Sign In

AttendMD Privacy Policy

Effective Date: March 10, 2026

Last Updated: July 14, 2026

AttendMD, Inc. (“AttendMD,” “we,” “us,” or “our”) provides healthcare operations software, applications, dashboards, integrations, and related services to healthcare and behavioral health organizations.

This Privacy Policy explains how AttendMD collects, receives, accesses, uses, discloses, protects, retains, and deletes information through:

  • The AttendMD public website;
  • The AttendMD software platform and applications;
  • Customer-configured integrations;
  • Demonstrations, support, onboarding, and other business communications; and
  • Other services that link to this Privacy Policy.

1. Important distinction between AttendMD and healthcare providers

AttendMD is a healthcare technology and operations software company. AttendMD does not provide medical, behavioral health, substance-use-disorder, diagnostic, emergency, or treatment services through its public website.

When a healthcare organization provides a user with access to AttendMD, that organization generally determines what information is placed in the service, why the information is processed, who may access it, and how long it must be retained. In that context, the healthcare organization is generally the controller or responsible organization, and AttendMD processes the information on its behalf.

This Privacy Policy is not a healthcare provider’s HIPAA Notice of Privacy Practices and does not replace a customer organization’s patient privacy notices, consent forms, authorizations, or other legal obligations.

When AttendMD processes protected health information or other regulated healthcare information under a Business Associate Agreement, qualified service organization agreement, data-processing agreement, or other customer contract, the applicable agreement controls in the event of a conflict with this Privacy Policy.

2. Information covered by this policy

For purposes of this Privacy Policy:

“Personal Information” means information that identifies, relates to, describes, or can reasonably be linked to a person or household.

“Customer Data” means information submitted to, received by, generated through, or processed within AttendMD on behalf of a customer organization.

“Protected Health Information” or “PHI” has the meaning assigned under the Health Insurance Portability and Accountability Act and its implementing regulations.

“Part 2 Records” means patient-identifying information protected by 42 C.F.R. Part 2 concerning substance-use-disorder diagnosis, treatment, or referral for treatment.

“Google User Data” means information AttendMD receives through a customer-authorized Google API connection.

Information that has been properly deidentified or aggregated so that it cannot reasonably identify an individual is not treated as Personal Information to the extent permitted by applicable law.

3. Information we collect

Depending on how the website, platform, and integrations are used, AttendMD may collect or process the following categories of information.

A. Account and organization information

This may include:

  • Name;
  • Business email address and telephone number;
  • Employer or organization;
  • Job title and professional role;
  • Facility and organizational assignments;
  • Username and authentication information;
  • Role-based permissions;
  • Multi-factor-authentication status;
  • Account settings and preferences; and
  • Records concerning account creation, modification, suspension, or termination.

B. Customer operational and healthcare information

Customers may configure AttendMD to process operational or healthcare-related information, including:

  • Attendance and participation information;
  • Admission and discharge information;
  • Scheduling information;
  • Facility census and utilization data;
  • Referral and admissions workflow information;
  • Billing, claims, revenue-cycle, and payment-status information;
  • Financial and operational reporting information;
  • Marketing-source and performance information;
  • Call-tracking and customer-relationship-management information;
  • Quality, compliance, and performance information; and
  • Other information a customer instructs AttendMD to process.

Depending on the customer’s use of the service, Customer Data may include PHI, Part 2 Records, mental health information, information about minors, disability information, financial information, or other sensitive information.

C. Website, device, security, and usage information

AttendMD may automatically collect:

  • Internet Protocol address;
  • Browser and device type;
  • Operating system;
  • Approximate location inferred from an Internet Protocol address;
  • Referring and exit pages;
  • Pages or features accessed;
  • Dates and times of access;
  • Session information;
  • Login attempts and authentication events;
  • Audit and administrative events;
  • Error reports and diagnostic information;
  • Feature-use and system-interaction information; and
  • Security, fraud-prevention, and performance information.

