Skip to content

Privacy

Privacy notice

This notice explains how EMR Chart handles information when a practice uses our software and when someone visits this website.

Last updated: August 11, 2026

Our role

EMR Chart provides software to healthcare practices. When a practice stores patient information in EMR Chart, the practice decides what is collected and why; we process that information on the practice’s behalf and under our agreement with them. Patients who want to access, correct, or ask questions about their medical record should contact their practice directly, because the practice controls that record.

Information we process

  • Account information for staff and portal users: name, email address, role, and authentication data such as password hashes and multi-factor secrets.
  • Patient information entered by a practice: demographics, contact details, clinical notes, forms, orders, payments, and uploaded documents.
  • Security and audit records: sign-in events, permission denials, and records of who viewed or changed what, retained in an append-only log.
  • Operational data needed to run the service, such as error diagnostics that reference record identifiers rather than personal details.

What this website collects

These public pages carry no analytics, advertising, or session replay technology, and no externally hosted assets. We set cookies only for authentication and security once you sign in; there are no tracking or advertising cookies anywhere on the site.

Email

We send only transactional authentication messages, and never marketing email. Bounced and complained-about addresses are suppressed automatically. See our email practices page for the complete list of messages and how to stop them.

How we use information

We use information to operate the service the practice has asked for: authenticating users, running clinical and billing workflows, keeping records secure, producing the practice’s own reports, meeting our legal obligations, and investigating security incidents or misuse. We do not sell personal information, and we do not use patient information to advertise anything.

Sharing

Information is shared with infrastructure providers that host or transmit it on our behalf, under agreements that require appropriate protection, including business associate agreements where patient information is involved. Optional integrations remain disabled until the required agreement exists. We may disclose information when law requires it, and we will tell the affected practice unless we are prohibited from doing so.

Retention

A practice’s records are retained for as long as the practice’s account is active and afterwards as required by the practice’s retention obligations and our agreement. Audit records are retained for their full retention period and are never edited or deleted in place. Backups age out on a defined schedule.

Security

Controls include encryption in transit and at rest, role-based access enforced server-side, multi-factor authentication support, session timeouts, private object storage with audited retrieval, and append-only auditing. Our security page describes these in more detail. No system is perfectly secure, and we do not claim otherwise.

Children

EMR Chart is used by practices, not by the public. A practice may hold records about minors as part of care; those records are governed by the practice’s own privacy practices and applicable law.

Changes

When this notice changes materially, we update the date above and notify practices through the product or by email to their administrators.

Contact

Privacy questions, abuse reports, and suppression requests can be sent to the address on our contact page.