Legal
Privacy Policy
This Privacy Policy explains how Comara Care handles information across our service: our marketing website, our secure dashboard for healthcare provider teams, and the messages we send patients and family caregivers on a provider's behalf.
The short version
- Comara Care is a United States software company. We help healthcare provider organizations close gaps in follow-up after a hospital stay and run Transitional Care Management (TCM).
- For patient health information, we are a Business Associate (a processor) under the Health Insurance Portability and Accountability Act (HIPAA). Your healthcare provider is the Covered Entity. A written Business Associate Agreement (BAA) and HIPAA, not this policy, control how we may use that information. We use it only to deliver the service to your provider.
- If you are a patient or family caregiver, you exercise your rights about your own health information through your provider, not through us. We help your provider honor your requests. See your provider's Notice of Privacy Practices.
- We do not sell personal information. We do not use health information for advertising. We do not use patient health information to train general or third-party artificial intelligence (AI) models beyond what the BAA and law allow.
- We use AI to assist people, not to replace them. AI extracts tasks and follow-ups, summarizes, and drafts outreach. Licensed clinicians make every medical decision. AI does not diagnose, prescribe, or change medication instructions.
- We text and call patients and caregivers on behalf of your provider. You can reply STOP to opt out. Message and data rates may apply. The service is not for emergencies. If you have an emergency, call 911.
- Our security program is built to the HIPAA Security Rule. Encryption, access controls, multi-factor sign-in, audit logging, staff training, and vendor agreements. We pursue independent assessments such as System and Organization Controls 2 (SOC 2).
- Questions? Email us at hello@comaracare.com.
This summary is a plain-English overview. The full policy below has the details. For patient health information, the BAA and HIPAA control.
1. About this policy and who we are
Comara Care ("Comara Care," "we," "us," or "our") is a United States software company. Our product helps healthcare provider organizations follow up with patients after a hospital stay and run Transitional Care Management (TCM). Our customers include Medicare-focused primary care practices, hospital-owned primary care networks, Accountable Care Organizations and Clinically Integrated Networks, rural health clinics, and dementia-care organizations.
We sell our service to provider organizations, and those providers use it to care for their patients. When we handle patient health information, we do so on behalf of those providers.
This policy explains what information we handle, how we handle it, and the choices and rights you have. It covers our marketing website at comaracare.com, our secure dashboard for providers and care managers, and our patient and caregiver messaging across text message (SMS), phone or voice, secure web links, and our optional mobile app.
For patient health information, the Business Associate Agreement (BAA) we sign with your provider and HIPAA control. Where this policy and a BAA differ for that information, the BAA and HIPAA govern.
2. The two roles we play
We play two different roles depending on the information involved. The role decides which rules apply.
As a Business Associate (a processor). For patient Protected Health Information (PHI), we act as a Business Associate under HIPAA. Your healthcare provider is the Covered Entity. We process PHI only on the provider's behalf, under a written BAA and HIPAA. The BAA and HIPAA, not this policy, govern what we may do with PHI. Before a provider gives PHI to us, HIPAA requires the provider to get written assurances from us that we will protect it. That is the BAA (45 Code of Federal Regulations (CFR) 164.502(e) and 164.504(e)).
As a controller (a business) in our own right. For some information, we decide how and why it is used, so we are the controller. This includes data from our marketing website, the account details of provider users, and the contact details of prospects who reach out to us. This policy's own promises cover that information.
3. Who this policy is for and how it applies
This policy speaks to three audiences. Your role changes how we handle your data.
(a) Visitors to our marketing website (comaracare.com). When you browse comaracare.com, request a demo, or book a meeting, we are the controller of the limited data you give us and the analytics our site collects. We do not put PHI on the marketing site. See Sections 6 and 10.
(b) Provider-customer users (clinicians, nurses, care managers, administrators). When your organization buys our service and you use the dashboard, we are the controller of your account and usage data (such as your name, work email, role, and sign-in activity). We process the patient information you work with as a Business Associate on your organization's behalf. See Sections 4, 5, 6, and 12.
(c) Patients and family caregivers. When your provider uses Comara Care to follow up with you, we handle your health information as a Business Associate on your provider's behalf. We are not your provider, and we do not make decisions about your care. Your rights about your own health information run through your provider. Your provider's Notice of Privacy Practices is the authoritative description of how your health information is used and how you exercise your rights. See Sections 4, 8, and 12.
