01
Who we are, and which parts of this policy apply to you
ZScribe is clinical software built by Z360. Clinics, practices, and health organisations license ZScribe to run scheduling, patient check-in, intake forms, document capture, charting, and patient communication.
We hold two very different roles depending on whose data is involved, and it matters which one applies to you:
- Patient health information — we act as a Business Associate
- When you complete an intake form, check in at a kiosk, upload an insurance card, or join a telehealth visit, the clinic is the HIPAA Covered Entity and the owner of that record. We handle that information only as a Business Associate, under a written Business Associate Agreement, and only to perform services for your clinic.
- Clinic staff accounts and website visitors — we act as the controller
- When a staff member creates a ZScribe account, or when someone browses our marketing site or contacts our sales team, we decide how that limited business information is used. Sections 3, 10, and 12 apply to that data.
02
Patients: your clinic controls your health record
Your clinic's Notice of Privacy Practices (NPP) is the document that explains how your health information is used and disclosed for treatment, payment, and healthcare operations. Ask your clinic's front desk or privacy officer for a copy.
Because your clinic — not ZScribe — is the custodian of your medical record, HIPAA rights are exercised through your clinic. Contact your clinic to:
- Request access to, or a copy of, your health record.
- Ask for a correction or amendment to information you believe is wrong.
- Request an accounting of disclosures of your health information.
- Request restrictions on how your information is used or shared.
- Request confidential communication through a specific channel or address.
- File a complaint about how your health information was handled.
If you send us a request directly, we will forward it to your clinic and support them in responding. We cannot release, amend, or delete a clinical record on our own — doing so without the clinic's instruction would breach both our agreement with them and medical record retention law.
03
Information we collect
Information you provide during check-in, intake, booking, or a telehealth visit:
- Identity and contact details — name, date of birth, address, phone number, email address, preferred language, and emergency contact.
- Insurance and coverage details — payer, member ID, group number, subscriber relationship, and photographs of the front and back of an insurance card.
- Identity documents — photographs of a driver's licence, state ID, or passport where your clinic requires identity verification.
- Health information — reason for visit, symptoms, medical and surgical history, current medications, allergies, family history, and answers to any questionnaire your clinic has configured.
- Consents and signatures — the consent forms you review, the electronic signature you draw or type, and the date, time, and IP address captured with it as proof of signing.
- Payments — where your clinic has enabled payment collection, card details are entered directly into our payment processor and are never stored on ZScribe servers.
- Feedback and messages — reviews, survey answers, and messages you send through the patient portal.
Information we receive from your clinic:
- Your appointment details, assigned provider, visit type, and location.
- Existing demographic and chart information the clinic has already recorded for you.
- Records synced from the clinic's other systems, such as an EPD or EHR integration the clinic has connected.
Information collected automatically when you use our patient-facing pages:
- Device and browser type, operating system, screen size, and approximate time zone.
- IP address, page timestamps, and the actions taken in a session — recorded as an audit trail so your clinic can evidence who accessed what and when.
- Strictly necessary cookies and local session storage used to keep your place in a form. We do not run advertising or cross-site tracking technology on kiosk, check-in, intake, booking, or telehealth pages.
04
How we use information
We use patient information only to deliver the service your clinic has asked us to provide, and for the narrow set of purposes a Business Associate Agreement permits:
- Run check-in, intake, booking, telehealth, and patient portal workflows for your clinic.
- Place the information you submit into your clinic's chart so your care team sees it before your visit.
- Read documents you photograph — such as an ID or insurance card — so the details are filled in for you instead of typed by hand.
- Send appointment reminders, intake requests, follow-ups, and visit summaries by email or SMS on your clinic's behalf.
- Generate PDFs of completed forms, signed consents, and visit documents for the clinic record.
- Maintain security, prevent fraud and abuse, diagnose faults, and keep an audit trail your clinic can review.
- Meet our legal obligations and support your clinic in meeting theirs.
We do not sell it. We do not share it with data brokers. We do not use it for advertising, profiling, or lead generation. We do not use it to train public or third-party AI models. And we do not use it for our own product analytics beyond de-identified, aggregate usage counts that cannot be linked back to a patient.
05
AI-assisted features and human review
ZScribe uses AI to reduce typing, not to make decisions. Two features touch patient information:
- Document extraction
- When you photograph an ID or insurance card, the image is sent to our AI provider to read the printed fields. The extracted values are shown back to you or to clinic staff for confirmation before anything is saved. Nothing is written to the record without a human accepting it.
- Visit preparation and drafting
- Where your clinic has enabled it, AI drafts a summary of the information you submitted so the clinician can review it faster. A drafted summary is never the medical record until a clinician reviews, edits, and signs it.
Our AI processing runs through enterprise API endpoints under contractual terms that prohibit the provider from using our submissions to train their models, and we configure zero data retention where the provider offers it. AI output is always advisory. A clinician remains responsible for every clinical decision.
Where your clinic has enabled AI features that require your agreement, you are asked for consent during intake and can decline. Declining does not stop you completing your paperwork — it just means the fields are typed rather than read automatically.
