Last Updated: [DATE — TO BE CONFIRMED]
1. Introduction & Scope
Ratna HealthPlex ("we," "us," or "our") provides an AI-powered healthcare management platform used by hospitals, clinics, and healthcare organizations ("Customers") to deliver care to their patients. This Privacy Policy explains how we collect, use, disclose, and safeguard information in connection with our website and platform (collectively, the "Services").
This Privacy Policy applies to visitors of our website, administrators and staff of our Customers, and, where applicable, patients whose information is processed through the Services. Where a Customer (such as a hospital or clinic) is the data controller/fiduciary of patient information, we act as a data processor/data processor on their behalf, and this Policy should be read together with that Customer's own privacy notice.
Our platform is designed to operate in compliance with the U.S. Health Insurance Portability and Accountability Act ("HIPAA") and the Health Information Technology for Economic and Clinical Health Act ("HITECH Act"), consistent with the compliance framework described elsewhere on this site.
2. Information We Collect
We collect the following categories of information in connection with the Services:
- Personal information — name, email address, phone number, job title, organization, and account credentials for individuals who register for or use the Services.
- Health and protected health information (PHI) — medical history, diagnoses, treatment records, lab and radiology results, prescriptions, and other clinical data entered into the platform by healthcare providers on behalf of patients.
- Usage and device data — log files, IP address, browser type, device identifiers, pages visited, and interaction data collected automatically when the Services are used.
- Cookies and similar technologies — data collected through cookies, pixels, and local storage to support authentication, preferences, analytics, and security. See our Cookie Policy for details.
3. How We Use Information
We use the information described above to:
- Provide, operate, maintain, and support the Services, including clinical workflows, AI-assisted diagnostics, and reporting features.
- Authenticate users, manage accounts, and enforce role-based access controls.
- Communicate with Customers and users about the Services, including updates, security notices, and support requests.
- Monitor, analyze, and improve the performance, reliability, and security of the Services.
- Comply with applicable legal, regulatory, and contractual obligations, including HIPAA and the HITECH Act.
We do not use PHI to serve advertising, and we do not use patient health information for any purpose beyond providing and supporting the Services and as instructed by the relevant Customer.
4. Legal Basis for Processing
We and our Customers process personal data on the basis of the individual's consent, collected through a clear affirmative action, or another legally recognized basis such as performance of a contract or compliance with a legal obligation. Consent notices are designed to be presented in clear and plain language, and individuals may withdraw consent at any time (see Section 8, Your Rights).
Where HIPAA applies, PHI is used and disclosed only for treatment, payment, and health care operations, as otherwise permitted or required by law, or with appropriate authorization, consistent with the Business Associate Agreements in place between Ratna HealthPlex and its Customers.
6. Data Security
We maintain administrative, technical, and physical safeguards designed to protect personal information and PHI against unauthorized access, disclosure, alteration, or destruction. Consistent with our published security standards, data at rest is encrypted using AES-256 encryption, and data in transit is protected using TLS 1.3. PHI is encrypted at the field level, not just the database level, and key management uses HSM-backed infrastructure that is audited periodically by independent security firms.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. We maintain incident response procedures designed to detect, investigate, and respond to security incidents in accordance with applicable breach notification requirements.
7. Data Retention
We retain personal information and PHI for as long as necessary to provide the Services, fulfill the purposes described in this Policy, and comply with applicable legal, regulatory, tax, and accounting requirements. Retention periods for PHI are generally governed by the record retention obligations applicable to our Customers under HIPAA and other health care recordkeeping laws. Personal data is retained only as long as necessary for the purpose for which it was collected, unless a longer retention period is required by law.
8. Your Rights
Depending on your jurisdiction and role, you may have the following rights with respect to your personal information and PHI:
- Access — request access to and a copy of the personal information or PHI we hold about you.
- Correction — request correction of inaccurate or incomplete information.
- Deletion / erasure — request deletion of personal information, subject to legal and regulatory retention obligations.
- Portability — request a copy of your information in a structured, commonly used format, where applicable.
- Withdrawal of consent — withdraw previously given consent for the processing of your personal data at any time, without affecting the lawfulness of processing carried out before withdrawal.
- Grievance redressal — lodge a complaint with our Privacy Officer and, if unresolved, with your state Attorney General's office or the Federal Trade Commission.
Where your health information is held on behalf of a healthcare provider Customer, requests relating to that PHI should generally be directed to the relevant provider in the first instance, consistent with HIPAA's designated record set procedures.
[Process and timeline for submitting and responding to rights requests to be confirmed by legal/compliance team]
9. International Data Transfers
We and our sub-processors may process and store information in locations other than where it was originally collected, including across the United States. Where personal information is transferred, we use appropriate safeguards designed to ensure the information continues to receive an adequate level of protection, consistent with applicable requirements under HIPAA and the HITECH Act.
10. Children's Privacy
The Services are intended for use by healthcare organizations and their authorized staff, and are not directed to children. Where health information relating to a minor patient is processed through the Services, it is collected and managed by the relevant healthcare provider Customer in accordance with applicable law, including any applicable parental or guardian consent requirements under state law.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will post the updated Policy on this page with a revised "Last Updated" date. Material changes will be communicated through appropriate channels, such as email or an in-product notice, where required by law.
12. Contact Us
If you have questions about this Privacy Policy or would like to exercise any of the rights described above, please contact our Data Protection Officer / Privacy Team.
[Data Protection Officer / Privacy Team — contact email to be confirmed]
[Registered company address to be confirmed]