Privacy Policy
Effective Date: March 5, 2026 | Last Updated: September 2, 2026
1. Introduction
Krasyn LLC ("Krasyn," "we," "us," or "our") operates the Krasyn electronic medical records platform ("Platform"). This Privacy Policy describes how we collect, use, disclose, store, and protect information when you use our services, Chrome extension, marketing website, or a Krasyn business inquiry form hosted by a third-party platform. This policy applies to healthcare providers, clinical staff, administrative personnel, prospective business customers, and patients who access information through the patient portal.
This Privacy Policy is supplemented by our Notice of Privacy Practices, which describes how Protected Health Information ("PHI") may be used and disclosed, and your rights regarding your health information under HIPAA.
2. Information We Collect
2.1 Information You Provide
- Account information: Name, email address, professional credentials, organization affiliation, role
- Clinical data: Patient demographics, medical histories, clinical notes, orders, prescriptions, lab results, allergies, vital signs, billing codes, and other health information entered into the Platform
- Communications: Messages sent through the Platform, support requests, and feedback submissions
2.2 Information Collected Automatically
- Usage data: Pages visited, features used, timestamps, session duration
- Device information: Browser type, operating system, screen resolution
- Audit logs: All actions taken within the Platform, including data access, modifications, and authentication events (required by HIPAA)
- Error logs: Application errors and performance data (no PHI included)
2.3 Business Inquiries and Lead Forms
If you request a workflow review through a Krasyn form hosted by Meta, we may receive your name, work email, practice name, business role, practice size, current practice system, and requested business-software next step. These forms are for prospective practice customers only. Do not submit client, patient, diagnosis, treatment, caseload, or other clinical information. Krasyn does not use Meta Pixel, Conversions API, or cross-site retargeting on the EMR application or patient portal.
2.4 Krasyn Clinical Assistant Chrome Extension
The extension acts only after an explicit user action. For coding assistance, it reads the visible text of the active tab only when you select Analyze Note and sends that text to the Krasyn API over HTTPS. For Scribe handoff, the authenticated Krasyn app sends only the clinician-reviewed note to the extension. The extension holds that note in Chrome session storage for no more than 30 minutes, requires confirmation of the patient and destination field before insertion, and deletes the note after insertion, when you choose Forget this note, or when the browser session ends. It does not read existing destination-field text and does not save or sign the EHR note.
The extension may retain the 20 most recent metadata-only insertion receipts in Chrome local storage. A receipt contains the handoff identifier, insertion time, destination origin and field label, character counts, extension version, status, and a SHA-256 note fingerprint. It does not contain note text or patient identity. The extension does not collect browsing history, bookmarks, cookies, or advertising identifiers.
2.5 Information We Do Not Collect
- We do not use cookies for advertising or tracking purposes
- We do not sell, rent, or trade any personal or health information
- We do not use PHI for marketing purposes
- We do not persist PHI in browser local storage or cookies; short-lived reviewed-note handoffs use Chrome session storage as described above
3. Protected Health Information (PHI)
Krasyn processes Protected Health Information as defined under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), as amended by the HITECH Act. All PHI is handled in accordance with HIPAA requirements, our Business Associate Agreement with covered entities, and applicable state health privacy laws.
We implement administrative, physical, and technical safeguards to protect PHI:
- Encryption in transit: All data transmitted over TLS 1.2 or higher
- Encryption at rest: AES-256 encryption for all stored data
- Role-based access controls: Users access only what is necessary for their role
- Audit logging: Comprehensive, tamper-proof logging of all PHI access and modifications
- Automatic session timeout: Sessions expire after 15 minutes of inactivity
- Tenant isolation: Multi-layer enforcement ensures organizations can only access their own data
4. How We Use Your Information
We use collected information to:
- Provide, maintain, and improve the EMR Platform
- Authenticate and authorize user access
- Generate audit trails required by HIPAA and other regulations
- Provide AI-assisted clinical decision support features
- Communicate service updates, security notices, and maintenance schedules
- Respond to support requests and provide technical assistance
- Respond to requested business-software demonstrations and workflow reviews
- Monitor platform security, detect threats, and prevent unauthorized access
- Comply with legal obligations and regulatory requirements
We do not: Sell your information. Use PHI for marketing. Share clinical data with third parties except as described in this policy or required by law.
