Privacy Policy

Last Updated: 29th October 2025

ClinicianCore Privacy Policy for Providers and Clinical Teams 

ClinicianCore is a platform owned and operated by Healthcare Provider Network, Inc. (“Healthcare Provider Network,” “ClinicianCore,” “we,” “us,” or “our”).

This Privacy Policy explains how ClinicianCore collects, uses, protects, retains, and discloses information when you visit our websites, create or use an account, use our services, or otherwise interact with ClinicianCore.

ClinicianCore is designed primarily for healthcare professionals, healthcare organizations, and authorized members of clinical, administrative, and professional teams.

ClinicianCore does not provide medical care, diagnosis, treatment, telehealth services, medical advice, medical coding, or medical billing.

  1. Our Privacy Commitment

ClinicianCore is committed to protecting the privacy, security, and confidentiality of information entrusted to us.

We seek to collect, use, retain, and process information only for legitimate and appropriate purposes related to providing, securing, supporting, and improving our services and meeting applicable legal and contractual obligations.

Where ClinicianCore processes Protected Health Information (“PHI”) on behalf of a healthcare organization, ClinicianCore does so in accordance with applicable law and the terms of the applicable contractual relationship, including a Business Associate Agreement (“BAA”) where required.

  1. Information We May Collect

The information we collect depends on how you interact with ClinicianCore and which services or features you use.

Account and Professional Information

We may collect:

  • Name
  • Professional title or role
  • Healthcare organization or affiliation
  • Specialty or professional information
  • Email address
  • Telephone or mobile number
  • Account credentials and authentication information
  • User preferences
  • Account and authorization information

Communication and Service Information

When you use ClinicianCore services, we may process information submitted or generated through those services, which may include:

  • Messages and communications
  • Notes and documentation
  • Files or attachments
  • Voice or video-related information, where applicable
  • Information provided by authorized users
  • Communication metadata
  • Dates, times, participants, and routing information
  • Other information necessary to provide requested functionality

Where such information constitutes PHI, it is handled in accordance with applicable HIPAA requirements and applicable contractual arrangements.

Technical and Security Information

We may collect technical information necessary to operate, maintain, secure, troubleshoot, and improve our services, including:

  • IP address
  • Device type
  • Operating system
  • Browser or application information
  • Application version
  • Login and authentication events
  • Session information
  • Security events
  • Diagnostic and error information
  • Platform usage information
  • Audit and accountability information

Website Information

When you visit our public website, we may collect information such as:

  • Pages viewed
  • General website interaction information
  • Browser and device information
  • Referral information
  • Cookie and preference information
  • Analytics information

Website information is handled separately from information submitted through authenticated ClinicianCore services, where appropriate.

  1. Sources of Information

We may collect information from:

  • You directly
  • Your healthcare organization or authorized administrator
  • Other authorized users
  • Your use of ClinicianCore services
  • Devices and applications used to access our services
  • Our public websites
  • Service providers that support our operations
  • Security, fraud-prevention, or authentication services
  • Publicly available professional information, where appropriate

We seek to limit collection to information reasonably necessary for the applicable purpose.

  1. How We Use Information

We may use information to:

  • Provide and operate ClinicianCore services
  • Create and manage accounts
  • Authenticate users
  • Facilitate authorized communication and collaboration
  • Support requested workflows and functionality
  • Maintain service availability, performance, and reliability
  • Provide customer and technical support
  • Detect, prevent, and investigate security incidents, fraud, misuse, and unauthorized access
  • Maintain auditability and accountability
  • Troubleshoot and resolve technical problems
  • Improve the functionality, reliability, security, and usability of our services
  • Meet contractual obligations
  • Comply with applicable laws, regulations, and lawful requests
  • Protect the rights, safety, and security of ClinicianCore, our users, healthcare organizations, and others
  • Maintain appropriate business and operational records
  • Perform other purposes permitted by applicable law

We do not use information for purposes incompatible with the purpose for which it was collected without appropriate authorization or another lawful basis.

  1. Protected Health Information and HIPAA

ClinicianCore is designed to support healthcare organizations subject to HIPAA and other applicable healthcare privacy and security requirements.

Where ClinicianCore acts as a Business Associate, PHI is processed according to applicable law and the applicable contractual relationship, including a BAA where required.

ClinicianCore does not independently determine the healthcare organization’s HIPAA obligations.

Healthcare organizations remain responsible for their own privacy practices, policies, procedures, workforce practices, access controls, risk management, and regulatory compliance.

