Last Updated: 04/08/2026

1. Introduction

DoctorFare (“DoctorFare,” “we,” “us,” or “our”) provides a patient access and referral coordination platform used by healthcare providers, including imaging centers, medical offices, specialist practices, and care networks (collectively, “Healthcare Providers” or “Customers”). This Privacy Policy explains how we collect, use, disclose, and protect information in connection with our platform (the “Service”).

This Policy applies to:

  • Healthcare Providers and their authorized staff who use DoctorFare
  • Patients who interact with DoctorFare through a Healthcare Provider (e.g., booking appointments, using chat, accessing records)
  • Visitors to our website

2. Information We Collect

2.1 Information from Healthcare Providers
  • Account and staff information (name, role, contact details, login credentials)
  • Practice information (office name, address, specialties, insurance accepted, availability)
2.2 Protected Health Information (PHI)

On behalf of Healthcare Providers, DoctorFare processes patient information including:

  • Patient name, date of birth, contact information
  • Referral details, reason for visit, exam/appointment type
  • Appointment history, scheduling, and status
  • Communications between providers, and between providers and patients
  • Faxed referral documents and extracted data (via AI Fax intake)
  • Insurance information relevant to referrals and appointments
2.3 Information from Patients Directly
  • Information patients provide via chat, self-service booking, or exam preparation tools
  • Device and usage information when accessing patient-facing features
2.4 Automatically Collected Information
  • Log data, IP address, browser/device type, usage analytics on our website and platform

3. How We Use Information

We use information to:

  • Provide, operate, and maintain the Service (referral routing, scheduling, communication, analytics)
  • Facilitate communication between Healthcare Providers, specialists, and patients
  • Generate referral and appointment analytics for Healthcare Providers
  • Maintain platform security, detect fraud, and prevent misuse
  • Comply with legal and regulatory obligations
  • Improve and develop the Service

4. How We Share Information

We may share information with:

  • The Healthcare Provider’s referral network (specialists, specialist groups) as necessary to facilitate care coordination
  • Service providers and subprocessors who support our infrastructure (hosting, eFax delivery, communications), under appropriate confidentiality and data protection agreements
  • Legal and regulatory authorities, where required by law
  • In connection with a business transaction (merger, acquisition, sale of assets), subject to continued privacy protections

We do not sell patient information.

5. Data Security

DoctorFare maintains administrative, technical, and physical safeguards designed to protect information, consistent with our SOC 2 Type II controls and HIPAA Security Rule obligations, including:

  • Encryption of data in transit and at rest
  • Access controls and audit logging
  • Regular security assessments

6. Data Retention

We retain information for as long as necessary to provide the Service and as required by applicable law, including healthcare record retention requirements, which vary by state and record type.

7. Patient Rights

Depending on applicable law, patients may have rights regarding their health information, including the right to access, request correction of, or request restrictions on their PHI. Requests regarding PHI should generally be directed to the Healthcare Provider, as DoctorFare acts on the Provider’s behalf.

8. Children’s Privacy

DoctorFare may process health information relating to minor patients where such information is submitted by a Healthcare Provider on behalf of a parent or legal guardian. We rely on the Healthcare Provider to obtain appropriate parental or guardian consent before submitting a minor’s information to the Service. Parents or legal guardians seeking to access, correct, or restrict a minor’s information should contact the Healthcare Provider directly, as DoctorFare processes this information on the Provider’s behalf.

We do not knowingly collect information directly from children outside the context of a Healthcare Provider relationship, and our patient-facing features are intended for use by adult patients or by parents/guardians acting on a minor’s behalf.

9. International Data / State-Specific Rights

DoctorFare currently operates primarily within the United States, and this Policy is intended to comply with applicable U.S. federal and state health privacy laws, including HIPAA. Depending on your state of residence, you may have additional rights regarding your health and personal information under state law.

As DoctorFare expands to serve Healthcare Providers in other countries, this Policy will be updated to address applicable regional data protection requirements, and users in those regions will be notified of any additional rights and protections that apply to them.

10. Changes to This Policy

We may update this Policy from time to time. Material changes will be communicated to Healthcare Provider Customers as required under our agreements.

11. Contact Us

hello@doctorfare.com

 

 

© 2024 DoctorFare. All rights reserved.

HIPAA COMPLIANT

SOC2 CERTIFIED