Privacy Policy

Last updated: March 15, 2026


Remedi Health, Inc. ("Remedi Health," "we," "our," or "us") operates Remedi, a healthcare operations service. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service at remedihealth.ai.

1. Information We Collect

Account Information

When you create an account or contact us, we collect your name, email address, organization name, and role. This information is necessary to provide our services.

Clinical and Operational Data

Remedi processes clinical, operational, and revenue-cycle data provided by your organization. This may include Protected Health Information (PHI) as defined by HIPAA. We process this data solely to provide our services and do not use it for any other purpose.

Usage Data

We automatically collect technical information including IP address, browser type, pages visited, and timestamps. This data helps us maintain and improve the service.

2. How We Use Your Information

  • Provide, maintain, and improve Remedi's services
  • Analyze clinical, operational, and revenue-cycle data against CMS regulations and payer rules
  • Generate reports, findings, and recommendations across clinical, workforce, and revenue-cycle workflows
  • Communicate with you about your account and our services
  • Ensure service security and prevent unauthorized access

3. HIPAA Compliance

Remedi Health operates as a Business Associate under HIPAA when processing PHI on behalf of covered entities. We will enter into a Business Associate Agreement (BAA) with each covered entity customer prior to processing any PHI. We implement administrative, physical, and technical safeguards to protect PHI in accordance with the HIPAA Security Rule.

4. AI Processing

Remedi uses Anthropic's Claude to power its reasoning layer. Our posture on AI and your data:

  • Data sent to the model travels over encrypted connections and is not used to train AI models
  • Protected health information does not reach any AI provider outside business associate terms with that provider; until such terms are in place, AI features operate on non-PHI operational data
  • AI output is grounded: findings cite their sources, and what cannot be cited is not stated

5. Data Security

We use industry-standard security measures including:

  • Encryption in transit (TLS 1.3) and at rest (AES-256)
  • Role-based access controls
  • JWT-based authentication with token expiration
  • Rate limiting and request validation
  • Regular security reviews and monitoring

6. Data Retention

We retain account information for the duration of your subscription and a reasonable period thereafter. Clinical, operational, and revenue-cycle data and findings are retained according to the terms of your service agreement and applicable regulatory requirements.

7. Third-Party Services

We use the following third-party services:

  • Anthropic (Claude) — AI reasoning across clinical, workforce, and revenue-cycle workflows
  • Cloudflare — CDN, DDoS protection, and DNS
  • Google Cloud Platform — Secret management and infrastructure

8. Your Rights

You have the right to:

  • Access the personal information we hold about you
  • Request correction of inaccurate information
  • Request deletion of your information (subject to legal and regulatory retention requirements)
  • Withdraw consent for optional data processing

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a notice on our service prior to the change becoming effective.

10. Contact Us

If you have questions about this Privacy Policy or our data practices, contact us at:

Remedi Health, Inc.
Email: hello@remedihealth.ai