Use of ClinicianCore does not, by itself, make an organization compliant with HIPAA or any other law or regulation.

ClinicianCore is not a HIPAA Notice of Privacy Practices for a healthcare organization. Covered entities remain responsible for their own Notices of Privacy Practices and applicable individual-rights obligations.

Where ClinicianCore processes PHI on behalf of a covered entity, certain privacy requests may need to be directed through that healthcare organization.

  1. How We Share Information

ClinicianCore does not sell personal information or PHI.

Information may be disclosed or made available when reasonably necessary for legitimate and authorized purposes, including:

Healthcare Organizations and Authorized Users

Information may be made available to the healthcare organization, administrators, or authorized users associated with an account, consistent with applicable permissions, agreements, and law.

Service Providers and Subprocessors

ClinicianCore may use trusted third-party providers to support services such as:

  • Cloud infrastructure
  • Data storage
  • Authentication
  • Security
  • Monitoring
  • Communications
  • Technical support
  • Analytics
  • Application performance
  • Other essential business and technology functions

Where applicable, contractual safeguards are used to address the handling of PHI and other regulated information.

Legal and Regulatory Requirements

Information may be disclosed when required or authorized by applicable law, regulation, legal process, court order, or lawful governmental request.

Security and Protection

Information may be disclosed when reasonably necessary to detect, prevent, investigate, or respond to fraud, abuse, security incidents, threats, or unlawful activity.

Corporate Transactions

Information may be transferred as part of a merger, acquisition, financing, reorganization, sale of assets, bankruptcy, or similar transaction, subject to applicable legal requirements and appropriate privacy protections.

  1. Information We Do Not Sell

ClinicianCore does not sell personal information, PHI, or consumer health data.

We do not rent or otherwise monetize PHI for purposes unrelated to providing our services.

We do not use PHI for targeted advertising.

Where applicable law imposes additional restrictions on the sale or sharing of personal information or consumer health data, ClinicianCore will comply with those requirements.

  1. Advertising and Marketing

ClinicianCore does not use PHI for advertising or targeted marketing.

We may use general website information, contact information, or other non-clinical information for legitimate business communications, service announcements, educational communications, or marketing activities where permitted by applicable law.

Users may have choices regarding certain marketing communications.

Transactional, security, account, and service-related communications may continue when necessary to operate or protect an account.

  1. Cookies and Analytics

ClinicianCore uses cookies and similar technologies on its public websites.

These technologies may be used to:

  • Provide essential website functionality
  • Remember preferences
  • Understand website usage
  • Measure website performance
  • Improve user experience
  • Support website security
  • Analyze general website traffic

ClinicianCore may use third-party analytics services, including Google Analytics, on its public website.

Third-party analytics technologies may collect information such as browser characteristics, device information, pages viewed, and general website interaction information.

Website analytics are separate from authenticated clinical communications and are not intended to collect PHI submitted through ClinicianCore clinical services.

ClinicianCore does not knowingly direct third-party website analytics providers to collect PHI through the ClinicianCore website.

Users may manage cookies through available website controls and browser settings.

Where applicable law requires consent for certain cookies or tracking technologies, ClinicianCore will provide appropriate controls.

Third-Party Cross-Site Collection

ClinicianCore does not intentionally authorize third parties to collect consumer health data through ClinicianCore’s public website for the purpose of tracking an individual over time and across different websites or online services.

Third-party website technologies may collect general website usage information as described above. Such technologies are not intended to collect PHI from authenticated ClinicianCore clinical services.

  1. Consumer Health Data

Where applicable law defines information processed by ClinicianCore as consumer health data, ClinicianCore will handle that information in accordance with applicable requirements.

Depending on applicable law and circumstances, consumer health data may include information relating to an individual’s health condition, diagnosis, treatment, medical history, medications, symptoms, healthcare services, or other information defined by law.

Categories of Consumer Health Data

Depending on the applicable service and circumstances, consumer health data may include:

  • Health or medical information
  • Information concerning healthcare services
  • Information concerning diagnoses, symptoms, or treatment
  • Information concerning medications or medical history
  • Other information defined as consumer health data under applicable law

Sources

Consumer health data may be obtained from:

  • Individuals
  • Authorized healthcare organizations
  • Authorized users
  • Use of ClinicianCore services
  • Devices or applications used to access services
  • Other authorized sources

Purposes

Consumer health data may be processed to:

  • Provide requested services
  • Support authorized healthcare workflows
  • Maintain account and service functionality
  • Provide security and fraud prevention
  • Provide customer support
  • Meet legal and contractual obligations
  • Maintain and improve service reliability and functionality

Categories of Consumer Health Data Shared

Where permitted by applicable law, consumer health data may be shared only as appropriate for the applicable purpose, including with:

  • Healthcare organizations
  • Authorized users
  • Service providers
  • Subprocessors
  • Other parties where required or permitted by applicable law or contractual obligations

ClinicianCore does not sell consumer health data.