D. Integration information

When authorized by a customer, AttendMD may receive information from connected services, including:

  • Electronic health record or electronic medical record systems;
  • Scheduling and admissions systems;
  • Billing and revenue-cycle systems;
  • Accounting and financial systems;
  • Customer-relationship-management systems;
  • Call-tracking systems;
  • Marketing and analytics systems;
  • Payment-processing systems; and
  • Other customer-selected vendors.

The information received depends on the customer’s configuration, the connected provider, and the permissions granted.

E. Communications and support information

AttendMD may collect information submitted through:

  • Demonstration or contact requests;
  • Customer-support requests;
  • Implementation and onboarding communications;
  • Training sessions;
  • Security or privacy inquiries;
  • Surveys and product feedback; and
  • Other communications with AttendMD.

Do not submit PHI, Part 2 Records, or other sensitive patient information through AttendMD’s public website forms or ordinary email unless AttendMD has expressly designated the communication method for that purpose and your organization has authorized its use.

F. Commercial and billing information

AttendMD may process customer subscription information, invoices, payment status, contract information, and related business records. When a third-party payment processor is used, that processor may collect payment-card or banking information directly under its own privacy policy.

4. Sources of information

AttendMD may obtain information:

  • Directly from website visitors and users;
  • From customer organizations and their authorized personnel;
  • Automatically from devices, browsers, and use of the service;
  • From customer-authorized integrations;
  • From AttendMD’s service providers;
  • From business partners or referral sources; and
  • From publicly available business and professional sources.

5. How we use information

AttendMD may use information to:

  • Provide, operate, administer, and support the service;
  • Create and manage accounts;
  • Authenticate users and enforce permissions;
  • Configure organizations, facilities, integrations, and workflows;
  • Generate customer-requested dashboards, reports, and analytics;
  • Support interoperability and data-exchange functions;
  • Process customer-authorized operational workflows;
  • Provide demonstrations, implementation, training, and support;
  • Communicate about service notices, security matters, and customer relationships;
  • Monitor availability, performance, reliability, and accessibility;
  • Maintain audit records and system integrity;
  • Detect, investigate, prevent, and respond to fraud, misuse, and security incidents;
  • Enforce contracts and acceptable-use requirements;
  • Comply with legal and regulatory obligations;
  • Protect the rights, safety, and property of AttendMD, customers, users, and others; and
  • Improve the service using information permitted by applicable law and customer agreements.

AttendMD does not sell PHI or Part 2 Records. AttendMD does not use PHI or Part 2 Records for third-party targeted advertising.

AttendMD may use deidentified or aggregated information for security, service measurement, capacity planning, product improvement, and lawful business analytics when permitted by applicable law and the applicable customer agreement. AttendMD will not attempt to reidentify information that has been deidentified in accordance with applicable legal requirements.

6. HIPAA and protected health information

When AttendMD creates, receives, maintains, or transmits PHI on behalf of a HIPAA covered entity or another business associate, AttendMD acts as a business associate and processes the PHI under:

  • The applicable Business Associate Agreement;
  • The customer’s lawful instructions;
  • The HIPAA Privacy, Security, and Breach Notification Rules; and
  • Other applicable federal and state requirements.

AttendMD uses and discloses PHI only as permitted by the applicable Business Associate Agreement or as required by law. AttendMD requires subcontractors that create, receive, maintain, or transmit PHI on AttendMD’s behalf to provide legally required privacy and security assurances.

Customer organizations remain responsible for matters within their control, including determining authorized users, assigning appropriate permissions, obtaining patient consents or authorizations, maintaining patient-facing Notices of Privacy Practices, responding to patient requests, and configuring AttendMD consistently with their legal and professional obligations.

7. Substance-use-disorder information and 42 C.F.R. Part 2

When AttendMD receives or processes Part 2 Records for a federally assisted substance-use-disorder program, AttendMD will process those records only as permitted by:

  • 42 C.F.R. Part 2;
  • Applicable patient consent;
  • A qualified service organization agreement, Business Associate Agreement, or other legally sufficient agreement;
  • The lawful instructions of the Part 2 program or other lawful holder; and
  • Applicable federal and state law.

AttendMD may act as a qualified service organization or business associate when the applicable legal and contractual requirements are satisfied.

