FirstAssistantAI, Inc. — Clinical Decision Support Platform
FirstAssistantAI, Inc. ("Company," "we," "us," or "our") is committed to protecting the privacy of healthcare professionals and their patients. This Privacy Policy describes how we collect, use, disclose, and protect information in connection with the FirstAssistantAI clinical decision support platform (the "Platform").
When you register for an account, we collect:
When you use the Platform to score and document surgical cases, we collect the clinical variables, scoring inputs, intraoperative findings, procedure details, and patient outcome data you enter. This data may constitute PHI and is governed by our Business Associate Agreement. We store case data in association with your account and do not share it with other providers or third parties except as described in Section 4 or as required by law.
Surgery dates are a HIPAA-identified date element. The Platform does not store the specific date of surgery. Instead, we store the surgery year and the number of days elapsed since surgery, which are non-identifying temporal variables under the HIPAA Safe Harbor de-identification standard (45 C.F.R. § 164.514(b)).
When you enroll patients in the PROMs program, we collect validated outcome measure responses (mHHS, IKDC, ASES, and similar instruments) submitted by patients through tokenized, time-limited links. These links contain no PHI and expire after use. PROMs responses are linked to the associated case record under your account and are treated as PHI subject to the BAA.
When you accept the Terms of Service, BAA, or this Privacy Policy, we record the acceptance timestamp (server-generated), your IP address, browser and device information (user agent), and the specific version of each document accepted. The Business Associate Agreement is executed by electronic signature, so we additionally record the full legal name you type as your signature; the Terms of Service and Privacy Policy are accepted by checkbox (clickwrap) and do not require a typed signature. These records are retained in an append-only ledger as evidence of your legal acknowledgment, consistent with HIPAA documentation requirements (45 C.F.R. § 164.530(j)) and the E-SIGN Act (15 U.S.C. § 7001 et seq.).
We automatically collect certain technical data when you use the Platform, including:
This data is used to operate, maintain, secure, and improve the Platform. It does not constitute PHI and is not associated with patient records.
If you contact us by email or through the Platform, we retain your communications and our responses for customer service and product improvement purposes. Communications related to PHI breaches or legal matters are retained as required by law.
| Purpose | Information Used | Legal Basis |
|---|---|---|
| Provide and operate the Platform | Account info, clinical case data, usage data | Performance of contract; HIPAA BAA |
| Generate scoring outputs and clinical decision support recommendations | Clinical case inputs | Performance of contract; HIPAA BAA |
| Send PROMs enrollment and follow-up communications to patients | Patient email (via tokenized link only; no PHI transmitted to patient outside tokenized link) | Performance of contract; HIPAA BAA |
| Send weekly clinical summary emails to surgeons | Account info, aggregate case activity data | Performance of contract; legitimate interest |
| Improve, validate, and train Platform algorithms | De-identified aggregate data only (Safe Harbor standard) | Legitimate interest; Terms of Service consent |
| Clinical research and publication | De-identified aggregate data only | Legitimate interest; Terms of Service consent |
| Billing and subscription management | Payment and account information | Performance of contract |
| Security, fraud prevention, and abuse detection | Usage data, account info, technical data | Legitimate interest; legal obligation |
| Maintain legal acknowledgment records | Acceptance timestamps, typed name, IP, user agent, document version | Legal obligation (HIPAA, E-SIGN Act) |
| Customer support and communications | Account info, communications | Legitimate interest; performance of contract |
| Legal compliance and enforcement | All categories as necessary | Legal obligation; legitimate interest |
We de-identify clinical case data in accordance with the HIPAA Safe Harbor method (45 C.F.R. § 164.514(b)), under which all eighteen categories of HIPAA-specified identifiers are removed or transformed before any use or disclosure outside the Platform. De-identified data is not PHI and is not subject to HIPAA restrictions or this Privacy Policy's PHI-specific protections.
We may use de-identified aggregate data for:
By accepting the Terms of Service, you expressly consent to FirstAssistantAI's use of your de-identified data as described above. FirstAssistantAI, Inc. retains full and exclusive ownership of all de-identified data and all statistical, aggregate, and derivative outputs generated from such data. This consent is irrevocable with respect to data already de-identified, because de-identified data cannot be re-linked to you and therefore cannot be selectively withdrawn.