4. How we handle Protected Health Information for your provider
This is the core of what we do, so we want to be clear about it.
We use PHI only as the BAA and HIPAA allow. We use and disclose PHI only for the purposes set in the BAA, which is delivering the post-discharge follow-up and Transitional Care Management service to your provider. We do not use or further disclose PHI for any other purpose unless the BAA or the law allows it.
Minimum necessary. When we use, disclose, or request PHI, we make reasonable efforts to limit it to the minimum necessary for the task, as HIPAA requires (45 CFR 164.502(b) and 164.514(d)).
Where PHI comes from. We receive PHI from your provider and the systems your provider connects to us. This can include electronic health record (EHR) exports and admit, discharge, and transfer (ADT) notification feeds that tell the care team when a patient has been discharged. We also collect the contact details and engagement information needed to reach patients and caregivers, such as a phone number, message replies, and responses to follow-up questions.
Your provider's Notice of Privacy Practices controls. Your provider issues a Notice of Privacy Practices under HIPAA (45 CFR 164.520). That notice, not this policy, describes how your PHI is used and how you exercise your rights. Our handling of PHI on your provider's behalf is consistent with that notice and the BAA.
5. How we use artificial intelligence, and what it does not do
We use artificial intelligence (AI) to help care teams work through messy paperwork faster. Here is what it does and does not do.
What the AI does. AI reads care documents and other artifacts to pull out tasks, dates, medication changes, missing information, red flags, and needed follow-ups. It summarizes a patient's care episode. It drafts outreach messages for staff to review.
Humans make the decisions. AI routes work to people and drafts text for them. Licensed clinicians make every medical decision. Clinicians can review the source material behind any AI output. AI does not diagnose, does not prescribe, and does not change medication instructions. It is not an autonomous medical device, and it does not make medical decisions on its own.
No overstated claims. We describe what the AI does plainly and do not overstate its accuracy or abilities.
We do not train general models on your PHI. We do not use patient PHI to train general-purpose or third-party AI models beyond what the BAA and the law permit. Any use of PHI for our own purposes is limited to what the BAA allows, which under HIPAA can include our proper management and administration, data aggregation for your provider's health care operations, and de-identification where the BAA authorizes it (45 CFR 164.504(e) and 164.514).
Fairness. Our provider customers carry the legal duty to identify and reduce discrimination from patient care decision support tools. We support that work and avoid using protected-class details to drive who gets follow-up in a way that treats people unequally.
6. The marketing website and provider accounts
Outside the PHI we handle for providers, we collect a small amount of information as a controller.
Marketing website data. When you visit comaracare.com, we collect standard analytics such as pages viewed, approximate location from your Internet Protocol (IP) address, device and browser type, and how you arrived. If you fill out a form, join a waitlist, or book a meeting, we collect the details you provide, such as your name, work email, organization, and message.
Provider account data. When you use the dashboard, we collect your account details (name, work email, role) and usage and security logs (sign-in times, actions taken, device and IP information). Accounts use a password or single sign-on (SSO), and multi-factor authentication (MFA) is available.
We use this information to operate and secure the service, respond to inquiries, schedule meetings, improve our website and product using data that is not PHI, and meet our legal duties.
7. How we share information
We share information only in the ways described here. We do not sell personal information, and we do not use PHI for advertising. We use no advertising networks, no advertising pixels, and no cross-context behavioral advertising.
With the care team. We make PHI available to the authorized clinicians, nurses, care managers, and administrators at your provider so they can deliver your care.
With service providers (subprocessors). We use vendors to run the service. See Section 9. Every vendor that handles PHI is under a BAA.
As required by law. We may disclose information when the law requires it, such as a valid legal request, or to protect safety. For PHI, we do so consistent with the BAA and HIPAA.
In a business transfer. If we are involved in a merger, acquisition, financing, or sale of assets, information may transfer as part of that deal. Any PHI stays protected under HIPAA and the BAA, and we will not use it in a way the BAA forbids.
A disclosure of personal information to a service provider or processor under a compliant contract is not a "sale" or a "share" under state privacy laws such as the California Consumer Privacy Act (CCPA).
8. Communications with patients and caregivers
We send outreach to patients and family caregivers on behalf of your provider, for care coordination and treatment. We do this by text message (SMS), phone or voice, secure web links, transactional email, and our optional mobile app.
