Provider Privacy Notice

OutcomeMD provides a patient outcome tracking and management platform to help patients and their healthcare providers understand treatment results in order to enhance care and communication.

This Platform Privacy Notice explains how OutcomeMD may collect, use, disclose, and secure information obtained through our website, located at www.outcomemd.com (the “Site”); our cloud-based patient outcome tracking and management platform, located at www.portal.outcomemd.com (the “Platform”); and web-enabled emails sent as part of, in connection with, or relating to such software and information services (collectively, the “Service”).  The terms “OutcomeMD,” “we,” “us,” and/or “our” include OutcomeMD, Inc. and our affiliates and subsidiaries.  This Platform Privacy Notice is incorporated by reference into the OutcomeMD Site Terms and OutcomeMD Services Agreement, as applicable, and any capitalized terms used and not defined in this Provider Privacy Notice shall have the meaning given to those capitalized terms in that agreement.

This Provider Privacy Notice applies to information we collect and use for our own purposes, including information we collect from and about visitors to our Site, customers when they register for and access their OutcomeMD account, and individuals in relation to our marketing activities. This Provider Privacy Notice does not apply to the data we process under contract as a service provider to healthcare organizations and clinicians. When we store, process, or transmit protected health information (as defined by HIPAA) on behalf of a healthcare organization or clinician who has entered into an OutcomeMD Services Agreement or other agreement, as applicable, we do so as its “business associate” (as also defined by HIPAA) and our use of that data is limited by our agreement with that healthcare organization and/or clinician.

“Personal Information” means information that alone or when in combination with other information may be used to readily identify, contact, or locate you, such as: name, address, email address, or phone number.  We collect Personal Information when you register to use the Service, use the Service, or communicate with us.  We may also receive Personal Information about you from the healthcare organization that employs you.  In addition, we collect information, such as anonymous usage statistics, by using cookies, server logs, and other similar technology as you use the Service.


THE SERVICE COLLECTS YOUR INFORMATION

Filling in Forms. When you fill in forms on our Site including when you request additional information about our Service, request a demo, or contact our sales team, we may require that you provide us with your contact information such as your name, job title, company name, email address, physical address, and phone number. We may also ask for additional information such as the number of members on your team, how you heard about OutcomeMD, and which electronic health records provider you use.

Purchasing a Subscription. Depending on your agreement with us, we may require that you provide us or our third-party payment processor with your billing information, including payment card information or other forms of payment. By submitting this information, you expressly consent to the sharing of your information with third-party payment processors and other third-party services (including but not limited to vendors who provide fraud detection services). In general, we do not store your payment card information, but we may receive limited information from our third-party payment processors, such as the last four digits of your card, the country of issuance, and the expiration date.

Registering and Creating an Account.  If you become an OutcomeMD customer, we will provide you with an invitation link that will give you access to the OutcomeMD Platform. We will ask that you create a password for your account and populate your profile with certain Personal Information, including your name, email address, and mobile phone number. We also ask for information about the healthcare organization you service, including the organization’s name, business address, and office phone number.

Using the Service.  We collect information you provide when you use the Service, which may include information you submit when you upload a document, image, or other data file or send a message to another user. If you use our Marketing Services, we ask that you provide URLs for your personal or healthcare organizations’s website and Facebook, Yelp, Twitter, and Google Reviews pages.

Signing Up to Receive Product Newsletters, Offers, and Usage Tips or Completing a Survey. When you engage in any of these activities, we may collect your name, contact details, areas of expertise, interests, and any information you provide to us as part of that request (such as information about your satisfaction with our Service in response to a survey).

Communicating with Us.  We may collect Personal Information through your communications with our customer support team or through other communications with us, including through social media.  Please note that we may record sales and customer service calls for quality assurance, training, and operational purposes. These recordings may be transcribed and analyzed using AI transcription tools, provided by third-party platforms such as Zoom. These third-party platforms may access or use transcripts in accordance with their own privacy notices. We encourage you to review the privacy notices of any third-party platforms used in your communications with us. Any data we collect through these interactions will be handled in accordance with this Provider Privacy Notice.  