07
Email and text messages
Your clinic may send you appointment reminders, intake requests, check-in links, and follow-ups through ZScribe.
- SMS messages are link-only. They carry your clinic's name and a secure link, and never a diagnosis, medication, test result, or visit detail. Health information stays behind the link, on an encrypted page.
- Reply STOP to any text message to opt out of further messages, or HELP for assistance. Message and data rates from your mobile carrier may apply.
- Email may contain more detail than SMS where your clinic has determined it is appropriate. Email is not a fully secure channel — tell your clinic if you would prefer to be contacted another way.
- Opting out of reminders does not opt you out of messages your clinic must send you for your care or for legal reasons.
08
How we protect information
ZScribe is architected against the HIPAA Security Rule's administrative, physical, and technical safeguards. We hold no formal certification today, and we will not imply otherwise — see our Security page for our honest, per-framework posture. Controls we operate:
- Encryption in transit using TLS 1.2 or higher, and encryption at rest for stored records and uploaded documents.
- Strict tenant isolation — every query is scoped to a single organisation, so one clinic cannot read another clinic's data.
- Role-based access control, so a staff member sees only what their role requires.
- Audit logging of access to patient records, retained for clinic review.
- Multi-factor authentication available on staff accounts, and session timeouts on shared devices.
- Least-privilege internal access — our engineers do not browse patient records, and production access is limited, logged, and used only to resolve a reported fault.
- Regular dependency patching, code review, and automated security checks in our release pipeline.
We notify the affected clinic without unreasonable delay and no later than 60 days after discovering a breach of unsecured protected health information, with the detail HIPAA's Breach Notification Rule requires. Your clinic is responsible for notifying affected patients. Report a suspected vulnerability to security@z360.biz.
No system is perfectly secure. We do not claim ZScribe is immune to attack — we claim that we design against known risk, monitor for it, and tell the truth when something goes wrong.
10
How long we keep information
Patient health information is retained for as long as your clinic instructs us to retain it, which is generally set by the medical record retention period in the clinic's state or country. We do not set that period, and we do not delete clinical records on our own initiative.
- When a clinic's agreement with us ends, we return or securely destroy the patient information we hold for them, as directed in the Business Associate Agreement.
- Audit logs are retained for the period the clinic's compliance obligations require.
- Incomplete kiosk and intake sessions that are abandoned are purged on a rolling schedule.
- Backups are retained on a rolling window and are encrypted; deleted records age out of backups as that window rolls forward.
- Marketing contact details for staff and prospective clinics are kept until you unsubscribe or ask us to delete them.
11
Your privacy rights
Which rights apply depends on which category your information falls into.
- HIPAA rights (health information)
- Access, copies, amendment, accounting of disclosures, restriction requests, confidential communication, and the right to complain. Exercise these through your clinic — see section 2.
- US state privacy rights (non-health information)
- Residents of states with comprehensive privacy laws — including California, Colorado, Connecticut, Texas, Utah, and Virginia — have rights to know, access, correct, delete, and opt out of sale or targeted advertising. We do not sell personal information or use it for targeted advertising, so there is nothing to opt out of. Note that information already regulated by HIPAA is generally exempt from these state laws and is handled under HIPAA instead.
- GDPR and UK GDPR
- Where these apply, our clinic customers are the controller and we are the processor. Individuals may exercise access, rectification, erasure, restriction, portability, and objection rights through the clinic, and we will assist the clinic in responding.
To ask about the information we hold about you as a staff user or website visitor, contact privacy@z360.biz. We may need to verify your identity before acting, and we will not discriminate against you for exercising a privacy right.
You may also complain to the US Department of Health and Human Services Office for Civil Rights, or to your local data protection authority, and we will not retaliate for a complaint.
12
Children's information
Clinics use ZScribe to treat patients of every age, including children. Where a patient is a minor, intake and consent are completed by a parent, legal guardian, or authorised personal representative, and the resulting record is handled under the same protections as any other patient record.
We do not knowingly collect information directly from a child through our marketing site, and we do not build advertising profiles of anyone, of any age.
13
Where information is processed
Patient records and uploaded documents are stored with our cloud infrastructure providers in the region we have agreed with the clinic. Some of our service providers and our own team may access information from other countries in order to operate and support the service.
Where information moves across borders, we rely on appropriate safeguards — including Standard Contractual Clauses — and apply the same technical and contractual protections regardless of where processing takes place.
14
Changes to this policy
We update this policy when the service or the law changes. The effective date at the top of this page always reflects the current version.
For material changes that affect how patient information is handled, we notify clinics in advance so they can review the change and inform their patients. Continuing to use ZScribe after a change takes effect means the updated policy applies.
15
Contact us
- About your own medical record
- Contact your clinic. They hold and control your record, and they are the only party who can release, amend, or delete it.
- Privacy questions and HIPAA enquiries
- privacy@z360.biz — routed to our Privacy Officer.
- Security disclosures
- security@z360.biz — we respond to good-faith vulnerability reports and will not pursue researchers who report responsibly.
- Postal mail
- Z360 — Attn: Privacy Officer, Lahore, Pakistan