◆FirstAssistantAI
Back to FirstAssistantAI
Legal Document

Privacy Policy

FirstAssistantAI, Inc. — Clinical Decision Support Platform

Effective: June 8, 2026Version: 2026-06-08-v1

FirstAssistantAI, Inc. ("Company," "we," "us," or "our") is committed to protecting the privacy of healthcare professionals and their patients. This Privacy Policy describes how we collect, use, disclose, and protect information in connection with the FirstAssistantAI clinical decision support platform (the "Platform").

Scope. This Privacy Policy applies to information collected from licensed healthcare professionals who register for and use the Platform. It does not apply to patients, who interact with the Platform only through their treating clinicians. Patient health information submitted through the Platform is Protected Health Information (PHI) governed by HIPAA, HITECH, and the Business Associate Agreement (BAA) embedded in our Terms of Service. The BAA controls in the event of any conflict between it and this Privacy Policy with respect to PHI handling.

1. Information We Collect

1.1 Account and Registration Information

When you register for an account, we collect:

  • Full name, professional title, and specialty;
  • Email address and password (stored in cryptographically hashed form; we never store plaintext passwords);
  • National Provider Identifier (NPI) and primary state of licensure;
  • Institution or practice affiliation; and
  • Billing information (processed by our payment processor; we do not store full payment card numbers or bank account details).

1.2 Clinical Case Data (PHI)

When you use the Platform to score and document surgical cases, we collect the clinical variables, scoring inputs, intraoperative findings, procedure details, and patient outcome data you enter. This data may constitute PHI and is governed by our Business Associate Agreement. We store case data in association with your account and do not share it with other providers or third parties except as described in Section 4 or as required by law.

Surgery dates are a HIPAA-identified date element. The Platform does not store the specific date of surgery. Instead, we store the surgery year and the number of days elapsed since surgery, which are non-identifying temporal variables under the HIPAA Safe Harbor de-identification standard (45 C.F.R. § 164.514(b)).

1.3 Patient-Reported Outcome Data (PROMs)

When you enroll patients in the PROMs program, we collect validated outcome measure responses (mHHS, IKDC, ASES, and similar instruments) submitted by patients through tokenized, time-limited links. These links contain no PHI and expire after use. PROMs responses are linked to the associated case record under your account and are treated as PHI subject to the BAA.

1.4 Legal Acknowledgment Records

When you accept the Terms of Service, BAA, or this Privacy Policy, we record the acceptance timestamp (server-generated), your IP address, browser and device information (user agent), and the specific version of each document accepted. The Business Associate Agreement is executed by electronic signature, so we additionally record the full legal name you type as your signature; the Terms of Service and Privacy Policy are accepted by checkbox (clickwrap) and do not require a typed signature. These records are retained in an append-only ledger as evidence of your legal acknowledgment, consistent with HIPAA documentation requirements (45 C.F.R. § 164.530(j)) and the E-SIGN Act (15 U.S.C. § 7001 et seq.).

1.5 Usage and Technical Data

We automatically collect certain technical data when you use the Platform, including:

  • IP address, browser type and version, operating system;
  • Pages visited, features used, session duration, and interaction patterns;
  • Device identifiers and screen resolution; and
  • Error logs and performance data.

This data is used to operate, maintain, secure, and improve the Platform. It does not constitute PHI and is not associated with patient records.

1.6 Communications

If you contact us by email or through the Platform, we retain your communications and our responses for customer service and product improvement purposes. Communications related to PHI breaches or legal matters are retained as required by law.


2. How We Use Your Information

PurposeInformation UsedLegal Basis
Provide and operate the PlatformAccount info, clinical case data, usage dataPerformance of contract; HIPAA BAA
Generate scoring outputs and clinical decision support recommendationsClinical case inputsPerformance of contract; HIPAA BAA
Send PROMs enrollment and follow-up communications to patientsPatient email (via tokenized link only; no PHI transmitted to patient outside tokenized link)Performance of contract; HIPAA BAA
Send weekly clinical summary emails to surgeonsAccount info, aggregate case activity dataPerformance of contract; legitimate interest
Improve, validate, and train Platform algorithmsDe-identified aggregate data only (Safe Harbor standard)Legitimate interest; Terms of Service consent
Clinical research and publicationDe-identified aggregate data onlyLegitimate interest; Terms of Service consent
Billing and subscription managementPayment and account informationPerformance of contract
Security, fraud prevention, and abuse detectionUsage data, account info, technical dataLegitimate interest; legal obligation
Maintain legal acknowledgment recordsAcceptance timestamps, typed name, IP, user agent, document versionLegal obligation (HIPAA, E-SIGN Act)
Customer support and communicationsAccount info, communicationsLegitimate interest; performance of contract
Legal compliance and enforcementAll categories as necessaryLegal obligation; legitimate interest

