Privacy Policy

Last updated: September 1, 2025SOAP-E, LLC

Your privacy is fundamental to our mission. As healthcare professionals ourselves, we understand the critical importance of protecting patient information and maintaining your trust through transparent, secure data practices.

1. Overview and Commitment to Privacy

SOAP-E, LLC ("Company," "we," "us," or "our") is committed to protecting the privacy and security of all information entrusted to us. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our healthcare documentation platform and related services (collectively, the "Service").

Our Privacy Promise

We are built by healthcare professionals, for healthcare professionals. We understand the sacred trust placed in us when handling patient information and personal data. Our privacy practices are designed to exceed industry standards and regulatory requirements.

Scope of This Policy

This Privacy Policy applies to:

  • All users of the SOAP-E platform, including healthcare professionals and authorized personnel
  • Information collected through our website, mobile applications, and related services
  • Protected Health Information (PHI) processed in connection with our Service
  • Personal information of users and any individuals whose information may be processed through the Service

Regulatory Compliance

Our privacy practices are designed to comply with applicable federal and state privacy laws, including but not limited to the Health Insurance Portability and Accountability Act (HIPAA), the California Consumer Privacy Act (CCPA), and other relevant privacy regulations.

2. Information We Collect

Account and Profile Information

When you create an account or use our Service, we may collect:

  • Professional credentials and licensing information
  • Contact information (name, email address, phone number)
  • Professional affiliation and workplace information
  • Account authentication data (encrypted passwords, OAuth tokens)
  • User preferences and settings
  • Profile information you choose to provide

Clinical Documentation Data

In the course of providing our documentation assistance service, we process:

  • Clinical observations and notes you input into the system
  • Generated documentation content and AI-assisted outputs
  • Conversation transcripts and session data (when applicable)
  • Documentation metadata (timestamps, revision history, user interactions)
  • Quality assurance and accuracy feedback data

Important: We process this information solely to provide our documentation services and do not use it for any other purpose without your explicit consent.

Technical and Usage Information

We automatically collect certain technical information to operate and improve our Service:

  • Device information (browser type, operating system, device identifiers)
  • IP addresses and location data (general geographic region only)
  • Usage patterns and interaction data (pages visited, features used, session duration)
  • Performance metrics and error logs (anonymized)
  • Security monitoring data (login attempts, access patterns)
  • Cookie data and similar tracking technologies (see Section 10 for details)

Communications and Support Data

When you contact us or interact with our support services:

  • Customer support communications and correspondence
  • Feedback, surveys, and user research responses
  • Training session recordings (with your consent)
  • Marketing communication preferences
  • Event and webinar participation data

Information from Third Parties

We may receive information from:

  • OAuth providers (Google, Microsoft) for authentication purposes
  • Professional licensing databases for credential verification
  • Healthcare institutions for authorized users (with proper agreements)
  • Legal and compliance service providers (for regulatory requirements)
  • Analytics and security service providers (anonymized data only)

3. Protected Health Information (PHI)

HIPAA Compliance Statement

We understand that you may input Protected Health Information (PHI) as defined by HIPAA into our system. We act as a Business Associate and implement all required safeguards to protect PHI in accordance with HIPAA regulations.

What Constitutes PHI in Our System

PHI may include any information you input that relates to:

  • Patient identifiers (names, dates of birth, medical record numbers)
  • Clinical observations and treatment notes
  • Diagnostic information and assessment data
  • Treatment plans and therapy goals
  • Progress notes and session summaries
  • Any other individually identifiable health information

PHI Processing and Minimization

We process PHI only as necessary to provide our documentation services. We encourage users to follow data minimization principles:

  • Use patient initials rather than full names when possible
  • Include only clinically relevant information necessary for documentation
  • Consider using de-identification techniques where appropriate
  • Regularly review and purge unnecessary PHI from the system

PHI Security Measures

We protect PHI through comprehensive security measures including:

  • End-to-end encryption for all PHI in transit and at rest
  • Strict access controls and authentication requirements
  • Audit logging of all PHI access and modifications
  • Employee training on HIPAA compliance and PHI handling
  • Incident response procedures for potential PHI breaches

PHI Retention and Disposal

PHI is retained only as long as necessary to provide our services or as required by applicable law. We provide secure deletion mechanisms and maintain detailed records of PHI disposal activities.

