HIPAA Compliant

Privacy Policy

Last updated: January 26, 2026

Overview

FrontaHealth("we," "our," or "us") is committed to protecting the privacy and security of your data. This Privacy Policy explains how we collect, use, and safeguard information when you use our AI-powered insurance verification and appointment intake services.

Information We Collect

We collect the following types of information:

  • Patient Information: Names, contact details, dates of birth, and medical record numbers
  • Insurance Data: Insurance provider details, policy numbers, coverage information, and eligibility data
  • Appointment Information: Scheduling preferences, appointment history, and communication logs
  • Usage Data: System logs, interaction patterns, and service performance metrics

How We Use Your Information

  • Verify patient insurance eligibility and coverage
  • Automate appointment scheduling and intake processes
  • Communicate with patients on behalf of healthcare providers
  • Improve our AI models and service quality
  • Comply with legal and regulatory requirements

HIPAA Compliance

FrontaHealthis fully HIPAA compliant and serves as a Business Associate to healthcare providers. We implement comprehensive administrative, physical, and technical safeguards to protect Protected Health Information (PHI). All customers receive a Business Associate Agreement (BAA) at no additional cost.

Data Security

We protect your data through:

  • Encryption: AES-256 encryption for data at rest and in transit
  • Access Controls: Role-based access with multi-factor authentication
  • Audit Logging: Complete audit trails of all data access and modifications
  • Infrastructure: HIPAA-compliant Google Cloud servers with 99.9% uptime SLA
  • Certifications: SOC 2 Type II certified with annual third-party security audits

Data Sharing

We do not sell your data. We only share information with:

  • Insurance providers for verification purposes
  • Your healthcare provider organization
  • Service providers bound by confidentiality agreements (e.g., cloud hosting, security services)
  • Legal authorities when required by law or to protect rights and safety

Data Retention

We retain data only as long as necessary to provide our services and comply with legal obligations. Healthcare providers control patient data retention policies. Upon request, we will securely delete or return data in accordance with our BAA and applicable regulations.

Your Rights

You have the right to:

  • Access your personal information
  • Request corrections to inaccurate data
  • Request deletion of your data (subject to legal requirements)
  • Opt-out of certain data processing activities
  • Receive an audit log of data access

Cookies and Tracking

Our website uses essential cookies for functionality and analytics cookies to improve user experience. You can control cookie preferences through your browser settings. We use analytics tools to understand service usage and improve our platform.

Updates to This Policy

We may update this Privacy Policy periodically. We will notify you of material changes via email or through our service. Continued use of FrontaHealthafter changes constitutes acceptance of the updated policy.

Contact Us

For questions about this Privacy Policy or to exercise your privacy rights:

Email: privacy@fronta.health

Address: FrontaHealth Privacy Team

Response time: 48 hours for general inquiries, 24 hours for urgent security matters