Client Portal Privacy Notice

Last Updated: [6/22/26]

This Privacy Notice (“Notice”) explains how Jorie AI (“we,” “us,” “our”) collects, uses, discloses, and protects personal information—including Protected Health Information (“PHI”) where applicable—processed through the Jorie AI Client Portal (“Portal”).

This Notice applies only to information processed through the Portal and should be read together with your organization’s service agreement and, where applicable, the Business Associate Agreement (“BAA”).

By using the Portal, you acknowledge and agree to the practices described in this Notice.

 

1. Information We Collect

We may collect the following categories of information when you use the Portal:

1.1 Protected Health Information (PHI)

If your organization is a HIPAAcovered entity or provides PHI to Jorie AI under a BAA, the Portal may process PHI such as:

Patient identifiers (e.g., name, ID numbers)

Clinical, operational, or administrative data

Documents or files containing PHI uploaded or shared through the Portal

We do not collect PHI directly from individuals; all PHI is provided by your organization.

1.2 Personal Information (NonPHI)

Name

Email address

Organization affiliation

Login credentials (hashed and encrypted)

1.3 Usage & Activity Information

Pages accessed

Files viewed or downloaded

User actions within the Portal

Timestamps and session activity

Device, browser, and IP information

1.4 Communications & Submissions

Support requests

Comments or feedback

Uploaded documents or information

 

2. How We Use Information

We use personal information and PHI solely to:

Provide secure access to Portal features and resources

Support your organization’s operational, analytical, or clinical workflows

Maintain and improve Portal performance and security

Respond to support requests and client inquiries

Monitor for security, compliance, and misuse

Fulfill obligations under your organization’s service agreement and, if applicable, the BAA

We do not sell personal information or PHI, and we do not use Portal data for advertising or unrelated purposes.

 

3. How We Disclose Information

We may disclose information only as permitted under applicable law, your service agreement, and—if PHI is involved—your BAA.

3.1 Permitted Disclosures

To your organization, for operational or administrative purposes

To authorized Jorie AI personnel, solely for support, security, or service delivery

To subcontractors, only if they are bound by confidentiality and, where applicable, HIPAAcompliant agreements

As required by law, such as in response to a court order or regulatory request

To address security threats or prevent harm, consistent with legal allowances

We do not disclose PHI or personal information to third parties for independent use.

 

4. Data Security

We implement administrative, technical, and physical safeguards designed to protect personal information and PHI, including:

Encryption in transit and at rest

Access controls and authentication measures

Audit logging and activity monitoring

Secure hosting environments

Workforce training and access restrictions

These safeguards are designed to meet HIPAA Security Rule requirements where PHI is involved.

 

5. Data Retention and Destruction

We retain Portalrelated information only as long as necessary to:

Provide Portal access

Support your organization’s engagement

Meet legal, contractual, or operational requirements

Upon termination of your organization’s service agreement or BAA, PHI and other data will be returned or securely destroyed in accordance with contractual and regulatory obligations.

 

6. Your Responsibilities

Your organization and its authorized users must:

Maintain the confidentiality of login credentials

Use secure devices and networks

Avoid uploading unnecessary personal information or PHI

Ensure that any PHI shared through the Portal is permitted under the BAA

Report suspected security incidents promptly

Your organization is responsible for managing user access and ensuring compliance with internal policies and applicable laws.

 

7. Individual Rights (HIPAA Context)

If PHI is involved, requests related to HIPAA individual rights (e.g., access, amendment, accounting of disclosures) must be directed to your organization.

Jorie AI will assist your organization as required under the BAA.

 

8. Children’s Privacy

The Portal is not intended for use by individuals under the age of 18. We do not knowingly collect information from minors.

 

9. Changes to This Privacy Notice

We may update this Notice from time to time. Continued use of the Portal after changes are posted constitutes acceptance of the updated Notice.

 

10. Contact

For questions about this Privacy Notice or how your information is handled, contact:

compliancesupport@joriehc.com