Skip to main content
Built specifically for med spas, aesthetic practices and wellness clinics. Book a live demo →
DigiMEDSPA

Privacy Policy

Effective Date: September 5, 2026

DigiMEDSPA, Inc. (“DigiMEDSPA”) is committed to protecting the privacy, confidentiality, integrity, and security of information entrusted to DigiMEDSPA.

DigiMEDSPA provides a HIPAA-compliant, cloud-based Electronic Medical Record (EMR), practice management, communications, patient engagement, and Native AI platform for healthcare organizations.

This Privacy Policy explains how DigiMEDSPA collects, uses, discloses, protects, and manages information when individuals visit the DigiMEDSPA website, communicate with DigiMEDSPA, or use DigiMEDSPA services.

This Privacy Policy should be read together with any applicable Business Associate Agreement (“BAA”), Client Services Agreement, Terms of Service, and other agreements governing the use of DigiMEDSPA services.

1

Information We Collect

The information DigiMEDSPA collects depends on how you interact with us.

Website and Business Information

When you visit our website, request information, schedule a demonstration, contact us, or otherwise interact with DigiMEDSPA, we may collect information including:

  • Name
  • Business or clinic name
  • Business email address
  • Telephone number
  • Job title
  • Practice type
  • Business location
  • Information submitted through website forms
  • Communications with DigiMEDSPA
  • Device and browser information
  • IP address
  • Website usage information
  • Cookie and similar technology information

Please do not submit patient information or Protected Health Information through general marketing, sales, demonstration request, or contact forms unless the form is specifically designated by DigiMEDSPA for secure healthcare information.

2

Protected Health Information and HIPAA

DigiMEDSPA provides a fully HIPAA-compliant EMR platform designed for healthcare organizations subject to the Health Insurance Portability and Accountability Act of 1996 (HIPAA).

Healthcare organizations using DigiMEDSPA may be Covered Entities under HIPAA.

When DigiMEDSPA creates, receives, maintains, processes, or transmits Protected Health Information (PHI) on behalf of a Covered Entity or other applicable healthcare organization, DigiMEDSPA acts as a Business Associate under HIPAA.

PHI processed through the DigiMEDSPA healthcare platform is protected in accordance with applicable HIPAA requirements, contractual obligations, and DigiMEDSPA’s Business Associate Agreement with the applicable healthcare organization.

DigiMEDSPA maintains administrative, physical, and technical safeguards designed to protect the confidentiality, integrity, and availability of electronic Protected Health Information (ePHI).

These safeguards include, as applicable:

  • Encryption of data in transit
  • Protection of data at rest
  • Role-based access controls
  • Individual user authentication
  • Access restrictions
  • Audit logging
  • Activity monitoring
  • Session security controls
  • Workforce access controls
  • Security policies and procedures
  • Incident response procedures
  • Backup and recovery controls
  • Business continuity procedures
  • Vendor and subprocessor security review
3

Business Associate Agreements

DigiMEDSPA enters into Business Associate Agreements with healthcare customers where required under HIPAA.

The BAA establishes DigiMEDSPA’s responsibilities relating to PHI, including permitted uses and disclosures, safeguards, incident and breach notification requirements, subcontractor obligations, and other applicable HIPAA requirements.

Where a DigiMEDSPA service provider or subprocessor creates, receives, maintains, processes, or transmits PHI on behalf of DigiMEDSPA, DigiMEDSPA requires appropriate contractual and security protections, including a Business Associate Agreement where required by HIPAA.

4

Patient Information

DigiMEDSPA generally processes patient information on behalf of healthcare organizations using our platform.

Depending on the services used by a healthcare organization, patient information may include:

  • Patient name and contact information
  • Date of birth
  • Demographic information
  • Medical history
  • Clinical notes
  • Diagnoses
  • Treatment information
  • Procedures
  • Prescriptions
  • Laboratory information
  • Medical images and photographs
  • Appointment information
  • Patient forms and consents
  • Billing information
  • Healthcare communications
  • Other information maintained as part of the patient’s healthcare record

DigiMEDSPA does not independently determine how a healthcare provider uses patient information for treatment.

The healthcare organization remains responsible for its relationship with the patient, its clinical activities, and its obligations as a Covered Entity where applicable.

Patients seeking access to, correction of, or information regarding their medical records should generally contact their healthcare provider directly.

