Version 2.1 | Effective Date: July 2026
Version 2.1 | Effective Date: July 2026
Atelia Software Inc., doing business as Atelia Health (“Atelia Health,” “we,” “us,” or “our”) respects your privacy and is committed to protecting your Personal Information and Protected Health Information. This Privacy Policy describes the types of information we collect when you visit our website(s), use our mobile application (“App”), interact with us online or through email, participate in our programs or services, or engage in other business interactions with us (collectively, our “Services”). It also explains how we collect, use, share, and protect your information.
This Privacy Policy applies to all users of our Services, including healthcare providers (“Providers”), their staff and authorized representatives, and patients who receive communications through our platform on behalf of their healthcare provider.
Atelia Health provides healthcare operations, billing, communication, and practice management services to healthcare providers. Under the Health Insurance Portability and Accountability Act of 1996, as amended by the HITECH Act (collectively, “HIPAA”):
Before any PHI is transmitted to or through Atelia Health, Providers must agree to a Business Associate Agreement (“BAA”) with Atelia Health. The BAA governs the permitted uses and disclosures of PHI and establishes the obligations of both parties under HIPAA.
If you are a patient receiving communications through Atelia Health (such as text messages, phone calls, or video calls) on behalf of your healthcare provider, please be aware that:
We may collect and process the following categories of Personal Information:
When Providers use our Services, we receive, create, maintain, and transmit Protected Health Information on behalf of the Provider. PHI handled through our platform may include:
We collect information through the following methods:
We use PHI only as permitted by HIPAA and our Business Associate Agreement with the Provider. Permitted uses include:
We will NOT: sell PHI; use PHI for marketing purposes without Provider authorization; share PHI with third parties except as permitted by the BAA and HIPAA; use PHI for any purpose other than delivering the Services or as required by law; or use PHI to discriminate against any individual.
We may use your Personal Information (that is not PHI) to:
We may disclose PHI only as permitted by HIPAA and our Business Associate Agreement:
We engage the following categories of subcontractors who may create, receive, maintain, or transmit PHI on our behalf. All subcontractors handling PHI are bound by Business Associate Agreements with Atelia Health:
We may engage additional subcontractors from time to time. All subcontractors who handle PHI will be required to enter into a BAA with Atelia Health before receiving any PHI.
We may disclose your Personal Information (that is not PHI) to:
We implement administrative, technical, and physical safeguards designed to protect PHI and Personal Information in accordance with the HIPAA Security Rule and industry best practices:
Despite our efforts, no information security measures can guarantee absolute security. We encourage you to take steps to protect your own information, such as using strong passwords and not sharing account credentials.
We retain data only for as long as it is needed for the purpose it was collected, or for the period required by law. Our retention periods by category are:
You may request deletion of your account and associated personal data at any time, free of charge, by either of the following methods:
We acknowledge deletion requests within five (5) business days and complete verified requests within thirty (30) days. We may need to verify your identity before acting on a request. Deleting your account removes your login credentials, profile, preferences, and device identifiers, and revokes your access to the Services.
Some information cannot be deleted on request. Protected Health Information that forms part of a patient’s medical record belongs to the Covered Entity and is retained under the retention periods described in Section 7.1; the same applies to records we are required to keep for legal, audit, tax, or security purposes. Where we cannot delete data, we will tell you why and continue to protect it under this Privacy Policy.
If you are a patient, your health record is held by your healthcare provider, not by Atelia Health. Please direct requests to access, amend, or delete your health information to your provider’s office. If you contact us directly, we will refer your request to your provider and support them in responding to it.
Upon termination of a Provider’s or organization’s account, we will return or destroy PHI as specified in the Business Associate Agreement, except where retention is required by law or where return or destruction is not feasible, in which case we will continue to protect the information in accordance with the BAA.
In the event of a breach of unsecured PHI, Atelia Health will comply with the HIPAA Breach Notification Rule (45 CFR §§ 164.400–414):
Atelia Health maintains a formal Incident Response Plan based on the NIST SP 800-61 framework, with a designated Incident Response Team (IRT) available 24/7.
Our mobile application allows Providers and their staff to access the Services from mobile devices. When using the App:
Atelia Health provides dedicated e-fax numbers for receiving documents from hospitals, referring physicians, insurance companies, and other healthcare entities:
Atelia Health uses artificial intelligence and machine learning technologies to:
All AI processing of PHI is performed within our HIPAA-compliant infrastructure. AI outputs are presented to Providers for review and confirmation before any clinical or billing actions are taken. Atelia Health does not use PHI to train general-purpose AI models.
We may use cookies and other tracking technologies (such as web beacons, tags, scripts, and device identifiers) to collect and store analytics and other information when you use our website or App. These technologies may provide us with:
We use this information to analyze usage patterns, improve our Services, and personalize your experience. We do not use tracking technologies to collect PHI.
As a Provider using our Services, you have the right to:
If you are a patient whose healthcare provider uses Atelia Health:
Depending on your jurisdiction, you may have additional rights under applicable state and federal privacy laws, including the right to:
To exercise any of these rights, please contact us at privacy@ateliahealth.com. We may require you to verify your identity before processing your request.
Our Services are intended for use by healthcare providers and their authorized staff. We do not knowingly collect Personal Information directly from individuals under 18 years of age. PHI of minor patients may be processed through our platform at the direction of the Provider in accordance with HIPAA and applicable state laws governing the privacy of minors’ health information.
Atelia Health may update this Privacy Policy from time to time to reflect changes in our practices, Services, or applicable laws. When we make material changes, we will update the “Effective Date” at the top of this policy and, where required, provide notice to affected users. We encourage you to review this policy periodically.
Atelia Health sends SMS/text messages to patients and users on behalf of the healthcare providers who use our Services — for example, appointment reminders, care and follow-up communications, secure document links, and replies to messages you send. The following terms apply to our text messaging program:
If you have questions, concerns, or requests related to this Privacy Policy, your Personal Information, or our HIPAA compliance practices, please contact us:
Atelia Software Inc. (dba Atelia Health)
Privacy Officer
Email: privacy@ateliahealth.com
Phone: (415) 505-6124
Website: ateliahealth.com
For HIPAA compliance inquiries or to report a potential breach, contact: compliance@ateliahealth.com