Legal
Privacy Policy & Terms
Last updated: June 30, 2026
Legal
Last updated: June 30, 2026
Aletheia Health Inc. (“Aletheia Health,” “we,” “us,” or “our”) builds agentic AI for healthcare payments. We help healthcare providers and the organizations that serve them get paid correctly, reduce avoidable payment work, and protect patients from billing failures.
This Privacy Policy explains how we collect, use, disclose, and safeguard information when you visit our website, request a demo, or when your organization uses our platform. We operate in both the United States and Canada and design our practices to meet the requirements of each jurisdiction.
Information you provide to us: When you request a demo, contact us, or sign up for updates, we may collect your name, work email, organization or clinic name, role, EMR, and any message you send. We use this to respond and to set up your demo.
Information processed on behalf of our customers: When a healthcare provider or partner uses our platform, we process clinical, claims, billing, eligibility, and remittance data on their behalf and under their instructions. This may include protected health information (PHI) in the U.S. and personal health information (PHI) in Canada. We act as a service provider for this data — we do not use it for our own independent purposes.
Technical and usage information: Like most websites, we automatically collect limited technical data such as IP address, browser type, pages viewed, and aggregate analytics to operate and improve our site.
We use information to: provide, operate, and improve our services; respond to inquiries and schedule demos; surface billing intelligence and recover correctly owed reimbursement for our customers; maintain the security and integrity of our systems; and comply with our legal and contractual obligations.
We do not sell personal information, and we do not use protected/personal health information for advertising or for any purpose other than providing services to the responsible healthcare organization.
For our U.S. customers, Aletheia Health typically acts as a “Business Associate” under the Health Insurance Portability and Accountability Act (HIPAA). We process PHI only as permitted by a Business Associate Agreement (BAA) with the covered entity or business associate that engages us.
We implement administrative, physical, and technical safeguards consistent with the HIPAA Security Rule, including encryption, access controls, and audit logging. We use and disclose PHI only as the BAA allows or as required by law, and we will report any breach of unsecured PHI as required.
For our Canadian customers, Aletheia Health acts as an information manager / agent for health information custodians (for example, physicians and clinics) under Ontario’s Personal Health Information Protection Act (PHIPA), and we handle personal information in accordance with the federal Personal Information Protection and Electronic Documents Act (PIPEDA).
We collect, use, and disclose personal health information only on behalf of, and as instructed by, the custodian, and only as needed to provide our services. We support custodians in meeting their obligations, including responding to patient access and correction requests.
We maintain Canadian data residency for Canadian customer data, and we store U.S. customer data within the United States. Where any transfer or processing occurs across borders, we apply appropriate contractual and technical safeguards and act consistently with applicable law.
We protect information using encryption in transit and at rest, role-based access controls, audit trails, and ongoing monitoring. While no system can be guaranteed perfectly secure, we work continuously to protect the data entrusted to us.
We retain personal information for as long as needed to provide our services, to satisfy our contractual obligations to customers, and to comply with legal, accounting, or reporting requirements. Health information is retained and deleted in accordance with our agreements with the responsible organization and applicable law.
Depending on where you live, you may have rights to access, correct, or delete your personal information, and to object to or restrict certain processing. For website and demo-request data, contact us using the details below.
For protected/personal health information that we process on behalf of a healthcare organization, please direct access and correction requests to that organization (the covered entity or custodian), and we will support them in responding.
Our website and services are intended for healthcare organizations and professionals, not for children, and we do not knowingly collect personal information directly from children.
We may update this Privacy Policy from time to time. When we do, we will revise the “last updated” date above. Material changes will be communicated as appropriate.
If you have questions about this Privacy Policy or our handling of your information, contact us at privacy@aletheiahealth.com.
This page is provided for general information and is a starting template tailored to Aletheia Health. It is not legal advice. Please have it reviewed and finalized by qualified legal counsel in each jurisdiction before relying on it, and update the contact details and effective date to match your final policy.