Legal

Privacy Policy

How ZScribe handles personal and health information when you check in, complete intake forms, book a visit, or join a telehealth room — and what your clinic controls versus what we control.

Effective July 23, 2026

The short version

  • Your clinic owns your record

    We process your health information only on your clinic's instructions. Your clinic's Notice of Privacy Practices governs your record — ask them for access, copies, or corrections.

  • We never sell your data

    We do not sell personal or health information, do not use it for advertising, and do not use patient data to train public or third-party AI models.

  • No health details in text messages

    SMS from ZScribe carries a secure link and nothing else. Diagnoses, medications, and visit details never appear in a message body.

  • Shared kiosks clear themselves

    Lobby kiosk sessions time out and wipe the on-screen session so the next patient never sees what you entered.

01

Who we are, and which parts of this policy apply to you

ZScribe is clinical software built by Z360. Clinics, practices, and health organisations license ZScribe to run scheduling, patient check-in, intake forms, document capture, charting, and patient communication.

We hold two very different roles depending on whose data is involved, and it matters which one applies to you:

Patient health information — we act as a Business Associate
When you complete an intake form, check in at a kiosk, upload an insurance card, or join a telehealth visit, the clinic is the HIPAA Covered Entity and the owner of that record. We handle that information only as a Business Associate, under a written Business Associate Agreement, and only to perform services for your clinic.
Clinic staff accounts and website visitors — we act as the controller
When a staff member creates a ZScribe account, or when someone browses our marketing site or contacts our sales team, we decide how that limited business information is used. Sections 3, 10, and 12 apply to that data.

02

Patients: your clinic controls your health record

Because your clinic — not ZScribe — is the custodian of your medical record, HIPAA rights are exercised through your clinic. Contact your clinic to:

  • Request access to, or a copy of, your health record.
  • Ask for a correction or amendment to information you believe is wrong.
  • Request an accounting of disclosures of your health information.
  • Request restrictions on how your information is used or shared.
  • Request confidential communication through a specific channel or address.
  • File a complaint about how your health information was handled.

If you send us a request directly, we will forward it to your clinic and support them in responding. We cannot release, amend, or delete a clinical record on our own — doing so without the clinic's instruction would breach both our agreement with them and medical record retention law.

03

Information we collect

Information you provide during check-in, intake, booking, or a telehealth visit:

  • Identity and contact details — name, date of birth, address, phone number, email address, preferred language, and emergency contact.
  • Insurance and coverage details — payer, member ID, group number, subscriber relationship, and photographs of the front and back of an insurance card.
  • Identity documents — photographs of a driver's licence, state ID, or passport where your clinic requires identity verification.
  • Health information — reason for visit, symptoms, medical and surgical history, current medications, allergies, family history, and answers to any questionnaire your clinic has configured.
  • Consents and signatures — the consent forms you review, the electronic signature you draw or type, and the date, time, and IP address captured with it as proof of signing.
  • Payments — where your clinic has enabled payment collection, card details are entered directly into our payment processor and are never stored on ZScribe servers.
  • Feedback and messages — reviews, survey answers, and messages you send through the patient portal.

Information we receive from your clinic:

  • Your appointment details, assigned provider, visit type, and location.
  • Existing demographic and chart information the clinic has already recorded for you.
  • Records synced from the clinic's other systems, such as an EPD or EHR integration the clinic has connected.

Information collected automatically when you use our patient-facing pages:

  • Device and browser type, operating system, screen size, and approximate time zone.
  • IP address, page timestamps, and the actions taken in a session — recorded as an audit trail so your clinic can evidence who accessed what and when.
  • Strictly necessary cookies and local session storage used to keep your place in a form. We do not run advertising or cross-site tracking technology on kiosk, check-in, intake, booking, or telehealth pages.

