Privacy Policy
Last updated: March 2026
1. Introduction
Sanara Health, Inc. ("Sanara Health," "we," "us," or "our") operates the Rubin platform, an AI-powered clinical documentation tool designed for use in intensive care settings. This Privacy Policy describes how we collect, use, disclose, and protect information — including Protected Health Information (PHI) — when you use our platform.
2. Information We Collect
When launched from an Electronic Health Record (EHR) system, we may access the following patient data through FHIR (Fast Healthcare Interoperability Resources) APIs:
- Patient demographics — name, date of birth, medical record number (MRN), gender
- Conditions — active problem list and diagnoses
- Medications — active medication orders
- Allergies — documented allergies and intolerances
- Observations — vital signs, laboratory results
- Documents — existing clinical documents for context
We also collect practitioner identity information (name, role) through OpenID Connect for authentication and audit logging purposes.
3. How We Use Your Information
We use the information we collect to:
- Generate AI-assisted clinical documentation from voice recordings
- Pre-populate clinical notes with relevant patient context
- Write completed, clinician-reviewed notes back to the EHR
- Authenticate and authorize healthcare practitioners
- Maintain audit logs as required by HIPAA regulations
4. HIPAA Compliance
Sanara Health is committed to compliance with the Health Insurance Portability and Accountability Act (HIPAA). We maintain appropriate administrative, physical, and technical safeguards to protect PHI, including:
- Business Associate Agreements (BAAs) with all third-party service providers that handle PHI
- Role-based access controls and authentication requirements
- Comprehensive audit logging of all PHI access
- Workforce training on HIPAA requirements
5. Data Storage and Security
All data is processed and stored on HIPAA-compliant infrastructure:
- Data in transit is encrypted with TLS 1.2 or higher
- Data at rest is encrypted with AES-256 encryption
- Application infrastructure is hosted on Aptible, a HIPAA-compliant platform
- Audio recordings and documents are stored in encrypted cloud storage
6. Third-Party Services
We use the following categories of third-party services to provide our platform:
- Cloud infrastructure — HIPAA-compliant hosting and storage providers with BAAs
- AI/ML services — Speech-to-text transcription and language model services with BAAs
- Authentication — Identity providers for secure practitioner authentication
We do not sell, rent, or share PHI with third parties for marketing or advertising purposes.
7. Data Retention
We retain PHI in accordance with HIPAA requirements and applicable state and federal regulations. Audit logs are retained for a minimum of six (6) years. Clinical documentation is retained in accordance with the policies of the healthcare organization that controls the data.
8. Your Rights
Under HIPAA and applicable privacy laws, patients and authorized representatives have the right to:
- Access their PHI maintained by our platform
- Request corrections to their PHI
- Receive an accounting of disclosures of their PHI
- Request restrictions on certain uses and disclosures
- File a complaint regarding our privacy practices
Healthcare organizations using Rubin should direct patient inquiries through their established privacy office procedures.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify affected parties of material changes in accordance with applicable law and our contractual obligations.
10. Contact Us
For questions about this Privacy Policy or our privacy practices, please contact:
Sanara Health, Inc.
Email: privacy@sanarahealth.com
Website: www.sanarahealth.com