Privacy Policy
Last Updated: 29th October 2025
ClinicianCore Privacy Policy for Providers and Clinical Teams
Healthcare Provider Network, Inc., doing business as ClinicianCore (“ClinicianCore,” “we,” “us,” or “our”), respects the privacy of individuals and is committed to protecting the information entrusted to us through our websites, applications, and services.
This Privacy Policy describes how ClinicianCore collects, uses, discloses, retains, and protects information in connection with the ClinicianCore platform, websites, applications, and related services (collectively, the “Services”). It also describes certain rights and choices that may apply to individuals under applicable privacy laws.
ClinicianCore is designed primarily for physicians, healthcare professionals, healthcare organizations, and authorized members of clinical, administrative, and professional teams. ClinicianCore provides technology infrastructure for healthcare communication, collaboration, documentation, and operational workflows. ClinicianCore does not provide medical care, diagnosis, treatment, telehealth services, medical advice, medical coding, or medical billing.
1. Scope of This Privacy Policy
This Privacy Policy applies to information collected or processed through ClinicianCore’s public websites, applications, Services, communications, and other interactions with ClinicianCore, except where a separate privacy notice expressly applies.
ClinicianCore may process information in different capacities depending on the Service and the relationship with the applicable healthcare organization or customer. Where ClinicianCore processes information on behalf of a healthcare organization pursuant to a written agreement, Business Associate Agreement (“BAA”), or other applicable contractual arrangement, that agreement may establish additional requirements governing the processing of such information.
Where ClinicianCore acts as a Business Associate under the Health Insurance Portability and Accountability Act of 1996, as amended (“HIPAA”), the applicable BAA and applicable law govern ClinicianCore’s obligations with respect to Protected Health Information (“PHI”).
2. Information We Collect
The information ClinicianCore collects depends on how you interact with the Services, the Service or functionality you use, your relationship with ClinicianCore, and the configuration established by the applicable healthcare organization or customer.
ClinicianCore may collect information that you provide directly, including your name, professional title or role, healthcare organization or affiliation, specialty or professional information, email address, telephone or mobile number, account credentials, authentication information, preferences, and other information necessary to establish and administer an account or provide requested Services.
When you use the Services, ClinicianCore may process information submitted, transmitted, generated, or otherwise made available through those Services. Depending on the applicable Service, this may include messages, communications, consultation information, documentation, notes, files, attachments, voice or video-related information where supported, routing information, dates and times, participants, and related communication or service metadata. Such information may include PHI where submitted or processed as part of an authorized healthcare workflow.
ClinicianCore may also collect technical, diagnostic, security, and operational information necessary to operate, maintain, secure, troubleshoot, and improve the Services. This may include IP addresses, device and operating-system information, browser or application information, application versions, login and authentication events, session information, security events, error information, audit and accountability information, and other technical information associated with use of the Services.
When you visit a public ClinicianCore website, we may collect information concerning your interaction with the website, including pages viewed, browser and device information, referral information, cookie and preference information, and general website analytics information.
ClinicianCore does not intentionally request PHI through public website forms unless the applicable form or Service is specifically designed and authorized for that purpose.
3. Sources of Information
ClinicianCore may obtain information directly from you, from your healthcare organization or authorized administrator, from other authorized users, through your use of the Services, from devices or applications used to access the Services, through our public websites, and from service providers or other third parties that support authentication, security, fraud prevention, communications, analytics, infrastructure, or other legitimate business functions.
ClinicianCore may also receive professional or business information from publicly available sources where reasonably necessary for legitimate business purposes.
4. How We Use Information
ClinicianCore may collect and process Information as reasonably necessary to provide, administer, maintain, secure, and improve the Services; establish and manage user accounts; authenticate and authorize users; facilitate authorized communication and collaboration; support healthcare organization workflows; provide customer and technical support; maintain service availability and performance; detect, prevent, investigate, and respond to fraud, misuse, unauthorized access, security incidents, and other threats; maintain appropriate audit and accountability records; comply with applicable contractual, legal, regulatory, and governmental requirements; and protect the rights, safety, security, and integrity of ClinicianCore, its customers, users, systems, and Services.
ClinicianCore may also process information for other purposes that are compatible with the purposes described in this Privacy Policy, permitted by applicable law, or authorized by an applicable agreement.
ClinicianCore does not use PHI for purposes unrelated to providing or supporting the applicable Services except as permitted or required by applicable law, the applicable BAA, or other contractual authorization.
5. Healthcare Organizations, Customer Data, and PHI
Healthcare organizations and other customers may submit, transmit, or generate information through the Services. Such information may include Customer Data and, depending on the applicable Service and use, PHI or other regulated information.
