HIPAA compliance in progress
Clarity is not currently HIPAA compliant. Use de-identified information only. Do not enter or upload protected health information (PHI).
This applies to chat, uploads, saved plans, and patient follow-ups. Do not use invitations or check-ins to collect identifiable health information while this work is underway.
We will update this page when the compliance work is complete. Contact our team for the latest status.
Clinical questions and saved work
Account information, saved conversations, treatment plans, and submitted check-in responses are processed by the service. Use de-identified information in clinical questions and case descriptions. Remove identifiers before uploading documents; do not upload identifiable records for Clarity to de-identify. Review uploads before submitting them and follow your organization’s requirements.
Patient check-in links
Use fictional or de-identified examples to explore this workflow for now. Do not collect identifiable patient responses. Patients can respond without an account using a unique link. Anyone with that link can open the check-in, so share it only with the intended recipient. Links expire after 30 days; this does not mean the underlying response is deleted after 30 days.
Email delivery
Do not send invitations that associate an identifiable patient with health information while HIPAA compliance work is underway. When you email a check-in invitation, the recipient address and invitation are processed by the email delivery service. Confirm the address and use an appropriate patient communication workflow.
Clinical review
Check the sources and review recommendations before using them in care. AI output can be incomplete or incorrect. Interaction coverage is not exhaustive. Patient check-ins require clinician review and are not continuous monitoring or an emergency channel.
Data requests
Contact us about access, correction, retention, or deletion of information. Specify whether your request includes saved conversations, plans, or check-in responses so the team can address the relevant records.
Contact our team Your organization’s requirements
Before sharing sensitive information, ask us about the agreements, service providers, and controls your organization requires. Read the privacy policy for the existing data-handling terms.
Read the privacy policy