Privacy Policy
Last updated September 2, 2026
VizzitMD is a HIPAA-compliant CRM and EHR for house-call and mobile medical practices, published by Heliora Technologies, Inc. ("VizzitMD", "we", "us", or "our"). This Privacy Policy explains what information we collect from visitors to vizzitmd.com (the "Site"), how we use it, and the choices you have. It also describes, at a high level, how we handle data inside the VizzitMD application (the "Service").
1. Information we collect
Information you give us
When you request a demo or otherwise contact us through the Site, we collect the information you submit in the form: your name, work email address, and — where you choose to provide them — your practice name, phone number, number of providers, and any message you write. This is business contact information used to respond to your inquiry. Please do not include patient information or PHI in a demo request or message.
Information collected automatically
Like most websites, our hosting provider automatically records standard technical information when you visit — such as your IP address, browser type, and the pages you view — in server logs used to operate and secure the Site. The Site does not use advertising cookies, third-party analytics trackers, or cross-site tracking. See Cookies and tracking below.
2. How we use information
We use the information you provide to:
- respond to your demo request or inquiry and schedule a walkthrough;
- communicate with you about VizzitMD, including answering questions and providing information you ask for;
- operate, maintain, secure, and improve the Site and the Service; and
- comply with our legal obligations and enforce our agreements.
We do not sell your personal information, and we do not use the contact information you submit for third-party advertising.
3. Cookies and tracking
The Site does not set advertising or analytics cookies and does not track you across other websites. We load a web font from Google Fonts to display the Site's typography; when your browser requests that font, Google receives your IP address as a normal part of serving the file. We do not use Google Fonts to identify you. Any cookies used are strictly necessary to operate the Site and to submit the demo form securely.
4. How we share information
We share information only in the following circumstances:
- Service providers. We use vendors that process information on our behalf to run the Site and our business — for example, our website host and form provider (Netlify) and the provider of our website typography (Google Fonts). These providers may only use the information to perform services for us.
- Customer-directed integrations. Where a customer connects VizzitMD to a third-party service they use (for example, a CRM such as HubSpot, a clearinghouse, or a mapping/geolocation provider), data is exchanged with that service to provide the functionality the customer has enabled, under that service's own terms and privacy policy.
- Legal and safety. We may disclose information if required by law, subpoena, or other legal process, or to protect the rights, property, or safety of VizzitMD, our customers, or others.
- Business transfers. If we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this Policy.
5. Protected health information and HIPAA
When a healthcare practice uses the VizzitMD Service, VizzitMD acts as a Business Associate to that practice under HIPAA. Patient PHI entered into the Service belongs to and is controlled by the practice (the "Covered Entity"), and our handling of that PHI is governed by the signed Business Associate Agreement (BAA) between VizzitMD and the practice — not by this Privacy Policy. A signed BAA is available with every plan. To request one, contact the VizzitMD team.
The technical and organizational safeguards we apply to PHI in the Service include:
- AES-256-GCM encryption. All protected health information is encrypted at rest with AES-256-GCM.
- BAA-eligible geolocation. Routing and geocoding run on Amazon Location Service, which is BAA-eligible, so patient addresses are never sent to a consumer maps API.
- Append-only audit logs. Every action against a chart, order, or claim is logged permanently and cannot be erased or edited.
- Per-practice tenant isolation. Each practice's data is isolated at the tenant level, so one practice can never read another's records.
- Enterprise authentication. Access is controlled through OAuth 2.0 / OIDC, with SSO, SAML, and role-based access available on Enterprise.
6. Data security
We use administrative, technical, and physical safeguards designed to protect the information we hold, including encryption in transit and at rest, tenant isolation, access controls, and append-only audit logging within the Service. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we work to protect your information and to promptly address issues we become aware of.
7. Data retention
We retain the business contact information you submit through the Site for as long as needed to respond to your inquiry and for our legitimate business and legal purposes, after which we delete or de-identify it. Retention of PHI within the Service is governed by the applicable BAA and the practice's own instructions.
8. Your choices and rights
You may ask us to access, correct, or delete the business contact information you have submitted, and you may opt out of non-essential communications from us at any time by replying to any message or emailing us at the address below. Depending on where you live, you may have additional rights under applicable privacy laws; we will honor those rights as required. For PHI held in the Service, individual rights (such as access and amendment) are exercised through the healthcare practice that is the Covered Entity, consistent with HIPAA and the BAA.
9. Children's privacy
The Site is intended for healthcare professionals and is not directed to children. We do not knowingly collect personal information from children through the Site. (This is separate from pediatric patient information a practice may lawfully record in the Service as part of care, which is handled as PHI under HIPAA and the BAA.)
10. Where we operate
VizzitMD is operated in the United States and intended for use by practices in the United States. If you access the Site from outside the United States, you understand that your information will be processed in the United States, where data-protection laws may differ from those in your country.
11. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. Material changes will be communicated through the Site or by other appropriate means.
12. Contact us
Questions about this Privacy Policy or your information can be sent to techheliora@gmail.com. VizzitMD is a product of Heliora Technologies, Inc.. You can also read our Terms of Service.