5. How We Share Information
We may share information only in the following circumstances:
- With your organization: Account administrators within your organization may access audit logs and usage reports as required for compliance
- Service providers (subprocessors): We use Google Cloud / Firebase (Firestore database, authentication, hosting); Microsoft Azure (application hosting, Key Vault); Azure OpenAI (AI documentation features; PHI is processed under Microsoft's BAA and is not sent to OpenAI's public API by default); Azure Application Insights (operational telemetry, 90-day retention, no PHI); and Azure Communication Services (email/SMS/video). These providers have executed BAAs and maintain SOC 2 Type II certifications. See our HIPAA page for a complete list. Organizations that connect their own third-party credentials (for example a Twilio account or an OpenAI API key) are responsible for their own agreements with those vendors, and Krasyn requires an attestation before any such connection processes patient information
- Legal compliance: When required by law, subpoena, court order, or government investigation, or to protect our rights, safety, or property
- Meta Platforms: Meta hosts optional Krasyn business lead forms and processes the non-PHI business contact fields a prospective practice chooses to submit. Meta is not used to collect clinical information and is not connected to authenticated EMR or patient-portal activity
- Business transfers: In connection with a merger, acquisition, or sale of assets, your information may be transferred. We will notify you before your information becomes subject to a different privacy policy
- With your consent: For any purpose not described here, we will obtain your explicit consent before sharing
6. Data Retention
We retain information according to the following schedule:
- Clinical records (PHI): Retained for a minimum of seven (7) years from the date of last encounter, or longer as required by applicable state law. For minors, records are retained until the patient reaches age 21, or seven years from the date of last encounter, whichever is later
- Audit logs: Retained for a minimum of six (6) years as required by HIPAA (45 CFR §164.530(j))
- Account data: Retained for the duration of the service agreement plus ninety (90) days for data export
- Usage analytics: Aggregated, de-identified usage data may be retained indefinitely for service improvement
- Business lead forms: Campaign exports and unmatched inquiry records are deleted within ninety (90) days after the campaign closes. If an inquiry becomes an active customer relationship, ordinary account and contract retention rules apply
- Chrome extension handoffs: Pending reviewed-note text expires after 30 minutes and is cleared after insertion, when you choose Forget this note, or when the browser session ends. The extension retains at most 20 metadata-only insertion receipts on the device
See our full Data Retention Policy for complete details.
7. Data Security
We employ industry-standard security measures to protect your information. Our infrastructure is hosted on Google Cloud Platform and Microsoft Azure, both of which maintain SOC 2 Type II certifications and HIPAA eligibility. Specific security measures are described in our Security & Privacy Practices.
In the event of a data breach involving PHI, we will comply with the HIPAA Breach Notification Rule (45 CFR §§164.400-414) and all applicable state breach notification laws. See our Breach Notification Policy for details.
8. Your Rights
8.1 HIPAA Rights (for patients)
Under HIPAA, patients have the right to:
- Access and receive a copy of your health information
- Request amendment of inaccurate health information
- Receive an accounting of disclosures of your PHI
- Request restrictions on certain uses and disclosures
- Request confidential communications by alternative means or locations
- File a complaint with us or with the U.S. Department of Health and Human Services
See our Notice of Privacy Practices for complete information about your HIPAA rights.
8.2 State Privacy Rights
Depending on your state of residence, you may have additional rights:
- California (CCPA/CPRA): California residents have the right to know what personal information we collect, request deletion, opt out of sales (we do not sell personal information), and non-discrimination for exercising these rights. Note: PHI handled under HIPAA is exempt from CCPA/CPRA
- Colorado, Connecticut, Virginia, Utah, Oregon, Texas, Montana, Iowa, Indiana, Tennessee: Residents of states with comprehensive privacy laws have rights similar to California regarding access, deletion, correction, and data portability for non-PHI personal data
- New York: The SHIELD Act requires reasonable safeguards for private information of New York residents, which we maintain
- Washington State: The My Health My Data Act provides additional protections for consumer health data not covered by HIPAA
8.3 How to Exercise Your Rights
To exercise any of the above rights, contact us at privacy@krasyn.com with your specific request. We will respond within thirty (30) days (or the applicable state-required timeframe). We may request verification of your identity before processing your request.
9. Children's Privacy
The Platform is not directed to individuals under 18. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13 without parental consent, we will take steps to delete that information. Clinical records of minor patients are managed by their authorized healthcare providers in accordance with applicable state law.
10. International Data Transfers
The Platform is hosted in the United States. If you access the Platform from outside the United States, your information will be transferred to and processed in the United States. By using the Platform, you consent to this transfer. We will take appropriate measures to protect your information in accordance with this Privacy Policy and applicable data protection laws.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or in-app notification at least thirty (30) days before the changes take effect. Your continued use of the Platform after the effective date constitutes acceptance of the updated policy. The "Last Updated" date at the top of this page indicates when this policy was last revised.
12. Contact Us
For privacy-related inquiries or to exercise your rights:
- Privacy Officer: privacy@krasyn.com
- HIPAA/compliance: compliance@krasyn.com
- Security concerns: security@krasyn.com
Krasyn LLC
2489 N Side Saddle Lane
Post Falls, ID, United States
If you believe your privacy rights have been violated, you may also file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights at hhs.gov/hipaa/filing-a-complaint.