Privacy Policy
Ayra Health ("we," "us," "our") provides AI-powered claim risk intelligence software to medical practices. This Privacy Policy explains how we handle information when you visit our website (ayrahealth.ai) and when you use our software platform under a service agreement with your practice.
HIPAA-regulated data. When Ayra processes Protected Health Information (PHI) on behalf of a covered entity, we operate as a Business Associate under a signed Business Associate Agreement (BAA). The terms of that BAA — not this Privacy Policy — govern how PHI is handled.
1. Information We Collect
1.1 Information you provide on this website
If you contact us via the email link on our home page, we receive the contents of your email and your email address. We use this information solely to respond to your inquiry.
1.2 Information collected automatically on this website
- Standard server logs (IP address, browser type, pages visited, referring URL, timestamp)
- Aggregated, non-identifying analytics about site usage (if analytics are enabled)
We do not use third-party advertising trackers or sell visitor data.
1.3 Information processed through our software platform
When your medical practice uses Ayra under a service agreement, the platform processes data your practice authorizes us to receive from your electronic medical record (EMR) system. This may include patient demographic data, encounter records, claim information, insurance information, and clinical documentation. All such data is handled exclusively under the terms of the executed BAA between Ayra Health and your practice.
2. How We Use Information
- To respond to inquiries you send us
- To provide, maintain, and improve our software platform
- To detect, prevent, and respond to fraud, abuse, and security incidents
- To comply with legal obligations including HIPAA, HITECH, and applicable state laws
We do not sell, rent, or share PHI for marketing purposes. We do not use PHI to train general-purpose AI models.
3. Data Security
We maintain administrative, physical, and technical safeguards consistent with HIPAA Security Rule requirements, including:
- Encryption of PHI in transit (TLS 1.2+) and at rest (AES-256)
- Role-based access controls and audit logging of all PHI access
- Multi-factor authentication for administrative accounts
- Regular security reviews and penetration testing
- Background checks and HIPAA training for all employees with PHI access
4. Data Sharing and Subprocessors
We share PHI only as authorized by your practice's BAA, and only with subprocessors who have signed BAAs with us. Current categories of subprocessors include:
- Cloud infrastructure: Amazon Web Services (under AWS BAA)
- EMR integrations: Athena Health (under Athena's data use agreement)
- AI processing: Anthropic (under Anthropic's commercial Zero Data Retention terms; PHI is de-identified before transmission)
A current list of subprocessors is available upon request. We do not transfer PHI outside the United States.
5. Data Retention
Data processed through our platform is retained for the duration of the service agreement with your practice plus the period required by HIPAA and applicable state law. Upon termination of the service agreement, data is returned to your practice or securely destroyed in accordance with the BAA.
Website inquiry emails are retained for up to 24 months unless you request earlier deletion.
6. Your Rights
If you are a patient whose PHI is processed by Ayra on behalf of your medical practice, please direct questions about your records, access requests, or amendments to your medical practice. Your practice is the covered entity under HIPAA and is the appropriate point of contact for individual rights requests.
If you are a website visitor, you may request that we delete the contents of any inquiry you sent us by emailing hello@ayrahealth.ai.
7. Cookies
Our website uses only essential cookies required for basic site functionality (for example, to remember your authenticated session if you sign into the application). We do not use advertising cookies or third-party tracking cookies on the marketing website.
The application platform (app.ayrahealth.ai) uses an authentication session cookie. This cookie is essential for the secure operation of the platform and is governed by your practice's service agreement.
8. Children's Privacy
The Ayra Health website and platform are not directed at children under 13 and we do not knowingly collect personal information from children through the website.
9. Changes to this Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top. For material changes, we will provide notice through the website or directly to your practice administrator.
10. Contact
Questions about this Privacy Policy or our privacy practices can be sent to:
Ayra Health
hello@ayrahealth.ai
Disclaimer: This Privacy Policy is a template that should be reviewed and customized by qualified legal counsel before publication. Healthcare-specific legal review is strongly recommended given HIPAA and state privacy law obligations.