CloserMDCloserMD — Physician Privacy Notice
This notice explains how CloserMD LLC ("CloserMD") handles information about you,
the physician using the service. It does *not* cover patient PHI — that is governed
by HIPAA and the Business Associate Agreement.
1. What we collect about you. Your name, email, NPI, practice state, facility,
the result of NPI verification, account and usage activity (which patients you
opened and when you signed notes), device and app information (iOS version, build
number), and diagnostic/crash logs. Your card number is held by our payment
processor — we never store it.
2. Your EMR login credentials. To read charts and file notes on your behalf, we
collect and store the credentials you provide for your EMR (for example,
SigmaCare or MatrixCare). We store them encrypted as an AWS SSM SecureString
under AWS KMS, decrypt them only server-side at the moment a connection to your
EMR is needed, and never return them to the app or any other client. We use them
only to access your EMR on your behalf to provide the service. We never sell your
credentials and never use them — or any data obtained with them — to train or
improve AI or machine-learning models. You can delete your stored credentials at
any time by disconnecting your EMR in the app, after which we no longer hold
them.
3. AI processing of PHI within our HIPAA-covered environment. Some CloserMD
features use artificial intelligence (for example, to summarize
interdisciplinary recommendations into your note). Where AI is used, it
processes PHI only within our HIPAA-covered cloud environment, on a
HIPAA-eligible AWS service (Amazon Bedrock) under our Business Associate
Agreement with AWS. Your PHI is not sent to any consumer or third-party model
provider outside that environment, is not used to train or improve any AI model,
and is not retained by the model service beyond what is needed to generate the
result. Other charting aids remain rule-based.
4. Why we use it. To operate and secure the service, verify your eligibility,
prevent abuse, meet compliance and audit obligations, bill you, and send you
service-related messages.
5. Who we share it with. Our cloud provider, Amazon Web Services, under a HIPAA
Business Associate Agreement; our payment processor, Stripe, for billing only;
and others where required by law. We do not sell your data and do no third-party
marketing.
6. How we protect it. We encrypt data at rest (AWS KMS) and in transit (TLS),
require unique per-user logins with multi-factor authentication, apply least-
privilege access controls, keep an encrypted tamper-evident audit log of PHI and
credential access, hash-chain a tamper-evident integrity record of every signed
note, automatically purge in-progress data on inactivity, and take automated
encrypted backups. Voice dictation is deleted immediately after it is
transcribed.
7. How long we keep it. Audit, integrity, and compliance records are retained
for at least six (6) years, as HIPAA requires. Other physician-account data,
including your stored EMR credentials, is kept while your account is active and
deleted after you disconnect your EMR or close your account (within 90 days),
unless we are legally required to retain it.
8. Your choices. Email privacy@closermd.com to access your data, request a
correction, or delete your physician account. You can disconnect your EMR, and
manage billing or cancel, anytime from the app.