5

How We Use Information

DigiMEDSPA may use information to:

  • Provide and operate DigiMEDSPA services
  • Maintain healthcare and EMR functionality
  • Authenticate and manage users
  • Provide customer support
  • Process authorized transactions
  • Facilitate clinical and administrative workflows
  • Provide integrated communications
  • Support appointments and patient engagement
  • Maintain platform security
  • Detect and prevent fraud or unauthorized access
  • Monitor system performance
  • Troubleshoot technical issues
  • Improve DigiMEDSPA products and services
  • Communicate with customers and prospective customers
  • Comply with legal and regulatory requirements
  • Enforce contractual obligations

PHI is used and disclosed only as permitted under applicable agreements, HIPAA, and other applicable legal requirements.

6

Native AI and Protected Health Information

DigiMEDSPA incorporates Native AI capabilities directly within its healthcare platform.

These capabilities may include:

  • AI Scribe & Charting Assistant
  • AI Front Desk
  • AI SMS Agent
  • Clinical documentation assistance
  • Patient chart summarization
  • Administrative workflow assistance
  • Other authorized AI-assisted healthcare workflows

Certain Native AI workflows may require PHI to be processed to perform an authorized healthcare function.

DigiMEDSPA applies healthcare privacy and security controls to AI workflows involving PHI.

Our approach includes:

  • Limiting PHI processing to authorized healthcare workflows
  • Applying minimum-necessary principles where appropriate
  • Restricting AI access to information required for the authorized function
  • Protecting information during transmission
  • Maintaining role-based access controls
  • Maintaining applicable audit and security controls
  • Evaluating AI service providers before allowing PHI processing
  • Requiring appropriate contractual protections and BAAs where required
  • Maintaining human review for applicable clinical AI outputs

DigiMEDSPA does not authorize PHI to be transmitted to a third-party AI provider for production healthcare workflows unless that provider and the applicable service have been evaluated for healthcare use and appropriate contractual protections are in place.

7

AI Does Not Replace Healthcare Professionals

DigiMEDSPA’s Native AI capabilities are intended to assist healthcare professionals and administrative staff.

AI-generated clinical documentation or other clinical content is not intended to independently replace the professional judgment of a licensed healthcare provider.

Applicable AI-generated clinical documentation should be reviewed and approved by an authorized healthcare professional before becoming part of a finalized patient medical record or being relied upon for patient care.

Healthcare providers remain responsible for diagnoses, treatments, prescriptions, medical decisions, and other professional clinical judgments.

8

Information Sharing and Subprocessors

DigiMEDSPA may use service providers and subprocessors to support operation of our platform.

These may include providers supporting:

  • Cloud infrastructure
  • Data storage
  • Communications
  • Telecommunications
  • SMS
  • Electronic fax
  • Electronic prescribing
  • Laboratory integrations
  • Payment processing
  • Security
  • Monitoring
  • Customer support
  • Artificial intelligence
  • Other technical infrastructure

DigiMEDSPA evaluates applicable service providers based on factors including security, privacy, contractual protections, data handling, and the nature of the services being provided.

Where a service provider creates, receives, maintains, processes, or transmits PHI on behalf of DigiMEDSPA, we require appropriate contractual and security safeguards, including a Business Associate Agreement where required by HIPAA.

DigiMEDSPA does not sell PHI.

9

Data Security

DigiMEDSPA maintains security measures designed to protect information against unauthorized access, acquisition, use, alteration, disclosure, or destruction.

Our security program includes administrative, physical, and technical safeguards appropriate to the nature of the information we process.

Security controls may include:

  • Encryption
  • Secure communications
  • Authentication
  • Role-based access
  • Account management
  • Access logging
  • Security monitoring
  • Infrastructure protection
  • Backup and recovery
  • Vulnerability management
  • Incident response
  • Workforce security
  • Vendor risk management

Security is an ongoing process. DigiMEDSPA continuously evaluates its systems, policies, infrastructure, vendors, and security controls as technologies and threats evolve.

10

Minimum Necessary Access

DigiMEDSPA follows the principle of limiting access to sensitive healthcare information based on legitimate business, operational, technical, and clinical requirements.

Access to PHI is restricted to authorized individuals, systems, and service providers as necessary to perform permitted functions.

Where appropriate, DigiMEDSPA designs integrations and AI workflows to minimize unnecessary transmission or exposure of patient information.

11

Payment Information

DigiMEDSPA may integrate with third-party payment processors to enable healthcare organizations to accept payments.

Payment processing may be performed by the applicable payment processor rather than DigiMEDSPA directly.

Payment processors maintain their own privacy, security, and compliance obligations.

DigiMEDSPA does not sell payment information.

12

Cookies and Website Technologies

Our public website may use cookies and similar technologies for purposes such as:

  • Website functionality
  • Security
  • Performance
  • Analytics
  • Understanding website usage
  • Improving the user experience

Cookies used on DigiMEDSPA’s general marketing website are separate from the healthcare and EMR environment in which PHI is processed.

Visitors may be able to manage certain cookie preferences through their browser or applicable cookie controls provided on our website.

