Hygieia Privacy Policy

Last updated: July 27, 2026

Hygieia is operated by Saar Inc. ("Hygieia," "we," "us," or "our"). Hygieia provides AI-assisted clinical documentation and practice revenue tools for licensed healthcare professionals and their practices. This Privacy Policy explains what information we collect, how we use it, and the choices you have. It applies to our websites (including hygieiamed.ai), our web application, and our mobile applications (together, the "Service").

Two kinds of information

The Service handles two very different kinds of information, and we treat them differently:

  1. Your information as a professional user — the account, security, and billing information of the clinicians and practice staff who use Hygieia. This Policy describes how we handle it.
  2. Patient information — the clinical content our users create and process while documenting care, which is Protected Health Information ("PHI") under the Health Insurance Portability and Accountability Act ("HIPAA"). We process PHI as a Business Associate, on behalf of and at the direction of the treating clinician or their practice, under a HIPAA Business Associate Agreement ("BAA"). Where this Policy and a BAA conflict with respect to PHI, the BAA controls.

If you are a patient: your healthcare provider — not Hygieia — controls your medical records. Please direct any questions or requests about your information to your provider; we support them in responding as their business associate.

Information we collect

From professional users:

Patient information processed at your direction:

How we use information

We use information to:

We do not sell personal information. We do not use patient information for advertising. We do not use your patients' information to train shared AI models, and our AI vendors are contractually restricted from using it to train theirs.

AI processing and de-identification

Our core privacy commitment: patient identities are never shared with AI vendors.

Before any content is sent to an AI service to draft a note or generate suggestions, Hygieia replaces direct identifiers — names, dates, record numbers, and similar identifying details — with placeholder tokens. The AI model works only with this de-identified text. The mapping between placeholders and real identities remains within Hygieia's HIPAA-covered systems, encrypted, and is joined back to the note only when it is displayed to you and your authorized staff.

Every external vendor that processes patient information for us does so under a signed HIPAA Business Associate Agreement.

Recordings and transcription

Recording is always initiated by the clinician, never automatically. The clinician is responsible for obtaining any consent to record required by the law of the state where the visit takes place and by their facility's policies; Hygieia prompts for confirmation before each ambient recording but does not obtain consent on the clinician's behalf.

Encounter audio is encrypted and retained for review. When cloud transcription is enabled, audio is processed transiently through Hygieia's API and a transcription provider covered by a HIPAA Business Associate Agreement, and is not retained by that provider for its own purposes.

Recordings are deleted automatically a short time after they have been transcribed and the resulting note is available (currently seven days), and the clinician can delete a recording sooner at any time. Audio that has not yet been transcribed is kept until it is transcribed or the encounter is deleted, because it may be the only record of the visit.

Service providers

We share information only with service providers that help us operate the Service, under contracts that restrict their use of it — and, wherever patient information is involved, under a HIPAA Business Associate Agreement:

ProviderPurposePatient information?
Google CloudHosting, storage, authentication infrastructureYes — under BAA
AnthropicAI drafting of notes and suggestionsDe-identified text only — under BAA
DeepgramMedical speech-to-text transcriptionAudio processed transiently — under BAA
StripePayment processingNo
ResendTransactional email (verification, receipts, invitations)No
ElevenLabsVoice synthesis of in-app assistant repliesNo patient identities
PerplexityMedical reference lookups for the in-app assistantNo patient identifiers

Within your practice: if you join a practice on Hygieia, authorized practice staff (such as billers) can view signed-off notes and related patient and billing details, according to your practice's configuration. Access is logged.

Legal requirements: we may disclose information if required by law, legal process, or to protect the rights, safety, or property of our users, the public, or Hygieia — consistent with HIPAA where PHI is involved.

Business transfers: if Hygieia is involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction, subject to the commitments in this Policy and our BAAs.

Security

We protect information with encryption in transit and at rest, multi-factor authentication, biometric app locking and an encrypted database on mobile devices, role-based access controls, environment separation, and append-only audit logging of access to identified patient information. No method of transmission or storage is completely secure; we maintain a written incident-response plan and will notify affected parties as required by law and by our Business Associate Agreements.

Retention and deletion

Your rights and choices

You can review and update your account information in Settings, and delete your account as described above. Depending on where you live, you may have additional rights under state privacy laws — such as the right to access, correct, or delete personal information. To exercise any of these rights, contact us at the address below. Patients should direct requests concerning their medical records to their healthcare provider; we support providers in fulfilling those requests under our BAAs.

Children

The Service is intended for licensed healthcare professionals and their staff, all of whom must be at least 18 years old. It is not directed to children. Patient records processed through the Service may concern minors as part of their medical care; that information is handled as PHI as described above.

Where information is processed

Hygieia is operated from the United States, and information is stored and processed on Google Cloud infrastructure in the United States. The Service is intended for use in the United States.

Changes to this Policy

We may update this Policy from time to time. We will post the updated version here and revise the "Last updated" date. For material changes, we will notify account holders by email or in the app.

Contact us

Saar Inc. Email: support@hygieiamed.ai