04

How we use information

We use patient information only to deliver the service your clinic has asked us to provide, and for the narrow set of purposes a Business Associate Agreement permits:

  • Run check-in, intake, booking, telehealth, and patient portal workflows for your clinic.
  • Place the information you submit into your clinic's chart so your care team sees it before your visit.
  • Read documents you photograph — such as an ID or insurance card — so the details are filled in for you instead of typed by hand.
  • Send appointment reminders, intake requests, follow-ups, and visit summaries by email or SMS on your clinic's behalf.
  • Generate PDFs of completed forms, signed consents, and visit documents for the clinic record.
  • Maintain security, prevent fraud and abuse, diagnose faults, and keep an audit trail your clinic can review.
  • Meet our legal obligations and support your clinic in meeting theirs.

05

AI-assisted features and human review

ZScribe uses AI to reduce typing, not to make decisions. Two features touch patient information:

Document extraction
When you photograph an ID or insurance card, the image is sent to our AI provider to read the printed fields. The extracted values are shown back to you or to clinic staff for confirmation before anything is saved. Nothing is written to the record without a human accepting it.
Visit preparation and drafting
Where your clinic has enabled it, AI drafts a summary of the information you submitted so the clinician can review it faster. A drafted summary is never the medical record until a clinician reviews, edits, and signs it.

Our AI processing runs through enterprise API endpoints under contractual terms that prohibit the provider from using our submissions to train their models, and we configure zero data retention where the provider offers it. AI output is always advisory. A clinician remains responsible for every clinical decision.

Where your clinic has enabled AI features that require your agreement, you are asked for consent during intake and can decline. Declining does not stop you completing your paperwork — it just means the fields are typed rather than read automatically.

06

When we share information

We share patient information in a deliberately short list of situations:

  • With your clinic — the staff members your clinic has authorised, scoped by their role in the system.
  • With service providers acting on our behalf — cloud hosting and database infrastructure, our AI document-reading provider, email delivery, SMS delivery, secure fax, and payment processing. Each is bound by a Business Associate Agreement or equivalent data protection agreement, may use the data only to perform the service, and may not use it for their own purposes.
  • With systems your clinic connects — where your clinic has enabled an EHR, EPD, or practice management integration, information flows to that system on the clinic's instruction and under the clinic's agreement with that vendor.
  • When the law requires it — in response to a valid subpoena, court order, or lawful government request, and only after confirming the request's validity and, where permitted, notifying the clinic.
  • To prevent serious harm — where disclosure is necessary to prevent an imminent threat to health or safety, as permitted by HIPAA.
  • In a business transfer — if ZScribe is acquired or merged, patient information moves with the service under the same protections, and clinics are notified.

We do not disclose patient information to anyone else without your clinic's instruction or your authorisation. A current list of our subprocessors is available to clinics on request.

07

Email and text messages

Your clinic may send you appointment reminders, intake requests, check-in links, and follow-ups through ZScribe.

  • SMS messages are link-only. They carry your clinic's name and a secure link, and never a diagnosis, medication, test result, or visit detail. Health information stays behind the link, on an encrypted page.
  • Reply STOP to any text message to opt out of further messages, or HELP for assistance. Message and data rates from your mobile carrier may apply.
  • Email may contain more detail than SMS where your clinic has determined it is appropriate. Email is not a fully secure channel — tell your clinic if you would prefer to be contacted another way.
  • Opting out of reminders does not opt you out of messages your clinic must send you for your care or for legal reasons.

08

How we protect information

ZScribe is architected against the HIPAA Security Rule's administrative, physical, and technical safeguards. We hold no formal certification today, and we will not imply otherwise — see our Security page for our honest, per-framework posture. Controls we operate:

  • Encryption in transit using TLS 1.2 or higher, and encryption at rest for stored records and uploaded documents.
  • Strict tenant isolation — every query is scoped to a single organisation, so one clinic cannot read another clinic's data.
  • Role-based access control, so a staff member sees only what their role requires.
  • Audit logging of access to patient records, retained for clinic review.
  • Multi-factor authentication available on staff accounts, and session timeouts on shared devices.
  • Least-privilege internal access — our engineers do not browse patient records, and production access is limited, logged, and used only to resolve a reported fault.
  • Regular dependency patching, code review, and automated security checks in our release pipeline.