13

Marketing Communications

If you provide DigiMEDSPA with business contact information, we may use it to communicate with you regarding:

  • Product information
  • Demonstrations
  • Service updates
  • Educational information
  • Events
  • Offers
  • Other DigiMEDSPA services

You may opt out of applicable promotional emails using the unsubscribe mechanism provided in the communication.

Transactional, administrative, security, and service-related communications may still be sent when necessary.

14

Data Retention

DigiMEDSPA retains information for periods appropriate to:

  • Provide contracted services
  • Meet healthcare customer requirements
  • Maintain business and transaction records
  • Satisfy contractual obligations
  • Meet applicable regulatory or legal requirements
  • Maintain security and audit records
  • Resolve disputes

Retention requirements for PHI may also be governed by agreements between DigiMEDSPA and the applicable healthcare organization.

15

Security Incidents and Breach Response

DigiMEDSPA maintains procedures designed to identify, investigate, contain, document, mitigate, and respond to security incidents.

Where an incident involves PHI, DigiMEDSPA follows applicable Business Associate Agreement obligations and legal requirements, including applicable HIPAA breach notification requirements.

DigiMEDSPA works with affected healthcare customers when required to investigate and respond to incidents affecting information under their control.

16

Children’s Privacy

DigiMEDSPA’s public website and business services are not directed to children for independent consumer use.

Patient information involving minors may be processed through the DigiMEDSPA healthcare platform on behalf of authorized healthcare providers as part of legitimate healthcare services.

Such information is treated as healthcare information and protected in accordance with applicable requirements.

17

Your Privacy Rights

Depending on where you reside and the nature of your relationship with DigiMEDSPA, applicable law may provide privacy rights regarding certain personal information.

These may include rights to:

  • Request access
  • Request correction
  • Request deletion where applicable
  • Obtain information regarding certain uses or disclosures
  • Opt out of certain communications
  • Exercise other rights provided by applicable law

Different rules may apply to PHI maintained by healthcare providers.

Patients seeking to exercise HIPAA rights relating to their healthcare records should generally contact the healthcare provider responsible for those records.

18

California Privacy Rights

California residents may have rights under applicable California privacy laws concerning personal information that is not otherwise exempt or governed by other applicable laws.

Depending on applicability, these rights may include requesting information regarding personal information collected, requesting correction or deletion, and exercising other applicable privacy rights.

Certain medical information and PHI may be governed by HIPAA or other healthcare privacy laws rather than general consumer privacy provisions.

DigiMEDSPA will not discriminate against an individual for exercising applicable privacy rights.

19

Sale of Personal Information

DigiMEDSPA does not sell Protected Health Information.

DigiMEDSPA does not sell patient medical records.

DigiMEDSPA does not sell PHI processed on behalf of its healthcare customers for advertising or marketing purposes.

20

International Processing

DigiMEDSPA primarily provides services to healthcare organizations in the United States.

Where information is processed by authorized service providers, DigiMEDSPA evaluates applicable privacy, security, contractual, and regulatory considerations appropriate to the information involved.

PHI is processed only through authorized systems and services approved for the applicable healthcare workflow.

21

Changes to This Privacy Policy

DigiMEDSPA may update this Privacy Policy periodically to reflect changes in:

  • Our products and services
  • Technology
  • Security practices
  • Privacy practices
  • Regulatory requirements
  • Native AI capabilities
  • Business operations

When material changes are made, we may update the effective date above and provide additional notice when appropriate.

22

Business Associate Agreement Information

DigiMEDSPA enters into Business Associate Agreements with eligible healthcare organizations where required under HIPAA.

Healthcare organizations evaluating DigiMEDSPA or existing customers seeking BAA information may contact DigiMEDSPA.

Please do not include patient information or Protected Health Information in a general website inquiry or BAA request form.

23

Security & HIPAA Information

Additional information regarding DigiMEDSPA’s healthcare security practices, HIPAA compliance, Native AI security, PHI safeguards, and Business Associate Agreements is available through our Security & HIPAA Center.

24

Contact Us

Questions regarding this Privacy Policy, DigiMEDSPA’s privacy practices, HIPAA, security, or Business Associate Agreements may be directed to:

  • DigiMEDSPA, Inc.
  • Websitewww.digimedspa.com
  • Privacy & Security Inquiriessecurity@digimedspa.com
  • Business Associate Agreement Requests

Please do not transmit patient information or Protected Health Information through ordinary email or general website contact forms unless DigiMEDSPA specifically provides an approved secure method for doing so.

DigiMEDSPA, Inc.

Native AI + EMR + Practice Management for Modern Healthcare Practices

HIPAA Compliant. Secure. Connected. Native AI.