The healthcare organization or customer generally determines which individuals are authorized to access its account, the roles and permissions assigned to those individuals, and how the organization uses and configures the Services. Customers are responsible for their own privacy practices, policies, procedures, workforce practices, access-management decisions, information-governance requirements, and compliance obligations.
Where ClinicianCore processes PHI on behalf of a HIPAA Covered Entity or Business Associate, ClinicianCore may act as a Business Associate or subcontractor Business Associate, as applicable. A BAA may be provided as appropriate to the applicable relationship, Services, and contractual requirements.
ClinicianCore’s role as a technology provider does not make the healthcare organization compliant with HIPAA or any other applicable law. Customers remain responsible for determining and satisfying the legal, regulatory, and professional requirements applicable to their operations.
6. Platform Services and Data Handling
ClinicianCore provides multiple Services and functionality intended to support healthcare communication, collaboration, documentation, professional interaction, and operational workflows. The information processed, available controls, and applicable data-management practices may differ depending on the applicable Service, functionality, technology environment, organizational configuration, and intended use.
Healthcare organizations and users should use each Service consistently with its intended purpose, applicable organizational policies, applicable contractual requirements, and applicable law.
Where a Service or environment is intended for professional discussion or collaboration rather than clinical communication, users should not submit identifiable patient information or PHI unless the applicable Service, organizational configuration, and applicable requirements expressly permit such use.
7. Disclosure and Sharing of Information
ClinicianCore does not sell PHI or consumer health data. ClinicianCore may disclose or make information available where reasonably necessary to provide the Services, fulfill contractual obligations, maintain security, comply with law, or perform other legitimate and authorized functions.
Information may be made available to the healthcare organization, customer, administrators, or authorized users associated with an account in accordance with applicable permissions, organizational configuration, contractual requirements, and law.
ClinicianCore may engage service providers and subprocessors to provide infrastructure, hosting, data storage, authentication, security, monitoring, communications, technical support, analytics, application performance, and other services necessary to operate the Services. Where applicable, ClinicianCore uses contractual and organizational safeguards appropriate to the information being processed. Subcontractors that handle PHI are subject to appropriate contractual requirements where required by applicable law.
ClinicianCore may disclose information when reasonably necessary to comply with applicable law, regulation, legal process, court order, or lawful governmental request, or when reasonably necessary to detect, prevent, investigate, or respond to fraud, abuse, security incidents, threats, unlawful activity, or violations of applicable agreements or policies.
Information may also be transferred in connection with a merger, acquisition, financing, reorganization, sale of assets, bankruptcy, or similar corporate transaction, subject to applicable legal requirements and appropriate privacy protections.
8. Information We Do Not Sell or Use for Advertising
ClinicianCore does not sell PHI, Customer Data, or consumer health data.
ClinicianCore does not use PHI for advertising or targeted marketing. ClinicianCore does not rent PHI to third parties.
Information obtained through public websites or voluntary business communications may be used for legitimate business, marketing, communications, analytics, and service-improvement purposes where permitted by applicable law.
ClinicianCore does not use PHI obtained through authenticated healthcare Services to create advertising profiles or to provide targeted advertising.
9. Artificial Intelligence and Automated Technologies
ClinicianCore may provide artificial intelligence (“AI”), machine learning, automation, or other technology-assisted functionality as part of certain Services. Depending on the applicable feature, such functionality may support documentation, summarization, communication routing, workflow assistance, operational insights, security monitoring, or other functions described in the applicable Service.
When an AI-enabled feature is used, information may be processed as reasonably necessary to provide the requested functionality. The information processed may include information submitted by users or generated through use of the applicable Service.
Where information processed by an AI-enabled feature constitutes PHI, its processing is subject to applicable law, contractual requirements, the applicable BAA where applicable, and the configuration and intended use of the Service.
ClinicianCore does not represent that every AI-enabled feature processes information in the same manner. AI processing, retention, security controls, and third-party involvement may vary depending on the specific feature, technology environment, and applicable Service.
ClinicianCore does not use Customer Data or PHI to train general-purpose AI models except where expressly authorized by an applicable agreement or otherwise permitted by applicable law.
ClinicianCore may use third-party technology providers in connection with AI-enabled functionality. Where such providers process regulated information on behalf of ClinicianCore or a healthcare organization, ClinicianCore applies appropriate contractual and organizational requirements consistent with applicable law.
AI-generated or automated outputs are intended to support, and not replace, professional judgment. Healthcare professionals and healthcare organizations remain responsible for reviewing and appropriately using such outputs.
10. Cookies and Website Technologies
ClinicianCore uses cookies and similar technologies on its public websites to provide website functionality, remember preferences, understand website usage, measure performance, support security, and analyze general website traffic.