AttendMD does not independently authorize the disclosure of Part 2 Records for law-enforcement, civil, criminal, administrative, or legislative proceedings. Requests involving Part 2 Records are evaluated with the responsible customer and are handled only as permitted by applicable law.

Where required, AttendMD will preserve applicable restrictions, notices, and protections associated with Part 2 Records. Nothing in this Privacy Policy authorizes a use or disclosure prohibited by 42 C.F.R. Part 2.

8. Mental health information and Massachusetts confidentiality requirements

Customer Data may include mental health records or communications protected by Massachusetts law, professional confidentiality requirements, privilege rules, or facility-specific regulations.

AttendMD processes such information only under the direction of the responsible customer and in accordance with applicable agreements and law. When federal and Massachusetts requirements differ, AttendMD and the customer must apply the requirement providing the applicable protection or restriction.

AttendMD does not determine whether a provider may disclose a patient’s mental health information. That determination remains the responsibility of the provider or other legally responsible organization.

9. When information may be disclosed

AttendMD may disclose information in the following circumstances.

A. To the responsible customer organization

Customer Data may be made available to the customer organization and its authorized users according to customer-configured roles, facilities, and permissions.

B. To service providers and subprocessors

AttendMD may use service providers for functions such as:

  • Cloud infrastructure;
  • Database services;
  • Authentication;
  • Encrypted secret storage;
  • Application hosting;
  • Security monitoring;
  • Error detection;
  • Communications;
  • Customer support; and
  • Other technical and operational services.

Service providers may process information only to perform services for AttendMD and are subject to applicable contractual confidentiality, privacy, and security requirements. When a service provider handles PHI or Part 2 Records, AttendMD will require the agreement legally appropriate to that relationship.

C. Through customer-authorized integrations

When a customer enables an integration, AttendMD may exchange information with the selected provider as necessary to perform the requested function. The third-party provider’s own privacy policy, terms, security practices, and contractual relationship with the customer may also apply.

D. At the customer’s direction or with authorization

AttendMD may disclose information when directed by the responsible customer, authorized by the affected person, or otherwise permitted under the applicable customer agreement and law.

E. For legal, compliance, and safety purposes

AttendMD may preserve, use, or disclose information when reasonably necessary to:

  • Comply with applicable law or a valid legal process;
  • Respond to regulatory or governmental requests;
  • Enforce contracts;
  • Protect the service and its users;
  • Investigate suspected fraud, misuse, or security incidents; or
  • Protect rights, safety, or property.

Any disclosure of PHI or Part 2 Records under this section will occur only when permitted by the applicable healthcare privacy requirements. AttendMD may challenge, narrow, or resist a request when appropriate or legally required.

F. Business transactions

Information may be reviewed or transferred in connection with a merger, financing, acquisition, reorganization, sale of assets, or similar transaction, subject to applicable confidentiality obligations and healthcare privacy restrictions. A successor receiving regulated Customer Data must assume the applicable contractual and legal obligations.

10. No sale of personal or healthcare information

AttendMD does not sell:

  • Customer Data;
  • PHI;
  • Part 2 Records;
  • Google User Data; or
  • Personal Information collected through the AttendMD service.

AttendMD does not disclose those categories to data brokers, advertising networks, or unrelated third parties for their independent advertising use.

11. Google User Data

This section specifically describes AttendMD’s optional Google Ads and Google Analytics 4 integrations.

The integrations are initiated by an authorized customer user and may be disconnected at any time. AttendMD does not use Google as an AttendMD sign-in provider.

A. Google data AttendMD accesses

For Google Ads, AttendMD may access:

  • Google Ads customer identifiers and account names available to the authorizing user;
  • Manager-account relationships and the manager identifier needed to route a reporting request;
  • Account-manager, status, and test-account classifications used to validate account selection;
  • Campaign identifiers and campaign names; and
  • Aggregated campaign metrics, including impressions, clicks, advertising cost, and conversions for a customer-selected date range.

For Google Analytics 4, AttendMD may access:

  • Analytics account and property identifiers and display names;
  • Source, medium, and campaign dimensions; and
  • Aggregated metrics such as sessions, total users, and key events or conversions for a customer-selected date range.

