Equipo Health ("Equipo," "we," "our," or "us") respects the privacy of our customers, healthcare organizations, providers, patients, business partners, authorized users, and website and application visitors. This Privacy Policy explains how we collect, receive, access, use, store, disclose, protect, and otherwise process information.through our websites, cloud-based software platforms, web and mobile applications, patient and provider portals, application programming interfaces (APIs), artificial intelligence (AI) services, integrations, browser extensions, connected devices, and other products and services that reference this Privacy Policy (collectively, the "Services").
Equipo provides an integrated healthcare technology ecosystem that enables healthcare organizations to deliver coordinated, patient-centered care while supporting clinical, operational, and administrative workflows. The Services support care coordination, chronic care management, patient engagement, population health management, referral management, healthcare operations, analytics, interoperability, and other healthcare programs, and are accessible through both web application and native mobile application interfaces.
The Services include, but are not limited to:
- Compass - Care Coordination Platform
- Contigo - Patient Portal and Mobile Application
- Pulse - Provider Portal
- CareLink – Referral and Care Network Platform
- Prism - Population Health and Analytics Platform
- Foresight - Equipo's AI ecosystem includes intelligent automation, predictive analytics, AI assistants, clinical decision support, documentation assistance, workflow optimization, operational insights, and future AI capabilities.
- CareConnect, CareAssist, CareEdge, CareLens, and other Equipo applications
- Equipo browser extensions and plugins (including, where applicable, a browser extension) that integrate with EHR systems, web portals, or other third-party web applications
- Wearable devices, remote patient monitoring devices, and other connected health technologies that transmit data to the Services, where enabled by a healthcare organization or authorized user
- Electronic Health Record (EHR) integrations, APIs, interoperability services, mobile applications, customer support services, and any current or future products, features, channels, or services that incorporate or reference this Privacy Policy
This Privacy Policy applies whether you access the Services through a web browser, a downloaded mobile application (iOS or Android), a browser extension or plugin (including a browser extension), a wearable or connected health device, or any other current or future access channel Equipo may offer. Where a requirement or disclosure below applies only to one access channel, it is identified as such.
Equipo Health acts as a Business Associate, as defined under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations ("HIPAA"), when it creates, receives, maintains, or transmits Protected Health Information ("PHI") on behalf of healthcare organization customers. Equipo is not a Covered Entity with respect to that PHI. The healthcare organization that engages Equipo remains responsible for its own Notice of Privacy Practices and for determining the permissible uses and disclosures of its patients' PHI. Nothing in this Privacy Policy is intended to expand, limit, or otherwise alter Equipo's obligations under any Business Associate Agreement ("BAA") in place with a customer.
By accessing or using the Services, you acknowledge that you have read and understand this Privacy Policy. By voluntarily submitting information to Equipo through our website, web application, mobile application, registering for events or webinars, communicating with us, or otherwise interacting with Equipo, you consent to the collection, use, and disclosure of your information as described in this Privacy Policy, to the extent permitted by applicable law.
1. Scope of This Privacy Policy
This Privacy Policy applies to information collected through our Services, including information provided by healthcare organizations, providers, patients, authorized users, business partners, and visitors to our website, web application, or mobile application.
As used in this Privacy Policy: "Authorized User" means an individual granted credentials to access the Services by a healthcare organization customer or by Equipo, including but not limited to clinicians, care coordinators, administrative staff, and patients. "Business Partner" means an entity with which Equipo has a contractual relationship to provide, support, or integrate with the Services, including vendors, subcontractors, referral partners, and technology integration partners.
When Equipo provides technology services to healthcare organizations, hospitals, physician practices, Accountable Care Organizations (ACOs), Federally Qualified Health Centers (FQHCs), Managed Service Organizations (MSOs), payers, or other healthcare entities, Equipo may process PHI on behalf of those organizations in accordance with applicable BAAs and federal law.
2. Information We Collect
Depending on how you access or use our Services — through our website, web application, or mobile application — Equipo may collect, receive, access, or otherwise process the following categories of information:
2.1 Personal and Professional Information
Name, mailing address, email address, telephone number, organization, job title, professional credentials, National Provider Identifier (NPI), user account information, authentication credentials, and other information necessary to establish, administer, and support your access to the Services.
2.2 Protected Health Information (PHI)
When providing Services to healthcare organizations, Equipo may receive, create, maintain, transmit, or process PHI on behalf of our customers in accordance with applicable BAAs and law. Such information may include patient identifiers (including Medical Record Number (MRN)), demographic information, insurance and eligibility information, appointments, diagnoses, problem lists, medications, allergies, immunizations, laboratory and diagnostic information, vital signs, care plans, assessments, referrals, clinical documentation, care coordination records, patient communications, billing-related information, and other health information necessary to provide the Services.