4. How We Use Your Information

Primary Service Functions

We use your information to:

  • Provide AI-assisted clinical documentation services
  • Generate, organize, and manage your clinical notes and documentation
  • Authenticate your identity and maintain account security
  • Process payments and manage subscription services
  • Provide customer support and technical assistance
  • Maintain and improve the functionality of our Service

Service Improvement and Development

We may use aggregated, de-identified information to:

  • Analyze usage patterns to improve user experience
  • Develop new features and enhance existing functionality
  • Train and improve our AI models (using only de-identified data)
  • Conduct quality assurance and performance optimization
  • Generate anonymized research and industry insights

Legal and Compliance Purposes

We may use information as necessary to:

  • Comply with applicable laws, regulations, and legal processes
  • Respond to lawful requests from government authorities
  • Enforce our Terms of Service and other agreements
  • Protect the rights, privacy, safety, or property of users or third parties
  • Investigate and prevent fraud, security breaches, or other illegal activities

Communications and Marketing

With your consent, we may use your contact information to:

  • Send service-related notifications and updates
  • Provide educational content and training materials
  • Share product announcements and feature updates
  • Invite you to participate in surveys or research studies
  • Send marketing communications (you can opt out at any time)

5. Information Sharing and Disclosure

Fundamental Principle

We do not sell, rent, or trade your personal information or PHI. We share information only in limited circumstances as described below, and always with appropriate safeguards in place.

Service Providers and Business Associates

We may share information with trusted third-party service providers who assist us in operating our Service, subject to strict contractual obligations:

  • Cloud infrastructure providers (with HIPAA-compliant services)
  • Authentication and security service providers
  • Payment processing and billing services
  • Customer support and help desk platforms
  • Analytics providers (using only de-identified data)
  • Legal and professional service providers

All service providers that may access PHI are required to sign Business Associate Agreements and implement appropriate safeguards.

Healthcare Institutions and Authorized Personnel

Where applicable and with proper authorization, we may share information with:

  • Your employing healthcare institution (as specified in institutional agreements)
  • Authorized supervisors or colleagues (with your explicit permission)
  • Quality assurance and compliance personnel (for institutional requirements)
  • IT administrators (for technical support and system administration)

Legal Requirements and Public Safety

We may disclose information when required by law or to protect public safety:

  • In response to valid legal process (subpoenas, court orders, search warrants)
  • To comply with regulatory investigations or audits
  • To report suspected abuse or neglect as required by law
  • To prevent imminent harm to individuals or public safety
  • To protect against fraud or other illegal activities
  • In connection with law enforcement investigations (with proper authorization)

Business Transfers

In the event of a merger, acquisition, or sale of assets, user information may be transferred to the acquiring entity, subject to:

  • Advance notice to affected users
  • Continued protection under equivalent privacy standards
  • Option for users to request data deletion before transfer
  • Compliance with all applicable privacy laws and regulations

De-identified and Aggregated Information

We may share de-identified, aggregated information for legitimate business purposes, including research, industry analysis, and service improvement, provided such information cannot be used to identify individuals or patients.

6. Security Measures and Safeguards

Comprehensive Security Framework

We implement a multi-layered security approach designed to protect your information from unauthorized access, disclosure, alteration, or destruction:

Technical Safeguards

  • End-to-end encryption (AES-256) for all data in transit and at rest
  • Multi-factor authentication for all user accounts
  • Role-based access controls with principle of least privilege
  • Intrusion detection and prevention systems
  • Secure API design
  • Automated security monitoring and anomaly detection
  • Regular security updates and patch management

Administrative Safeguards

  • Comprehensive employee background checks and security training
  • Regular HIPAA and privacy training for all personnel
  • Incident response procedures and breach notification protocols
  • Business Associate Agreements with all relevant vendors
  • Regular review and updating of security policies and procedures
  • Designated Privacy Officer and security team oversight
  • Data governance and classification protocols

Continuous Monitoring and Improvement

Our security program includes continuous monitoring, regular assessments, and ongoing improvement based on evolving threats and best practices. We maintain compliance with industry standards including HIPAA Security Rule requirements.

