Legal
Privacy Policy
Effective Date: May 19, 2026
Contents
- 1. Overview
- 2. Information We Collect
- 3. How We Use Your Information
- 4. HIPAA Compliance & Business Associate Obligations
- 5. How We Share Information
- 6. Data Security
- 7. Cookies & Tracking Technologies
- 8. Data Retention
- 9. Your Rights
- 10. Children's Privacy
- 11. Third-Party Links
- 12. International Users
- 13. Changes to This Policy
- 14. SMS / Text Messaging Program
- 15. Contact & Complaints
1. Overview
360eMed, LLC ("360eMed," "we," "us," or "our") operates a healthcare scheduling platform and related services (collectively, the "Services"). We are committed to protecting the privacy and security of the information we receive and process, including Protected Health Information ("PHI") as defined by the Health Insurance Portability and Accountability Act of 1996 ("HIPAA") and its implementing regulations.
This Privacy Policy describes how we collect, use, disclose, and safeguard information when you visit our website (360emed.com) or use our Services. It also describes your rights with respect to your information and how to contact us with questions or concerns.
If you are a covered entity or business associate entering into an agreement for our Services, please refer to your Business Associate Agreement (“BAA”) with 360eMed, which governs our handling of PHI on your behalf.
2. Information We Collect
2.1 Information You Provide Directly
- Contact and account information (name, email address, phone number, organization name, job title)
- Billing and payment information (processed via PCI-DSS-compliant third-party processors; we do not store full payment card numbers)
- Communications you send us (support requests, demo inquiries, feedback)
- Scheduling configuration data entered by practice administrators
2.2 Protected Health Information (PHI)
When 360eMed acts as a Business Associate for a healthcare covered entity, our platform may process PHI such as patient names, dates of appointments, provider names, and appointment-related clinical notes as directed by the covered entity. 360eMed processes PHI solely on behalf of and under the instructions of the covered entity pursuant to a signed BAA. We do not sell PHI and do not use PHI for our own commercial purposes.
2.3 Automatically Collected Technical Data
- Log data: IP address, browser type and version, pages visited, timestamps, referring URLs
- Device data: device type, operating system, screen resolution
- Cookies and similar tracking technologies (see Section 7)
- Usage analytics to understand how the Services are used and improve them
3. How We Use Your Information
- Provide, operate, and maintain the Services
- Process transactions and send related notices (receipts, invoices, renewal reminders)
- Respond to inquiries, provide customer support, and troubleshoot issues
- Send technical notices, security alerts, and administrative messages
- Improve and develop our Services through aggregated, de-identified analytics
- Comply with applicable laws, regulations, and legal obligations
- Enforce our Terms of Service and other agreements
- Detect, prevent, and investigate fraud, security incidents, and abuse
- With your consent, send marketing communications about products and services you may find relevant (you may opt out at any time)
We do not use PHI for any purpose beyond providing the Services as directed by the covered entity, as required by law, or as permitted under our BAA.
4. HIPAA Compliance & Business Associate Obligations
360eMed recognizes its obligations as a Business Associate under HIPAA. When we receive, create, maintain, or transmit PHI on behalf of a covered entity, we:
- Execute a Business Associate Agreement (BAA) with each covered entity prior to accessing or processing PHI
- Use and disclose PHI only as permitted or required by the BAA and HIPAA
- Implement administrative, physical, and technical safeguards required by the HIPAA Security Rule (45 C.F.R. Part 164, Subpart C) to protect the confidentiality, integrity, and availability of electronic PHI
- Report to the covered entity any use or disclosure of PHI not provided for in the BAA, including breaches of unsecured PHI, within the timeframes required by the HIPAA Breach Notification Rule
- Make our internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of Health and Human Services for compliance purposes
- Return or destroy PHI upon termination of the BAA, where feasible
Covered entities should contact info@360eMed.com to request a BAA or to ask questions about our HIPAA compliance program.
5. How We Share Information
5.1 Service Providers
We share information with third-party vendors and service providers who perform functions on our behalf (e.g., cloud hosting, payment processing, email delivery, customer support software). These parties are contractually required to handle information only as directed by us and in a manner consistent with this Privacy Policy. Where they may access PHI, we execute appropriate BAAs.
5.2 Covered Entity Direction
As a Business Associate, we disclose PHI only at the direction of the covered entity or as required by law. We do not disclose PHI to third parties for their own marketing or business purposes.
5.3 Legal Requirements
We may disclose information when we believe in good faith that disclosure is required by applicable law, regulation, subpoena, court order, or governmental authority, or to protect the rights, property, or safety of 360eMed, our users, or the public.
5.4 Business Transfers
If 360eMed is involved in a merger, acquisition, asset sale, or similar transaction, information (including PHI, subject to applicable BAA requirements) may be transferred as part of that transaction. We will notify affected covered entities and comply with HIPAA requirements in such circumstances.