AttendMD does not request event-level or individual-user Google Analytics records for this feature.

AttendMD also receives OAuth authorization information, which may include:

  • The scopes granted;
  • An access token;
  • A refresh token when Google provides one; and
  • Token-expiration information.

AttendMD does not use this integration to access Gmail, Google Drive, Google Calendar, Google Contacts, Google Photos, or other unrelated Google services.

B. Google OAuth scopes

AttendMD uses the Google Ads scope:

https://www.googleapis.com/auth/adwords

Google does not provide a narrower read-only reporting scope for Google Ads. Although the consent screen may describe broader capabilities, AttendMD uses this scope only for account discovery, access verification, and reporting reads.

AttendMD does not use the integration to create, modify, upload, or delete advertisements, campaigns, ad groups, bids, budgets, targeting, schedules, recommendations, or billing settings.

AttendMD uses the following read-only Google Analytics scope:

https://www.googleapis.com/auth/analytics.readonly

C. How AttendMD uses Google User Data

AttendMD uses Google User Data only to:

  • Allow an authorized customer administrator to select an accessible Google Ads account or Google Analytics property;
  • Verify that the authorizing user can access the selected account;
  • Display Google Ads campaign-performance reports;
  • Display Google Analytics acquisition reports;
  • Combine aggregated advertising information with the customer’s own operational data to calculate customer-requested performance metrics;
  • Display integration status; and
  • Diagnose integration errors.

Google User Data is displayed only to authorized users of the customer organization that enabled the connection.

AttendMD does not use Google User Data for:

  • Independent advertising;
  • Advertising profiles;
  • Data brokerage;
  • Lending or credit decisions;
  • Surveillance;
  • Unrelated profiling;
  • Training generalized artificial-intelligence or machine-learning models; or
  • Any purpose unrelated to providing and securing the customer-requested integration.

D. Google data storage and processing

Google OAuth credentials and integration metadata are processed in AttendMD’s Supabase environment.

OAuth tokens are encrypted at rest in Supabase Vault. Tokens are decrypted briefly in server memory only when needed to make an authorized Google API request. OAuth credentials are not returned to the browser and are not stored in client-side code.

Google report responses are fetched on demand and transmitted to the authorized user’s current AttendMD session for display. Under AttendMD’s current architecture, Google Ads and Google Analytics report rows are not persistently stored in AttendMD’s application database or browser storage.

Amazon Web Services hosts and delivers AttendMD’s static web-application files. Under the current Google integration architecture, AttendMD does not send Google OAuth credentials or Google API report payloads to Amazon Web Services or Amazon Bedrock.

E. Google data disclosures

Google User Data may be disclosed only to:

  • Authorized users within the customer organization that enabled the connection; and
  • AttendMD’s contracted infrastructure provider, Supabase, to provide authentication, database services, encrypted secret storage, and server-side integration functions.

AttendMD does not disclose Google User Data to:

  • Data brokers;
  • Advertisers or advertising networks;
  • Other AttendMD customers;
  • Unrelated third parties;
  • Generative artificial-intelligence providers; or
  • Third parties for their independent use.

F. Google data security

AttendMD uses safeguards designed to protect Google User Data, including:

  • Encrypted network transmission;
  • Encryption of OAuth credentials at rest;
  • Server-side API requests;
  • Organization-, facility-, and role-based access controls;
  • Database-level row security;
  • Multi-factor authentication for authorized integration changes;
  • Short-lived user sessions;
  • Audit logging; and
  • Controls designed to prevent browser access to integration secrets.

G. Google data retention, disconnection, and deletion

Google report rows are not retained in AttendMD’s application database or browser storage after the live request and current display session.

OAuth credentials are retained only while the applicable provider-and-facility connection remains active. When an authorized user disconnects or replaces the connection, AttendMD permanently deletes the locally stored access and refresh tokens associated with that connection and stops further access through that connection.

A disabled connection record and limited security, operational, or audit metadata may be retained for the life of the customer account or longer when reasonably necessary for legal, contractual, security, fraud-prevention, or accountability purposes. Such records will not contain a usable OAuth credential after token deletion.

