Privacy Policy

Last Updated: August 29, 2026

1. Introduction

Voxirad ("we," "our," or "us") is committed to protecting the privacy and security of your information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our voice-powered radiology reporting platform and related services (collectively, the "Services").

This policy applies to healthcare providers, radiology departments, and their authorized personnel who use our Services. We comply with applicable healthcare privacy regulations, including the Health Insurance Portability and Accountability Act (HIPAA) and other relevant data protection laws.

2. Information We Collect

2.1 Information You Provide

  • Account information (name, email, phone number, professional credentials)
  • Organization information (facility name, department, billing details)
  • Voice recordings and dictation data submitted through our platform
  • Communications with our support team
  • Preferences and settings you configure in the platform

2.2 Protected Health Information (PHI)

As a Business Associate under HIPAA, we may process Protected Health Information (PHI) on behalf of Covered Entities. This includes patient identifiers, clinical findings, and diagnostic information contained in radiology reports. We handle all PHI in accordance with our Business Associate Agreement (BAA) and HIPAA requirements.

2.3 Automatically Collected Information

  • Usage data (feature interactions, session duration, report generation metrics)
  • Device information (browser type, operating system, IP address)
  • Log data (access times, error logs, system diagnostics)
  • Performance metrics and analytics data

3. How We Use Your Information

We use collected information for the following purposes:

  • Service Delivery: To provide, maintain, and improve our AI-powered radiology reporting platform
  • Report Generation: To process voice dictation and generate structured radiology reports using AI/ML technologies
  • Quality Assurance: To monitor system performance, ensure accuracy, and improve our AI models
  • Customer Support: To respond to inquiries, provide technical assistance, and resolve issues
  • Account Management: To manage your account, process payments, and communicate about service updates
  • Security: To detect, prevent, and respond to security incidents and fraudulent activity
  • Compliance: To comply with legal obligations and regulatory requirements
  • Research and Development: To develop new features and improve our AI algorithms (using only de-identified data)

4. Data Sharing and Disclosure

We do not sell your personal information or PHI. We may share information only in the following circumstances:

4.1 With Your Organization

We share generated reports and related data with authorized users within your healthcare organization as designated by your organization's administrators.

4.2 Service Providers

We work with trusted third-party service providers who assist us in operating our platform, including cloud infrastructure providers, AI/ML service providers, and payment processors. All service providers handling PHI execute Business Associate Agreements and are contractually obligated to maintain confidentiality.

4.3 Legal Requirements

We may disclose information when required by law, court order, or government regulation, or when necessary to protect our rights, safety, or the safety of others.

4.4 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of the transaction, subject to the same privacy protections outlined in this policy.

5. Data Security

We implement comprehensive security measures to protect your information:

  • Encryption: Data is encrypted in transit (TLS 1.3+) and at rest (AES-256)
  • Access Controls: Role-based access controls and multi-factor authentication
  • Infrastructure: HIPAA-compliant cloud infrastructure with regular security audits
  • Monitoring: 24/7 security monitoring and incident response procedures
  • Personnel: Background checks and HIPAA training for all employees with access to PHI
  • Penetration Testing: Regular security assessments and vulnerability scanning

6. Data Retention

We retain information for as long as necessary to provide our Services and comply with legal obligations:

  • Active Accounts: Data is retained for the duration of your active subscription
  • PHI: Retained according to your organization's requirements and applicable regulations (typically 7 years minimum)
  • De-identified Data: May be retained indefinitely for research and improvement purposes
  • Account Closure: Upon request, we will delete or return PHI within 30 days, subject to legal retention requirements

7. Your Rights and Choices

Depending on your jurisdiction, you may have the following rights:

  • Access: Request access to your personal information
  • Correction: Request correction of inaccurate information
  • Deletion: Request deletion of your information (subject to legal requirements)
  • Restriction: Request restriction of processing in certain circumstances
  • Portability: Request transfer of your data to another service provider
  • Objection: Object to certain types of processing

For PHI access requests, please contact your organization's Privacy Officer. For other requests, contact us at privacy@voxirad.com.

8. HIPAA Compliance

As a HIPAA Business Associate, we:

  • Execute Business Associate Agreements (BAAs) with all Covered Entity clients
  • Implement administrative, physical, and technical safeguards required by HIPAA
  • Report breaches of unsecured PHI as required by the HIPAA Breach Notification Rule
  • Limit use and disclosure of PHI to purposes permitted under the BAA
  • Provide patients with access to their PHI through your organization

9. International Data Transfers

Our Services are primarily operated in the United States. If you access our Services from outside the U.S., your information may be transferred to, stored, and processed in the U.S. or other countries where our service providers operate. We implement appropriate safeguards for international transfers, including Standard Contractual Clauses where applicable.

10. Children's Privacy

Our Services are designed for healthcare professionals and are not intended for use by individuals under 18 years of age. We do not knowingly collect personal information from children.

11. Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by email or through our platform. Your continued use of the Services after such notice constitutes acceptance of the updated policy.

12. Contact Information

For questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact:

Voxirad Privacy Office

Email: privacy@voxirad.com

Phone: 1-800-VOXIRAD

For HIPAA-related inquiries or to report a potential breach, please contact:
Email: hipaa@voxirad.com

This Privacy Policy is effective as of the date listed above and governs your use of our Services. By using Voxirad, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.