InjuryDesk Clinic
Back to home

Placeholder — to be reviewed by InjuryDesk Clinic / legal counsel before publication. Nothing on this page is legal advice or a binding commitment.

Privacy Policy

Last updated September 27, 2026 (placeholder date — confirm before publication)

InjuryDesk Clinic provides personal injury case management software to medical clinics and providers. This policy explains what information we collect when you use the service, how we use it, and the choices you have.

1. Who this policy covers

This policy applies to the InjuryDesk Clinic website and web application (the “Service”). It covers information about the clinic staff who create and use accounts, and it describes how we handle the clinic and patient records our customers store in the Service.

When a clinic uses the Service to manage patient cases, the clinic is the controller of that patient information and InjuryDesk Clinic acts as a service provider processing it on the clinic’s instructions.

2. Information we collect

  • Account information: name, work email address, clinic or practice name, specialty, state, and optional NPI number.
  • Clinic records you enter: patients, personal injury cases, treatments, record requests, authorizations, liens, settlements, and payments.
  • Documents you upload, such as medical records, authorizations, and correspondence with attorneys.
  • Usage and device information: pages viewed, actions taken in the app, browser type, and approximate location derived from IP address.
  • Support communications you send to us.

3. Protected health information and HIPAA

Personal injury case management necessarily involves protected health information (PHI). Where InjuryDesk Clinic handles PHI on behalf of a covered entity, we intend to do so as a business associate under HIPAA and to enter into a Business Associate Agreement (BAA) with the customer clinic.

We use and disclose PHI only as permitted by that agreement, as required to provide and support the Service, or as required by law. We do not sell PHI, and we do not use PHI for advertising.

Placeholder — the BAA process, covered subprocessors, and breach notification timelines must be confirmed by InjuryDesk Clinic and its legal counsel before publication.

4. How we use information

  • To provide, maintain, and secure the Service and your account.
  • To display case timelines, financial tracking, and reporting to authorized users in your clinic.
  • To provide customer support and respond to your requests.
  • To send service and billing notices, including trial and subscription reminders.
  • To detect, investigate, and prevent fraud, abuse, and security incidents.
  • To improve the Service, using aggregated or de-identified information that does not identify any individual.

5. How we share information

We do not sell personal information. We share information only in these circumstances:

  • With other authorized users in your clinic, according to the access your clinic configures.
  • With attorneys or other recipients when a user in your clinic chooses to send or share a case record, request, or portal link.
  • With subprocessors that host and operate the Service (for example cloud hosting, database, authentication, and email delivery providers) under contractual confidentiality and security obligations.
  • When required by law, subpoena, or other legal process, or to protect the rights and safety of users and the public.
  • In connection with a merger, acquisition, or sale of assets, subject to this policy and applicable law.

6. Security

We use administrative, technical, and physical safeguards intended to protect information in the Service, including encryption in transit, encryption at rest for stored records, role-based access control, row-level database authorization, and audit logging of case activity.

No method of transmission or storage is completely secure. You are responsible for keeping account credentials confidential and for promptly notifying us of any suspected unauthorized access.

7. Data retention

We retain clinic and patient records for as long as the clinic’s account is active, and afterwards for the period described in the customer agreement or as required by applicable medical record retention laws. Backups are retained on a rolling schedule and then deleted.

Placeholder — specific retention windows to be confirmed with legal counsel.

8. Your choices and rights

Clinic staff can review and update their account information in the Service. Patients who want to access, correct, or delete records held by a clinic should contact that clinic directly; as a service provider, we refer such requests to our customer.

Depending on where you live, you may have rights to access, correct, delete, or port personal information, or to object to certain processing. Contact us using the details below and we will respond as required by applicable law.

9. Cookies and analytics

We use cookies and similar technologies that are necessary to keep you signed in and to keep the Service secure. If we add product analytics, we will limit collection to usage events and will not include PHI in those events.

10. Children's privacy

The Service is intended for use by clinic staff and is not directed to children. Case records may include information about minors who are patients of our customers; that information is handled under the clinic’s instructions and the applicable Business Associate Agreement.

11. Changes to this policy

We may update this policy from time to time. If we make material changes, we will update the date at the top of this page and notify account owners through the Service or by email.

12. Contact

Questions about this policy or about how information is handled in the Service can be sent to support@injurydeskclinic.us.

Placeholder — confirm the correct privacy contact address, mailing address, and any required data protection representative before publication.