3. De-Identified and Aggregate Data

We de-identify clinical case data in accordance with the HIPAA Safe Harbor method (45 C.F.R. § 164.514(b)), under which all eighteen categories of HIPAA-specified identifiers are removed or transformed before any use or disclosure outside the Platform. De-identified data is not PHI and is not subject to HIPAA restrictions or this Privacy Policy's PHI-specific protections.

We may use de-identified aggregate data for:

  • Training, developing, validating, and improving machine learning and artificial intelligence models incorporated into the Platform;
  • Clinical outcomes research and academic publication;
  • Product development, benchmarking, and platform analytics;
  • Licensing to third parties in de-identified, aggregate form for research or commercial purposes; and
  • Investor and partner reporting (in aggregate statistical form only; never individual-level data).

By accepting the Terms of Service, you expressly consent to FirstAssistantAI's use of your de-identified data as described above. FirstAssistantAI, Inc. retains full and exclusive ownership of all de-identified data and all statistical, aggregate, and derivative outputs generated from such data. This consent is irrevocable with respect to data already de-identified, because de-identified data cannot be re-linked to you and therefore cannot be selectively withdrawn.

De-identification in practice: The Platform stores surgery year and days elapsed since surgery rather than the specific surgery date, consistent with Safe Harbor requirements. Case numbers are system-generated identifiers with no connection to patient names or medical record numbers. Patient emails used for PROMs enrollment are stored separately from case records and are never included in de-identified exports. For longitudinal outcomes research, de-identified records of the same case or patient may carry a non-identifying linkage code (per 45 C.F.R. § 164.514(b)–(c)) that allows records to be associated over time without re-identifying any individual.

4. Disclosure of Information

We do not sell your personal information or PHI. We may disclose information only as follows:

4.1 Service Providers and Subprocessors

We engage trusted third-party service providers to operate the Platform. These parties process information only on our behalf, under our instructions, and subject to confidentiality obligations. Before any protected health information (PHI) is processed through a subprocessor, we require an executed HIPAA Business Associate Agreement with that subprocessor. Features that would route PHI through a subprocessor whose BAA is not yet executed (for example, patient-reported outcome collection) remain disabled until that agreement is in place.

SubprocessorPurposePHI AccessBAA Status
Supabase, Inc.Primary database, authentication, transactional emailYes (once PHI features are enabled)Pending — will be executed before any PHI is processed
Vercel, Inc.Application hosting, serverless functions, edge networkYes (once PHI features are enabled)Pending — will be executed before any PHI is processed
Google LLC (Workspace)Email delivery via Gmail SMTP: account emails, weekly digests, and patient-facing PROMs enrollment links (tokenized link only; no clinical data in message body)Limited — recipient email addresses; no case dataExecuted (Google Workspace BAA)
Google LLC (Cloud / Vertex AI)AI model inference (Anthropic Claude hosted by Google Cloud) for dictation parsing, pinned to a U.S. regionPotential — de-identified clinical text today; PHI only after full BAA chain is completeExecuted (Google Cloud BAA)
Payment ProcessorSubscription billing and payment processing (currently dormant — the Platform is free)No — no PHI transmitted to payment processorN/A

We will notify you of material changes to subprocessors that handle PHI no less than thirty (30) days before the change takes effect, and we will update this table accordingly. The current authoritative subprocessor list is maintained in our BAA.

4.2 Legal Requirements

We may disclose information if required to do so by applicable law, valid court order, subpoena, government regulation, or regulatory investigation, or if we believe in good faith that disclosure is necessary to: (i) comply with a legal obligation; (ii) protect the rights, property, or safety of the Company, our users, or the public; or (iii) detect, prevent, or address fraud, security, or technical issues. We will notify you of any such disclosure to the extent permitted by law.

4.3 Business Transfers

In connection with a merger, acquisition, reorganization, or sale of all or substantially all of the Company's assets, your information — including PHI — may be transferred to a successor entity. Any such transfer of PHI requires: (i) that the successor execute a HIPAA-compliant BAA before receiving any PHI; (ii) that the successor be bound by this Privacy Policy or provide you with protections at least as strong; and (iii) that we provide you with advance written notice of the transfer and any material changes to data handling practices no less than thirty (30) days before such transfer takes effect.

