Trust and transparency

HIPAA and your health information

This notice describes how health information about you may be used and disclosed, the safeguards applied to it, and how you can get access to it. Please read it carefully.

Effective 4 August 2026

Where SpineSense sits

SpineSense is a tool you use directly. It is not your doctor, it does not bill your insurer, and using it does not create a treating relationship or a medical record at any hospital or practice. That matters for how HIPAA applies, because HIPAA governs healthcare providers, health plans, clearinghouses, and the vendors who handle health information on their behalf.

Rather than argue about which box we sit in, we have built the product to the standard that applies when health information is at its most sensitive, and we hold ourselves to it whether or not a given deployment brings us formally within HIPAA’s scope. Where SpineSense is used alongside a healthcare organisation, we act as a business associate of that organisation and operate under a Business Associate Agreement with it.

What counts as your health information here

Your own description of your problem, your questionnaire answers, the body areas you mark, any imaging report or clinical document you upload, and the assessment produced from them. Your email address and sign-in details are account information rather than health information, but they are protected to the same standard because they are the route to it.

How it is used and disclosed

We use it to produce your assessment and show it to you, to keep it available to you afterwards, and to keep the service secure and working. We disclose it in only three circumstances:

  • Because you asked us to. If you choose to share a result, it goes where you direct it and nowhere else.
  • To the providers who run the infrastructure, described below, who process it only on our instruction.
  • Where the law requires it. A valid legal demand, or a situation where disclosure is necessary to prevent serious harm.

We do not sell it, we do not use it for advertising, and we do not disclose it to insurers or employers.

Who processes it under a Business Associate Agreement

The platform runs on Microsoft Azure in the United States. The language model that helps produce your summary is Azure OpenAI, running inside that same Microsoft boundary rather than a consumer AI service. Both are covered by Microsoft’s Business Associate Agreement, which binds them to protect health information and forbids them using it for their own purposes, including training models on it.

The safeguards applied

  • Health information is encrypted in transit and at rest.
  • The browser never holds a backend credential. All access runs through a server-side layer, so no token is readable by JavaScript on the page.
  • Nothing durable is written to browser storage, so your health information is not left behind on a shared or borrowed device.
  • Access is enforced per patient at the database level, not by application code alone, so a fault in one part of the product cannot expose another person’s record.
  • Access to health information is logged to an audit trail that cannot be edited away.
  • Multi-factor authentication is available on your account, and we recommend turning it on.

Your rights over your information

  • To see it and get a copy. Your assessment is visible to you in the app, and you can ask us for an export of what we hold.
  • To correct it. If something we hold about you is wrong, ask us to amend it.
  • To have it deleted. You can ask us to delete your account and the health information in it.
  • To restrict how it is used, and to ask us to communicate with you by a particular method.
  • To an accounting of disclosures, meaning a record of where it has been sent.
  • To a paper or electronic copy of this notice on request, even if you agreed to receive it electronically.
  • To complain without being penalised for it. Tell us through the contact page. You may also complain to the US Department of Health and Human Services Office for Civil Rights.

If something goes wrong

If health information is exposed in a way it should not have been, we will investigate it, contain it, and notify the people affected, along with any regulator we are required to notify, within the timeframes the law sets. We will tell you what happened rather than the minimum we can get away with saying.

Our duties, and changes to this notice

We are required to protect the health information we hold, to give you this notice of our duties and your rights, and to follow the version of it currently in effect. We can change this notice, and a change applies to information we already hold as well as to information we receive later. The current version is always the one on this page, dated at the top.

Contact

To exercise any right above, to raise a concern, or to ask a question about this notice, use the contact page. See also the privacy policy for information beyond health information, and the terms of service for the rules of using the product.