2.3 Technical and Usage Information (Web, Mobile, and Browser Extension)
We may automatically collect technical and usage information related to your interaction with the Services, including:
- IP address, browser type, and operating system
- Device identifiers, device type, and mobile carrier information (mobile application)
- Authentication records, session tokens, and browser local storage or similar client-side storage used to maintain your session
- Access times, application performance data, crash logs, and diagnostic data
- Audit trails and security logs, including login and access history
- Cookies and similar tracking technologies (web application and marketing website)
- Mobile application analytics and crash-reporting data collected through third-party software development kits (SDKs) embedded in the application
- Device permissions you grant to the mobile application (for example, camera, photo library, push notifications, or location, where applicable to a specific feature), and only the data associated with the permission you grant
- Approximate or precise geolocation, only where a specific feature requests it (for example, locating a nearby provider) and only with your permission
- Push notification tokens and delivery data, where you have enabled push notifications on the mobile application
- Biometric authentication signals (for example, use of Face ID, Touch ID, fingerprint, or WebAuthn/passkey login), where you elect to enable biometric login; Equipo does not receive or store the underlying biometric template, which is retained by your device's operating system
- Browser extension activity, limited to the specific web pages, fields, or workflows the extension is designed to read from or write to (for example, an EHR or provider portal page), as further described in Section 4.4
- Data transmitted from wearable devices or remote patient monitoring devices connected to the Services with authorization from a healthcare organization or authorized user, as further described in Section 17.2
2.4 Business and Communication Information
Information you voluntarily provide through our website, web application, customer support requests, product demonstrations, live chat, webinars, conferences, networking events, surveys, newsletters, marketing communications, event registrations, and other interactions with Equipo.
2.5 Information from Third-Party Sources
Where authorized by our customers or permitted by applicable law, we may receive information from healthcare organizations, EHR systems, health information exchanges, APIs, authorized third-party integrations, referral partners, customer administrators, or other authorized sources to facilitate the delivery of our Services.
Equipo collects, accesses, uses, and processes only the information reasonably necessary to provide, operate, maintain, secure, support, improve, and comply with our contractual, legal, regulatory, and operational obligations in connection with the Services.
3. How Information Is Collected
Information may be collected directly from users, healthcare organizations, EHR systems, authorized integrations, APIs, patient portals, provider portals, our web application, our mobile application, customer administrators, referral partners, healthcare staff, customer support interactions, uploaded documents, authorized third-party systems, and publicly available sources where permitted by law.
Certain technical information may be collected automatically through cookies, browser local storage, mobile SDKs, log files, analytics tools, and other technologies used to improve the functionality, performance, reliability, and security of our Services.
4. Cookies, Mobile SDKs, Browser Extensions, and Similar Technologies
4.1 Categories of Tracking Technologies
Our website and web application may use the following categories of cookies and similar technologies:
- Strictly necessary / session cookies — required for login, authentication, and core functionality; cannot be disabled without affecting your ability to use the Services
- Functional cookies — remember user preferences and settings
- Analytics cookies — help us understand usage patterns and improve the Services
- Security cookies — support fraud prevention, device recognition, and account security, including browser and device fingerprinting used to detect anomalous login activity
4.2 Mobile Application SDKs
Our mobile applications may incorporate third-party SDKs for functions such as crash reporting, performance monitoring, push notification delivery, and analytics. These SDKs may collect device identifiers, usage data, and diagnostic information as described in Section 2.3. Equipo requires that any such SDK provider process data only as necessary to provide its function and is consistent with this Privacy Policy and applicable law.
4.3 Advertising Technologies, Targeted Advertising, and Opt-Out Rights
Equipo does not sell Protected Health Information or personal information for monetary consideration. Where Equipo engages third-party service providers for analytics, communications, service delivery, or operational purposes, information is shared only as necessary to support the provision, maintenance, security, improvement, or lawful operation of the Services and subject to appropriate contractual and confidentiality obligations. Where applicable, Equipo will provide users with any required choices, preferences, or opt-out mechanisms regarding such data practices in accordance with applicable law and this Privacy Policy.
4.4 Browser Extensions and Plugins
Equipo offers one or more browser extensions or plugins (including, where applicable, a browser extension distributed through the Chrome Web Store) that allow authorized users to access Equipo functionality, such as care coordination prompts, documentation assistance, or data capture, directly within a third-party web application, EHR system, or web portal.
