Last updated 24 July 2026
Privacy policy
01What this policy covers
This policy describes how ITAS Health handles information collected through this website — the pages you are reading now.
It does not govern patient information. When a practice uses our platform, protected health information is handled under a signed business associate agreement with that practice, and that agreement controls. The practice, not us, decides what happens to its patients' records. Nothing in this policy grants us rights over clinical data or modifies any agreement between us and a practice.
02What this website collects
Less than you are used to. This site has no sign-up, no account, no contact form, and no chat widget. Every action that looks like a form on this site simply opens your own email client.
No cookies, no analytics, no advertising. We set no cookies. We do not run Google Analytics or any comparable product, we do not embed advertising or social tracking pixels, and we do not build visitor profiles or sell anything to anybody.
Server logs. Our hosting provider records ordinary technical request data — IP address, timestamp, the page requested, and browser user agent — for security, abuse prevention, and diagnosing errors. We do not use those logs to identify individuals or to market to them.
Fonts. Typefaces are served from our own domain rather than a third-party font service, so loading a page here does not report your visit to another company.
03If you email or text us
When you write to us, we hold your message and your contact details in order to reply and, if a conversation develops, to keep an ordinary record of it. We use that information to correspond with you about ITAS Health and for nothing else. We do not add you to a marketing list you did not ask for, and we do not sell or rent contact information.
Please do not send patient information by email or text. If we need to look at anything real, we will establish an appropriate path for it under a business associate agreement first.
Ask us to delete your correspondence at any time and we will, except where we are required to keep it.
04Who else is involved
Two categories of provider touch website information: the host that serves these pages and stores the request logs described above, and the email provider that carries messages you send us. Each acts on our instructions.
The vendors involved in running the platform for a practice are a separate matter and are disclosed to that practice during its security review, along with the agreement status for each. Our security page describes them by function.
05How long we keep things
Server logs are retained for a short operational window by our host and then discarded. Correspondence is kept for as long as the relationship or a legal obligation requires, and deleted on request otherwise.
Records that exist to support a claim our platform helped a practice prepare are retained for ten years, because that is the window in which a payer can come back and ask. Those records belong to the practice and are governed by its agreement with us, not by this policy.
06Your choices
Because we do not track you, there is no advertising profile to opt out of and no cookie banner to dismiss. For correspondence, you can ask us what we hold about you, ask for a copy, ask us to correct it, or ask us to delete it. Write to hello@itas.health and a person will handle it.
If you are a patient of a practice that uses our platform, your rights in your medical record run through that practice, which is the covered entity. Ask them, and they can direct a request to us if we hold something relevant.
07Children
This website is aimed at medical practices, not consumers, and is not directed to children. We do not knowingly collect information from children through it.
08Changes to this policy
If we change how any of this works — if we ever add analytics, for instance — we will update this page and change the date at the top. We will not quietly start collecting something this page says we do not.
09Contacting us
Privacy questions go to hello@itas.health. Security matters, including a vulnerability you would like to report, go to security@itas.health.
This policy describes our practices in plain language; it is not legal advice. If you are evaluating us as a vendor, the documents that actually bind us are the master services agreement and the business associate agreement — website terms are here.