Privacy Policy
Last updated: February 2026
Zero Patient Data
OccDocs is not an electronic medical record. We do not store, transmit, or process protected health information (PHI). All encounter data entered into OccDocs is anonymized server-side before any storage or AI processing occurs. The original clinical content exists only in memory during the request lifecycle and is never persisted.
What We Collect
We collect the minimum information necessary to operate the service: your name, email address, organization name, and usage data (anonymized session logs, API usage counts). No clinical content, patient identifiers, or PHI is ever stored in our database.
HIPAA Safe Harbor
OccDocs applies HIPAA Safe Harbor de-identification (45 CFR §164.514(b)) to all encounter data before analysis. This includes removal of the 18 HIPAA identifiers: names, dates, geographic data, phone numbers, and all other direct or indirect identifiers.
Audit Logging
Every AI query, authentication event, and data mutation is recorded in an immutable audit log. Logs contain only anonymized session identifiers — no PHI. Logs are retained for 7 years in compliance with WAC 296-20 requirements.
Contact
Privacy questions: [email protected]