Surveys, Clinical Trials, and Research. We may contact you to ask if you are interested in participating in a survey, clinical trial, or other research study. For example, if you have appropriate experience and have agreed to be contacted about potentially serving as a clinical trial investigator, we may share your Personal Information (such as your name and business email) with clinical trial teams so they can follow up with you directly. If you choose to participate, the research team will provide its own consent and privacy documentation. If you choose to participate in a survey conducted by OutcomeMD, you may be asked to provide demographic details, professional feedback, or other relevant information. Participation is entirely voluntary, and your responses will be used only for the purposes described in this Provide Privacy Notice or clearly disclosed to you at the time of the request. Survey results may be published in aggregated, de-identified form.

Information from Your Computer or Mobile Device.  The Service automatically collects information about your device, such as its model, operating system, browser version and add-ons, device ID and features, cookie IDs and your internet service provider or your mobile carrier, so that we can provide and customize functionality.

Automatic Data Collection: Cookies and Related Technologies.  When you visit our Service or open our emails, we and our third-party partners, such as analytics providers, may collect certain information by automated means, such as cookies, web beacons and web server logs.  The information collected in this manner includes IP address, browser characteristics, device IDs and characteristics, operating system version, language preferences, referring URLs, and information about the usage of our Service. We may use this information, for example, to determine how many users have visited certain pages or opened messages or newsletters, or to prevent fraud.  We may link this data to your profile.  Our third-party partners also may collect information about your online activities over time, on other devices, and on other websites or apps, if those websites and apps also use the same partners.  When they provide such services, they are governed by their own privacy policies.  We may use Google Analytics to collect and process certain Service usage data.  Google provides additional privacy options regarding cookie use described at www.google.com/policies/privacy/partners/.

Another Individual at Your Organization. We may collect your Personal Information from another individual at your organization who may provide us with your business contact information in order to invite you to create a user account on our Platform.

Publicly Available Sources and Other Third Parties. We may obtain Personal Information about you from other sources, including public records, publicly available information on internet sites, and third parties that help up update, expand, analyze our records.

Third-Party Services. Our Service allows users to enable a variety of third-party services on the Platform. Once enabled, the provider of a third-party service may share certain information with OutcomeMD, such as the username and email address associated with that user on the third-party service as well as additional information that the third-party service has chosen to make available to OutcomeMD to facilitate the integration. You should check the privacy settings and privacy notices of these third-party services to understand what information may be shared with us.

Third-Party Authentication Providers. OutcomeMD allows you to sign up and log in to our Service using third-party authentication providers such as DrChrono. If you choose to sign up and log in in this manner, the third-party authentication provider will ask your permission to share certain information with us, including your name and email address. You can control the information that we receive from third-party authentication providers using the privacy settings in your accounts with those providers. In some cases, such as when using our embedded applications within your electronic health record (EHR) provider’s platform, you may be required to authenticate with your EHR provider in order to enable or access the integration.

Online Events. From time to time, we may host webinars or other online events. To enable these events, we stream video and audio feed of interactions between participants as well as the contents of any communications enabled by integrated chat features within any third-party services that we use to provide the events. This includes collecting your image, voice, movements, physical environment, and any other information provided during the event. Occasionally, we may record events and make those recording accessible to other OutcomeMD users or the general public. If we do so, we will indicate that the event will be recorded.

 

HOW OUTCOMEMD USES YOUR INFORMATION

We use Personal Information to facilitate and improve our services or to communicate with you on our behalf and on behalf of healthcare organizations and providers.

Providing the Service. We use information, including Personal Information in order to provide you with the Service if you are or become an OutcomeMD customer, including creating your account and identifying you at sign-in.

Internal and Service-Related Usage.  Subject to potential limitations in our other agreements, by using the Service, you authorize us to gather, process, analyze, and retain data related to the provision of the Service.  We use this information, including Personal Information, for internal and Service-related purposes, such as to operate, evaluate, and improve our business or the Service and to identify and protect against fraud, misuse of our Service, or other unlawful behavior.  We may also use and retain data to develop new functionality and features; measure the effectiveness of our content, programs, and advertising; and improve our networking, marketing, social, and recruitment strategies.

Data Analysis. We analyze the information we collect to provide our Service, such as providing reports to our customers. To the extent permitted by law and our agreements with healthcare organizations and clinicians, we may de-identify and/or aggregate information, and use and disclose it for business purposes (for example, to perform research and provide statistical information and data regarding trends to our partners).

Our Communications.  We use Personal Information to communicate with you including by sending email to the email address you provide to us, push notifications to your mobile device if they are enabled, and/or text messages to your mobile device to verify your account and for informational and operational purposes, such as account management, reminders, customer service, system maintenance, and other Service-related purposes.

