AHI Logo
Products
Healthcare Intelligence
HAL
The Healthcare Intelligence
HALi
Healthcare guidance for families
Revenue Intelligence
MDMai
Revenue optimization — free
CODEai
Billing intelligence
Documentation
ENCOUNTERai
AI-generated encounter notes
REFERRALai
Referral processing
HAL Alert Network
HAL Alerts
Infectious disease intelligence
HALi Alerts
For your family
Vision
ACI + HAL CHI
The future of Healthcare Intelligence
ProductsHow It WorksAboutSecurityPricing
For Providers
HAL
MDMai
ENCOUNTERai
CODEai
REFERRALai
For Patients & Families
HALi
Log in
Get Started

Effective Date: September 5, 2026

Privacy Policy

1. Who We Are This Privacy Policy describes how HALai, Inc. ("HALai," "we," "us," or "our"), a wholly-owned subsidiary of Artificial Healthcare Intelligence, Inc., a Delaware 501(c)(3) non-profit organization ("AHI"), collects, uses, and shares information about you when you visit our websites at www.halai.ai, www.artificialhealthcareintelligence.com, and mdm.halai.ai (the "Sites") and when you use our Healthcare Intelligence products and services, including HAL, MDMai, ENCOUNTERai, CODEai, REFERRALai, HALi, and HAL Alerts (collectively, the "Services"). This Policy applies to information we collect from (a) website visitors, (b) licensed healthcare providers who register for the Services, and (c) patients or family members who use the HALi consumer application. If you are a licensed healthcare provider using the Services in your professional capacity, additional terms apply under our Healthcare Provider User Agreement, which includes a HIPAA Business Associate Agreement. 2. Information We Collect Information you provide. Account registration details (name, email, National Provider Identifier, practice affiliation, billing address), payment information you submit to our payment processor, communications you send us, content you upload to the Services (including clinical encounter notes, referral documents, uploaded images or audio), and voice audio you dictate when you use voice features. Information collected automatically. IP address, device identifiers, browser type, operating system, referring URL, pages viewed, timestamps, and interaction events, collected using cookies, local storage, server logs, and similar technologies. Information from third parties. Authentication data from Auth0 when you sign in; payment confirmation and card metadata (never the full card number) from Stripe; and public NPI registry information used to verify your provider status. Protected Health Information ("PHI"). When a healthcare provider uses the Services to process, store, or transmit information about a patient, that PHI is handled under HIPAA and the Business Associate Agreement executed with the provider. Individuals whose PHI is processed through the Services should direct privacy requests, including requests to access or amend PHI, to their healthcare provider, who is the HIPAA Covered Entity. 3. How We Use Information We use the information described above to: (a) provide, operate, secure, and improve the Services; (b) authenticate users and prevent fraud and abuse; (c) process payments and issue receipts; (d) communicate with you about your account, security, and service changes; (e) send you product announcements and educational content (which you can unsubscribe from at any time); (f) generate analytics and reports for you about your own practice; (g) comply with legal obligations; and (h) enforce our agreements. AI model training. We do not use PHI or your identifiable clinical content to train general-purpose AI models, and we do not use your data to train models that serve any other customer. The ENCOUNTERai documentation product creates a personalized model that is trained exclusively on the individual provider's own notes and used exclusively to serve that provider; that model is tenant-isolated and is not shared or reused across accounts. We do not sell your information and we do not use PHI for advertising or marketing. 4. How We Share Information We share information with the following categories of recipients, and only as described here: Service providers (subprocessors). We use the following subprocessors to operate the Services: - Microsoft Azure (United States) — cloud hosting, storage, database, and network infrastructure. Covered by a HIPAA Business Associate Agreement with Microsoft. - OpenAI, L.L.C. (United States) — large-language-model and realtime voice inference. Covered by a HIPAA Business Associate Agreement with zero data retention on the endpoints we use. - Anthropic, PBC (United States) — large-language-model inference. Covered by a HIPAA Business Associate Agreement with zero data retention on the endpoints we use. - Auth0 by Okta, Inc. (United States) — identity and authentication. Auth0 processes account credentials and profile metadata (name, email) and does not receive Protected Health Information. - Stripe, Inc. (United States) — payment processing. Stripe receives billing contact details and payment card information and does not receive Protected Health Information. Covered by a data processing agreement. We will update this list before adding any new subprocessor that processes PHI. A current list is maintained at halai.ai/subprocessors. Legal and safety. We may disclose information to comply with a subpoena, court order, or other legal obligation; to enforce our terms; to detect and prevent fraud, abuse, or security incidents; or to protect the rights, property, or safety of any person. Business transfers. If HALai is involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction, subject to standard confidentiality protections and a requirement that the recipient honor this Policy. With your direction. When you direct us to share information — for example, when a provider chooses to share a referral or export data — we do so at your instruction. We do not sell your personal information and we do not share it for cross-context behavioral advertising. 5. Data Retention We retain information for the periods below, and longer where required by law or reasonably necessary for tax, accounting, audit, dispute resolution, or fraud-prevention purposes. When retention ends, we delete or de-identify the information. - Account records (name, email, NPI, practice affiliation): life of account plus 7 years. - Billing records (invoices, payment metadata): 7 years from the transaction. - Content you upload (clinical notes, referrals, documents): retained per your account and returned or destroyed in accordance with the BAA on termination. - AI prompts and outputs generated in your account: retained per your account; not used to train models that serve other customers. - Voice audio submitted to realtime features: not persisted by us beyond the duration of the session, unless you save it as part of a note; then treated as Content. - Server logs, security logs, telemetry: 12 months, then aggregated or deleted. - Cookies and similar identifiers: per the retention set for each cookie, up to 24 months. - Support communications: 3 years from close of the ticket. - PHI processed on behalf of a Covered Entity: retained, returned, or destroyed in accordance with the Business Associate Agreement and the direction of the Covered Entity. You may request deletion of your account and associated non-PHI information at any time by writing to privacy@halai.ai. PHI retained on behalf of a Covered Entity is deleted only at the direction of the Covered Entity. 