MedAstrixby Astrix

MedAstrix Privacy Policy

Effective date: July 15, 2026 · Last updated: July 15, 2026

1. Who we are and what this policy covers

MedAstrix ("MedAstrix," "we," "us") is a practice-management and AI voice-agent platform for healthcare clinics, operated by Astrix. This policy covers the MedAstrix marketing site (medastrix.com), the tenant dashboard (app.medastrix.com), and the AI-powered scheduling, chat, and voice services we provide to clinics that use our platform.

This policy describes two different things, and it's important to keep them separate:

  • Platform account data — information about the clinics and staff who use MedAstrix (names, emails, login credentials, billing details, usage of the dashboard). For this data, MedAstrix is the data controller.
  • Patient health information (PHI) — information about a clinic's patients, collected through that clinic's use of our scheduling, chat, and voice-agent tools (names, dates of birth, phone numbers, appointment details, call recordings and transcripts, intake information). For this data, MedAstrix acts as a Business Associate to the clinic under the Health Insurance Portability and Accountability Act (HIPAA), not as an independent controller. The clinic itself is the HIPAA Covered Entity and is responsible for its own Notice of Privacy Practices given directly to its patients. A Business Associate Agreement (BAA) is executed between MedAstrix and each clinic before any patient data is handled, governing exactly how we may use and protect that information on the clinic's behalf.

If you are a patient of a clinic that uses MedAstrix and you have a question about your own health information, please contact that clinic directly — they are the party responsible for your HIPAA rights. If you are a clinic evaluating or using MedAstrix, this policy (together with your BAA) describes how we handle data on your behalf.

2. Information we collect

From clinics and their staff (account data):

  • Name, email address, phone number, role, and clinic/practice details provided at signup or while using the dashboard
  • Billing and payment information, processed through our payment provider (we do not store full card numbers ourselves)
  • Usage information: pages visited, actions taken in the dashboard, log-in times, IP address, browser/device information
  • Support communications

On behalf of clinics (patient data / PHI), collected only through a clinic's use of the platform:

  • Patient name, date of birth, phone number, and (where provided) email
  • Appointment scheduling details, intake responses, and booking history
  • Voice call audio, real-time transcripts, and call metadata, where the clinic has enabled call recording and disclosed this to callers
  • Chat conversation content, where a clinic has the chat feature enabled

We do not collect patient health information for our own independent purposes — it exists on the platform solely because a clinic that has executed a BAA with us is using our tools to serve their own patients.

3. How we use information

Account data is used to operate and improve the platform: authenticating staff logins, running the dashboard, billing, customer support, and communicating with clinics about their account (service updates, security notices, and — where a clinic has opted in — product updates).

Patient data (PHI) is used strictly to perform the services a clinic has configured: answering calls, checking and booking appointments, capturing intake information, and generating the records a clinic needs to run its practice. We do not use PHI for our own marketing, do not sell it, and do not use it to train AI models beyond what is strictly necessary to deliver the service the clinic has configured, consistent with our BAA obligations.

4. AI processing

Our voice agent and chat features use AI models to have appointment-scheduling and clinic-information conversations with callers. Speech-to-text, text-to-speech, and language-model processing for any call or conversation involving PHI are performed exclusively through infrastructure covered by our AWS Business Associate Agreement. A hardcoded safety layer, not configurable by any clinic, always checks for emergency or crisis language before the AI ever generates a response, and directs the caller to call 911 or the 988 Suicide & Crisis Lifeline rather than attempting to handle the situation itself.

5. Who we share information with

We do not sell personal information or patient health information.

We share information only with the service providers necessary to operate the platform, each bound by an appropriate agreement (a signed AWS Business Associate Agreement for any provider touching PHI):

  • Amazon Web Services (AWS) — hosting, database infrastructure, and the AI services (transcription, text-to-speech, and language-model processing) used to power the voice agent and chat, all covered under our AWS Business Associate Agreement.
  • A telephony provider — connects phone calls and carries their audio, under a Business Associate Agreement. Recording, transcription and all AI processing happen on our AWS-covered infrastructure, not on the carrier's systems.
  • A payment processor — subscription billing between MedAstrix and each clinic. It never receives patient information, and we do not store full payment card numbers.

All other platform functionality (scheduling, patient records, staff messaging, appointment reminders, marketing tools used internally by us) runs on infrastructure we operate and host ourselves — it is not handed off to an additional third-party SaaS vendor.

We may also disclose information where required by law, to protect the rights and safety of MedAstrix, our clinics, or the public, or in connection with a merger, acquisition, or sale of assets (with notice to affected clinics where required).

6. How we protect information

  • Encryption at rest (AES-256, via AWS Key Management Service) on every storage volume, and encryption in transit (TLS) on every connection, including internal service-to-service traffic.
  • Every clinic's data is logically isolated using database-enforced access controls (Postgres Row-Level Security) — isolation is enforced at the database layer itself, not only by application logic.
  • Multi-factor authentication is required for staff logins.
  • Access to identifiable patient information (such as a caller's phone number or a call transcript) requires an explicit, logged confirmation step, and every such access is recorded in an audit log.
  • Patient names, dates of birth, and phone numbers are never written to application or system logs — only whether an action succeeded or failed is logged, never the underlying patient data itself.
  • Our production database and application servers run in a private network, not directly reachable from the internet, with administrative access restricted to authenticated, logged sessions.
  • Signed clinical notes are retained for a minimum of six years, consistent with federal HIPAA requirements (or longer where a clinic's state law requires it). Raw audio from AI-assisted clinical documentation is deleted once the treating provider reviews and signs the resulting note — it is not retained as part of the permanent record.

No system is perfectly secure, and we do not claim otherwise. We maintain an incident response process and will notify affected clinics in the event of a security incident affecting their data, consistent with our BAA and applicable law (including HIPAA's Breach Notification Rule and applicable state breach notification laws).

7. Your rights

If you are a patient of a clinic using MedAstrix: your clinic is the party responsible for your HIPAA rights, including the right to access, amend, or receive an accounting of disclosures of your health information. Please contact your clinic directly. We will support our clinic partners in fulfilling these requests as their Business Associate.

If you are a clinic administrator or staff member with a MedAstrix account: you may access, correct, or request deletion of your account information by contacting us at the address below or through your account settings. Certain records (such as those required for HIPAA compliance, billing, or legal recordkeeping) may need to be retained even after an account is closed.

If you are a resident of California or another state with its own privacy law: you may have additional rights, such as the right to know what personal information we hold about you, the right to request deletion, and the right to opt out of the sale or sharing of personal information (we do not sell personal information). To exercise these rights, contact us at the address below.

8. Cookies and tracking

Our marketing site may use cookies or similar technologies for basic site functionality and to understand how visitors use the site. We do not use this data to build advertising profiles, and Astrix products do not run third-party advertising.

9. Children's privacy

MedAstrix is a business tool for healthcare clinics and is not directed at children. We do not knowingly collect personal information directly from children through our marketing site or account signup. Patient information a clinic enters for a pediatric patient is handled as PHI under that clinic's BAA with us, the same as for any other patient.

10. Where data is stored

Platform infrastructure runs in AWS's US East (N. Virginia) region. We do not currently transfer data outside the United States as part of standard platform operation.

11. Changes to this policy

We may update this policy as our practices or applicable law change. We will post the updated version here with a new "Last updated" date, and for material changes affecting how we handle PHI, we will notify clinic partners directly as required by our BAA.

12. Contact us

Questions about this policy, or requests regarding your account data, can be sent to:

legal@medastrix.com

If you are a patient with a question about your own health information, please contact your healthcare provider's office directly.