7. HIPAA Compliance and Your Rights

Business Associate Relationship

When you use our Service to process PHI, we act as your Business Associate under HIPAA. This means we are legally bound to protect PHI and use it only for the purposes specified in our Business Associate Agreement.

Your HIPAA Rights Regarding PHI

As a covered entity or individual, you have the following rights regarding PHI:

  • Right of Access: Request copies of PHI we maintain on your behalf
  • Right to Amend: Request corrections to inaccurate or incomplete PHI
  • Right to Restrict: Request limitations on how PHI is used or disclosed
  • Right to an Accounting: Receive a list of disclosures we have made
  • Right to Alternative Communications: Request confidential communications
  • Right to Complain: File complaints about our privacy practices

Exercising Your HIPAA Rights

To exercise any of these rights, please contact our Privacy Officer using the information provided in Section 16. We will respond to your request within the timeframes required by HIPAA (typically 30 days for most requests).

Minimum Necessary Standard

We follow the HIPAA minimum necessary standard, which means we access, use, and disclose only the minimum amount of PHI necessary to accomplish the intended purpose.

Notice of Privacy Practices

This Privacy Policy serves as our Notice of Privacy Practices as required by HIPAA. If you are a covered entity using our Service, you should provide appropriate notice to your patients regarding your use of our services.

8. Data Retention and Deletion

Retention Periods

We retain different types of information for varying periods based on legal requirements and business needs:

Retention Schedule:

  • Account Information: Retained while your account is active, plus 7 years after closure
  • Clinical Documentation: Retained as long as required by applicable healthcare records laws (typically 7-10 years)
  • PHI: Retained only as long as necessary to provide services or as required by law
  • Usage and Technical Data: Retained for up to 2 years for service improvement purposes
  • Support Communications: Retained for 3 years for quality assurance
  • Financial Records: Retained for 7 years in accordance with tax and business requirements

Secure Data Deletion

When information is no longer needed, we securely delete or destroy it using industry-standard methods:

  • Cryptographic erasure for encrypted data
  • Physical destruction of hardware when appropriate
  • Verification and documentation of deletion activities
  • Coordination with third-party service providers for complete removal

User-Initiated Deletion

You can request deletion of your data at any time, subject to legal and regulatory retention requirements. We provide tools within the Service for you to delete specific documentation and manage your data retention preferences.

Legal Holds and Preservation

In certain circumstances (such as litigation or regulatory investigations), we may be required to preserve information beyond normal retention periods. We will notify you of such requirements when legally permissible.

9. Your Privacy Rights and Choices

Access and Control

You have comprehensive rights regarding your personal information:

  • Access: Request copies of all personal information we maintain about you
  • Correction: Request correction of inaccurate or incomplete information
  • Deletion: Request deletion of your personal information (subject to legal requirements)
  • Portability: Request your data in a structured, machine-readable format
  • Restriction: Request limitations on how we process your information
  • Objection: Object to certain types of processing

Communication Preferences

You can control how we communicate with you:

  • Opt out of marketing communications at any time
  • Choose preferred communication channels (email, phone, mail)
  • Set frequency preferences for non-essential communications
  • Request confidential communication methods when necessary

Account Settings and Privacy Controls

Within your account settings, you can:

  • Review and update your profile information
  • Manage data sharing preferences
  • Configure security settings and authentication methods
  • View and download your data
  • Request account deletion
  • Access privacy and consent management tools

Exercising Your Rights

To exercise any of these rights, you can:

  • Use the privacy controls within your account settings
  • Contact our Privacy Officer directly (see Section 16)
  • Submit a written request via email or mail
  • Call our privacy helpline during business hours

We will respond to your requests within 30 days and provide updates if additional time is needed. There is generally no charge for exercising these rights, though we may charge a reasonable fee for excessive or repetitive requests.