Processing

Consumer health data may be processed through ClinicianCore’s technology infrastructure and authorized service providers as necessary to provide requested functionality, maintain security, support operations, fulfill contractual obligations, and comply with applicable law.

Requests and Review

Where applicable law provides rights concerning consumer health data, individuals may submit requests regarding their information using the process described in the Privacy Requests and Appeals section below.

Depending on the circumstances, requests concerning information maintained on behalf of a healthcare organization may need to be directed to that organization.

Changes

When material changes are made to this Privacy Policy, ClinicianCore will update the policy and provide additional notice where required by applicable law.

Cross-Site Collection

ClinicianCore does not intentionally authorize third parties to collect consumer health data through the ClinicianCore public website over time and across different Internet websites or online services.

Third-party website analytics may collect general website usage information as described in the Cookies and Analytics section.

  1. AI and Automated Technologies

ClinicianCore may offer AI-assisted or automated functionality as part of its services.

Where such functionality is used, information may be processed as necessary to provide the requested feature, subject to applicable law, contractual requirements, and the organization’s configuration and use of the service.

AI or automated functionality does not change ClinicianCore’s obligations concerning applicable privacy, security, confidentiality, or data-protection requirements.

Organizations remain responsible for determining whether and how particular AI-enabled functionality may be used within their own policies, clinical workflows, and compliance programs.

Additional information regarding a specific AI-enabled feature may be provided in applicable product documentation, agreements, or notices.

  1. Data Retention

ClinicianCore manages retention according to the purpose of the applicable service, the nature of the information, organizational requirements, contractual obligations, and applicable legal, regulatory, security, and operational considerations.

Retention periods may differ depending on the type of information, service, functionality, and applicable requirements.

We do not retain information longer than reasonably necessary for the applicable purpose, except where longer retention is required or permitted by law, contract, security requirements, legal holds, audit obligations, or other legitimate recordkeeping requirements.

Specific retention and deletion practices may be governed by applicable customer agreements, data-processing terms, BAAs, service documentation, or other applicable policies.

  1. Data Deletion

Where deletion functionality is available, authorized users or organizations may request or perform deletion of eligible information subject to applicable permissions and service functionality.

Deletion requests may be subject to:

  • Legal requirements
  • Regulatory requirements
  • Contractual obligations
  • Security requirements
  • Audit requirements
  • Legal holds
  • Recordkeeping requirements
  • Backup and disaster-recovery processes

Deletion from an active system does not necessarily mean immediate physical removal from all backups or disaster-recovery systems.

Where information must be retained, ClinicianCore will retain it only as required or permitted for the applicable purpose.

  1. Access to Information

Users may have access to information through their ClinicianCore account or through their healthcare organization, depending on the service, account configuration, permissions, and applicable law.

Where ClinicianCore processes PHI on behalf of a covered entity, requests relating to HIPAA individual rights may need to be directed to the applicable healthcare organization.

ClinicianCore will provide reasonable assistance to covered entities as required by applicable agreements and law.

  1. Privacy Rights

Depending on your location, applicable law, and your relationship with ClinicianCore, you may have rights concerning your personal information.

These rights may include, where applicable:

  • Requesting access to personal information
  • Requesting correction of inaccurate information
  • Requesting deletion
  • Requesting information about categories of information collected or shared
  • Requesting information about how information is used
  • Exercising applicable rights concerning consumer health data
  • Withdrawing consent where processing is based on consent
  • Requesting information regarding certain disclosures or processing activities
  • Appealing certain decisions where required by applicable law

Some rights may be limited by law or may not apply to information processed on behalf of a healthcare organization.

Where ClinicianCore processes PHI as a Business Associate, the applicable healthcare organization may be responsible for responding to certain HIPAA requests.

  1. Privacy Requests and Appeals

To submit a privacy request, question, or applicable appeal, contact ClinicianCore using the information provided below.

We may need to verify your identity before completing certain requests.

Where a request concerns information maintained on behalf of a healthcare organization, we may direct you to the applicable organization or coordinate with that organization as appropriate.

