.
- To Improve Our AI Models: De-identified and aggregated data may be used to train, test, and improve our machine learning algorithms, ensuring higher accuracy and safety standards.
- Regulatory & Legal Compliance: Fulfilling obligations under applicable health data laws (e.g., HIPAA, GDPR, CCPA).
- Communication: Sending technical notices, security alerts, updates, and customer support messages.
4. HIPAA Compliance and Health Data Protection
Enterprise Users & Covered Entities: When operating as a Business Associate under the Health Insurance Portability and Accountability Act (HIPAA), we handle Protected Health Information (PHI) strictly in accordance with signed Business Associate Agreements (BAAs) and HIPAA Security Rules.
- De-Identification Standards: Before any data is used for algorithmic improvement, research, or analysis, it is strictly de-identified in compliance with applicable regulatory standards (such as the HIPAA Safe Harbor method) so that it can no longer be linked to an individual.
5. How We Share Your Information
We do not sell, rent, or trade your personal health data to third-party advertisers. We may share information only under the following circumstances:
- With Healthcare Providers: If you use our Services through or on behalf of a clinical provider, your data will be accessible to authorized medical personnel within that care system.
- Service Providers & Subprocessors: Secure cloud hosting providers, data analytics services, and security auditors operating under strict confidentiality and data protection agreements.
- Legal Requirements: When required by law, subpoena, or government regulation, or to protect the safety, rights, or property of the Company or others.
- Business Transfers: In connection with a merger, acquisition, or sale of company assets, subject to standard non-disclosure protections.
6. Data Security Measures
We implement robust administrative, physical, and technical safeguards designed to protect your data, including:
- Encryption: End-to-end encryption for data in transit (TLS 1.3+) and at rest (AES-256 encryption).
- Access Control: Strict role-based access control (RBAC) and multi-factor authentication (MFA) for personnel accessing systems hosting sensitive data.
- Continuous Monitoring: Regular vulnerability scans, penetration testing, and security audits.
7. Your Data Rights
Depending on your jurisdiction (e.g., California, EU/UK), you may hold the following rights regarding your personal information:
- Access & Portability: Request a copy of the personal data we hold about you.
- Correction: Request corrections to inaccurate or incomplete personal records.
- Deletion: Request erasure of your personal data, subject to legal and medical record-retention requirements.
- Opt-Out: Opt out of certain data-processing activities, such as secondary research use of de-identified data.
To exercise these rights, contact our Privacy Officer at privacy@AMGHealthAI.com.
8. Data Retention
We retain personal and health data only for as long as necessary to fulfill the purposes outlined in this policy, satisfy legal obligations, resolve disputes, and enforce our agreements. Once data is no longer required, it is securely destroyed or permanently anonymized.
9. Updates to This Policy
We may update this Privacy Policy periodically to reflect changes in our technology, legal obligations, or operational practices. We will notify you of material changes by posting the updated policy on our platform with a revised "Effective Date."
10. Contact Us
If you have questions, concerns, or complaints regarding this Privacy Policy or our data security practices, please contact:
Data Protection / Privacy Officer: Donald Stalworthson
Email: privacy@AMGHealthAI.com
Address: 826 Tangerine St. San Juan, TX 78589, USA