Disconnecting one provider-and-facility connection does not automatically disconnect separately authorized connections for other facilities or providers. A user may revoke the broader Google authorization through the security and third-party-connections settings in the user’s Google Account.

A verified request concerning eligible Google-derived information may be submitted to contact@attendmd.com. AttendMD will coordinate with the customer organization that controls the account and will delete eligible information within 30 days, subject to information that must be retained for legal, security, contractual, or protected audit purposes.

H. Google API Limited Use disclosure

AttendMD’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

12. Cookies, browser storage, and online tracking

AttendMD may use cookies, local browser storage, and similar technologies for:

  • Authentication;
  • Session management;
  • Security;
  • Fraud prevention;
  • User preferences;
  • Interface state;
  • Public-website analytics;
  • Error detection; and
  • Website and platform performance.

AttendMD does not store Google OAuth access tokens, Google refresh tokens, or Google report rows in browser storage.

AttendMD does not intentionally configure third-party advertising technologies to collect PHI or Part 2 Records from authenticated AttendMD application pages. Technologies used in a healthcare context must be evaluated under applicable contracts and healthcare privacy requirements before deployment.

Users may control certain cookies through browser settings or an available cookie-preference tool. Disabling essential cookies may prevent parts of the website or service from functioning.

AttendMD may not respond to every browser “Do Not Track” signal. Where applicable law requires recognition of a legally valid opt-out preference signal, AttendMD will handle the signal as required.

13. Artificial intelligence features

AttendMD may offer separately configured artificial-intelligence or machine-learning features. The data used by such a feature, its purpose, and the applicable service provider will be governed by the customer agreement, applicable Business Associate Agreement or qualified service organization terms, customer configuration, and any feature-specific disclosures.

AttendMD does not send Google OAuth credentials or Google report content to generative artificial-intelligence or machine-learning models.

AttendMD does not use PHI or Part 2 Records to train generalized models except where such use is expressly authorized by the responsible customer and legally permitted. AttendMD will not rely on this Privacy Policy alone as authorization for such use.

14. Data security

AttendMD maintains administrative, technical, and physical safeguards designed to protect information appropriate to its sensitivity and the nature of the service. Safeguards may include:

  • Encryption during transmission;
  • Encryption at rest where appropriate;
  • Role- and facility-based access controls;
  • Organization-level data segregation;
  • Multi-factor authentication;
  • Secure credential and secret management;
  • Audit and security logging;
  • Monitoring and alerting;
  • Vulnerability and patch management;
  • Secure software-development practices;
  • Workforce confidentiality and security requirements;
  • Vendor-risk management;
  • Incident-response procedures;
  • Backup and recovery controls; and
  • A written information security program where required by Massachusetts law.

No transmission, storage system, or security control is guaranteed to be completely secure. Users and customers are responsible for protecting their credentials, using appropriate access settings, promptly removing unnecessary access, and notifying AttendMD of suspected misuse.

15. Security incidents and breach notification

AttendMD maintains procedures for identifying, investigating, mitigating, documenting, and responding to suspected security incidents.

When an incident triggers a legal or contractual notification requirement, AttendMD will provide notice to the responsible customer, affected individuals, government agencies, regulators, or others as required by:

  • The applicable customer agreement;
  • The HIPAA Breach Notification Rule;
  • 42 C.F.R. Part 2;
  • The Federal Trade Commission Health Breach Notification Rule, when applicable;
  • Massachusetts General Laws Chapter 93H;
  • Other applicable state breach-notification laws; or
  • Other applicable requirements.

Notifications will be made within the time and in the manner required by the controlling law or agreement.

16. Data retention and deletion

AttendMD retains information only for as long as reasonably necessary to:

  • Provide and secure the service;
  • Perform the applicable customer agreement;
  • Follow customer instructions;
  • Maintain required business, billing, security, and audit records;
  • Meet healthcare, accounting, tax, legal, and regulatory requirements;
  • Resolve disputes;
  • Investigate incidents; and
  • Enforce agreements.

