Last Updated: September 26, 2026
Lamics, Inc. ("Lamics," "we," "us," or "our") is committed to protecting the privacy and security of your information. This Privacy Policy describes how we collect, use, disclose, and safeguard information when you use our AI-powered healthcare communication and clinical documentation services, including our Voice Agent and AI Scribe (the "Services").
PHI we process on behalf of a healthcare provider is also governed by the Business Associate Agreement (BAA) we sign with that provider. If this Privacy Policy and a BAA conflict, the BAA controls. This Privacy Policy should also be read together with our Terms of Service.
1. Information We Collect
1.1 Protected Health Information (PHI)
As a Business Associate under HIPAA, we collect and process PHI on behalf of covered entities (healthcare providers). This includes:
- Patient names, contact information, and demographic data
- Health insurance information and policy numbers
- Appointment scheduling data and visit history
- Audio recordings and summaries of phone calls between patients and our Voice Agent
- Audio recordings and transcripts of patient-provider encounters captured by our AI Scribe
- Clinical notes (such as SOAP notes) and other documentation generated from those encounters
- Prior chart information imported from your EHR to provide context for documentation
- Medical history and clinical observations discussed during calls and encounters
1.2 Account and Business Information
We collect information from healthcare providers who use our Services:
- Practice name, address, and contact information
- Account administrator names and email addresses
- Billing information and payment details
- EMR system integration credentials and configuration data
- User preferences and service configuration settings
1.3 Usage and Technical Information
We automatically collect certain information when you use our Services:
- Call volume, duration, and timing data
- Service performance metrics and response times
- IP addresses, browser type, and device information
- Error logs and diagnostic information
- Feature usage and interaction patterns
1.4 Communication Data
We collect information from your communications with us:
- Support requests and customer service communications
- Feedback, suggestions, and survey responses
- Email correspondence and chat messages
2. How We Use Information
2.1 To Provide Services
We use the information we collect to:
- Answer patient calls and schedule appointments via our Voice Agent
- Verify insurance coverage and benefits
- Process patient calls, appointment requests, and insurance-related inquiries
- Transcribe patient-provider encounters and generate draft clinical documentation for clinician review
- Synchronize data with EMR systems (Epic, Cerner, Athenahealth, etc.)
- Process and route patient inquiries to appropriate staff
- Maintain and improve AI model accuracy and performance
2.2 To Improve and Develop Services
We use de-identified and aggregated data to:
- Train and improve our AI models and algorithms
- Analyze service performance and identify areas for enhancement
- Develop new features and capabilities
- Conduct research and analytics (using only de-identified data)
2.3 For Business Operations
We use account and business information to:
- Process billing and payments
- Provide customer support and technical assistance
- Send service updates, security alerts, and administrative messages
- Maintain account security and prevent fraud
- Comply with legal obligations and regulatory requirements
2.4 With Your Consent
We may use information for other purposes with your explicit consent, such as marketing communications (which you can opt out of at any time).
3. How We Share Information
3.1 We Do Not Sell Your Information
Important: We do not sell, rent, or trade PHI or any personal information to third parties for their marketing purposes.
3.2 Service Providers and Subprocessors
We share information with trusted third-party service providers who assist us in operating our Services. All such providers are bound by contractual obligations to protect your information and comply with HIPAA:
- Cloud Infrastructure Provider: Google Cloud Platform (hosting, storage, and backups in the United States)
- Telephony Providers: Twilio, for connecting and routing phone calls
- Speech Recognition and AI Model Providers: Third-party speech-to-text, text-to-speech, and language model services used to operate the Voice Agent
- EHR and Practice Management Systems: The system your practice uses (e.g., athenahealth, eClinicalWorks), at your direction
- Payment Processors: Secure payment processing services (PCI-DSS compliant)
- Analytics Services: Service monitoring and performance analytics (using de-identified data only)
3.3 Legal Requirements
We may disclose information when required by law, such as:
- In response to subpoenas, court orders, or legal process
- To comply with HIPAA and other healthcare regulations
- To protect our rights, property, or safety, or that of others
- In connection with legal investigations or proceedings
3.4 Business Transfers
If Lamics is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will provide notice and ensure continued protection under HIPAA.
3.5 With Your Authorization
We may share information with your explicit authorization or as directed by the covered entity we serve.