6. Security We host the Services on Microsoft Azure's HIPAA-eligible infrastructure. Safeguards include AES-256 encryption at rest, TLS 1.2 or higher in transit, tenant-isolated data containers, private-network isolation, role-based access controls, multi-factor authentication for administrative access, continuous security logging and monitoring, and regular vulnerability and penetration testing. No system is perfectly secure. If we become aware of a security incident affecting your personal information, we will notify you as required by law and, where the incident involves PHI, in accordance with the Business Associate Agreement and HIPAA Breach Notification Rule. 7. Your Privacy Rights HIPAA (patients). If you are an individual whose PHI is processed through the Services on behalf of a healthcare provider, HIPAA gives you rights to access, amend, and receive an accounting of certain disclosures of your PHI. Direct those requests to your healthcare provider. California residents (CCPA/CPRA). If you are a California resident, subject to certain exceptions you have the right to (a) know what personal information we collect, use, and disclose about you; (b) request a copy of your personal information; (c) request correction of inaccurate personal information; (d) request deletion of your personal information; (e) opt out of the sale or sharing of personal information (we do not sell or share personal information); and (f) limit the use of sensitive personal information (we do not use sensitive personal information for purposes that trigger this right). We will not discriminate against you for exercising these rights. To exercise a right, email privacy@halai.ai. You may authorize an agent to act on your behalf, subject to verification. PHI held under HIPAA is exempt from the CCPA and must be requested through your Covered Entity. Other U.S. state privacy laws. Residents of other states with comprehensive privacy laws (including Colorado, Connecticut, Utah, Virginia, Oregon, Texas, and others as enacted) have substantially similar rights and may exercise them by writing to privacy@halai.ai. Consumer health data laws (Washington, Nevada, Connecticut). If you are a resident of Washington (My Health My Data Act), Nevada (SB 370), Connecticut (as amended), or any other state with a consumer health data law, and you provide health information to us as a consumer (for example, through HALi), you have additional rights, which include: the right to confirm whether we collect, share, or sell your consumer health data; the right to withdraw consent to our collection and sharing of consumer health data; the right to have your consumer health data deleted; and the right to appeal a denial of any of these rights. We do not sell consumer health data. We will obtain your affirmative consent before collecting or sharing consumer health data beyond what is necessary to provide the Services you have requested. Full details are in our separate Consumer Health Data Privacy Policy at halai.ai/consumer-health-data. To exercise these rights, email privacy@halai.ai. Communications. You can opt out of marketing emails at any time using the unsubscribe link. Transactional and security communications are required and cannot be opted out of while your account is active. 8. Cookies and Tracking We use cookies and similar technologies to keep you signed in, remember your preferences, secure the Services, measure how the Services are used, and improve them. We do not use cookies for cross-context behavioral advertising. Your browser lets you block or delete cookies; parts of the Services may not function correctly if you do so. We honor Global Privacy Control signals as an opt-out preference for California residents. 9. Children The Services are not directed to children under 13, and we do not knowingly collect personal information from a child under 13. The HALi patient application is intended for use by adults or by minors under the supervision of a parent or legal guardian, and the account holder must be at least 18. If you believe a child under 13 has provided us with personal information, contact privacy@halai.ai and we will delete it. 10. International Users The Services are operated in the United States and are intended for users located in the United States. If you access the Services from outside the United States, you understand that your information will be transferred to and processed in the United States, which may have different data-protection laws than your jurisdiction. We do not target the Services to residents of the European Union, the United Kingdom, or Switzerland. 11. Third-Party Sites and Services The Services may contain links to third-party websites or integrate with third-party services (for example, EHR integrations you elect to enable). Those third parties are governed by their own privacy policies, which we do not control and are not responsible for. Review their policies before using them. 12. Changes to this Policy We may update this Policy from time to time. We will post the updated Policy on this page with a new Effective Date. If the changes are material, we will provide additional notice (for example, by email or an in-product notice) before they take effect. Your continued use of the Services after the Effective Date of a change constitutes acceptance of the updated Policy. 13. Contact Us HALai, Inc. Attn: Privacy Officer privacy@halai.ai info@halai.ai For HIPAA-related requests concerning PHI processed on behalf of a healthcare provider, contact your provider directly. For all other privacy inquiries, contact us at the addresses above.

Related: Consumer Health Data Privacy Policy · Terms of Use · Healthcare Provider User Agreement · HALi User Agreement · Security & Compliance

Products

HALHALiMDMaiENCOUNTERaiCODEaiREFERRALai

Platform

How It WorksSecurityPricingHAL Alerts

Company

AboutWhitepapersAHI VisionInvest in AHIContactInvest in AHI

Legal

Privacy PolicyTerms of UseProvider AgreementBAA
© 2026 Artificial Healthcare Intelligence, Inc. All rights reserved.