4.4 With Your Consent

We may disclose information for any other purpose with your explicit, documented prior written consent. Consent may be withdrawn for future processing but does not affect disclosures already made in reliance on prior consent.


5. Data Security

We implement administrative, physical, and technical safeguards designed to protect your information and PHI against unauthorized access, use, alteration, and destruction, consistent with HIPAA Security Rule requirements (45 C.F.R. Part 164, Subpart C). Safeguards include:

  • AES-256 encryption of data at rest and TLS 1.2+ encryption of data in transit;
  • Role-based access controls and Row-Level Security (RLS) enforced at the database layer, ensuring each surgeon accesses only their own case data;
  • Cryptographically hashed password storage (plaintext passwords are never stored or transmitted);
  • Audit logging of all access to PHI and significant system events;
  • Tokenized, expiring patient communication links that contain no PHI;
  • Multi-factor authentication requirements for administrative access; and
  • Regular security review of infrastructure configuration and third-party subprocessors.

No method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security. You are responsible for maintaining the security of your account credentials and for notifying us promptly at security@firstassistantai.com of any suspected unauthorized access or PHI exposure.


6. Data Retention

We retain information for the following minimum periods:

Data CategoryRetention PeriodBasis
Account information (non-PHI)Duration of account plus 7 years after closureBusiness records; applicable law
Clinical case data (PHI)Duration of account plus 7 years, or as required by applicable state medical records law, whichever is longerHIPAA; state medical records law
PROMs response data (PHI)Duration of account plus 7 years, or applicable state law, whichever is longerHIPAA; state medical records law
De-identified aggregate dataIndefinitely — no longer subject to HIPAA retention limits once de-identified under Safe HarborCompany IP; legitimate interest
Legal acknowledgment records (ToS, BAA acceptance)Minimum 6 years from last effective date45 C.F.R. § 164.530(j); E-SIGN Act
Usage and technical logsUp to 2 yearsSecurity; operational need
Payment and billing records7 yearsIRS; applicable financial law
Security incident records6 years from date of discovery45 C.F.R. § 164.530(j)

Upon account closure, we will return or securely destroy your PHI as described in the BAA within thirty (30) days of your written request, subject to legal hold obligations. You may request early deletion of non-PHI personal information as described in Section 7.


7. Your Privacy Rights

Depending on your jurisdiction, you may have the following rights regarding your personal information (distinct from PHI, which is governed by HIPAA and the BAA):

  • Access. Request a copy of the personal information we hold about your account;
  • Correction. Request correction of inaccurate personal information (e.g., name, institution, NPI);
  • Deletion. Request deletion of your personal information, subject to our legal retention obligations and any active legal holds;
  • Portability. Request export of your case data in a structured, machine-readable format (JSON or CSV export available through the Platform and upon account closure);
  • Objection. Object to processing for direct marketing purposes (though we do not engage in direct marketing to non-users);
  • Restriction. Request restriction of processing in certain circumstances as provided by applicable law; and
  • Withdrawal of Consent. Where processing is based on your consent (e.g., optional analytics), withdraw consent at any time without affecting the lawfulness of prior processing.

To exercise any right, contact us at legal@firstassistantai.com. We will respond within thirty (30) days. We may require reasonable verification of your identity before processing requests. Some requests may be limited by our legal obligations, the rights of other parties, or the inherent limitations of de-identification (de-identified data cannot be re-linked to you and therefore cannot be subject to access or deletion requests).

Regarding patient PHI: patients seeking to exercise HIPAA rights (access, amendment, or accounting of disclosures) must contact their treating clinician, who is the Covered Entity responsible for the patient relationship. We will cooperate with Covered Entities in facilitating patient rights requests as required by HIPAA.


8. California Privacy Rights (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), may provide you with additional rights.

We do not sell or share your personal information as those terms are defined under the CCPA/CPRA. We do not use your personal information for cross-context behavioral advertising. We do not use sensitive personal information for purposes beyond those necessary to provide the Platform.

California residents may exercise the following rights in addition to those described in Section 7: the right to know what personal information is collected and how it is used; the right to delete personal information (subject to exceptions); the right to correct inaccurate personal information; the right to opt out of sale or sharing (not applicable, as we do not sell); and the right to non-discrimination for exercising privacy rights.

To submit a California privacy request, contact us at legal@firstassistantai.com with subject line "California Privacy Request." Note that PHI submitted through the Platform is exempt from CCPA under the HIPAA exemption (Cal. Civ. Code § 1798.145(c)(1)(A)).


