Privacy Policy — Pretium Health Solutions
Pretium Health Solutions
Privacy Policy
Effective date: 8/1/2026 | Last updated: 7/25/2026
Pretium Health Solutions (“Pretium,” “we,” “us,” or “our”) provides a cloud-based electronic health record (EHR) and practice-management platform for healthcare organizations (the “Platform”), together with our website at pretiumhealthsolutions.com (the “Site”). This Privacy Policy explains how we collect, use, disclose, and safeguard information when you visit the Site, create an account, or use the Platform, and describes the choices available to you. By using the Site or Platform, you agree to the practices described in this Policy.
1. Our role under HIPAA
Pretium provides technology services to healthcare providers (“Clinics”). When a Clinic uses the Platform to create, receive, maintain, or transmit protected health information (“PHI”) about its patients, Pretium acts as a business associate of that Clinic under the Health Insurance Portability and Accountability Act (“HIPAA”), and our handling of that PHI is governed by the Business Associate Agreement (“BAA”) we sign with each Clinic and by HIPAA — not by this Privacy Policy. If you are a patient, your healthcare provider’s Notice of Privacy Practices describes how your health information is used and disclosed; questions or requests about your medical records should be directed to your provider.
2. Information we collect
Information you provide
Account and contact information such as name, work email address, phone number, professional role, and organization details when a Clinic registers for or administers the Platform; billing information processed through our payment processor; communications you send to us, including support requests; and, where applicable, a patient’s mobile phone number and communication preferences collected by a Clinic during patient registration for the purpose of appointment communications.
Information collected automatically
When you use the Site or Platform we automatically collect technical information such as IP address, browser type, device identifiers, operating system, pages viewed, access times, and referring URLs. We use cookies and similar technologies for authentication, security, and analytics. You can adjust browser settings to refuse cookies, though parts of the Site or Platform may not function properly without them.
Protected health information
PHI entered into the Platform by Clinics and their authorized users is processed on behalf of the Clinic under the applicable BAA, is encrypted in transit and at rest, and is used only as permitted by the BAA and HIPAA.
3. How we use information
We use the information described above to provide, operate, secure, and improve the Site and Platform; to authenticate users and manage accounts; to process subscription payments; to send transactional communications such as service notices, security alerts, and — on behalf of Clinics — appointment reminders and confirmations; to respond to inquiries and provide support; to monitor for and prevent fraud, abuse, and security incidents; to comply with legal, regulatory, and contractual obligations, including HIPAA; and to analyze usage in aggregated or de-identified form to improve our services.
4. SMS / text messaging
With patient consent obtained during registration with a participating Clinic, we send transactional SMS messages such as appointment reminders and appointment confirmations from our toll-free number on behalf of that Clinic. Message frequency varies based on scheduled appointments. Message and data rates may apply. Patients may reply STOP at any time to opt out of SMS messages and HELP for assistance, or contact their Clinic to update communication preferences. Consent to receive SMS messages is not a condition of receiving healthcare services.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties, except as necessary to deliver the messages through our SMS service providers.
5. How we share information
We do not sell personal information. We share information only in the following circumstances: with service providers who perform services on our behalf — such as cloud hosting (Microsoft Azure), payment processing (Stripe), communications delivery, and analytics — under contracts that restrict their use of the information and, where PHI is involved, under business associate agreements; with the Clinic that controls the relevant account or patient relationship; when required by law, subpoena, or other legal process, or when we believe disclosure is necessary to protect rights, safety, or the integrity of our services; in connection with a merger, acquisition, financing, or sale of assets, subject to confidentiality protections and, for PHI, HIPAA requirements; and with your consent or at your direction.
6. Security
We maintain administrative, technical, and physical safeguards designed to protect information against unauthorized access, use, or disclosure, including encryption of data in transit and at rest, role-based access controls, multi-factor authentication for administrative access, network isolation, audit logging, continuous security monitoring, and workforce training. No method of transmission or storage is completely secure; we cannot guarantee absolute security, but we work continuously to protect your information and to meet the requirements of HIPAA and industry standards.
7. Data retention
We retain personal information for as long as needed to provide the services, comply with legal and contractual obligations (including HIPAA and state medical-record retention requirements applicable to our Clinic customers), resolve disputes, and enforce agreements. PHI is retained and returned or destroyed in accordance with the applicable BAA. Audit records are retained for a minimum of six years consistent with HIPAA requirements.
8. Your choices and rights
Depending on your jurisdiction, you may have rights to access, correct, delete, or receive a copy of personal information we hold about you, or to object to or restrict certain processing. Account holders can review and update account information through the Platform or by contacting us. Patients should direct requests concerning their medical records to their healthcare provider, which controls that information; we will assist Clinics in fulfilling such requests as required by our BAAs. To exercise rights regarding information Pretium controls, contact us using the details below. We will respond consistent with applicable law.
9. Children’s privacy
The Site and Platform are intended for use by healthcare organizations and their authorized users, not by children. We do not knowingly collect personal information directly from children under 13. Health information about minors entered by a Clinic is handled as PHI under the applicable BAA and HIPAA.
10. Third-party links
The Site or Platform may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties, and we encourage you to review their privacy policies.
11. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated effective date, and, where appropriate, notified to account administrators. Your continued use of the Site or Platform after changes take effect constitutes acceptance of the revised Policy.
12. Contact us
Pretium Health Solutions
Email: sales@pretiumhealthsolutions.com
Phone: 470779-2933
© 2026 Pretium Health Solutions | Terms and Conditions
