Client Portal Privacy Notice
Last Updated: [6/22/26]
This Privacy Notice (“Notice”) explains how Jorie AI (“we,” “us,” “our”) collects, uses, discloses, and protects personal information—including Protected Health Information (“PHI”) where applicable—processed through the Jorie AI Client Portal (“Portal”).
This Notice applies only to information processed through the Portal and should be read together with your organization’s service agreement and, where applicable, the Business Associate Agreement (“BAA”).
By using the Portal, you acknowledge and agree to the practices described in this Notice.
1. Information We Collect
We may collect the following categories of information when you use the Portal:
1.1 Protected Health Information (PHI)
If your organization is a HIPAA‑covered entity or provides PHI to Jorie AI under a BAA, the Portal may process PHI such as:
• Patient identifiers (e.g., name, ID numbers)
• Clinical, operational, or administrative data
• Documents or files containing PHI uploaded or shared through the Portal
We do not collect PHI directly from individuals; all PHI is provided by your organization.
1.2 Personal Information (Non‑PHI)
• Name
• Email address
• Organization affiliation
• Login credentials (hashed and encrypted)
1.3 Usage & Activity Information
• Pages accessed
• Files viewed or downloaded
• User actions within the Portal
• Timestamps and session activity
• Device, browser, and IP information
1.4 Communications & Submissions
• Support requests
• Comments or feedback
• Uploaded documents or information
2. How We Use Information
We use personal information and PHI solely to:
• Provide secure access to Portal features and resources
• Support your organization’s operational, analytical, or clinical workflows
• Maintain and improve Portal performance and security
• Respond to support requests and client inquiries
• Monitor for security, compliance, and misuse
• Fulfill obligations under your organization’s service agreement and, if applicable, the BAA
We do not sell personal information or PHI, and we do not use Portal data for advertising or unrelated purposes.
3. How We Disclose Information
We may disclose information only as permitted under applicable law, your service agreement, and—if PHI is involved—your BAA.
3.1 Permitted Disclosures
• To your organization, for operational or administrative purposes
• To authorized Jorie AI personnel, solely for support, security, or service delivery
• To subcontractors, only if they are bound by confidentiality and, where applicable, HIPAA‑compliant agreements
• As required by law, such as in response to a court order or regulatory request
• To address security threats or prevent harm, consistent with legal allowances
We do not disclose PHI or personal information to third parties for independent use.
4. Data Security
We implement administrative, technical, and physical safeguards designed to protect personal information and PHI, including:
• Encryption in transit and at rest
• Access controls and authentication measures
• Audit logging and activity monitoring
• Secure hosting environments
• Workforce training and access restrictions
These safeguards are designed to meet HIPAA Security Rule requirements where PHI is involved.
5. Data Retention and Destruction
We retain Portal‑related information only as long as necessary to:
• Provide Portal access
• Support your organization’s engagement
• Meet legal, contractual, or operational requirements
Upon termination of your organization’s service agreement or BAA, PHI and other data will be returned or securely destroyed in accordance with contractual and regulatory obligations.
6. Your Responsibilities
Your organization and its authorized users must:
• Maintain the confidentiality of login credentials
• Use secure devices and networks
• Avoid uploading unnecessary personal information or PHI
• Ensure that any PHI shared through the Portal is permitted under the BAA
• Report suspected security incidents promptly
Your organization is responsible for managing user access and ensuring compliance with internal policies and applicable laws.
7. Individual Rights (HIPAA Context)
If PHI is involved, requests related to HIPAA individual rights (e.g., access, amendment, accounting of disclosures) must be directed to your organization.
Jorie AI will assist your organization as required under the BAA.
8. Children’s Privacy
The Portal is not intended for use by individuals under the age of 18. We do not knowingly collect information from minors.
9. Changes to This Privacy Notice
We may update this Notice from time to time. Continued use of the Portal after changes are posted constitutes acceptance of the updated Notice.
10. Contact
For questions about this Privacy Notice or how your information is handled, contact:
compliancesupport@joriehc.com