Where applicable law provides a right to appeal a decision concerning a privacy request, ClinicianCore will provide an appropriate process for submitting that appeal.

  1. Security

ClinicianCore maintains administrative, technical, and organizational safeguards designed to protect information against unauthorized access, use, disclosure, alteration, or loss.

Depending on the applicable service and functionality, safeguards may include:

  • Encryption
  • Authentication controls
  • Role-based access controls
  • Multi-factor authentication
  • Access management
  • Monitoring
  • Audit and accountability controls
  • Vulnerability management
  • Security testing
  • Incident response procedures
  • Backup and recovery controls
  • Administrative and organizational safeguards

Security measures may vary depending on the applicable service, functionality, technology environment, and intended use.

Additional information is available in the ClinicianCore Security & Compliance policy.

  1. Security Incidents and Breaches

ClinicianCore maintains processes designed to identify, investigate, contain, and respond to security incidents.

Where a security incident results in notification obligations under applicable law or contractual requirements, ClinicianCore will provide notifications in accordance with those requirements.

For healthcare organizations covered by HIPAA, applicable breach-notification responsibilities are also governed by the applicable BAA and applicable law.

  1. SMS and Text Messaging

If you voluntarily provide a telephone number and opt in to receive SMS messages from ClinicianCore, we may process your telephone number, messaging preferences, and related information to provide requested communications.

These communications may include:

  • Authentication messages
  • Account notifications
  • Security alerts
  • Service notifications
  • Other transactional communications

SMS information is not sold.

You may opt out of applicable SMS communications by replying STOP to the applicable message.

Additional terms governing SMS communications are provided in the ClinicianCore SMS/Text Messaging Terms and Conditions.

  1. Children’s Privacy

ClinicianCore is intended for healthcare professionals, healthcare organizations, and authorized users.

Our services are not directed to children, and ClinicianCore does not knowingly collect personal information directly from children for independent use of the platform.

If you believe a child has provided personal information to ClinicianCore inappropriately, please contact us.

  1. Third-Party Websites and Services

ClinicianCore may provide links to third-party websites, applications, or services.

Those third parties may have their own privacy policies and practices.

ClinicianCore is not responsible for the privacy, security, or content practices of third-party services that are outside ClinicianCore’s control.

We encourage users to review applicable third-party privacy policies before providing information to those services.

  1. Data Processing by Service Providers

ClinicianCore may engage service providers and subprocessors to provide infrastructure, security, communications, analytics, customer support, and other services necessary to operate the platform.

Where a service provider processes regulated information on ClinicianCore’s behalf, ClinicianCore uses appropriate contractual and organizational safeguards consistent with applicable requirements.

Where required, subcontractors that handle PHI are subject to appropriate contractual obligations concerning the protection of that information.

  1. Data Location and International Processing

ClinicianCore primarily serves healthcare organizations operating in the United States.

Information may be processed by ClinicianCore or authorized service providers in locations where infrastructure or operational services are provided.

Where applicable law imposes requirements concerning data transfers, data location, or international processing, ClinicianCore will implement appropriate safeguards.

  1. Changes to This Privacy Policy

ClinicianCore may update this Privacy Policy from time to time to reflect changes in:

  • Services
  • Data practices
  • Security practices
  • Technology
  • Legal or regulatory requirements
  • Business operations

When material changes are made, ClinicianCore will update this Privacy Policy and provide additional notice where required by applicable law.

The effective date of this Privacy Policy is the date identified at the beginning of the policy.

  1. Contact Us

For questions, privacy requests, or concerns regarding this Privacy Policy, contact:

Healthcare Provider Network, Inc.
ClinicianCore
5150 Mae Anne Ave., Suite 405
Reno, NV 89523
United States

Phone: 775-208-0990
Email: privacy@cliniciancore.com

For security-related concerns:

Email: security@cliniciancore.com

For compliance-related matters:

Email: compliance@cliniciancore.com

  1. Platform Scope and Responsibility

ClinicianCore provides secure technology infrastructure designed to support healthcare communication, collaboration, and operational workflows.

ClinicianCore does not provide medical care, telehealth services, medical advice, medical coding, or medical billing.

Clinical decisions, patient care, documentation, coding, billing, reimbursement, and compliance with an organization’s own policies remain the responsibility of the applicable licensed healthcare professionals and healthcare organizations.

ClinicianCore provides technology and safeguards designed to support privacy, security, and compliance programs.

Use of ClinicianCore does not, by itself, guarantee compliance with HIPAA or any other law or regulation.

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.