Marketing.  We may use information, including Personal Information, to send you information about our products and services we think you may be interested in, including promotional materials and information about events, programs, offers, surveys, and market research.  You may opt out of email marketing by using the unsubscribe link in a marketing email.

Personalization. We may use Personal Information to provide you with more relevant content, including features, content, assessments, programs, and advertising.

Consent. We use information, including Personal Information, to carry out any other purpose described to you at the time the information was collected.


OUTCOMEMD MAY DISCLOSE YOUR INFORMATION

We may share your Personal Information with our third-party vendors and service providers; to comply with legal obligations; to protect and defend our rights and property; and with your permission.

We do not rent, sell, or share Personal Information about you with other people or non-affiliated companies for their direct marketing purposes, unless we have your permission.

With Third-Party Vendors and Service Providers.  We may share any information we receive with the third-party vendors and service providers we use to help us provide and improve the Service.  For example, we will provide Personal Information to service providers that provide web and database hosting services.  We will require any vendor or service provider receiving your Personal Information to respect the privacy of your Personal Information.

With Third Parties at the Direction of Healthcare Organizations and Clinicians.  If you are healthcare organization or clinician, pursuant to our agreement, we may share information with third parties you have elected to establish integrations with, or who seek to establish integrations with you and to facilitate, maintain, and monitor the utilization of such integrations.

Marketing.  We do not rent, sell, or share Personal Information about you that we collect on the Service with other people or non-affiliated companies for their direct marketing purposes, unless we have your explicit permission.

Legal and Similar Disclosures.  We may access, preserve, and disclose collected information, if we believe doing so is required or appropriate to: comply with law enforcement requests and legal process, such as a court order or subpoena; respond to your requests; comply with the law; or protect your, our, or others’ rights, property, or safety.

Merger, Sale, or Other Asset Transfers.  If we are involved in a merger, acquisition, financing due diligence, reorganization, bankruptcy, receivership, sale of OutcomeMD assets, or transition of service to another provider, your information may be disclosed in connection with the negotiation of such transaction, and/or sold or transferred as part of such a transaction as permitted by law and/or contract.  We cannot control how such entities may use or disclose such information.

Companies Under Common Control. We may share information, including Personal Information, between and among any current or future parents, subsidiaries, affiliates, and other companies under common control and ownership with OutcomeMD.

With Your Permission.  We may also disclose your Personal Information with your permission.

De-identified Information. We may also share aggregate or de-identified information, which cannot reasonably be used to identify you, for various purposes including compliance with various reporting obligations; for business or marketing purposes; or to assist third parties in understanding our users’ habits and usage patterns for certain features, content, services, advertisements, promotions, and/or functionality available through the Service.

 

YOUR CHOICES AND INFORMATION RETENTION

Access, Correction, and Deletion. You may have the right to request access to and be informed about the information we maintain about you, update and correct inaccuracies in your information, and have the information deleted, as appropriate. If you wish to request access or an update to the information that we have concerning you, please email us at privacy@outcomemd.com.  Your rights to your information may be limited in some circumstances by local legal requirements and our agreements with healthcare organizations and clinicians. Note however that if you exercise your right of deletion, decline to share certain information with us, or withdraw your consent to our use of certain information, we may not be able to provide to you some of the features and functionalities of the Service.

Promotional Communications. You may opt out of receiving our promotional emails and texts at any time. You may do so by submitting a request to privacy@outcomemd.com, adjusting the text and notification preferences in your mobile device’s settings, or by following the opt-out instructions in the promotional emails or texts we send you. Please be aware that it may take up to 10 days for us to process your request and you may continue receiving promotional communications from us during that period. Even after you opt out of receiving certain messages from us, you may continue to receive administrative messages from us regarding the Service (such as emails related to our business relationship or emails about changes to our legal terms). You may turn off push notifications through your device settings.

Account Termination. Subject to the terms of your agreement with us, you may terminate your account by contacting customer support at privacy@outcomemd.com. We will retain information in accordance with any agreements we have with applicable healthcare organizations and clinicians. We will continue to use de-identified and/or aggregated information, for business purposes as permitted under applicable law and to comply with our legal obligations, agreements with healthcare organizations and clinicians, resolve disputes, enforce our rights, or similar purposes.

Restricting Cookies/Do Not Track. Please be aware that OutcomeMD does not change its behavior in response to web browser “do not track” signals. However, you can configure most browsers to reject cookies or to notify you when you are sent a cookie, giving you a chance to decide whether or not to accept it. You can consult the help section of your browser to learn how to do this. Please note that if you choose to remove or reject cookies, this could affect the availability and functionality of our Service.