We do not sell your personal information or PHI. We may disclose information only as follows:
We engage trusted third-party service providers to operate the Platform. These parties process information only on our behalf, under our instructions, and subject to confidentiality obligations. Before any protected health information (PHI) is processed through a subprocessor, we require an executed HIPAA Business Associate Agreement with that subprocessor. Features that would route PHI through a subprocessor whose BAA is not yet executed (for example, patient-reported outcome collection) remain disabled until that agreement is in place.
| Subprocessor | Purpose | PHI Access | BAA Status |
|---|---|---|---|
| Supabase, Inc. | Primary database, authentication, transactional email | Yes (once PHI features are enabled) | Pending — will be executed before any PHI is processed |
| Vercel, Inc. | Application hosting, serverless functions, edge network | Yes (once PHI features are enabled) | Pending — will be executed before any PHI is processed |
| Google LLC (Workspace) | Email delivery via Gmail SMTP: account emails, weekly digests, and patient-facing PROMs enrollment links (tokenized link only; no clinical data in message body) | Limited — recipient email addresses; no case data | Executed (Google Workspace BAA) |
| Google LLC (Cloud / Vertex AI) | AI model inference (Anthropic Claude hosted by Google Cloud) for dictation parsing, pinned to a U.S. region | Potential — de-identified clinical text today; PHI only after full BAA chain is complete | Executed (Google Cloud BAA) |
| Payment Processor | Subscription billing and payment processing (currently dormant — the Platform is free) | No — no PHI transmitted to payment processor | N/A |
We will notify you of material changes to subprocessors that handle PHI no less than thirty (30) days before the change takes effect, and we will update this table accordingly. The current authoritative subprocessor list is maintained in our BAA.
We may disclose information if required to do so by applicable law, valid court order, subpoena, government regulation, or regulatory investigation, or if we believe in good faith that disclosure is necessary to: (i) comply with a legal obligation; (ii) protect the rights, property, or safety of the Company, our users, or the public; or (iii) detect, prevent, or address fraud, security, or technical issues. We will notify you of any such disclosure to the extent permitted by law.
In connection with a merger, acquisition, reorganization, or sale of all or substantially all of the Company's assets, your information — including PHI — may be transferred to a successor entity. Any such transfer of PHI requires: (i) that the successor execute a HIPAA-compliant BAA before receiving any PHI; (ii) that the successor be bound by this Privacy Policy or provide you with protections at least as strong; and (iii) that we provide you with advance written notice of the transfer and any material changes to data handling practices no less than thirty (30) days before such transfer takes effect.
We may disclose information for any other purpose with your explicit, documented prior written consent. Consent may be withdrawn for future processing but does not affect disclosures already made in reliance on prior consent.
We implement administrative, physical, and technical safeguards designed to protect your information and PHI against unauthorized access, use, alteration, and destruction, consistent with HIPAA Security Rule requirements (45 C.F.R. Part 164, Subpart C). Safeguards include:
No method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security. You are responsible for maintaining the security of your account credentials and for notifying us promptly at security@firstassistantai.com of any suspected unauthorized access or PHI exposure.
We retain information for the following minimum periods:
| Data Category | Retention Period | Basis |
|---|---|---|
| Account information (non-PHI) | Duration of account plus 7 years after closure | Business records; applicable law |
| Clinical case data (PHI) | Duration of account plus 7 years, or as required by applicable state medical records law, whichever is longer | HIPAA; state medical records law |
| PROMs response data (PHI) | Duration of account plus 7 years, or applicable state law, whichever is longer | HIPAA; state medical records law |
| De-identified aggregate data | Indefinitely — no longer subject to HIPAA retention limits once de-identified under Safe Harbor | Company IP; legitimate interest |
| Legal acknowledgment records (ToS, BAA acceptance) | Minimum 6 years from last effective date | 45 C.F.R. § 164.530(j); E-SIGN Act |
| Usage and technical logs | Up to 2 years | Security; operational need |
| Payment and billing records | 7 years | IRS; applicable financial law |
| Security incident records | 6 years from date of discovery | 45 C.F.R. § 164.530(j) |
Upon account closure, we will return or securely destroy your PHI as described in the BAA within thirty (30) days of your written request, subject to legal hold obligations. You may request early deletion of non-PHI personal information as described in Section 7.