No system is perfectly secure. We do not claim ZScribe is immune to attack — we claim that we design against known risk, monitor for it, and tell the truth when something goes wrong.

09

Shared devices, lobby kiosks, and public computers

Lobby kiosks are used by many patients in the same day, so they get extra handling:

  • A kiosk session times out after a period of inactivity and returns to the welcome screen, clearing what was on screen.
  • Completed kiosk sessions are cleared when you finish, so the next patient does not see your answers.
  • Kiosk pages do not keep a browsing history trail of your entries in the device's browser storage after the session ends.
  • Legal pages such as this one open in a new tab from a kiosk, so reading them does not discard paperwork you have already filled in.

If you are using your own phone or a home computer on a shared device, close the tab when you are done and avoid saving the link in a browser others can access.

10

How long we keep information

Patient health information is retained for as long as your clinic instructs us to retain it, which is generally set by the medical record retention period in the clinic's state or country. We do not set that period, and we do not delete clinical records on our own initiative.

  • When a clinic's agreement with us ends, we return or securely destroy the patient information we hold for them, as directed in the Business Associate Agreement.
  • Audit logs are retained for the period the clinic's compliance obligations require.
  • Incomplete kiosk and intake sessions that are abandoned are purged on a rolling schedule.
  • Backups are retained on a rolling window and are encrypted; deleted records age out of backups as that window rolls forward.
  • Marketing contact details for staff and prospective clinics are kept until you unsubscribe or ask us to delete them.

11

Your privacy rights

Which rights apply depends on which category your information falls into.

HIPAA rights (health information)
Access, copies, amendment, accounting of disclosures, restriction requests, confidential communication, and the right to complain. Exercise these through your clinic — see section 2.
US state privacy rights (non-health information)
Residents of states with comprehensive privacy laws — including California, Colorado, Connecticut, Texas, Utah, and Virginia — have rights to know, access, correct, delete, and opt out of sale or targeted advertising. We do not sell personal information or use it for targeted advertising, so there is nothing to opt out of. Note that information already regulated by HIPAA is generally exempt from these state laws and is handled under HIPAA instead.
GDPR and UK GDPR
Where these apply, our clinic customers are the controller and we are the processor. Individuals may exercise access, rectification, erasure, restriction, portability, and objection rights through the clinic, and we will assist the clinic in responding.

To ask about the information we hold about you as a staff user or website visitor, contact privacy@z360.biz. We may need to verify your identity before acting, and we will not discriminate against you for exercising a privacy right.

You may also complain to the US Department of Health and Human Services Office for Civil Rights, or to your local data protection authority, and we will not retaliate for a complaint.

12

Children's information

Clinics use ZScribe to treat patients of every age, including children. Where a patient is a minor, intake and consent are completed by a parent, legal guardian, or authorised personal representative, and the resulting record is handled under the same protections as any other patient record.

We do not knowingly collect information directly from a child through our marketing site, and we do not build advertising profiles of anyone, of any age.

13

Where information is processed

Patient records and uploaded documents are stored with our cloud infrastructure providers in the region we have agreed with the clinic. Some of our service providers and our own team may access information from other countries in order to operate and support the service.

Where information moves across borders, we rely on appropriate safeguards — including Standard Contractual Clauses — and apply the same technical and contractual protections regardless of where processing takes place.

14

Changes to this policy

We update this policy when the service or the law changes. The effective date at the top of this page always reflects the current version.

For material changes that affect how patient information is handled, we notify clinics in advance so they can review the change and inform their patients. Continuing to use ZScribe after a change takes effect means the updated policy applies.

15

Contact us

About your own medical record
Contact your clinic. They hold and control your record, and they are the only party who can release, amend, or delete it.
Privacy questions and HIPAA enquiries
privacy@z360.biz — routed to our Privacy Officer.
Security disclosures
security@z360.biz — we respond to good-faith vulnerability reports and will not pursue researchers who report responsibly.
Postal mail
Z360 — Attn: Privacy Officer, Lahore, Pakistan