Consistent with Google's User Data Policy for Chrome Web Store items and comparable requirements of other browser stores, Equipo discloses the following regarding any such extension:
- The extension requests only the browser permissions and host permissions (that is, access to specific website domains) necessary to perform its disclosed function, such as reading or writing specific fields on an authorized EHR or portal page
- The extension may access page content, form field data, or clipboard content only where necessary to the feature you invoke, and only on the specific domains disclosed at installation or in the extension's Chrome Web Store listing
- Where the extension accesses PHI displayed within a third-party system (for example, an EHR), that PHI is handled subject to the same safeguards, BAA obligations, and use restrictions described elsewhere in this Privacy Policy
- If the extension accesses Google Workspace or other Google user data, Equipo's use of that data adheres to Google's Limited Use requirements: such data is used only to provide or improve the disclosed, user-facing features of the extension, is not used for advertising, and is not transferred to third parties except as necessary to provide the feature, to comply with law, or as part of a merger or acquisition as described in Section 9
- Equipo does not sell data collected through the extension and does not use it to train generalized (non-user-facing) AI or machine learning models except as permitted under Section 8.1
You may review and revoke the extension's permissions, or remove the extension entirely, at any time through your browser's extension management settings.
4.5 Your Choices and Opt-Out Rights
You may modify your browser settings to limit or disable certain cookies; doing so may affect the availability or functionality of portions of the web application. You may also disable specific device permissions (such as camera, location, or push notifications) for the mobile application at any time through your device's operating system settings, without affecting your ability to use core, non-permission-dependent features.
Where required by applicable law, Equipo will honor recognized opt-out preference signals, including the Global Privacy Control (GPC), with respect to the sale or sharing of personal information as those terms are defined under applicable state law.
5. How We Use Information
Equipo uses information to:
- Provide and maintain our Services across web and mobile access points
- Support patient engagement and care coordination
- Facilitate clinical, operational, and administrative workflows
- Enable chronic care management, population health management, referral management, and related healthcare programs
- Authenticate users and manage user accounts, including biometric or passkey-based login where enabled
- Respond to customer inquiries and provide technical support
- Improve system performance, functionality, usability, and security across web and mobile platforms
- Generate reports, analytics, and operational insights
- Detect, investigate, and prevent fraud, misuse, unauthorized access, or security incidents
- Deliver push notifications, in-app messages, email, or SMS communications you have consented to receive
- Communicate product updates, service notifications, educational materials, and marketing communications where permitted by law
- Train, validate, and improve artificial intelligence and machine learning features, subject to Section 8 below
- Comply with contractual obligations, legal requirements, court orders, regulatory requests, and applicable federal and state laws
Equipo does not sell personal information or PHI to third parties in exchange for monetary payment. Where applicable state law defines "sale" or "share" more broadly than a monetary exchange (for example, to include certain disclosures to advertising or analytics partners), Equipo will identify any such practices and provide the opt-out mechanisms described in Section 4.3.
6. Protected Health Information
Where applicable, Equipo processes PHI as a Business Associate on behalf of healthcare organizations and only as authorized by applicable BAAs, customer instructions, contractual obligations, and applicable law.
Equipo does not independently determine clinical treatment decisions and does not use PHI for purposes inconsistent with applicable agreements or legal requirements.
Patients seeking information regarding the use or disclosure of their medical information should contact their healthcare provider or healthcare organization directly.
7. Consumer Health Data (Non-HIPAA)
Certain state laws — including but not limited to Washington's My Health My Data Act and comparable laws in other states — regulate "consumer health data" collected outside the traditional HIPAA framework, such as wellness information, health-related search or usage activity, or location data collected through our website or web application from individuals not otherwise covered by a BAA (for example, prospective customers or website visitors researching health topics).
Where such laws apply, Equipo will not use precise geolocation to identify a consumer's attempt to access health care services, will not use geofencing around healthcare facilities for advertising purposes, and will obtain any consent required before collecting or sharing consumer health data outside the scope of a BAA.
8. Artificial Intelligence and Analytics
Certain Services, including those offered through Foresight, may include artificial intelligence, predictive analytics, automation, clinical decision support, workflow recommendations, population health analytics, risk stratification, documentation assistance, or similar capabilities, accessible through both the web application and mobile application.
These tools are intended solely to assist authorized users in clinical or operational decision-making. AI-generated information is advisory in nature and should not be considered medical advice, a diagnosis, treatment recommendation, or a substitute for independent professional judgment. Healthcare providers remain solely responsible for patient care, clinical decisions, and compliance with applicable laws and professional standards.
