Legal
Privacy Policy
How BrainBit collects, uses, and protects information across Od Suite, including the protected health information we handle on behalf of our customers.
Last updated August 15, 2026 · BrainBit LLC
1. Scope
This policy covers odsuite.com and the Od Suite products operated by BrainBit LLC (“BrainBit,” “we,” “us”), including Od Intake and QuickPA, together with any other Od Suite product we make available to you (together, the “Services”).
Od Suite is sold to healthcare organizations. It is not a consumer product, and we have no direct relationship with the patients whose information we process.
2. Our role under HIPAA
Our customers — clinics, practices, and other healthcare organizations — are Covered Entities or business associates of one. When we handle protected health information (“PHI”), we do so as a Business Associate: only at the customer's direction and only as permitted by our Business Associate Agreement (“BAA”) and HIPAA. We execute a BAA with each customer before their account is enabled to transmit PHI.
If anything in this policy conflicts with a signed BAA, the BAA controls with respect to PHI.
If you are a patient
We process your health information only on behalf of your healthcare provider, who controls those records. To see, correct, or restrict them, or to ask how they are used, contact your provider directly. We will support any request they make of us, but we cannot act on your records without their instruction.
3. Information we process
- Account and identity data. Name, username, work email, hashed password, multi-factor authentication enrollment secret, clinic membership, role, and permissions.
- Organization data. Clinic name, member roster, invitations, product entitlements, and usage or credit balances.
- Protected health information, processed only on behalf of a customer. Depending on the product this can include patient demographics and contact details, insurance and coverage information, encounters, conditions, medications, allergies, observations, procedures, diagnostic reports, and clinical documents retrieved from a connected EHR or submitted through an intake form or prior-authorization request.
- Integration credentials. Access tokens and connection metadata for connected EHR systems.
- Technical and audit data. IP address, browser user agent, timestamps, sign-in events, and records of administrative actions.
We do not intentionally collect PHI through the public pages of odsuite.com.
4. Cookies and tracking
Od Suite sets a single essential session cookie to keep you signed in, plus a cross-site request forgery token on forms. We use no advertising cookies, cross-site trackers, or third-party analytics.
Our pages load fonts and stylesheets from third-party content delivery networks. Those networks receive your IP address as a necessary part of serving those files, and receive no other information from us.
5. How we use information
- To deliver, authenticate, and support the Services.
- To carry out the specific task a customer asks of us — patient intake, prior authorization, and billing support.
- To secure the Services, prevent abuse, and maintain audit records.
- To meter usage and bill customers.
- To send service, security, and account notices.
We use PHI only to perform services for the customer, as required by law, or for our own proper management and administration as permitted by the BAA and 45 C.F.R. § 164.504(e)(4). We do not sell personal information or PHI, we do not share it for advertising, and we do not use it for marketing.
6. Artificial intelligence
Some Od Suite features use large language models to draft, summarize, or extract clinical and administrative content. Where PHI is sent to a model provider, we use enterprise offerings under a signed Business Associate Agreement with zero data retention, and the provider is contractually prohibited from using that content to train its models.
Model output is a draft. A qualified person at the customer's organization must review it before it is relied on or submitted. See section 6 of our Terms.
7. Service providers
We share information only with the small number of providers that need it to run the Services, each under contract and, where PHI is involved, a Business Associate Agreement. They fall into these categories:
- Cloud application and database hosting, located in the United States.
- Transactional email, for invitations, password resets, and service notices. We do not send PHI by email.
- Language model processing, for the features described above.
We name our current subprocessors to customers and prospective customers on request, under a non-disclosure agreement. Otherwise we disclose information only at the customer's direction, to comply with law or valid legal process, to protect the rights and safety of people or the Services, or to a successor in a merger or acquisition that is bound by these commitments and by the BAA.
8. EHR connections
Customers may connect a supported electronic health record system. The customer authorizes the connection within its own EHR, and we request read-only, least-privilege access limited to the data a product needs — we never write to the record.
Production connections require our review and approval before they are enabled. Access tokens are encrypted at rest and scoped to a single clinic. A customer may revoke a connection at any time from its EHR administration console or by contacting us.
9. Retention and deletion
- Account and clinic records are kept for the life of the account, then deleted or de-identified on request.
- PHI is retained only as long as needed to provide the Services, then returned or destroyed as the BAA requires. Customers may request deletion at any time.
- Audit logs are retained for seven years as compliance evidence. Because these records exist to be tamper-evident, they cannot be edited or selectively deleted on request.
- Short-lived items — authorization codes, invitations, and password reset tokens — expire and are purged automatically.
10. De-identified data
Where the BAA permits, we may create and use de-identified or aggregated data — de-identified in accordance with 45 C.F.R. § 164.514 — to operate, secure, and improve the Services. We do not attempt to re-identify it and do not permit others to.
11. Security
We encrypt data in transit and encrypt credentials and tokens at rest, require multi-factor authentication on every account, isolate each clinic's data, and keep a tamper-evident audit log. Our Security page describes the specific controls in place.
12. Breach notification
If we discover a breach of unsecured PHI, we notify the affected customer without unreasonable delay and no later than 60 calendar days after discovery, with the detail HIPAA requires so the customer can meet its own notification obligations. For incidents that do not involve PHI, we notify affected customers promptly.
13. Your choices and rights
- Account holders can review and update their information in the Od Suite console, or by writing to support@brainbit.ai.
- Patients should direct HIPAA rights requests — access, amendment, accounting of disclosures, restriction — to their healthcare provider, as described above.
- Customers may ask us to assist with any individual rights request or accounting they are obligated to fulfill.
PHI handled under HIPAA is exempt from most state consumer privacy laws. For personal information outside that scope, contact us and we will honor applicable rights.
14. Children
The Services are not directed to children, and account holders must be 18 or older and acting on behalf of a healthcare organization. We may process PHI about minors on a provider's behalf, governed by the BAA.
15. Location of processing
The Services are operated for United States healthcare organizations, and information is stored and processed in the United States.
16. Changes to this policy
We may update this policy; the date at the top always reflects the current version. For material changes we give notice to account holders by email or in the product before the change takes effect.
Contact
Questions about this page?
Write to support@brainbit.ai. We answer privacy requests, security questionnaires, and Business Associate Agreement requests at the same address.