Privacy Policy
Effective Date: March 5, 2026 | Last Updated: March 5, 2026
1. Introduction
Krasyn LLC ("Krasyn," "we," "us," or "our") operates the EMRAI electronic medical records platform ("Platform"). This Privacy Policy describes how we collect, use, disclose, store, and protect information when you use our services. This policy applies to all users of the Platform, including healthcare providers, clinical staff, administrative personnel, and patients who access information through the patient portal.
This Privacy Policy is supplemented by our Notice of Privacy Practices, which describes how Protected Health Information ("PHI") may be used and disclosed, and your rights regarding your health information under HIPAA.
2. Information We Collect
2.1 Information You Provide
- Account information: Name, email address, professional credentials, organization affiliation, role
- Clinical data: Patient demographics, medical histories, clinical notes, orders, prescriptions, lab results, allergies, vital signs, billing codes, and other health information entered into the Platform
- Communications: Messages sent through the Platform, support requests, and feedback submissions
2.2 Information Collected Automatically
- Usage data: Pages visited, features used, timestamps, session duration
- Device information: Browser type, operating system, screen resolution
- Audit logs: All actions taken within the Platform, including data access, modifications, and authentication events (required by HIPAA)
- Error logs: Application errors and performance data (no PHI included)
2.3 Information We Do Not Collect
- We do not use cookies for advertising or tracking purposes
- We do not sell, rent, or trade any personal or health information
- We do not use PHI for marketing purposes
- We do not store PHI in browser local storage, cookies, or on client devices
3. Protected Health Information (PHI)
EMRAI processes Protected Health Information as defined under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), as amended by the HITECH Act. All PHI is handled in accordance with HIPAA requirements, our Business Associate Agreement with covered entities, and applicable state health privacy laws.
We implement administrative, physical, and technical safeguards to protect PHI:
- Encryption in transit: All data transmitted over TLS 1.2 or higher
- Encryption at rest: AES-256 encryption for all stored data
- Role-based access controls: Users access only what is necessary for their role
- Audit logging: Comprehensive, tamper-proof logging of all PHI access and modifications
- Automatic session timeout: Sessions expire after 20 minutes of inactivity
- Tenant isolation: Multi-layer enforcement ensures organizations can only access their own data
4. How We Use Your Information
We use collected information to:
- Provide, maintain, and improve the EMR Platform
- Authenticate and authorize user access
- Generate audit trails required by HIPAA and other regulations
- Provide AI-assisted clinical decision support features
- Communicate service updates, security notices, and maintenance schedules
- Respond to support requests and provide technical assistance
- Monitor platform security, detect threats, and prevent unauthorized access
- Comply with legal obligations and regulatory requirements
We do not: Sell your information. Use PHI for marketing. Share clinical data with third parties except as described in this policy or required by law.
5. How We Share Information
We may share information only in the following circumstances:
- With your organization: Account administrators within your organization may access audit logs and usage reports as required for compliance
- Service providers (subprocessors): We use Google Cloud Platform (Firestore for data storage, Firebase for authentication) and Microsoft Azure (application hosting, AI services). These providers have executed BAAs and maintain SOC 2 Type II certifications. See our HIPAA page for a complete list
- Legal compliance: When required by law, subpoena, court order, or government investigation, or to protect our rights, safety, or property
- Business transfers: In connection with a merger, acquisition, or sale of assets, your information may be transferred. We will notify you before your information becomes subject to a different privacy policy
- With your consent: For any purpose not described here, we will obtain your explicit consent before sharing
6. Data Retention
We retain information according to the following schedule:
- Clinical records (PHI): Retained for a minimum of seven (7) years from the date of last encounter, or longer as required by applicable state law. For minors, records are retained until the patient reaches age 21, or seven years from the date of last encounter, whichever is later
- Audit logs: Retained for a minimum of six (6) years as required by HIPAA (45 CFR §164.530(j))
- Account data: Retained for the duration of the service agreement plus ninety (90) days for data export
- Usage analytics: Aggregated, de-identified usage data may be retained indefinitely for service improvement
See our full Data Retention Policy for complete details.
7. Data Security
We employ industry-standard security measures to protect your information. Our infrastructure is hosted on Google Cloud Platform and Microsoft Azure, both of which maintain SOC 2 Type II certifications and HIPAA eligibility. Specific security measures are described in our Security & Privacy Practices.
In the event of a data breach involving PHI, we will comply with the HIPAA Breach Notification Rule (45 CFR §§164.400-414) and all applicable state breach notification laws. See our Breach Notification Policy for details.
8. Your Rights
8.1 HIPAA Rights (for patients)
Under HIPAA, patients have the right to:
- Access and receive a copy of your health information
- Request amendment of inaccurate health information
- Receive an accounting of disclosures of your PHI
- Request restrictions on certain uses and disclosures
- Request confidential communications by alternative means or locations
- File a complaint with us or with the U.S. Department of Health and Human Services
See our Notice of Privacy Practices for complete information about your HIPAA rights.
8.2 State Privacy Rights
Depending on your state of residence, you may have additional rights:
- California (CCPA/CPRA): California residents have the right to know what personal information we collect, request deletion, opt out of sales (we do not sell personal information), and non-discrimination for exercising these rights. Note: PHI handled under HIPAA is exempt from CCPA/CPRA
- Colorado, Connecticut, Virginia, Utah, Oregon, Texas, Montana, Iowa, Indiana, Tennessee: Residents of states with comprehensive privacy laws have rights similar to California regarding access, deletion, correction, and data portability for non-PHI personal data
- New York: The SHIELD Act requires reasonable safeguards for private information of New York residents, which we maintain
- Washington State: The My Health My Data Act provides additional protections for consumer health data not covered by HIPAA
8.3 How to Exercise Your Rights
To exercise any of the above rights, contact us at privacy@krasyn.com with your specific request. We will respond within thirty (30) days (or the applicable state-required timeframe). We may request verification of your identity before processing your request.
9. Children's Privacy
The Platform is not directed to individuals under 18. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13 without parental consent, we will take steps to delete that information. Clinical records of minor patients are managed by their authorized healthcare providers in accordance with applicable state law.
10. International Data Transfers
The Platform is hosted in the United States. If you access the Platform from outside the United States, your information will be transferred to and processed in the United States. By using the Platform, you consent to this transfer. We will take appropriate measures to protect your information in accordance with this Privacy Policy and applicable data protection laws.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or in-app notification at least thirty (30) days before the changes take effect. Your continued use of the Platform after the effective date constitutes acceptance of the updated policy. The "Last Updated" date at the top of this page indicates when this policy was last revised.
12. Contact Us
For privacy-related inquiries or to exercise your rights:
- Privacy Officer: privacy@krasyn.com
- HIPAA/compliance: compliance@krasyn.com
- Security concerns: security@krasyn.com
Krasyn LLC
2489 N Side Saddle Lane
Post Falls, ID, United States
If you believe your privacy rights have been violated, you may also file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights at hhs.gov/hipaa/filing-a-complaint.