DyZen Med Privacy Policy
1. Overview
This Privacy Policy explains how DyZen Med LLC (“DyZen Med,” “we,” “us”) collects, uses, and handles information when you use our services (the “Service”).
DyZen Med is a physician-assist medical record intelligence platform that processes data at the direction of users to support chart review, IME drafting, and reviewable export outputs.
We are committed to handling data responsibly, minimizing unnecessary retention, and maintaining appropriate safeguards based on the nature of the information processed.
2. Information We Collect
We collect information in the following categories:
Account information
- Name
- Email address
- Organization name (if applicable)
- Role or account type
- Authentication data (including MFA where enabled)
Uploaded content
- Medical records and related documents you choose to upload
- Associated metadata (file names, timestamps, processing details)
Usage and system data
- Job activity (e.g., uploads, processing status, output generation)
- Timestamps and operational logs
- Basic device and session information used for security and performance
3. How We Use Information
We use information solely to operate and support the Service, including to:
- Process and organize uploaded records as directed by users
- Generate structured outputs for review
- Maintain system security, integrity, and performance
- Provide account functionality and usage visibility
DyZen Med does not use customer data to train public or shared AI models.
Protected health information is processed only at the direction of the customer organization and its authorized users. Where a Business Associate Agreement (BAA) is in effect, it supplements this Policy for the obligations it describes. This Policy is not a certification of full HIPAA compliance.
4. User Responsibility for Data
DyZen Med processes data only at the direction of users.
You are responsible for:
- Ensuring you have the legal right to upload and process records
- Obtaining any required consents or authorizations
- Using the Service in compliance with applicable laws and regulations
DyZen Med does not independently verify the legal status of uploaded data.
5. Medical Records and Sensitive Information
The Service may process medical records and other sensitive information.
DyZen Med uses artificial intelligence and related technologies to organize, summarize, analyze, and assist with the interpretation of clinical and medical-legal information. These features may identify patterns, inconsistencies, documentation issues, and potential opinion considerations for physician review. Depending on the feature used, this may include Chart Summary, Chart Integrity, Zentelligence analysis, Opinion Intelligence, HealthScribe-organized exam content, and report drafting. Not every feature performs every function.
DyZen Med does not independently diagnose or treat patients, make final clinical or medical-legal determinations, or replace professional judgment. Generated content must be reviewed and approved by the qualified healthcare professional responsible for its use.
DyZen Med does not provide medical advice as a substitute for professional care, and does not operate as an autonomous clinical decision-making system.
6. Subprocessors and External Data Providers
DyZen Med uses third-party service providers to operate the Service. These may include infrastructure and customer-data processors, AI and transcription vendors, payment and communications vendors, and external terminology or clinical-reference services.
Not every third party that receives information is a HIPAA “subprocessor.” Some providers receive customer content or PHI depending on the feature used. Others—such as public clinical-reference APIs—may receive only minimized clinical search concepts when Opinion Intelligence clinical-evidence features are used.
The maintained disclosure, including named providers currently used in production where applicable (for example AWS, AWS HealthScribe, OpenAI, Stripe, Amazon SES/SNS, UMLS/UTS, PubMed/NCBI, Europe PMC, ClinicalTrials.gov, DailyMed, and openFDA), is published at:
/subprocessors-and-external-providers.html
Providers used solely to support the Service are engaged under applicable confidentiality and data-protection arrangements where required. This Policy is not a certification of full HIPAA compliance.
6A. Opinion Intelligence, Terminology, and Outbound Clinical Queries
When Opinion Intelligence clinical-evidence features are enabled, DyZen Med may:
- Use UMLS/UTS for terminology normalization and evidence-query expansion within Opinion Intelligence
- Obtain SNOMED CT and RxNorm identifiers through UMLS where available
- Retrieve advisory references from external literature, trial, drug-labeling, and safety sources
A UMLS terminology match is not clinical evidence and is not itself support for an opinion. Returned references do not constitute DyZen Med conclusions and do not replace physician evaluation. Provider availability and returned information may vary.
DyZen Med is designed to transmit only minimized clinical concepts for these queries—not unnecessary patient identifiers or raw chart passages. Attribution and source disclaimers are available at /clinical-evidence-sources.html.
7. Security Practices
We implement administrative, technical, and organizational safeguards appropriate to the nature of the data processed, including:
- Encryption in transit (TLS)
- Access controls and authentication safeguards
- Logging of key system and administrative events
No system can guarantee absolute security, and users should exercise appropriate caution when handling sensitive information.
8. Data Retention and Deletion
Completed job records and generated artifacts are designed to become inaccessible in the platform 90 days after job completion. Expired jobs and artifacts are no longer downloadable through the product.
Platform inaccessibility (expiration) is distinct from physical deletion from object storage. After expiration, DyZen Med may purge eligible workspace objects through operational deletion processes and/or configured object-storage lifecycle rules. Until physical deletion completes, objects may remain in storage backups or storage systems even though they are not available in the product.
Certain audit or intermediate processing artifacts may be retained longer where needed for security, integrity, or operational accountability (for example, OCR audit artifacts may be retained on a longer tagged retention schedule). HealthScribe exam audio is intended to be transient and subject to an approximately 90-day storage lifecycle when retention tagging and storage rules are in effect; organized transcripts/encounter content and audit history may follow different retention rules.
DyZen Med is not a long-term medical record storage system. Deletion is not claimed to be immediate or automatic in every case.
For more detailed information, see our Data Retention & Deletion Policy: /data-retention.html
Users may request deletion of data through in-app support tools or by contacting DyZen Med directly.
9. Cookies and Similar Technologies
DyZen Med may use minimal cookies or similar technologies necessary for:
- Session management
- Authentication
- Basic site functionality
We do not use cookies for advertising or cross-site tracking.
10. User Rights and Requests
You may request:
- Access to your account data
- Correction of inaccurate information
- Deletion of your data, subject to operational or legal constraints
Requests can be submitted through available support channels.
11. Changes to This Policy
DyZen Med may update this Privacy Policy from time to time.
Material changes will be communicated where appropriate. Where the Service requires reacceptance of an updated Privacy Policy version, continued use after reacceptance is recorded in your account acceptance history. Historical acceptance records are retained and are not overwritten.
12. Contact
For privacy-related questions:
info@dyzenmed.com
13. SMS / Text Messaging Communications
DyZen Med may send SMS messages for account authentication and security purposes, including multi-factor authentication (MFA).
These messages are not promotional and are used to support secure account access. Message and data rates may apply. Delivery is not guaranteed. Where supported by the messaging pathway, you may reply STOP to opt out of SMS. SMS content is designed to avoid chart text and unnecessary PHI.
DyZen Med does not send marketing or promotional text messages and does not sell or share phone numbers for marketing purposes.
14. Related Disclosures
- Subprocessors and External Data Providers
- Clinical Evidence Sources and Attribution
- AI Transparency
- Data Retention & Deletion Policy
This Policy is a conservative product/legal draft subject to subsequent review by qualified counsel. It is not legal advice and not a certification of HIPAA compliance.