Consent runs through your provider. Your provider directs these messages and is responsible for the consent behind them. For care and treatment messages, this generally rests on the phone number you gave your provider for that purpose. Marketing or promotional messages are different and would need separate consent. We do not mix marketing into care messages.
Message frequency and rates. Message frequency varies with your care. Standard message and data rates may apply.
How to get help or stop messages. You can opt out at any time by replying STOP (other plain words such as QUIT, END, CANCEL, or UNSUBSCRIBE also work). Reply HELP for help. We honor opt-out requests by any reasonable method and process them promptly, immediately for the care and treatment messages covered by the federal healthcare messaging rules. Opting out of messages does not affect your ability to get care from your provider.
Security of text and email. Plain text messages and standard email are not fully secure. We limit the health information in a text and prefer secure web links for details. Your provider may, with your agreement after a warning that the channel is not secure, send certain information by text or email because you prefer that method. You can ask your provider to communicate with you by other means or at another location, and your provider will accommodate reasonable requests. We support configurable contact and channel preferences so your provider can honor these requests.
Messages to family caregivers. We add a caregiver's phone number or email only with the patient's or provider's authorization. Caregivers can opt out the same way (reply STOP) and can reply HELP for help.
Federal messaging law. Text and voice outreach is also governed by the Telephone Consumer Protection Act (TCPA), which is separate from HIPAA. Being HIPAA-compliant does not by itself satisfy the TCPA. Your provider holds the consent basis, and opt-out always works.
Not for emergencies. Our messaging and app are not monitored in real time and are not for medical emergencies. If you have an emergency, call 911 or go to the nearest emergency room.
9. Service providers and subprocessors
We use a small set of vendors (subprocessors) to run the service. Each vendor that creates, receives, maintains, or transmits PHI for us is bound by a BAA with the same protections that apply to us, as HIPAA requires (45 CFR 164.502(e)(1)(ii), 164.308(b), and 164.314(a)).
The categories of subprocessors include:
- Cloud hosting to run and store the application. Under a BAA.
- Text (SMS) and voice messaging to reach patients and caregivers. Under a BAA.
- Transactional email to send service and account messages. Configured to exclude PHI.
- Product and website analytics to understand and improve the service. Configured to exclude PHI.
- Error monitoring to find and fix software problems. Configured to exclude PHI.
We maintain a list of subprocessors and can make it available to provider customers, along with a way to learn about and object to material changes. We do not send PHI to analytics, advertising, or error-monitoring tools.
10. Cookies, analytics, and tracking on the marketing website
Our marketing website (comaracare.com) is separate from the secure application that handles PHI. We do not send PHI to analytics or advertising tools.
The marketing website uses PostHog for product analytics, including session replay with input masking so that text typed into form fields is masked and not captured. We use no advertising networks and no advertising pixels. The site links to Cal.com for scheduling meetings, and the site is hosted on Vercel.
You can opt out of marketing-site analytics with the control below or through your browser settings. We also honor Global Privacy Control and Do Not Track browser signals, and turn analytics and session replay off when we receive them.
Checking your current setting...
11. Security
Our security program is built to the HIPAA Security Rule, which requires administrative, physical, and technical safeguards for electronic PHI (45 CFR 164.306, 164.308, 164.310, and 164.312). Our safeguards include:
- Encryption of data in transit and at rest.
- Role-based access controls, so people see only what they need.
- Multi-factor authentication (MFA).
- Audit logging and review of system activity.
- Regular risk analysis and risk management.
- Workforce training on privacy and security.
- Business Associate Agreements with vendors that handle PHI.
We pursue and maintain independent third-party assessments of our program, such as a System and Organization Controls 2 (SOC 2) assessment. We describe these assessments as part of our ongoing program. No security program can promise perfect security.
If you believe you have found a security vulnerability or have a security concern, please contact us at hello@comaracare.com.
12. Your privacy rights
Your rights depend on the type of information.
Rights about your own health information (PHI). You exercise your HIPAA rights through your provider, the Covered Entity, not through us. These rights include access to your records (45 CFR 164.524), amendment (164.526), an accounting of disclosures (164.528), and requests for restrictions or confidential communications (164.522). To exercise them, contact your provider and see your provider's Notice of Privacy Practices. We assist your provider by making the PHI we hold available so your provider can answer your request, as the BAA requires. Where a BAA directs us to do so, we will also provide an electronic copy of PHI.