ClinicianCore may use third-party analytics services, including Google Analytics, on its public websites. Such services may collect information concerning browser characteristics, device information, pages viewed, referral information, and general website interactions.
Public website analytics are separate from authenticated clinical communications and are not intended to collect PHI submitted through ClinicianCore clinical Services.
You may manage available cookie preferences through applicable website controls and your browser settings. Where applicable law requires consent for particular cookies or similar technologies, ClinicianCore will provide appropriate controls.
11. Consumer Health Data
Certain information processed through the Services may constitute consumer health data under applicable state law. Depending on the circumstances and applicable law, this may include information relating to an individual’s health condition, diagnosis, treatment, medical history, medications, symptoms, healthcare services, or other information falling within an applicable statutory definition.
ClinicianCore may collect and process consumer health data to provide requested Services, support authorized healthcare workflows, maintain account and Service functionality, provide customer support, maintain security, prevent fraud and misuse, fulfill contractual obligations, and comply with applicable law.
ClinicianCore does not sell consumer health data.
Where consumer health data is processed on behalf of a healthcare organization, the applicable organization may be responsible for determining the lawful basis for processing and responding to certain individual requests.
12. Data Retention
ClinicianCore retains information according to the nature and purpose of the applicable Service, the type of information involved, organizational and contractual requirements, applicable legal and regulatory requirements, security and audit requirements, and legitimate operational requirements.
Retention practices may therefore differ among Services, information types, customers, and configurations. ClinicianCore does not represent that all information is retained for the same period across the platform.
Where a healthcare organization has established applicable contractual, regulatory, or organizational retention requirements, those requirements may govern the retention of information processed on its behalf.
ClinicianCore may retain certain information for security, audit, legal, regulatory, contractual, or operational purposes after the underlying Service or account has been discontinued, to the extent permitted or required by applicable law or agreement.
13. Data Deletion
Where deletion functionality is available, authorized users or customers may delete eligible information subject to applicable permissions, Service functionality, organizational requirements, contractual obligations, legal requirements, regulatory requirements, security requirements, audit requirements, and legal holds.
Deletion from an active production environment does not necessarily result in immediate physical deletion from all backup or disaster-recovery systems. Information may remain in such systems for a limited period in accordance with applicable backup, disaster-recovery, security, and operational procedures.
Where information is required to be retained, ClinicianCore will retain it only for the period and purpose permitted or required by applicable law, agreement, security requirements, or legitimate operational needs.
14. Security
ClinicianCore maintains administrative, technical, and organizational safeguards designed to protect information against unauthorized access, use, disclosure, alteration, or loss.
Depending on the applicable Service, functionality, technology environment, and intended use, such safeguards may include encryption, authentication measures, access management and authorization controls, multi-factor authentication, monitoring, audit and accountability capabilities, and other appropriate security controls.
ClinicianCore uses encryption and other security measures designed to protect information during transmission and while stored. ClinicianCore uses access-management and authorization controls designed to restrict access based on applicable user roles, permissions, and organizational requirements. ClinicianCore supports multi-factor authentication as an additional security measure designed to help protect accounts against unauthorized access.
ClinicianCore also incorporates audit and accountability capabilities designed to support security, operational oversight, and applicable compliance requirements. The nature and retention of audit information may vary based on the applicable Service, security requirements, and organizational policies.
The specific security measures applicable to a particular Service may vary depending on the Service, functionality, technology environment, information processed, organizational configuration, and intended use.
ClinicianCore regularly evaluates its security practices as the platform, technology environment, and applicable requirements evolve. No method of transmission, storage, or electronic security can be guaranteed to be completely secure.
15. Shared Responsibility
Security and privacy are shared responsibilities between ClinicianCore and the organizations and users that use the Services.
ClinicianCore provides technology, safeguards, and administrative capabilities designed to support secure healthcare communication and applicable privacy and security requirements. Customers remain responsible for their use and configuration of the Services, including authorization of users, assignment of roles and permissions, management of devices and credentials, establishment of internal policies and procedures, and compliance with laws and regulations applicable to their operations.
Use of ClinicianCore does not, by itself, constitute or guarantee compliance with HIPAA, state privacy laws, or any other applicable law or regulation.
16. Security Incidents and Breach Notification
ClinicianCore maintains processes designed to identify, investigate, contain, mitigate, and respond to security incidents.
Where ClinicianCore determines that an incident results in notification obligations under applicable law or contractual requirements, ClinicianCore will provide notice consistent with those requirements.
Where ClinicianCore acts as a Business Associate, security incident and breach notification obligations are governed by applicable HIPAA requirements, the applicable BAA, and applicable law.
