← AcuZen Practice

Privacy Policy

Last updated: 2026-05-31 · Beta

Data we collect

  • Account: email, name (Google sign-in)
  • Application info: country, license number, clinic name/address, contact, referrer, bio
  • Clinical data — entered by the practitioner; includes SOAP notes, acupoint prescriptions, and patient identifiers:
    • Patient code (practitioner-chosen identifier)
    • Patient name (optional, entered by practitioner) — PHI
    • Clinical narrative (symptoms, treatment plan, etc.)

All clinical data is stored on HIPAA BAA-covered infrastructure (Microsoft Azure, US West region). Access to clinical records is recorded in an audit log.

Purpose

For providing the service (charting assistance, note storage and retrieval), reviewing beta applications, and improving the service.

Storage

Stored on Azure PostgreSQL (US West, HIPAA-eligible infrastructure). AcuZen Practice operates under signed HIPAA Business Associate Agreements (BAA) with the infrastructure providers listed above.

AI Processing (Anthropic Claude)

Clinical narrative is sent to the Anthropic Claude API for SOAP generation. AI requests do not include patient identifying information (PHI):

  • Dates are replaced with [date] placeholders
  • Patient names and patient codes are not included in AI requests
  • If a practitioner enters patient identifying information into free-text fields, that text will be sent to AI (this is the practitioner's responsibility — see Terms §2)

Anthropic provides its API under a HIPAA Business Associate Agreement. Data sent to the API is not used to train models.

Retention

We delete accounts and data upon user request. Rejected applications are deleted.

Third-party sharing

We do not sell data or share it with third parties for marketing. No sharing beyond the processors required to operate the service (Azure, Anthropic).

Contact: drkim@skimacupuncture.com