Privacy Policy
Effective Date: Same Effective Date as the applicable Software as a Service Agreement and Business Associate Agreement
1. Scope
This Privacy Policy governs the collection, use, disclosure, safeguarding, and processing of information by NoBackOffice, Inc. ("NoBackOffice," "we," "our," or "us") through the NoBackOffice website and related online services made available to healthcare provider customers (each, a "Customer"). This Privacy Policy applies solely to Customers and prospective Customers located within the United States.
2. Relationship to HIPAA
NoBackOffice provides technology services to healthcare providers and, where applicable, acts as a Business Associate under the Health Insurance Portability and Accountability Act of 1996 (HIPAA). Protected Health Information ("PHI") processed on behalf of a Customer is governed by the applicable Business Associate Agreement ("BAA"). This Privacy Policy supplements, and does not replace, the parties' contractual rights and obligations under the SaaS Agreement or BAA. Patients seeking access to, amendment of, restriction of, or accounting relating to PHI should direct such requests to their healthcare provider.
3. Information We Collect
We may collect and process information including account registration information; names; email addresses; telephone numbers; mailing addresses; NPI, DEA, state license and other professional credentials; Tax Identification Numbers and EINs; payment and billing information; practice information; appointment information; insurance information; medical records; diagnoses; medications; laboratory information; questionnaires; uploaded files; communications; audio recordings; AI-generated summaries; and any other information submitted by or on behalf of a Customer through the Services.
4. Purposes of Processing
We use information to establish and administer accounts; authenticate users; provide scheduling, charting, billing, communications, practice management and related services; improve, maintain and secure the Services; detect fraud, abuse and unauthorized access; provide customer support; communicate regarding service updates, security notices and contractual matters; comply with legal obligations; and enforce our agreements.
5. Artificial Intelligence
The Services may incorporate artificial intelligence to assist Customers with documentation, questionnaire scoring, patient communications, workflow automation, summaries and other product functionality. AI-generated output is intended solely to assist licensed healthcare providers and is not a substitute for independent professional or clinical judgment. Customers remain solely responsible for reviewing all AI-generated content before relying upon or incorporating such content into the medical record or patient care.
6. Cookies and Analytics
We may use cookies, session cookies, analytics technologies, log files and similar technologies to operate the website, maintain security, understand website usage, diagnose technical issues, improve user experience and develop new features. We may introduce additional analytics technologies over time. Customers may adjust browser settings to limit certain cookies, although doing so may affect website functionality.
7. Disclosure of Information
We may disclose information where reasonably necessary to provide the Services, comply with applicable law, respond to lawful governmental requests, protect the rights, property or safety of NoBackOffice or others, investigate fraud or security incidents, enforce contractual rights, or in connection with a merger, financing, acquisition, restructuring or sale of assets. PHI is disclosed only as permitted by applicable law and the applicable BAA.
8. Security
NoBackOffice maintains administrative, technical and physical safeguards reasonably designed to protect information against unauthorized access, use, disclosure, alteration and destruction. No security measure is infallible, and except as expressly provided in the applicable agreements, we cannot guarantee absolute security of information transmitted over the Internet.
9. Marketing Communications
We may send newsletters, educational materials, product updates and promotional communications. Customers may opt out of promotional communications at any time through the unsubscribe mechanism included in such communications or by contacting support@nobackoffice.com. Transactional and security-related communications may continue where necessary to provide the Services.
10. Data Retention
Retention of Customer information and PHI is governed by the applicable SaaS Agreement, BAA and applicable law. Following termination of the Services, information may be retained for the periods required by contract, legal obligations, dispute resolution, security, backup integrity or legitimate business purposes.
11. Children's Privacy
The Services are not directed to children under thirteen (13), except to the extent patient information is processed by healthcare providers in connection with the delivery of healthcare services.
12. Modifications
We reserve the right to amend this Privacy Policy from time to time. Material revisions will become effective upon publication of the revised Privacy Policy or as otherwise required by law.
13. Contact Information
NoBackOffice, Inc.
Mailing Address (Mail Only):
10921 Wilshire Blvd Suite 409A
Los Angeles, CA 90024
Email: support@nobackoffice.com
Related documents: Software as a Service License Agreement and Business Associate Agreement.