8.1 Use of Data for AI Model Training
Equipo does not use PHI to train, fine-tune, or improve artificial intelligence or machine learning models except where such use is (a) expressly authorized by the applicable customer's BAA or written agreement, (b) limited to de-identified or aggregated data consistent with the HIPAA de-identification standard, or (c) otherwise required or permitted by law. Customers may contact Equipo to determine whether and how their data is used in connection with AI model development.
9. Disclosure of Information
Equipo may disclose information:
- To healthcare organizations and authorized users utilizing our Services
- To service providers, contractors, and vendors performing services on our behalf under appropriate contractual obligations, including Business Associate Agreements where PHI is involved
- To third-party integrations authorized by our customers or users
- To governmental authorities or regulators when required by applicable law
- To comply with legal process, court orders, subpoenas, or regulatory requirements
- To protect the rights, safety, security, property, or operations of Equipo, our customers, users, or others
- In connection with a merger, acquisition, financing, reorganization, or sale of assets; any successor entity will remain bound by applicable BAAs and this Privacy Policy with respect to previously collected PHI and personal information, subject to applicable legal obligations
Equipo does not disclose personal information except as described in this Privacy Policy, authorized by our customers, required by law, or otherwise permitted under applicable federal and state law.
10. Security
Equipo maintains administrative, technical, and physical safeguards designed to protect information against unauthorized access, alteration, disclosure, misuse, or destruction. These safeguards may include encryption in transit and at rest, access controls, multi-factor and biometric authentication options, audit logging, monitoring, backups, secure development practices, employee training, and vendor oversight.
Access to information is limited to authorized personnel and authorized users with a legitimate business or operational need.
Although Equipo maintains reasonable safeguards consistent with industry practices, no method of electronic transmission, storage, or information security can be guaranteed to be completely secure. Accordingly, Equipo does not warrant or guarantee that unauthorized access, cyber incidents, or security breaches will never occur.
11. Security Incident and Breach Notification
In the event Equipo discovers a breach of unsecured PHI, Equipo will notify affected customers without unreasonable delay and in accordance with the timelines and requirements of the HIPAA Breach Notification Rule (45 C.F.R. §§ 164.400-414) and the terms of the applicable Business Associate Agreement. Equipo's customers, as Covered Entities, remain responsible for any required notification to affected individuals and regulators unless otherwise agreed in writing.
For security incidents affecting personal information outside the scope of PHI (for example, web application or mobile application account credentials), Equipo will provide notification to affected individuals and, where required, state regulators, in accordance with applicable state breach notification laws.
12. Data Retention
Equipo retains information for as long as necessary to provide our Services, fulfill contractual obligations, comply with applicable laws, resolve disputes, enforce agreements, maintain security, or satisfy regulatory and record retention requirements.
Upon expiration of applicable retention periods, information may be securely deleted, archived, de-identified, or anonymized in accordance with legal, contractual, and operational requirements.
13. Third-Party Services
Our Services may contain links to, integrate with, or interoperate with third-party websites, applications, platforms, EHR systems, communication services, cloud providers, analytics providers, or other technologies that are not owned or controlled by Equipo.
Equipo is not responsible for the privacy, security, availability, content, or practices of third-party services. Users should review the applicable privacy policies and terms of those third parties before providing information or using their services.
14. Children's Privacy
Our public website and marketing materials are not directed toward children under the age of thirteen (13), and Equipo does not knowingly collect personal information directly from children through our public website.
Where the Services are used within a healthcare organization's pediatric care programs, information regarding minors may be collected, used, and disclosed by Equipo solely on behalf of, and as authorized by, the healthcare organization and the minor's parent, guardian, or authorized representative, consistent with HIPAA, applicable state minor-consent laws, and the organization's own policies. Parents or guardians with questions about a minor's information collected through the Services should contact the applicable healthcare organization directly.
15. Your Choices and Privacy Rights
15.1 Marketing Communications
You may discontinue marketing communications by using the unsubscribe instructions included in those communications or by contacting Equipo directly. Operational, security, contractual, administrative, product support, and legally required communications may continue to be sent as necessary to provide the Services or comply with applicable obligations.
15.2 Mobile Notifications
You may enable or disable push notifications for the mobile application at any time in your device settings or within the application's notification preferences.