5.5 No Sale of Personal Information or PHI
360eMed does not sell, rent, or trade personal information or PHI to third parties for their commercial purposes.
6. Data Security
360eMed implements and maintains a comprehensive information security program designed to protect information against unauthorized access, use, disclosure, alteration, and destruction. Our safeguards include:
- Encryption of data in transit using TLS 1.2 or higher
- Encryption of PHI and sensitive data at rest using AES-256 or equivalent standards
- Access controls and role-based permissions limiting access to PHI on a minimum-necessary basis
- Multi-factor authentication for administrative access to production systems
- Regular security risk assessments and vulnerability management
- Audit logging of access to and use of PHI
- Workforce training on HIPAA and information security requirements
- Incident response and breach notification procedures
No security system is impenetrable. In the event of a breach affecting PHI, we will notify the applicable covered entity and, where required, relevant authorities and individuals in accordance with HIPAA and applicable state breach notification laws.
8. Data Retention
We retain account and business information for as long as your account is active or as needed to provide the Services, comply with legal obligations, resolve disputes, and enforce our agreements.
PHI is retained in accordance with the applicable BAA and the covered entity's instructions. Upon termination of the BAA, we will return or destroy PHI as required, unless retention is required by law.
Aggregated, de-identified data that does not identify any individual or covered entity may be retained indefinitely for product improvement purposes.
9. Your Rights
9.1 Patient Rights Under HIPAA
If you are a patient whose PHI is processed through our platform, your rights regarding your PHI (e.g., right of access, amendment, accounting of disclosures, and restriction requests) must be exercised through your healthcare provider (the covered entity), not directly through 360eMed. Please contact your provider's privacy officer for assistance.
9.2 Rights Regarding Non-PHI Personal Information
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate or incomplete information
- Deletion: Request deletion of your personal information, subject to legal retention requirements
- Objection / Restriction: Object to or request restriction of certain processing activities
- Portability: Receive your personal information in a structured, machine-readable format
- Opt-out of marketing: Unsubscribe from marketing communications at any time using the link in any email or by contacting us
To exercise these rights, contact us at info@360eMed.com. We will respond within 30 days (or within the timeframe required by applicable law).
9.3 California Residents (CCPA/CPRA)
California residents have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), including the right to know, delete, correct, and opt out of the sale or sharing of personal information. 360eMed does not sell or share personal information for cross-context behavioral advertising. To submit a verifiable consumer request, contact us at info@360eMed.com or call us at the number listed on our website.
10. Children's Privacy
Our website and general marketing Services are not directed to children under the age of 13. We do not knowingly collect personal information from children under 13 through our marketing website. Our scheduling platform may process appointment information for minor patients as part of a covered entity's operations; such processing is governed by the applicable BAA and the covered entity's own privacy practices.
If you believe we have inadvertently collected personal information from a child under 13 through our marketing website, please contact us at info@360eMed.com and we will promptly delete it.
11. Third-Party Links
Our website may contain links to third-party websites or integrations with third-party services (e.g., EHR systems, patient portals). This Privacy Policy does not apply to those third parties. We encourage you to review the privacy policies of any third-party services you access.
12. International Users
360eMed is based in the United States. If you access our Services from outside the United States, your information will be transferred to and processed in the United States, where data protection laws may differ from those in your country. By using our Services, you consent to this transfer.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will post the revised policy on this page with an updated effective date. For material changes, we will provide notice by email (to the address associated with your account) or by prominent notice on our website at least 30 days before the change takes effect.
Continued use of the Services after the effective date constitutes your acceptance of the updated policy.
14. SMS / Text Messaging Program
Your privacy is important to us. This section outlines how we collect, use, and protect your information when you use our services, including our SMS/text messaging program.
Information We Collect
We collect personal information you provide, including your name, email address, phone number, and mobile number when you opt in to receive text messages from us.
How We Use Your Information
We use your information to deliver the services you requested, send transactional and informational messages, and improve your experience.
No Sharing of Mobile Information
No mobile information will be shared with third parties/affiliates for marketing/promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
Your Rights
You have the right to access, modify, or delete your personal information at any time. You may opt out of text messages by replying STOP to any message.
15. Contact & Complaints
If you have questions, concerns, or complaints about this Privacy Policy or our data practices, please contact our Privacy Officer:
If you are a covered entity with questions about our HIPAA compliance program or wish to request a BAA, please use the same contact information above.
360eMed, LLC — Privacy Officer
360emed.com
Email: info@360eMed.com
This Privacy Policy is provided for informational purposes. It does not constitute legal advice. Healthcare organizations using 360eMed services should consult qualified legal counsel to ensure their own privacy practices comply with HIPAA and applicable state laws.