Retention periods vary according to the type of information, customer configuration, contractual obligations, sensitivity, and applicable law.

Customer Data is returned or deleted in accordance with the applicable service agreement, Business Associate Agreement, qualified service organization terms, and customer instructions. Information may remain temporarily in protected backups until removed through AttendMD’s ordinary backup-deletion cycle.

AttendMD may retain information that it is legally required to preserve or that is reasonably necessary to establish, exercise, or defend legal rights.

Google User Data is subject to the more specific retention and deletion provisions in Section 11.

Google User Data Retention and Deletion

Reporting metrics retrieved from Google are used to render the dashboard and are retained no longer than necessary to provide that feature.

A customer may disconnect a Google integration at any time through Settings → Integrations in AttendMD. Upon disconnection, AttendMD immediately and permanently deletes the stored OAuth access and refresh credentials for that connection and stops all further access to the connected Google account.

A user may also revoke AttendMD’s access directly through their Google Account by navigating to:

Google Account → Security → Your connections to third-party apps and services

To request deletion of any remaining Google-derived data, contact contact@attendmd.com. AttendMD will delete the requested data within 30 days.

17. Individual privacy requests

Depending on applicable law and the nature of the information, an individual may request that AttendMD:

  • Confirm whether AttendMD processes the individual’s Personal Information;
  • Provide access to eligible Personal Information;
  • Correct inaccurate Personal Information;
  • Delete eligible Personal Information;
  • Provide an eligible copy in a portable format;
  • Restrict or object to certain processing; or
  • Withdraw consent when processing is based on consent.

Requests may be submitted to contact@attendmd.com.

AttendMD may verify the requester’s identity and authority before acting. AttendMD may deny or limit a request when permitted or required by law, including when information must be retained for security, legal, contractual, regulatory, audit, or healthcare-record purposes.

Customer-controlled information

When Personal Information is controlled by an AttendMD customer, the individual should submit the request to that customer organization first. AttendMD will assist the customer as required by the applicable agreement and law.

AttendMD will not independently alter or delete a healthcare provider’s records unless instructed by the responsible organization and legally permitted to do so.

AttendMD will not unlawfully discriminate against an individual for exercising an applicable privacy right.

18. Massachusetts residents

AttendMD protects covered personal information about Massachusetts residents in accordance with applicable Massachusetts requirements, including Massachusetts General Laws Chapter 93H and 201 CMR 17.00.

AttendMD will provide or support legally required notice if covered Massachusetts personal information is affected by a security breach. Additional Massachusetts medical-record, mental-health, professional-confidentiality, and substance-use-disorder protections may apply depending on the customer and information involved.

19. Communications and marketing choices

AttendMD may send administrative, transactional, security, support, and service-related communications. These communications may be necessary to operate the service and may not be subject to a marketing opt-out.

Recipients of promotional email may unsubscribe using the instructions in the message or by contacting AttendMD. Unsubscribing from promotional communications will not prevent necessary account, security, legal, or service communications.

20. Children and information about minors

The AttendMD public website and business service are not directed to children for independent consumer use, and AttendMD does not knowingly solicit Personal Information directly from children through the public website.

Healthcare customers may use AttendMD to process information about minors when legally authorized. Such information is controlled by the customer organization and is subject to applicable consent, access, confidentiality, record-retention, and healthcare privacy requirements.

21. Third-party websites and services

The website or platform may contain links to or integrations with third-party websites and services. AttendMD does not control the independent privacy or security practices of those third parties.

Customers and users should review the privacy policies, terms, permissions, and security practices of a third party before enabling an integration or providing information to that party.

22. Changes to this Privacy Policy

AttendMD may update this Privacy Policy to reflect changes in the service, integrations, legal requirements, or privacy and security practices.

AttendMD will post the revised policy with an updated effective date. When required by law or when a change is material, AttendMD may provide additional notice through the service, by email, or through another appropriate method.

Continued use of the service after a change does not constitute consent when applicable law requires a different form of authorization.

23. Contact AttendMD

Questions, privacy requests, security inquiries, and Google-data deletion requests may be submitted to:

AttendMD, Inc.

Email: support@attendmd.com