 

ADDITIONAL DISCLOSURES FOR U.S. RESIDENTS

Certain U.S. state privacy laws – such as those in California, Colorado, Virginia, Connecticut, and other applicable jurisdictions – require businesses to provide certain disclosures to residents, including (i) the categories of Personal Information collected, (ii) the purposes for which Personal Information is used or disclosed, (iii) the categories of third parties with whom Personal Information is shared, (iv) your rights with respect to your Personal Information, including the rights to access, delete, correct, or opt out of certain data processing, and (v) how you can exercise those rights. To the extent these laws apply, we provide those disclosures below.

 

Notice of Collection

While this information is covered in greater detail above, the categories of Personal Information that we have collected – as described by the California Consumer Privacy Act – are:

·       Identifiers, such as your name, email address, phone number, address, online identifiers (like social media usernames), and IP address.

·       Other individual records, such as your name and signature (for instance, if requested and provided as part of a survey or product research).

·       Protected Characteristics, such as age, self-identified gender, and race/ethnicity (for instance, if requested and provided as part of a survey or product research). 

·       Commercial information, such as usage data and account details related to our platform.  

·       Internet or other electronic network activity, such as authentication details, event timestamps, and behavioral patterns.

·       Audio, Electronic, Visual, or Similar Information, such an information collected if you call us on a recorded line or participate recorded meetings and webinars.

·       Inferences, such as information about your interests and preferences derived from your activity on the Service.

·       Sensitive Personal Information, such as age (over 40 years) or ethnicity if requested and provided as part of a survey or product research.

Business or Commercial Purpose for Collecting and Using Personal Information

We collect each category of Personal Information listed above for the business or commercial purposes described in section above titled “The Service Collects Your Information”.

Categories of Sources of Personal Information

We collect each category of Personal Information listed above directly from you, through automatic data collection means, or through the third-party sources described in the section above titled, “The Service Collects Your Information”.

Categories of Personal Information Disclosed

In the preceding 12 months, we have disclosed the categories of Personal Information listed above in the circumstances described in the section above titled, “OutcomeMD May Disclose Your Information”.

Right to Know

You have the right to request information about the categories and specific pieces of Personal Information we collect, use, disclose, and sell.

Right to Delete

You can request that your Personal Information be deleted, including from any third parties to whom your Personal Information has been sold, shared, or disclosed.

Right to Correct

You can request that we rectify, correct, or update your Personal Information. 

Right to Opt-Out

You can opt out of processing for:

·       sales of your Personal Information;

·       sharing of your Personal Information for the purpose of cross-context behavioral advertising; and

·       profiling or the use automated decision-making technology in furtherance of decisions that produce legal or similarly significant effect.  

We do not “sell” your Personal Information for monetary consideration. However, we may disclose Personal Information (in the form of identifiers and internet activity information) with third-party advertising and analytics partners who may use this information to provide services to us and for their own purposes. Depending on the nature of these disclosures and our contractual arrangements, such activities may be considered a “sale” or “sharing” of Personal Information under California law.

You have the right to direct us not to sell or share your Personal Information. You can exercise this right by emailing us using the contact information below or by using the Global Privacy Control (GPC). You can also adjust your cookie preferences to decline all non-essential cookies on our Services. If you notify us of your preference through GPC, we will honor your request with respect to the browser or device that sends us the GPC signal. If you are logged in, your preference will be associated with your account and if you log in from another device or browser, you will be automatically opted out. However, if you are not logged into your account, your request will only be associated with the browser you are currently using.

If you believe a decision about you was made solely using automated tools and would like to request a human review or learn more, please contact us using the contact details below.

Universal Opt-Out

In some states, we must honor universal opt-out preference signals.

As mentioned, above, you can opt out of targeted advertising by using the GPC. If you notify us of your preference through GPC, we will honor your request with respect to the browser or device that sends us the GPC signal. If you are logged in, your preference will be associated with your account and if you log in from another device or browser, you will be automatically opted out. However, if you are not logged into your account, your request will only be associated with the browser you are currently using. 

Sensitive Data Consent

In some states, we must obtain your opt-in consent before processing sensitive data (e.g., race/ethnicity, precise geolocation, health data, etc.). Where required, we will request this consent before colleting or using such data. 