State privacy rights for other information. If you are a website visitor or a provider user, you may have rights under state privacy laws for the non-PHI personal information we control, such as your business contact details, account data, and website-visitor data. Depending on your state (for example, California, Virginia, Colorado, or Connecticut), these can include the right to access, correct, delete, or receive a copy of your information, and to opt out of any sale, targeted advertising, or certain profiling. We do not sell personal information, do not use cross-context behavioral advertising, and do not use PHI for advertising. To make a request, email hello@comaracare.com. We will verify your request and respond as the law requires, and where a state law provides an appeal, we will tell you how to appeal.
How HIPAA and state laws fit together. Under the Washington My Health My Data Act (MHMDA), the exemption for HIPAA data works at the data level, not the entity level. Protected Health Information (PHI), data we keep intermingled with PHI, and data we de-identify under HIPAA are exempt, and that exemption covers the core of what we do for providers. The exemption does not switch off the law for everything we touch. For the limited consumer health data we collect and control through our marketing website, our analytics, and our optional consumer app, we are a regulated entity under the MHMDA. We describe that data, and your rights in it, in our separate Consumer Health Data Privacy Policy. Nevada and Connecticut exempt HIPAA business associates more broadly at the entity level, so our exposure there is lower, and we still follow their consumer health data rules for any data they cover.
De-identified data. If we de-identify data, we follow the HIPAA de-identification standard (45 CFR 164.514) and do not try to re-identify it.
13. Data retention, and return or deletion of PHI
PHI. We retain and dispose of PHI as the BAA and your provider's instructions direct. When our engagement with a provider ends, we return or destroy the PHI we still hold for that provider where feasible, and keep no copies. Where return or destruction is not feasible, we extend the BAA's protections to that PHI and limit further use to the purposes that make return or destruction infeasible (45 CFR 164.504(e)(2)(ii)(J)). Specific retention and deletion windows are set in the BAA.
Other information. We keep account, log, and website data only as long as we need it for the purposes in this policy and to meet legal, security, and recordkeeping needs, then delete or de-identify it.
14. Breach notification
As a Business Associate, if we discover a breach of unsecured PHI, we notify the affected provider (the Covered Entity) without unreasonable delay and in no case later than 60 calendar days after we discover it, consistent with HIPAA and the BAA (45 CFR 164.410). A BAA may set a shorter deadline, and we follow it. A breach is treated as discovered on the first day we know of it, or by reasonable diligence would have known of it.
Our notice identifies, to the extent possible, each individual whose unsecured PHI was, or is reasonably believed to have been, involved, and gives the provider the other information it needs for its own notifications, at the time of notice or promptly as that information becomes available. The provider, as the Covered Entity, generally notifies affected individuals, the United States Department of Health and Human Services, and where required the media. For any non-PHI personal information we control, we follow the applicable state breach-notification laws.
15. Children's privacy
Our service is directed to healthcare providers and adults, not to children. We do not knowingly collect personal information directly from children online, so the Children's Online Privacy Protection Act (COPPA) does not apply to our service. Where we process a minor's health information for a provider, we handle it as PHI under HIPAA and the BAA, on the provider's behalf.
16. International visitors and United States processing
Comara Care is a United States company, and we process PHI and personal information in the United States. If you access our website or service from outside the United States, your information will be processed in the United States, where privacy laws may differ from those in your location. If any subprocessor processes data outside the United States, that processing is bound by a BAA where PHI is involved and by appropriate safeguards.
17. Changes to this policy
We may update this policy as our service, technology, or the law changes. When we make a material change, we will update the "Last updated" date at the top and, where appropriate, provide additional notice. Some details described here are configurable by contract with a provider, and the operative terms for PHI live in the BAA.
18. How to contact us
For privacy or security questions, to report a suspected vulnerability or incident, or to make a state-law privacy request about non-PHI information we control, contact us at hello@comaracare.com.
If you are a patient or family caregiver and want to exercise rights about your own health information, please contact your healthcare provider and see your provider's Notice of Privacy Practices. We will support your provider's response. If you are a provider customer, you may also use the contacts and escalation path in your Business Associate Agreement.