4. Data Security
4.1 Security Measures
We implement industry-standard security measures to protect your information, including:
- Encryption: Customer data is encrypted at rest using AES-256 and in transit using TLS 1.2 or higher.
- Access Controls: Role-based access control (RBAC) and multi-factor authentication
- Audit Logging: Comprehensive logging of all PHI access and modifications
- Network Security: Firewalls, intrusion detection, and DDoS protection
- Employee Training: Regular HIPAA and security awareness training for all staff
- Incident Response: Documented procedures for security incidents and breaches
- Regular Assessments: Periodic security audits and vulnerability testing
4.2 HIPAA Compliance
We maintain comprehensive HIPAA compliance programs, including:
- Administrative, physical, and technical safeguards as required by the HIPAA Security Rule
- Privacy practices compliant with the HIPAA Privacy Rule
- Breach notification procedures as required by the HITECH Act
- Business Associate Agreements with all covered entities and subcontractors
4.3 Breach Notification
In the event of a breach of unsecured PHI, we will notify affected covered entities without unreasonable delay, as required by HIPAA and within the notification period set out in our Business Associate Agreement with that covered entity.
5. Data Retention and Deletion
5.1 Retention Periods
We retain information for the following periods (or as specified by the covered entity):
- Call Recordings and Call Summaries: 7 years or as specified by covered entity
- Encounter Recordings, Transcripts, and Clinical Notes: Per covered entity's retention policy
- Appointment and Scheduling Data: 3 years or as specified by covered entity
- Audit Logs: 7 years minimum
- Account Information: Duration of service relationship plus 7 years
5.2 Deletion Methods
When data is deleted, we use industry-standard secure deletion methods:
- Deletion of records from production databases and storage
- Expiration of backup copies on their scheduled retention cycle
- Sanitization of physical storage media by our cloud provider, Google Cloud, under its data deletion practices
- Verification of deletion completion
5.3 Data Portability
Upon request, we will provide covered entities with copies of their data in standard formats (JSON, CSV, HL7, etc.) to facilitate data portability.
6. Your Rights and Choices
6.1 For Healthcare Providers (Covered Entities)
As a covered entity using our Services, you have the right to:
- Access your account data and PHI we maintain on your behalf
- Request corrections or amendments to inaccurate data
- Receive an accounting of PHI disclosures
- Request restrictions on how we use or disclose PHI
- Export your data in portable formats
- Terminate our services and request data deletion
6.2 For Patients
If you are a patient whose information is processed through our Services, your rights under HIPAA are exercised through the healthcare provider (covered entity), not directly with Lamics. Please contact your healthcare provider to exercise your HIPAA rights.
6.3 Marketing Communications
You may opt out of marketing communications at any time by:
- Clicking the "unsubscribe" link in marketing emails
- Contacting us at support@lamicsai.com
- Adjusting your account preferences
Note: You cannot opt out of essential service communications (e.g., security alerts, billing notices).
7. Children's Privacy
Our Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. However, we may process PHI for pediatric patients on behalf of covered entities as part of our healthcare services. Such processing is governed by HIPAA and our Business Associate Agreement.
8. International Data Transfers
Our Services are provided from the United States. If you access our Services from outside the United States, your information will be transferred to, stored, and processed in the United States.
We take appropriate measures to ensure that international data transfers comply with applicable data protection laws.
9. California Privacy Rights
If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA). However, PHI covered by HIPAA is exempt from CCPA.
For non-PHI information, California residents have the right to:
- Know what personal information we collect and how it is used
- Request deletion of personal information
- Opt out of the sale of personal information (we do not sell personal information)
- Non-discrimination for exercising privacy rights
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will post the updated Privacy Policy on our website and update the "Last Updated" date.
For material changes, we will provide notice via email or through our Services at least thirty (30) days before the changes take effect.
Your continued use of the Services after changes become effective constitutes acceptance of the updated Privacy Policy.
11. Third-Party Links and Services
Our Services may contain links to third-party websites or integrate with third-party services (e.g., EMR systems). We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies.
Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:
Lamics, Inc.
Privacy Officer
Email: support@lamicsai.com
For HIPAA-related requests or to exercise your rights under HIPAA, please contact your healthcare provider directly.