Right to Limit Use of Sensitive Personal Information

You can request to limit the use of “sensitive personal information” to only what is necessary for providing goods or services.

Non-Discrimination

You have the right not to receive discriminatory treatment by us for the exercise of your rights conferred by the law of the state where you reside.

Authorized Agent

Only you, or someone legally authorized to act on your behalf, may make a verifiable consumer request related to your Personal Information. To designate an authorized agent, please contact us as set forth in “Contact Us” below and provide written authorization signed by you and your designated agent.

Response Time & Extension

We will respond to your request within the time period required by applicable law. Generally, this is within 45 days, with a possible extension of another 45 days, if reasonably necessary. Where required, we will also acknowledge receipt of your request within the applicable time period. Generally, this is10 business days.

Right of Appeal

If we deny (or otherwise refuse to act on) your request to exercise your rights, we will provide you with information our reasons for not taking action and any rights you may have to appeal our decision or contact the attorney general for the state in which you reside.  

“Do Not Track” Disclosure

Do Not Track (“DNT”) is a privacy preference that users can set in certain web browsers. Please note that we do not respond to or honor DNT signals or similar mechanisms transmitted by web browsers. In the event that a universally accepted standard emerges on how organizations should respond to “do not track” or similar opt-out signals, we will assess and provide an appropriate response to those signals.

“Shine the Light”

The California “Shine the Light” law permits users who are California residents to request and obtain from us once a year, free of charge, a list of the third parties to whom we have disclosed their personal information (if any) for their direct marketing purposes in the prior calendar year, as well as the type of personal information disclosed to those parties.

 

THIRD PARTY SERVICES

The Service may contain links to external websites or services. Your use of any third-party site or service, including the submission of Personal Information, will be governed by the terms and conditions of the such third party.  OUTCOMEMD IS NOT RESPONSIBLE FOR THE PRACTICES OR CONTENT OF ANY THIRD-PARTY, EVEN IF WE PROVIDE A LINK FROM OUR SERVICE.

 

INFORMATION SECURITY

We seek to use reasonable organizational, technical, and administrative measures to protect your information, including to secure protected health information in compliance with HIPAA. Unfortunately, no data transmission or storage system can be guaranteed to be 100% secure. If you have reason to believe that your interaction with us is no longer secure (for example, if you feel that the security of any account with us has been compromised), please immediately notify us of the problem by contacting us using the contact information below.

By using the Service or providing Personal Information to us, you agree that we may communicate with you electronically regarding security, privacy, and administrative issues relating to your use of the Service.  If we learn of a security system’s breach, we may attempt to notify you electronically by posting a notice on the Service or sending an email to you.

 

CHILDREN’S PRIVACY

The Service is intended to be used by adults. Parents or legal guardians may use the Service to provide health information about their children, including those under the age of 13. In some cases, a child may interact with the Service directly, such as when a mobile number is provided by a parent or clinician. Where we collect health information on behalf of a clinician, such collection is governed by HIPAA. Outside of that context, we do not knowingly collect Personal Information from children under 13 without parental consent.

 

INTERNATIONAL USERS

Data is processed and stored in the United States.

The Service is not targeted to users outside of the United States.  If you are using the Service, you agree to the transfer of your information to the United States and processing globally. By providing your information you consent to any transfer and processing in accordance with this Provider Privacy Notice.

 

UPDATE YOUR INFORMATION OR POSE A QUESTION OR SUGGESTION

If you would like to request that we update or correct any information that you have provided to us through your use of the Service or otherwise, or if you have suggestions for improving this Provider Privacy Notice, please send an email to privacy@outcomemd.com.

 

CHANGES TO PROVIDER PRIVACY NOTICE

We may revise this Provider Privacy Notice, so please be sure to review it periodically.

Posting of Revised Provider Privacy Notice. We will post any adjustments to the Provider Privacy Notice on this web page, and the revised version will be effective when it is posted.

New Uses of Personal Information. From time to time, we may desire to use Personal Information for uses not previously disclosed in our Provider Privacy Notice.  If our practices change regarding previously collected Personal Information in a way that would be materially less restrictive than stated in the version of this Provider Privacy Notice in effect at the time we collected the information, we will make reasonable efforts to provide notice and obtain consent to any such uses as may be required by law.

 

 

Last updated: October 27, 2025

 

Contact Information
OutcomeMD, Inc.
7500 Rialto Boulevard, Suite 1-250
Austin, TX 78735

privacy@outcomemd.com