Privacy Policy
What OptiMed collects, why, and what we will never touch. Section 5 covers text messaging, consent, and how to stop receiving messages.
Effective 3 August 2026
1.Who this policy covers
OptiMed AI (“OptiMed”, “we”) provides OptiMed, software that helps outpatient clinics follow up on missed calls, cancellations, no-shows, waitlists, and recalls. This policy explains what we do with information from three different groups of people, because our role is different for each.
- Website visitors. People who browse optimedmd.com or submit the demo request form. We decide how this information is used, so we are the controller of it.
- Clinic staff users. People who hold an account in the OptiMed application. We are the controller of their account and security information.
- Patients of our clinic customers. We process patient information only on behalf of, and under the instructions of, the clinic. The clinic — not OptiMed — decides what is collected and who is contacted. If you are a patient with a question about your information, contact your clinic first; they are the right party to answer it and to action a request.
Where a clinic is a HIPAA covered entity, OptiMed acts as its business associate under a written agreement. That agreement governs protected health information and takes precedence over this policy for that information.
2.What we collect
From website visitors. The details you type into the demo request form: clinic name, your name, work email, role, number of locations and providers, appointment and missed-call volumes, the software and phone system you use, and your timeline. We also keep standard server logs (IP address, user agent, page requested, timestamp) for security and troubleshooting.
From the chat assistant. If you leave an email address in the chat window, we keep that address and a one-word label for the topic you were asking about, such as “pricing” or “ehr”. We do not store the conversation. The messages you type are held in your browser for the length of the visit and are not written to our systems. Questions the assistant cannot answer from its own written answers are sent to a third-party language model to draft a reply; that request contains your question and nothing that identifies you.
Please do not type patient information into the chat
The chat window on this website is a sales tool, not a clinical system, and it is not covered by a business associate agreement. If a message looks like it contains patient details, the assistant refuses it, does not send it to the language model, and does not store it — but the safest course is not to enter it. If you want to discuss real data, ask for a private walkthrough instead.
From clinic staff users. Name, work email address, role and permissions, the clinic and locations you belong to, multi-factor authentication state, sign-in and session records, and a log of the actions you take in the application.
From clinic customers, about their patients. Only what is needed to contact someone about scheduling: name, phone number, email address, preferred language and timezone, communication preferences and opt-out status, appointment records (type, date, provider, location, status, and the clinic’s own value figure), call metadata such as the time and duration of an inbound call and whether it was answered, and the content of two-way scheduling messages.
What we deliberately do not collect
OptiMed is not a clinical system, and it is built to reject clinical data rather than merely discourage it. Diagnoses, medications, clinical notes, lab or test results, treatment plans, insurance and payer details, Social Security numbers, and demographic categories such as race, ethnicity, disability, genetic, or health status are not stored and are quarantined if they appear in an import file. We do not record calls.
3.How we use it
- To provide the service: identifying missed appointment opportunities, proposing a next action to clinic staff, sending the messages a staff member approves, offering and holding appointment slots, and reporting on outcomes.
- To secure the service: authentication, multi-factor verification, rate limiting, fraud and abuse prevention, and the audit trail that records who did what.
- To support and improve the service: diagnosing faults, measuring reliability, and improving the scheduling and prioritisation logic for the clinic whose data it is.
- To respond to a demo request and to run our own sales and billing operations.
- To meet legal obligations and to establish or defend legal claims.
4.Automated prioritisation
The service ranks opportunities and proposes a next action — for example, which patient to contact first and in which time window. These outputs are operational: likelihood of a reply, likelihood of attendance, and expected scheduling value.
They are never predictions about health, diagnosis, urgency, clinical eligibility, or insurance, and the inputs listed in section 2 are excluded from them by design. A model is built from a single clinic’s own historical outcomes; patient-level records are never pooled across clinics.
These outputs are recommendations to a person, not decisions. A staff member approves every outbound message and confirms every booking. Where there is not enough history, or the underlying data is out of date, the system reports that it is abstaining rather than producing a number.
5.Text messages, consent, and opting out
When a clinic uses OptiMed to send SMS, the messages come from the clinic and are about that patient’s own appointments and scheduling.
Consent. The clinic is responsible for obtaining consent to contact a patient by text, through its own intake forms, patient portal, or written communication preferences, and for recording that consent. OptiMed stores the consent status the clinic provides and will not send to a number that is not marked as consented, that has opted out, or that is on a suppression list.
Opting out. Reply STOP to any message to stop receiving them. The opt-out is applied before any other processing, takes effect immediately, and is permanent until the patient reverses it by replying START. Reply HELP for help, or contact your clinic directly.
Frequency and cost. Message frequency varies and depends on your clinic’s activity and on your replies. Messages are only sent within the hours the clinic configures, and per-patient frequency limits are enforced. Message and data rates may apply. Carriers are not liable for delayed or undelivered messages.
We do not sell or share mobile information
Mobile phone numbers and SMS consent are used only to deliver the clinic’s scheduling messages. No mobile information is sold, rented, or shared with third parties or affiliates for their own marketing or promotional purposes. It is disclosed only to the messaging and telephony providers strictly needed to deliver a message, and those providers may not use it for their own purposes.
Text messaging is not a way to reach anyone urgently. If you have a medical emergency, call 911 or go to the nearest emergency department. Messages that appear clinical or urgent are routed to clinic staff rather than answered automatically.
8.How we protect it
- Encryption in transit and at rest, with contact details additionally encrypted at the field level.
- Multi-factor authentication required for access to live clinic data, and re-authentication for high-risk actions.
- Each clinic’s data is isolated at the database level, and cross-clinic access is tested automatically on every build.
- An append-only audit trail of every change, which the application itself cannot edit or delete.
- Message content, credentials, and authentication secrets are excluded from application logs.
- Access is least-privilege, reviewed periodically, and support access to customer data follows a separate audited procedure.
We describe our safeguards factually. We do not claim to be “HIPAA certified”, to guarantee compliance, or to eliminate breach risk — no software vendor can honestly claim any of those. A business associate agreement is available to clinic customers.
9.How long we keep it
- Clinic and patient data is retained for as long as the clinic’s account is active, and afterwards according to the retention period in that clinic’s agreement.
- Demonstration and evaluation data is synthetic, is never real patient information, and expires automatically.
- Audit records are retained for the period required by the clinic’s agreement and applicable law, and are not deleted on request where a legal or contractual obligation requires them.
- Demo request submissions are kept for our sales records and deleted on request.
On termination, clinic data is exported or deleted as set out in the clinic’s agreement, subject to any legal hold.
10.Your choices and rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, to object to or restrict certain processing, and to appeal a refusal. We will not discriminate against you for exercising a right.
If you are a patient of one of our clinic customers, contact the clinic. They control your record, and we will support them in responding. If you contact us directly we will refer you to them and let them know.
If you are a website visitor or a clinic staff user, email us at privacy@optimedmd.com. We may need to verify your identity before acting.
11.Other things you should know
Children. The service is sold to clinics, not to individuals, and we do not knowingly collect information directly from children. Where a clinic’s patient is a minor, that information reaches us from the clinic and is governed by the clinic’s agreement.
Location of processing. The service is operated from the United States, and information is processed and stored there.
Changes. If we change this policy we will update the effective date above, and we will tell clinic customers in advance of a material change that affects them.
Contact. privacy@optimedmd.com. Our terms of service govern use of the software itself.