Privacy Policy

ModMed's Privacy Policy Simplified

🌐 www.modmed.com

ModMed is a healthcare technology company that provides electronic health records (EHR), practice management, and revenue cycle management solutions for medical practices.
AI-Powered Analysis
Last analyzed April 8, 2026 19:23
View Original Privacy Policy
63
Moderate Score

Overall Rating: 63/100

Based on analysis of data protection, legal compliance, transparency, and fairness

65

User Data Protection

Explicitly addresses biometric data (voiceprints) and location information with some safeguards, but lacks detail on encryption, retention periods, and specific security measures for sensitive data.

70

Legal Compliance

References HIPAA, includes U.S. state privacy rights section, and provides opt-out mechanisms, but lacks GDPR-specific provisions and detailed data subject rights procedures.

55

Balance & Fairness

Provides some user controls (opt-outs, location disabling) and contact methods, but includes broad data sharing provisions and unilateral modification rights favoring the company.

60

Transparency & Readability

Uses clear structure with table of contents and plain language in parts, but contains lengthy legal definitions and complex jurisdictional distinctions that may confuse non-lawyers.

AI Summary

The document appears to be a webpage containing a privacy policy and various website elements. The problematic aspects are primarily related to the privacy policy content and data collection practices.

The privacy policy states that Protected Health Information (PHI) is governed by separate agreements with healthcare providers and not by this policy, which could create confusion for patients about who governs their data.

The policy collects a broad range of personal information, including name, address, email, phone, employer, medical specialty, and biometric data like voice prints and recordings.

Location information is collected from device GPS, Wi-Fi, and IP addresses, which can be highly sensitive.

Usage data is automatically collected, including IP address, device details, and activity on the services.

Information is obtained from other sources like data aggregators, marketing companies, and publicly available databases, which means data collection extends beyond direct user interactions.

Data is shared with a wide range of third parties, including service providers, contractors, business partners, and potentially parties involved in business transactions like mergers or acquisitions.

The policy uses cookies, web beacons, and other tracking technologies, and explicitly states it does not respond to Do Not Track signals.

Biometric data, specifically voiceprints, is collected from medical providers using dictation features, with usage governed by third-party terms.

International users' data is transferred to and processed in the United States, which may not have equivalent privacy protections to their home countries.

The policy can be changed at any time at the company's discretion, with continued use constituting acceptance of changes.

The contact information for privacy questions includes a phone number and email, but the policy is not a contract and does not create contractual rights.

The document includes multiple embedded web forms requesting personal and professional information, which aligns with the broad data collection described.

The privacy policy is dated January 10, 2025, which is a future date, potentially indicating it is a draft or not yet in effect.

📋 Key Clauses Analyzed

Broad Personal Data Collection

Collects extensive personal info including biometric data, location, and usage details from devices and activities.

Third-Party Data Sharing

Shares data with service providers, business partners, and parties in mergers or acquisitions.

No Do Not Track Response

Explicitly states it does not respond to Do Not Track signals from browsers.

International Data Transfers

Transfers international users' data to the US, which may lack equivalent privacy protections.

Unilateral Policy Changes

Policy can be changed anytime at company discretion; continued use implies acceptance.

❓ Questions About This Privacy Policy

AI Enhanced Answers
Generating AI response
The policy states that PHI is governed by separate agreements with healthcare providers, not by this privacy policy. This means patients may need to refer to their provider's specific agreements for PHI handling, which could create confusion about data governance.
Generating AI response
The policy collects biometric data, specifically voiceprints and recordings, from medical providers using dictation features. Usage of this data is governed by third-party terms, not solely by this policy.
Generating AI response
No, the policy explicitly states that it does not respond to Do Not Track signals. This means users cannot rely on browser settings to opt out of tracking.
Location information is collected from device GPS, Wi-Fi, and IP addresses. This collection can be highly sensitive as it may track users' physical movements.
The policy allows data to be shared with parties involved in business transactions like mergers or acquisitions. This means user data could be transferred to a new entity without additional consent.

Never blindly click "agree" again

Install the free Termzy AI browser extension and get instant AI-powered analysis of any legal document you encounter online.

Add Termzy AI to the Browser - It's Free
🎉

Thank You for Using Termzy AI!

You're getting the full experience with complete policy analysis, all clauses unlocked, and unlimited FAQ access.