17. Individual Privacy Rights
Depending on your location, your relationship with ClinicianCore, and applicable law, you may have rights concerning personal information processed by ClinicianCore. These rights may include the right to request access to, correction of, or deletion of applicable personal information, as well as other rights provided by applicable law.
Certain rights may be subject to legal exceptions, limitations, verification requirements, contractual arrangements, or other applicable restrictions.
Where ClinicianCore processes PHI on behalf of a healthcare organization, the organization may be responsible for responding to requests relating to individual rights under HIPAA. ClinicianCore may assist the organization as required by the applicable BAA and law.
Where information is maintained by ClinicianCore solely on behalf of a healthcare organization, individuals may be directed to that organization to exercise applicable rights.
18. California Privacy Rights
If California privacy law applies to you, you may have additional rights concerning your personal information, including rights to know, access, correct, delete, or obtain information concerning the categories and purposes of processing, and other rights provided under applicable California privacy law.
Where applicable, California residents may also have rights concerning the sale or sharing of personal information, certain uses of sensitive personal information, and appeals of certain privacy-request decisions.
ClinicianCore does not sell PHI or consumer health data.
To exercise applicable California privacy rights, contact ClinicianCore using the contact information provided below. ClinicianCore may require information reasonably necessary to verify your identity and authority to make a request. Where permitted by applicable law, an authorized agent may submit a request on your behalf, subject to applicable verification and authorization requirements.
ClinicianCore will not discriminate against an individual for exercising a privacy right to the extent prohibited by applicable law.
19. SMS and Text Messaging
If you voluntarily provide a telephone number and opt in to receive SMS or text messages from ClinicianCore, ClinicianCore may process your telephone number, messaging preferences, consent information, and information necessary to provide the requested communications.
SMS communications may include authentication messages, account notifications, security alerts, service notifications, and other transactional communications.
ClinicianCore does not sell telephone numbers or SMS-related information.
You may opt out of applicable SMS communications by replying STOP to the applicable message. Additional terms governing SMS communications are provided in the ClinicianCore SMS/Text Messaging Terms and Conditions.
20. Children’s Privacy
The Services are intended for healthcare professionals, healthcare organizations, and authorized users and are not directed to children.
ClinicianCore does not knowingly collect personal information directly from children for independent use of the Services. If you believe that a child has provided personal information to ClinicianCore inappropriately, please contact us using the information below.
21. Third-Party Websites and Services
The Services or public websites may contain links to third-party websites, applications, or services. Third parties may maintain their own privacy policies and practices, and ClinicianCore is not responsible for the privacy or security practices of third-party services outside our control.
Users should review the applicable privacy notices and terms of third-party services before providing information to those services.
22. International Processing and Data Location
ClinicianCore primarily serves healthcare organizations operating in the United States. Information may be processed by ClinicianCore and authorized service providers in locations where infrastructure or operational services are provided.
Where applicable law imposes requirements concerning international data transfers, data location, or international processing, ClinicianCore will implement appropriate safeguards consistent with those requirements.
23. Changes to This Privacy Policy
ClinicianCore may update this Privacy Policy from time to time to reflect changes to the Services, our information practices, security practices, technology, legal or regulatory requirements, or business operations.
When material changes are made, ClinicianCore will update the “Last Updated” date and provide additional notice where required by applicable law.
24. Contact Us
Questions, privacy requests, complaints, or other inquiries concerning this Privacy Policy may be submitted to:
Healthcare Provider Network, Inc.
5150 Mae Anne Ave., Suite 405
Reno, NV 89523
United States
Privacy: privacy@cliniciancore.com
Security: security@cliniciancore.com
Compliance: compliance@cliniciancore.com
Phone: 775-208-0990
When submitting a privacy request, please provide sufficient information for ClinicianCore to identify and evaluate the request. ClinicianCore may request additional information where reasonably necessary to verify identity or authority.
25. Relationship to Other Agreements and Policies
This Privacy Policy should be read together with ClinicianCore’s applicable Terms of Use, Security & Compliance documentation, SMS/Text Messaging Terms and Conditions, customer agreements, BAAs, and other applicable contractual or product-specific documentation.
Where a written customer agreement or BAA establishes specific requirements concerning PHI, data processing, security, retention, deletion, or related matters, those contractual requirements will govern to the extent applicable.
ClinicianCore’s Security & Compliance documentation is the authoritative source for descriptions of ClinicianCore’s security architecture, security controls, and security practices. Nothing in this Privacy Policy is intended to expand, modify, or create security commitments beyond those described in the applicable Security & Compliance documentation, customer agreement, BAA, or other applicable contractual terms.
Where security practices, technical capabilities, or descriptions change, ClinicianCore may update this Privacy Policy and related documentation to maintain consistency with the Services as actually provided.