Depending on your jurisdiction, you may have the following rights regarding your personal information (distinct from PHI, which is governed by HIPAA and the BAA):
To exercise any right, contact us at legal@firstassistantai.com. We will respond within thirty (30) days. We may require reasonable verification of your identity before processing requests. Some requests may be limited by our legal obligations, the rights of other parties, or the inherent limitations of de-identification (de-identified data cannot be re-linked to you and therefore cannot be subject to access or deletion requests).
Regarding patient PHI: patients seeking to exercise HIPAA rights (access, amendment, or accounting of disclosures) must contact their treating clinician, who is the Covered Entity responsible for the patient relationship. We will cooperate with Covered Entities in facilitating patient rights requests as required by HIPAA.
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), may provide you with additional rights.
We do not sell or share your personal information as those terms are defined under the CCPA/CPRA. We do not use your personal information for cross-context behavioral advertising. We do not use sensitive personal information for purposes beyond those necessary to provide the Platform.
California residents may exercise the following rights in addition to those described in Section 7: the right to know what personal information is collected and how it is used; the right to delete personal information (subject to exceptions); the right to correct inaccurate personal information; the right to opt out of sale or sharing (not applicable, as we do not sell); and the right to non-discrimination for exercising privacy rights.
To submit a California privacy request, contact us at legal@firstassistantai.com with subject line "California Privacy Request." Note that PHI submitted through the Platform is exempt from CCPA under the HIPAA exemption (Cal. Civ. Code § 1798.145(c)(1)(A)).
We use cookies and similar technologies to operate and improve the Platform. Types include:
We do not use advertising cookies, retargeting pixels, or share usage data with advertising networks. The Platform does not display third-party advertisements. We do not engage in cross-site tracking.
As part of your agreement to the Terms of Service, you consent to receive the following communications from FirstAssistantAI:
We do not send unsolicited marketing emails. We do not share your email address with third parties for marketing purposes.
The Platform is intended exclusively for licensed healthcare professionals aged 18 or older and is not directed to, or intended for use by, individuals under the age of 18. We do not knowingly collect personal information from minors. If we learn that we have collected information from a person under 18 who is not a licensed healthcare professional, we will promptly delete such information and terminate the associated account. If you believe we may have collected information from a minor in error, contact us at legal@firstassistantai.com.
The Platform is operated in the United States and is primarily intended for use by healthcare professionals licensed in the United States. If you access the Platform from outside the United States, your information may be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your jurisdiction. By using the Platform, you consent to such transfer and processing.
Healthcare professionals in the European Economic Area (EEA), United Kingdom, or Switzerland who are subject to the EU General Data Protection Regulation (GDPR) or equivalent legislation should contact us at legal@firstassistantai.com to discuss applicable data transfer mechanisms (such as Standard Contractual Clauses) and any additional rights that may apply, including the right to lodge a complaint with a supervisory authority.
This Privacy Policy is governed by the laws of the State of Delaware, without regard to its conflict of law provisions. Any dispute arising out of or relating to this Privacy Policy or our data practices is subject to the binding-arbitration and class-action-waiver provisions of our Terms of Service (Section 15), except that either party may seek injunctive or other equitable relief in the state or federal courts located in Delaware.
Nothing in this section limits your rights to lodge a complaint with a government supervisory or regulatory authority in your jurisdiction, including the U.S. Federal Trade Commission, applicable state attorneys general, or, for EEA residents, the relevant data protection authority.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by email to your registered address no less than thirty (30) days before the effective date of the change, and by posting an updated policy with a revised version identifier and effective date.
Your continued use of the Platform after the effective date of any change constitutes your acceptance of the updated policy. Where changes materially affect how we handle PHI, we will provide advance notice as required and, where required by HIPAA or applicable law, obtain your renewed consent through the platform's legal acknowledgment flow.
We maintain a version-controlled history of all Privacy Policy versions. Prior versions are available upon request by contacting legal@firstassistantai.com.
For privacy questions, concerns, access requests, or to report a suspected data incident:
| Privacy & Legal | legal@firstassistantai.com General privacy questions, rights requests, legal inquiries |
| Security Incidents | security@firstassistantai.com Suspected PHI breaches or unauthorized access — please mark urgent communications "URGENT — PRIVACY INCIDENT." We will respond within one (1) business day. |
| Mailing Address | FirstAssistantAI, Inc. A Delaware Corporation Address on file with registered agent. Contact legal@firstassistantai.com for written correspondence address. |
We aim to respond to all privacy inquiries within thirty (30) calendar days. Response times for urgent security incidents are within one (1) business day.