DyZen Med Privacy Policy

Version: v1.2
Effective Date: July 23, 2026
Governing entity: DyZen Med LLC

1. Overview

This Privacy Policy explains how DyZen Med LLC (“DyZen Med,” “we,” “us”) collects, uses, and handles information when you use our services (the “Service”).

DyZen Med is a physician-assist medical record intelligence platform that processes data at the direction of users to support chart review, IME drafting, and reviewable export outputs.

We are committed to handling data responsibly, minimizing unnecessary retention, and maintaining appropriate safeguards based on the nature of the information processed.

2. Information We Collect

We collect information in the following categories:

Account information

Uploaded content

Usage and system data

3. How We Use Information

We use information solely to operate and support the Service, including to:

DyZen Med does not use customer data to train public or shared AI models.

Protected health information is processed only at the direction of the customer organization and its authorized users. Where a Business Associate Agreement (BAA) is in effect, it supplements this Policy for the obligations it describes. This Policy is not a certification of full HIPAA compliance.

4. User Responsibility for Data

DyZen Med processes data only at the direction of users.

You are responsible for:

DyZen Med does not independently verify the legal status of uploaded data.

5. Medical Records and Sensitive Information

The Service may process medical records and other sensitive information.

DyZen Med uses artificial intelligence and related technologies to organize, summarize, analyze, and assist with the interpretation of clinical and medical-legal information. These features may identify patterns, inconsistencies, documentation issues, and potential opinion considerations for physician review. Depending on the feature used, this may include Chart Summary, Chart Integrity, Zentelligence analysis, Opinion Intelligence, HealthScribe-organized exam content, and report drafting. Not every feature performs every function.

DyZen Med does not independently diagnose or treat patients, make final clinical or medical-legal determinations, or replace professional judgment. Generated content must be reviewed and approved by the qualified healthcare professional responsible for its use.

DyZen Med does not provide medical advice as a substitute for professional care, and does not operate as an autonomous clinical decision-making system.

6. Subprocessors and External Data Providers

DyZen Med uses third-party service providers to operate the Service. These may include infrastructure and customer-data processors, AI and transcription vendors, payment and communications vendors, and external terminology or clinical-reference services.

Not every third party that receives information is a HIPAA “subprocessor.” Some providers receive customer content or PHI depending on the feature used. Others—such as public clinical-reference APIs—may receive only minimized clinical search concepts when Opinion Intelligence clinical-evidence features are used.

The maintained disclosure, including named providers currently used in production where applicable (for example AWS, AWS HealthScribe, OpenAI, Stripe, Amazon SES/SNS, UMLS/UTS, PubMed/NCBI, Europe PMC, ClinicalTrials.gov, DailyMed, and openFDA), is published at:

/subprocessors-and-external-providers.html

Providers used solely to support the Service are engaged under applicable confidentiality and data-protection arrangements where required. This Policy is not a certification of full HIPAA compliance.

6A. Opinion Intelligence, Terminology, and Outbound Clinical Queries

When Opinion Intelligence clinical-evidence features are enabled, DyZen Med may:

A UMLS terminology match is not clinical evidence and is not itself support for an opinion. Returned references do not constitute DyZen Med conclusions and do not replace physician evaluation. Provider availability and returned information may vary.

DyZen Med is designed to transmit only minimized clinical concepts for these queries—not unnecessary patient identifiers or raw chart passages. Attribution and source disclaimers are available at /clinical-evidence-sources.html.

7. Security Practices

We implement administrative, technical, and organizational safeguards appropriate to the nature of the data processed, including:

No system can guarantee absolute security, and users should exercise appropriate caution when handling sensitive information.

8. Data Retention and Deletion

Completed job records and generated artifacts are designed to become inaccessible in the platform 90 days after job completion. Expired jobs and artifacts are no longer downloadable through the product.

Platform inaccessibility (expiration) is distinct from physical deletion from object storage. After expiration, DyZen Med may purge eligible workspace objects through operational deletion processes and/or configured object-storage lifecycle rules. Until physical deletion completes, objects may remain in storage backups or storage systems even though they are not available in the product.

Certain audit or intermediate processing artifacts may be retained longer where needed for security, integrity, or operational accountability (for example, OCR audit artifacts may be retained on a longer tagged retention schedule). HealthScribe exam audio is intended to be transient and subject to an approximately 90-day storage lifecycle when retention tagging and storage rules are in effect; organized transcripts/encounter content and audit history may follow different retention rules.

DyZen Med is not a long-term medical record storage system. Deletion is not claimed to be immediate or automatic in every case.

For more detailed information, see our Data Retention & Deletion Policy: /data-retention.html

Users may request deletion of data through in-app support tools or by contacting DyZen Med directly.

9. Cookies and Similar Technologies

DyZen Med may use minimal cookies or similar technologies necessary for:

We do not use cookies for advertising or cross-site tracking.

10. User Rights and Requests

You may request:

Requests can be submitted through available support channels.

11. Changes to This Policy

DyZen Med may update this Privacy Policy from time to time.

Material changes will be communicated where appropriate. Where the Service requires reacceptance of an updated Privacy Policy version, continued use after reacceptance is recorded in your account acceptance history. Historical acceptance records are retained and are not overwritten.

12. Contact

For privacy-related questions:

info@dyzenmed.com

13. SMS / Text Messaging Communications

DyZen Med may send SMS messages for account authentication and security purposes, including multi-factor authentication (MFA).

These messages are not promotional and are used to support secure account access. Message and data rates may apply. Delivery is not guaranteed. Where supported by the messaging pathway, you may reply STOP to opt out of SMS. SMS content is designed to avoid chart text and unnecessary PHI.

DyZen Med does not send marketing or promotional text messages and does not sell or share phone numbers for marketing purposes.

14. Related Disclosures

This Policy is a conservative product/legal draft subject to subsequent review by qualified counsel. It is not legal advice and not a certification of HIPAA compliance.