Legal
Privacy Policy
Last updated: April 21, 2026
Cedar Health ("Cedar Health," "we," "us," or "our") respects your privacy and is committed to protecting the personal information you share with us. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you visit cedarhealth.ai (the "Site") or use our remote patient monitoring, chronic care management, and related healthcare services (collectively, the "Services").
Our Role: Data Processor and Business Associate. In the context of patient care, your healthcare provider serves as the Data Controller (or "Covered Entity" under HIPAA). Cedar Health acts as a Data Processor and a Business Associate. This means we only process your Protected Health Information ("PHI") on behalf of and under the strict instructions of your healthcare provider, governed by a Business Associate Agreement (BAA) and the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), as well as our Notice of Privacy Practices.
1. Information We Collect
We may collect the following categories of information:
- Contact information you submit through forms, such as your name, email, phone number, organization, and message.
- Health-related information and patient physiological data submitted by providers or collected from remote monitoring, as well as when referring patients or coordinating care, which may include PHI subject to HIPAA.
- Third-Party Connected Devices: If you use connected health monitoring devices (e.g., Bluetooth or cellular-enabled sensors), our Services collect real-time readings to transmit to your provider.
- Payment information and billing details for services rendered.
- Device and usage data, including IP address, browser type, pages viewed, and referring URLs, collected automatically through cookies and similar technologies.
- Communications between you and Cedar Health (email, phone, or support requests).
2. How We Use Information
- To provide, operate, and improve our Services.
- To respond to inquiries, referrals, and support requests.
- To coordinate patient care with authorized providers.
- Artificial Intelligence and Cloud Hosting: Our infrastructure securely utilizes Amazon Web Services (AWS) for data hosting. To enhance clinical insights and system efficiency, we may use AWS Bedrock. When processing data via AWS Bedrock, your PHI remains inside our secure, HIPAA-compliant AWS environment and is never used to train public or foundational third-party AI models.
- Anonymized and Aggregated Data: We may de-identify your PHI so that it can no longer reasonably identify you. Once de-identified in compliance with HIPAA, this data is no longer considered personal information or PHI, and we may use or disclose it indefinitely for research, analytics, product development, or other lawful business purposes.
- To comply with legal, regulatory, and contractual obligations, including HIPAA.
- To detect, prevent, and address fraud, security, or technical issues.
3. How We Share Information
We do not sell your personal information. We may share information with:
- Healthcare providers involved in your care, consistent with HIPAA and your authorizations.
- Service providers and subcontractors (such as AWS) bound by strict confidentiality and, where applicable, Business Associate Agreements.
- Legal and regulatory authorities when required by law or to protect rights, safety, or property.
4. SMS and Text Messaging
As part of our remote monitoring services, we may send you automated SMS text messages containing adherence reminders, vital reading requests, and appointment notifications.
- Message frequency varies. Message and data rates may apply.
- You can cancel the SMS service at any time by texting STOP. For assistance, text HELP.
- Carriers are not liable for delayed or undelivered messages.
5. Cookies and Tracking
We use cookies and similar technologies to operate the Site, remember preferences, and analyze traffic. You can control cookies through your browser settings. Disabling cookies may affect Site functionality.
6. Data Security
Cedar Health maintains administrative, technical, and physical safeguards designed to protect personal information and PHI in accordance with HIPAA and industry best practices. Your data is encrypted both in transit and at rest. In the event of a data breach compromising your personal data, we will notify you and/or your healthcare provider as required by applicable law. No method of transmission or storage, however, is 100% secure.
7. Data Retention
We retain your personal information and PHI for as long as your account is active, as necessary to provide the Services, and to comply with our legal and HIPAA-related retention obligations (which can extend up to six years or longer). Once data is no longer legally required to be held, it is securely deleted or permanently de-identified.
8. Your Rights and Communication Preferences
Depending on your jurisdiction (including states like California, Virginia, and Texas), you may have the right to access, correct, delete, or restrict the use of your personal information. You also have the right to opt-out of the "sale or sharing" of your personal information (though Cedar Health does not sell your data). Patients have additional rights regarding PHI as described in our Notice of Privacy Practices.
Opting Out: You may opt out of non-essential marketing emails at any time using the "unsubscribe" link. However, you cannot opt out of essential service-related communications unless you terminate your use of the Services. To exercise any of these rights, contact us using the information below.
9. Children's Privacy
Our Site is not directed to children under 13, and we do not knowingly collect personal information directly from children. In cases where the Service is used for pediatric care, all pediatric health data must be explicitly inputted by or authorized by a parent, legal guardian, or healthcare provider.
10. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the most recent revision. We encourage you to review this Policy periodically.
11. Cedar Health Referral Bridge Chrome Extension
The Cedar Health Referral Bridge is a Chrome browser extension used by authorized healthcare providers and their staff to transfer patient demographic information from electronic health record (EHR) systems into the Cedar Health patient referral form.
Who Uses This Extension
The Extension is intended solely for use by licensed healthcare providers and their authorized administrative staff. It is not intended for use by patients.
Data Accessed
When a user activates the Extension on an EHR page, it reads visible page text and form field values to extract patient demographic data, which may include: name, date of birth, phone number, mailing address, insurance plan name and ID, and EHR/MRN identifier. The Extension only runs when explicitly triggered by the user clicking the extension icon or selecting a context menu item. It does not run automatically in the background on any tab.
Local Storage
Extracted data is stored exclusively in the browser's local extension storage (chrome.storage.local) on the user's device. It is not transmitted to Cedar Health servers or any third party unless AI Extraction mode is explicitly enabled (see below).
AI Extraction Mode (Optional)
If a user enables AI Extraction mode and configures a proxy URL and API key, extracted patient demographic data will be transmitted to a Cedar Health-operated proxy server and then to AWS Bedrock for parsing. This transmission occurs inside Cedar Health's HIPAA-compliant, BAA-governed AWS environment described in Section 2 of this Policy. Cedar Health does not log or store any data that passes through the AI proxy. All data is deleted immediately after processing. AI Extraction mode is opt-in and off by default. Users are shown a disclosure in the Extension settings when enabling it.
Data Retention
Extracted data persists in local browser storage until the user clicks "Clear Extracted Data," uninstalls the Extension, or clears browser storage manually. Cedar Health does not retain copies of data processed through the Extension. Data processed via AI Extraction mode is deleted immediately after parsing is complete.
No Sale or Sharing
Data processed by the Extension is not sold, shared with advertisers, or used for any purpose other than populating the Cedar Health referral form on behalf of the authorized user.
Security
In standard mode, the Extension does not transmit data over the network. In AI Extraction mode, all data is transmitted over encrypted HTTPS connections to Cedar Health's secure infrastructure.
12. Contact Us
Questions or concerns about this Privacy Policy? Reach out to us:
- Cedar Health
- 5016 Centennial Blvd, Suite 200
- Nashville, TN 37209
- Email: info@cedarhealth.ai
- Phone: (800) 990-9839