9. Cookies and Tracking Technologies

We use cookies and similar technologies to operate and improve the Platform. Types include:

  • Essential cookies: Required for authentication, session management, and security. These are strictly necessary for Platform functionality and cannot be disabled.
  • Functional cookies: Remember your preferences, display settings, and session state.
  • Analytics cookies: Collect aggregate usage data to help us understand how the Platform is used and where to improve it. These do not contain PHI.

We do not use advertising cookies, retargeting pixels, or share usage data with advertising networks. The Platform does not display third-party advertisements. We do not engage in cross-site tracking.


10. Communications and Email

As part of your agreement to the Terms of Service, you consent to receive the following communications from FirstAssistantAI:

  • Transactional emails: Account confirmations, security alerts, password resets, BAA/ToS update notices, and PROMs enrollment notifications. These are essential to the Platform and cannot be opted out of while your account is active.
  • Weekly clinical digest: A summary of your recent case activity, PROMs follow-up status, and relevant literature updates. You may opt out at any time through your account Notification Settings or by clicking the unsubscribe link in any digest email.
  • Legal and compliance notices: Material changes to the Terms, BAA, or Privacy Policy. These cannot be opted out of, as they are required by law or necessary to maintain the accuracy of your legal acknowledgments.

We do not send unsolicited marketing emails. We do not share your email address with third parties for marketing purposes.


11. Children's Privacy

The Platform is intended exclusively for licensed healthcare professionals aged 18 or older and is not directed to, or intended for use by, individuals under the age of 18. We do not knowingly collect personal information from minors. If we learn that we have collected information from a person under 18 who is not a licensed healthcare professional, we will promptly delete such information and terminate the associated account. If you believe we may have collected information from a minor in error, contact us at legal@firstassistantai.com.


12. International Users

The Platform is operated in the United States and is primarily intended for use by healthcare professionals licensed in the United States. If you access the Platform from outside the United States, your information may be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your jurisdiction. By using the Platform, you consent to such transfer and processing.

Healthcare professionals in the European Economic Area (EEA), United Kingdom, or Switzerland who are subject to the EU General Data Protection Regulation (GDPR) or equivalent legislation should contact us at legal@firstassistantai.com to discuss applicable data transfer mechanisms (such as Standard Contractual Clauses) and any additional rights that may apply, including the right to lodge a complaint with a supervisory authority.


13. Governing Law and Dispute Resolution

This Privacy Policy is governed by the laws of the State of Delaware, without regard to its conflict of law provisions. Any dispute arising out of or relating to this Privacy Policy or our data practices is subject to the binding-arbitration and class-action-waiver provisions of our Terms of Service (Section 15), except that either party may seek injunctive or other equitable relief in the state or federal courts located in Delaware.

Nothing in this section limits your rights to lodge a complaint with a government supervisory or regulatory authority in your jurisdiction, including the U.S. Federal Trade Commission, applicable state attorneys general, or, for EEA residents, the relevant data protection authority.


14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by email to your registered address no less than thirty (30) days before the effective date of the change, and by posting an updated policy with a revised version identifier and effective date.

Your continued use of the Platform after the effective date of any change constitutes your acceptance of the updated policy. Where changes materially affect how we handle PHI, we will provide advance notice as required and, where required by HIPAA or applicable law, obtain your renewed consent through the platform's legal acknowledgment flow.

We maintain a version-controlled history of all Privacy Policy versions. Prior versions are available upon request by contacting legal@firstassistantai.com.


15. Contact Us

For privacy questions, concerns, access requests, or to report a suspected data incident:

Privacy & Legallegal@firstassistantai.com
General privacy questions, rights requests, legal inquiries
Security Incidentssecurity@firstassistantai.com
Suspected PHI breaches or unauthorized access — please mark urgent communications "URGENT — PRIVACY INCIDENT." We will respond within one (1) business day.
Mailing AddressFirstAssistantAI, Inc.
A Delaware Corporation
Address on file with registered agent. Contact legal@firstassistantai.com for written correspondence address.

We aim to respond to all privacy inquiries within thirty (30) calendar days. Response times for urgent security incidents are within one (1) business day.

FirstAssistantAI, Inc.
A Delaware Corporation
Legal inquiries: legal@firstassistantai.com
Document version 2026-06-08-v1 · June 8, 2026
Contact management@firstassistantai.com for any technical difficulties or suggestions.