10. Cookies and Tracking Technologies

Types of Technologies We Use

We use various tracking technologies to provide and improve our Service:

  • Essential Cookies: Required for basic Service functionality and security
  • Functional Cookies: Remember your preferences and settings
  • Analytics Cookies: Help us understand how you use our Service (anonymized)
  • Session Management: Maintain your login state and session security
  • Security Tokens: Protect against cross-site request forgery and other attacks

Cookie Management

You can control cookie settings through:

  • Your browser settings (most browsers allow you to block or delete cookies)
  • Opt-out tools provided by analytics providers
  • Privacy-focused browser extensions and tools

Please note that disabling essential cookies may impact the functionality of our Service.

Third-Party Analytics

We use privacy-compliant analytics services to understand Service usage. These services:

  • Process only anonymized and aggregated data
  • Do not track individual users across other websites
  • Provide opt-out mechanisms for users
  • Comply with applicable privacy regulations
  • Are bound by data processing agreements that protect user privacy

Do Not Track Signals

We respect Do Not Track signals and similar privacy preferences. When we detect these signals, we limit data collection to essential Service functionality only.

11. Third-Party Services and Integrations

Authentication Providers

We use trusted OAuth providers (such as Google) for secure authentication. These providers:

  • Handle login credentials securely without us storing passwords
  • Provide only basic profile information necessary for account creation
  • Allow you to revoke access at any time through their platforms
  • Are subject to their own privacy policies and terms of service

Cloud Infrastructure and Services

We utilize enterprise-grade cloud services that provide:

  • HIPAA-compliant infrastructure and data processing
  • Advanced security features and compliance certifications
  • Data residency controls and geographic restrictions
  • Comprehensive audit logging and monitoring capabilities
  • Business Associate Agreements for PHI protection

Payment Processing

We use PCI DSS-compliant payment processors that:

  • Handle all payment card data securely
  • Do not share your financial information with us
  • Provide fraud protection and secure transaction processing
  • Maintain their own privacy policies and security standards

AI and Machine Learning Services

Our AI-powered features utilize secure, healthcare-compliant machine learning services that:

  • Process data within HIPAA-compliant environments
  • Do not retain or learn from individual user data
  • Provide audit trails for all AI processing activities
  • Implement appropriate safeguards for PHI protection
  • Are covered by comprehensive Business Associate Agreements

Third-Party Links and Integrations

Our Service may contain links to third-party websites or integrate with external services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any information.

12. International Data Transfers

Data Residency and Transfers

Your data is processed and stored within the United States in HIPAA-compliant data centers.

Cross-Border Access Controls

We implement strict controls on cross-border access to data:

  • Geographic restrictions on data access based on user location and applicable laws
  • Role-based access controls that consider jurisdictional requirements
  • Audit logging of all international data access activities
  • Regular review of access patterns and compliance requirements

Government Access and Surveillance

We are committed to protecting your data from unauthorized government access. We:

  • Respond only to lawful requests with proper legal authority
  • Challenge overly broad or inappropriate requests when legally possible
  • Provide transparency reports on government data requests (when legally permissible)
  • Implement technical measures to prevent unauthorized access
  • Notify users of government data requests when legally allowed

13. Children's Privacy

Age Restrictions

Our Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have inadvertently collected such information, we will take immediate steps to delete it.

Healthcare Professional Use Only

Our Service is designed exclusively for licensed healthcare professionals and authorized personnel. Users must meet professional licensing requirements and age restrictions to access the Service.