15.3 State Privacy Law Rights
If you are a resident of a state with a comprehensive consumer privacy law (including, where applicable, California, Colorado, Connecticut, Virginia, Utah, and other states with similar laws), you may have the right, with respect to personal information not otherwise governed by HIPAA, to:
- Request access to the personal information Equipo has collected about you
- Request correction of inaccurate personal information
- Request deletion of your personal information
- Request a portable copy of your personal information
- Opt out of the sale or sharing of personal information, and of targeted advertising, where applicable
- Appeal a denial of a request through the process identified in Equipo's response
These rights generally do not apply to PHI processed by Equipo as a Business Associate, which is governed by HIPAA and the applicable BAA. To exercise a right described in this section, contact Equipo using the information in Section 20. Equipo will verify your identity before responding and will respond within the timeframe required by applicable law.
15.4 Account and Data Deletion (Web and Mobile Application)
Authorized users with a login account for the web application or mobile application may request deletion of their account and associated non-PHI account data by submitting a request through account settings, where available, or by contacting Equipo directly. Requests concerning PHI maintained on behalf of a healthcare organization should be directed to the applicable healthcare provider or organization, as Equipo may not unilaterally delete PHI it maintains as a Business Associate without customer authorization.
16. International Users and Cross-Border Data Transfers
The Services are designed primarily for use within the United States. If Equipo processes personal information of individuals located outside the United States, including the European Economic Area, United Kingdom, or Switzerland, Equipo will implement appropriate safeguards for cross-border data transfers, such as Standard Contractual Clauses, and will provide additional disclosures regarding legal basis for processing and applicable rights upon request. Organizations seeking to use the Services outside the United States should contact Equipo in advance to confirm availability and applicable data protection commitments.
17. Mobile Application Permissions and Connected Device Summary
17.1 Mobile Application Permissions
The table below summarizes categories of device permissions the mobile application may request, depending on which features you use. Equipo requests each permission only at the time a relevant feature is used and only collects the associated data with your consent through your device's permission dialog.
| Permission |
Purpose |
Optional? |
| Camera |
Document/photo capture (e.g., insurance card, referral documents) |
Yes |
| Photo Library |
Uploading existing images or documents |
Yes |
| Push Notifications |
Appointment reminders, care alerts, messages |
Yes |
| Location |
Locating nearby in-network providers or facilities |
Yes |
| Biometric / Face ID / Touch ID |
Secure, convenient account login |
Yes |
| Contacts |
[Include only if applicable — e.g., inviting a caregive] |
Yes |
17.2 Wearable Devices and Remote Patient Monitoring
Where a healthcare organization or authorized user enables integration with a wearable device, remote patient monitoring device, or similar connected health technology, Equipo may receive data transmitted from that device, which may include biometric readings, vital signs, activity data, device identifiers, and timestamps.
Such data is received and processed by Equipo as a Business Associate on behalf of the applicable healthcare organization, subject to the same PHI safeguards, use restrictions, and BAA obligations described in Sections 6 and 10. Equipo does not independently control the data practices of the wearable device manufacturer or its companion application; you should review the privacy policy provided by the device manufacturer for information about how the device itself collects and transmits data before it reaches the Services.
You, or the healthcare organization managing your care, may disconnect a wearable or connected device from the Services at any time, which will stop future data transmission but will not delete data already received, subject to Section 12 (Data Retention).
18. Future Services, Channels, and Technologies
Equipo may, from time to time, introduce new products, features, access channels, or technologies not specifically enumerated in this Privacy Policy — including but not limited to new browser extensions, additional wearable or Internet of Things (IoT) device integrations, voice or conversational interfaces, kiosk or in-office check-in devices, SMS or messaging-based channels, or other emerging technologies (each, a "New Channel").
Any New Channel that references or incorporates this Privacy Policy will be governed by its terms to the extent applicable. Where a New Channel collects categories of information materially different from those described in this Privacy Policy, or introduces materially different data practices, Equipo will update this Privacy Policy prior to or concurrent with the launch of that New Channel and will provide notice consistent with Section 19 below. Equipo will not use PHI or personal information in connection with a New Channel in a manner inconsistent with the purposes and restrictions described in this Privacy Policy, applicable Business Associate Agreements, and applicable law.
19. Changes to This Privacy Policy
Equipo may revise this Privacy Policy from time to time to reflect changes in our Services, legal requirements, industry practices, or business operations. Updated versions will be posted on our website and within each applicable access channel, including the web application, mobile application, browser extension listing, and any wearable or connected device integration page, with a revised effective date. For material changes affecting how PHI or personal information is used, Equipo will provide additional notice as required by applicable law, which may include an in-app or in-extension notification, or email to registered users. Continued use of the Services after such updates constitutes acceptance of the revised Privacy Policy to the extent permitted by applicable law.
20. Contact Us
If you have questions regarding this Privacy Policy or our privacy practices, or wish to exercise a right described above, please contact: