Who we are and what this covers
HUVER, Inc. provides HUVA, including HUVA Chat, HUVA Work, Front Desk, and Scribe. In this policy, “HUVER,” “HUVA,” “we,” and “our” refer to HUVER, Inc. This policy explains how information is handled in connection with our website, professional accounts, support, product inquiries, and enabled services.
Different products have different data boundaries. The free HUVA Chat service is for individual healthcare professionals and must not receive identifiable patient information. An authorized HUVA Work or Scribe deployment may process patient information only within its approved scope and applicable agreements.
For information we process on behalf of a clinic, the clinic’s instructions, service agreement, data processing agreement where applicable, and Business Associate Agreement (“BAA”) govern that processing. This policy is not a BAA, a patient consent form, or the clinic’s Notice of Privacy Practices. It does not enlarge a contract’s permitted uses of patient information.
Information involved in each service
The information involved depends on the product, features enabled, and what you or an authorized organization provide.
| Context | Information and purpose |
|---|---|
| Website and inquiries | Name, work email, clinic or organization, professional role, selected product or plan, inquiry preferences, contact permission, and any optional business details. We use these to respond, arrange demonstrations, and manage requested updates. |
| Professional accounts | Account identifiers, professional profile information you provide, organization membership, access roles, account settings, and account or support communications. |
| HUVA Chat | Permitted clinical questions, de-identified context, attachments where enabled, generated responses, references, feedback, and conversation history where supported. These must not contain identifiable patient information. |
| Individual Scribe extension | Encounter content needed for transcription and draft documentation within the clinician’s EHR workflow. The extension’s temporary transcription data is deleted when the clinician completes documentation in the EHR and selects Confirm in Scribe. |
| Clinic-connected HUVA Work and Scribe | Authorized patient and appointment context, encounter documentation, and connected workflow records. Clinic-connected records are stored and managed in the clinic’s private cloud environment under its access and retention policies. |
| Front Desk | Enabled call and intake records, contact and insurance information, documents and Fax, scheduling activity, and review or delivery records. Front Desk uses AI models on HIPAA-compliant AI infrastructure and stores its retained patient and operational records only in the clinic’s private cloud environment. |
| Operations and security | Request times, device and browser information, network information such as IP addresses, authentication and security events, errors, feature usage, and service delivery records. The exact fields depend on the service and infrastructure used. |
The website inquiry workflow also records the request date, source page, product interest, campaign fields when supplied, and email delivery events. Do not put patient information in a demo request, early access form, URL, campaign field, or ordinary support email.
HUVA Chat: no identifiable patient data
HUVA Chat is a free service for individual healthcare professionals. Do not enter, upload, paste, dictate, or otherwise transmit identifiable patient information into HUVA Chat. This applies to prompts, files, screenshots, images, feedback, shared conversations, and support material.
- Remove names, contact details, medical record numbers, account and insurance identifiers, precise addresses, full dates of birth, recognizable faces, and other direct identifiers before submission.
- Remove or generalize indirect identifiers, including exact encounter dates, small locations, unusual occupations, institution details, or rare combinations of facts that could reveal a patient.
- Inspect image pixels, document properties, headers, file names, links, embedded text, and attachments. Removing a visible name does not necessarily remove identifying information elsewhere.
- Do not provide a re-identification key, patient lookup code, or link to the original patient record.
Pseudonymization is not automatically de-identification. Replacing a name with initials, a pseudonym, or “Patient A” is insufficient if the remaining material can identify the person. Only submit information that has been appropriately de-identified under applicable law and organizational policy. When HIPAA applies, follow an appropriate method such as Safe Harbor or Expert Determination. See HHS de-identification guidance.
You are responsible for completing this review before submission. Do not rely on HUVA Chat to remove identifiers automatically. A patient’s permission or a separate HUVA Work agreement does not change HUVA Chat’s input restrictions.
If information is submitted by mistake, stop sharing it, avoid reproducing it in a support message, and contact contact@huver.ai with the product, account, approximate time, and non-sensitive reference. We will assess the report and coordinate appropriate containment and handling under applicable obligations.
HUVA Work, Front Desk, and Scribe
HUVA Work supports clinic workflows such as intake, calls, scheduling, insurance review, documents, Fax, and connected case activity. Scribe supports recordings, transcription, draft documentation, and approved delivery where enabled. A personal Scribe subscription is distinct from the free HUVA Chat service.
Individual Scribe: delete transcription data on Confirm
Individual clinicians use Scribe as a Chrome extension within their EHR workflow. Scribe temporarily processes encounter content to support transcription and documentation. When the clinician completes the documentation in the EHR and selects Confirm in Scribe, the extension’s temporary transcription data is deleted. The clinician must first verify that the intended documentation has been saved in the correct EHR record.
This deletion applies to the individual extension’s temporary transcription data. It does not delete documentation already saved in the EHR or copies the clinician has exported. It is not a statement that no data is processed during the encounter or that account, billing, and security information is deleted at the same time.
Clinic-connected Scribe: records managed in the private cloud
After a clinic invites a clinician to HUVA Work, Scribe can connect to that clinic’s patient and encounter information within the clinician’s assigned permissions. HUVA Work is deployed in the clinic’s private cloud environment, where clinic-connected patient and encounter records are stored and managed. Those records follow the clinic’s authorized retention, access, export, and deletion policies and applicable agreements. Completing an encounter does not apply the individual extension’s Confirm-to-delete rule to the clinic’s records.
Front Desk: AI processing and clinic record storage
Front Desk uses AI models on HIPAA-compliant AI infrastructure. Its retained patient and operational records are stored only in the clinic’s private cloud environment. This covers the Front Desk records created for enabled call, intake, scheduling, document, and insurance workflows.
The record-storage boundary is distinct from the processing needed to provide AI, telephony, transcription, and authorized integrations. The deployment’s agreements must identify approved processors, permitted data flows, and any temporary processing or technical logging, consistent with that storage boundary. Authorized delivery to an EHR, payer, or other intended recipient creates records governed by the recipient’s applicable obligations. This policy does not represent that every model runs inside the clinic’s own server or that no authorized transmission occurs.
Authorization and responsibility across clinic workflows
Patient information may be used only after the specific product, organization, users, integrations, and workflow have been approved and required agreements are in place. Where HUVER acts as a business associate, an executed BAA must cover the relevant service before protected health information (“PHI”) is transmitted. A HIPAA compliance statement or badge does not itself establish a BAA or authorize every feature.
The clinic determines the lawful purpose, appropriate users, necessary data, patient notices and consents, and recordkeeping rules. HUVER processes clinic-controlled information to provide the contracted service, follow lawful instructions, protect the service, and meet applicable legal obligations. The service agreement and BAA limit permitted access, use, disclosure, and subcontracting.
Clinic administrators may manage accounts and access relevant workspace records, activity, and audit information within their authorized scope. Leaving a clinic or removing a user does not necessarily delete records that the clinic must retain. Patients seeking access, amendments, or other rights concerning clinical records should normally contact their healthcare provider; we support the clinic as required by our agreements and law.
Recordings, patient calls, texts, Fax, payer outreach, and EHR connections require the applicable notices, permissions, and safeguards. A feature being technically available does not replace those requirements. Do not use a demo, preview, unapproved connector, or HUVA One early access environment for PHI without express authorization for that environment.
How information is used
- Provide requested accounts, answers, transcripts, draft notes, workflow outputs, and authorized connections.
- Respond to inquiries, arrange access, communicate about an account, and provide requested support or product updates.
- Administer subscriptions and service agreements, maintain business records, and address payment or contractual issues where applicable.
- Authenticate users, manage permissions, investigate errors and abuse, maintain reliability, and protect information.
- Evaluate quality and improve permitted service operations subject to the product’s data restrictions, agreements, and notices.
- Comply with legal obligations, resolve disputes, and protect lawful rights.
Providing patient data for a clinic workflow does not authorize unrelated advertising, research, or model development. Any proposed additional use must have an appropriate legal basis and comply with the controlling agreement and any required permissions.
AI processing and model improvement
AI functionality requires processing permitted inputs to produce a response, transcript, draft, or suggested action. Depending on the approved deployment, this may involve service providers supplying model inference, transcription, retrieval, or other processing. Generating a response is different from training a model.
The permitted purposes of processing are limited by the applicable product notice and agreement. These terms do not grant unrestricted rights to train models on clinical content, disclose it publicly, or allow independent use by a model provider. For PHI, any additional processing must be permitted by the BAA and applicable law.
Model-training settings, provider retention, and any optional feedback or improvement program must be specified for the relevant service. Do not assume that a free account, a paid account, or a provider’s general policy establishes the settings of your HUVA deployment. Ask us for the applicable data handling terms before enabling a workflow with sensitive information.
Retention, deletion, and export
Retention follows the product and data category. The individual Scribe extension’s transcription deletion event is different from the retention of records in a clinic-connected HUVA Work deployment.
- Individual Scribe transcription: the extension’s temporary transcription data is deleted when the clinician finishes the EHR documentation and selects Confirm in Scribe. Stopping recording or generating a note is not the defined confirmation event. Verify the EHR record before confirming.
- Clinic-connected HUVA Work and Scribe: patient and encounter records are retained and managed in the clinic’s private cloud environment according to the clinic’s retention policy, service agreement, BAA, and applicable recordkeeping requirements.
- Front Desk: retained patient and operational records remain in the clinic’s private cloud environment. Clinic-specific retention and deletion schedules govern these records; the individual Scribe deletion rule does not apply.
- EHR and exported records: deleting Scribe’s temporary transcription data does not remove the final clinical documentation saved in the EHR or copies already exported by an authorized user.
- Other information: account, billing, business inquiry, and security information follow their own purposes and applicable retention requirements. They are not covered by the transcription deletion event.
For retained clinic records, recording retention, record exports, account closure, and deletion schedules are governed by the applicable service terms and clinic instructions. Closing an individual account or completing a visit does not erase a clinic’s records or replace its medical-record retention obligations.
At the end of a covered clinic service, return or destruction of retained PHI is governed by the BAA. If lawful return or destruction is not feasible, the continuing protections and limited retention purposes in that agreement apply. The clinic’s backup and recovery arrangements must respect its agreed storage boundary and retention rules.
Contact us to request account deletion or to confirm the applicable export and retention process. We may need to verify identity, authority, and the relevant organization before acting. Do not rely on HUVA as your only record archive unless your signed agreement expressly provides that function.
Security and incident handling
Safeguards must be appropriate to the product and information involved and may include controlled access, authentication, encryption, activity records, and incident-response procedures. No system can guarantee absolute security. Your organization must also protect user devices, credentials, exported files, and access to connected services.
Report suspected unauthorized access, disclosure, or unsafe data handling promptly. We address incidents and provide notices as required by applicable law and the relevant agreements. An incident affecting clinic-controlled information may require coordination with the clinic rather than direct contact with every patient.
A product input prohibition does not remove HUVER’s obligations if prohibited information is accidentally received. We assess and handle such reports according to applicable duties; we do not treat the prohibition as a waiver of those duties.
Your choices and privacy rights
Depending on your location and applicable law, you may have rights to access, correct, delete, or receive a copy of personal information; restrict or object to certain uses; withdraw consent where processing relies on consent; or appeal a decision. These rights may be subject to lawful exceptions and verification requirements.
Send requests to contact@huver.ai with your account email, product, and request type. We will explain the appropriate process and any applicable response or appeal path. Use only the minimum information needed to identify the request. We will not require patient records in ordinary email to process an account inquiry.
For clinical records controlled by a healthcare organization, contact that organization first. For a clinic administrator making a request on behalf of the organization, we verify organizational authority. Mandatory privacy rights are not waived by these policies or by use of the service.
Locations and professional eligibility
HUVA is intended for adult healthcare professionals and authorized healthcare organizations, not for children or direct patient self-treatment. HUVA Chat is not a patient portal or an emergency service.
Processing locations depend on the selected service and providers. A website location or company presence is not a promise of data residency. Any required regional safeguards, data processing terms, or residency restrictions must be confirmed before onboarding. Services may not be available or appropriate in every jurisdiction.
Policy changes and contact
When an effective policy changes, we will update its date and provide additional notice where required. Material changes to data use must follow applicable law and controlling contracts; publishing a revised page alone does not authorize a use prohibited by a BAA or replace any required permission.
For privacy questions, requests, or reports, contact HUVER, Inc. at contact@huver.ai. Use “Privacy Request” or “Privacy Incident” in the subject line. For permitted service use and professional responsibilities, read the Terms of Service.
Questions about this policy?
Contact HUVER, Inc. using your account email or business contact information. Do not include patient records or sensitive identifiers in ordinary email.
contact@huver.ai
HUVA