Patient Information Involving Minors

When healthcare professionals use our Service to document care for minor patients:

  • Additional safeguards apply to protect pediatric patient information
  • Users must comply with applicable laws regarding consent and authorization
  • Special retention and access controls may apply based on state and federal requirements
  • Parents and guardians retain all rights regarding their minor children's health information

14. Data Breach Notification

Incident Response Procedures

We maintain comprehensive incident response procedures to address potential data breaches:

  • Immediate containment and assessment of any suspected breach
  • Forensic investigation to determine scope and cause
  • Risk assessment to evaluate potential harm to individuals
  • Coordination with law enforcement and regulatory authorities as required
  • Implementation of corrective measures to prevent future incidents

Notification Timelines

In the event of a breach involving personal information or PHI, we will:

  • Notify affected individuals within 60 days of discovery (or sooner as required by applicable law)
  • Report to the Department of Health and Human Services within 60 days for PHI breaches
  • Notify regulatory authorities within 72 hours where required
  • Inform covered entities immediately if we are acting as a Business Associate
  • Provide media notification if the breach affects more than 500 individuals

Breach Notification Content

Our breach notifications will include:

  • Description of what happened and when the breach was discovered
  • Types of information involved in the breach
  • Steps we have taken to investigate and address the breach
  • Recommendations for individuals to protect themselves
  • Contact information for questions and assistance
  • Actions we are taking to prevent similar breaches in the future

Prevention and Preparedness

We continuously work to prevent breaches through:

  • Regular security assessments and vulnerability testing
  • Employee training on security best practices and threat recognition
  • Implementation of advanced threat detection and prevention systems
  • Regular review and updating of incident response procedures
  • Coordination with cybersecurity experts and law enforcement

15. Privacy Policy Updates

Notification of Changes

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or service offerings. We will notify you of material changes through:

  • Prominent notice on our website and within the Service
  • Email notification to your registered email address
  • In-app notifications highlighting key changes
  • Updated "Last Modified" date at the top of this policy
  • For significant changes, we may require your consent to continue using the Service

What Constitutes a Material Change

Material changes include:

  • Changes to how we collect, use, or share personal information or PHI
  • Changes to your rights or our legal bases for processing
  • Changes to data retention periods or deletion practices
  • Addition of new third-party service providers that may access your data
  • Changes to our security practices or breach notification procedures
  • Changes to international data transfer practices

Your Options Regarding Changes

When we make material changes to this Privacy Policy:

  • You will have the opportunity to review the changes before they take effect
  • You can choose to accept the changes and continue using the Service
  • You can request deletion of your account and data if you disagree with the changes
  • For certain types of changes, we may require your explicit consent
  • You can contact us with questions or concerns about any changes

Version History and Archive

We maintain an archive of previous versions of this Privacy Policy, which is available upon request. This allows you to review the evolution of our privacy practices over time.

16. Contact Information and Privacy Officer

Privacy Officer

We have designated a Privacy Officer who is responsible for overseeing our privacy program and handling privacy-related inquiries and requests. Our Privacy Officer can be reached at:

Email: privacy@soap-e.com

Phone: (910) 523-2612

Mailing Address:
Privacy Officer
SOAP-E, LLC
4030 Wake Forest Rd
Raleigh, NC 27609

General Contact Information

For general questions about our Service or this Privacy Policy, you can contact us at:

Regulatory Authorities

You also have the right to file complaints with relevant regulatory authorities:

  • For HIPAA-related concerns: U.S. Department of Health and Human Services, Office for Civil Rights
  • For general privacy concerns: Your state's Attorney General office
  • For California residents: California Privacy Protection Agency
  • For residents of other states: Relevant state privacy or consumer protection agencies

Response Times and Procedures

We are committed to responding to your privacy inquiries promptly:

  • General inquiries: Within 2 business days
  • Privacy rights requests: Within 30 days (may be extended by an additional 30 days for complex requests)
  • HIPAA-related requests: Within 30 days as required by law
  • Urgent privacy concerns: Within 24 hours
  • Data breach notifications: According to applicable legal requirements

This Privacy Policy was last updated on September 1, 2025. By continuing to use SOAP-E after this date, you acknowledge that you have read and understood this Privacy Policy.

Questions about this Privacy Policy? Contact our Privacy Officer at privacy@soap-e.com