Overview

Vitalis (“Vitalis,” “we,” “us,” or “our”) provides a practice-management platform for mobile, office-based dental anesthesia. Our service includes a web application and the Vitalis iOS app (together, the “Service”), which anesthesia providers and their staff use to run scheduling, patient intake, vitals monitoring, clinical charting, and billing.

This Privacy Policy explains what information we collect, how we use and protect it, and the choices you have. It applies to the Service. It does not apply to the separate systems of the dental offices, practices, or third parties that may work with providers who use Vitalis.

Our role, and a note about patient information

The Service handles two different kinds of information, and our responsibilities differ for each:

  • Provider and account information. Information about the providers, clinicians, and staff who hold Vitalis accounts. We act as the controller of this information and handle it as described in this policy.
  • Patient information. Clinical and personal information that providers enter into the Service to deliver care to their patients. The provider’s practice is responsible for that information as the covered entity, and Vitalis processes it on the practice’s behalf as its service provider (and, where applicable, business associate) under a separate agreement. Patients who have questions about their own records should contact the anesthesia provider or dental office that treated them.

Information we collect

Account information. When a provider or staff member signs in, we collect their name, email address, and (where provided) phone number and professional credentials or licensing documents. We support Sign in with Apple and Google sign-in; when you use those, the provider identity service shares your name and email with us to create and secure your account.

Patient information entered by providers. As part of clinical workflow, providers enter and store patient information in the Service, which may include: name, date of birth, medical record number, and contact details including phone number; clinical data such as vital signs (for example heart rate, oxygen saturation, end-tidal CO₂, respiratory rate, blood pressure, and EKG) streamed from an in-office patient-monitor relay and recorded on the anesthesia chart, along with weight, height, ASA classification, and procedure and anesthesia notes; and documents or photographs attached to a patient record or used to verify office facilities and credentials.

Payment information. When a practice collects deposits or processes billing through the Service, payments are handled by our payment processor, Stripe. Stripe collects and processes card and payment details directly; we do not store full payment card numbers.

Device, log, and diagnostic information. Like most online services, we automatically collect technical information needed to operate and secure the Service, such as IP address, device and browser type, and log data. We use an error- and performance-monitoring service to detect and diagnose crashes and problems so we can keep the Service reliable.

What we do not collect. The Vitalis app does not request or collect your location, does not read data from Apple Health / HealthKit, and does not track you across other companies’ apps or websites. We do not use your information for advertising.

How we use information

We use the information above only to run and improve the Service, specifically to:

  • provide scheduling, patient intake, vitals monitoring, charting, and billing features;
  • create, authenticate, and secure provider accounts;
  • enable communications, including appointment and paperwork text messages sent to patients on behalf of the treating practice;
  • process deposits and billing through our payment processor;
  • monitor, troubleshoot, secure, and improve the reliability of the Service; and
  • comply with legal, regulatory, and professional recordkeeping obligations.

We do not sell personal information, and we do not use it for cross-context behavioral advertising.

How we share information

We share information only as needed to operate the Service:

  • Service providers (subprocessors). We use vetted vendors to host and run the Service, including Supabase (authentication and database), Google Cloud and Firebase (data and document storage), Stripe (payments), Cloudflare (sign-in security), a telephony provider (patient text messaging), and an error-monitoring provider (diagnostics). These vendors may process information only to provide services to us and under obligations of confidentiality and security.
  • The provider’s practice. Information entered by a provider is available to the authorized members of that provider’s practice or care team, so they can coordinate patient care.
  • Legal and safety. We may disclose information if required by law or legal process, or where necessary to protect the rights, safety, and security of patients, providers, the public, or Vitalis.
  • Business transfers. If Vitalis is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this policy.

Data retention

We retain provider account information for as long as an account is active and as needed to provide the Service. Patient information is retained on behalf of the treating practice for as long as the practice requires and as necessary to meet medical-recordkeeping and other legal obligations. The practice directs retention and deletion of its patient records.

How we protect information

We use technical and organizational safeguards designed to protect information, including encryption of data in transit and at rest, role-based access controls, authentication protections, and audit logging. We design the Service to align with HIPAA safeguards for the patient information it handles. No system is perfectly secure, but we work to protect information appropriately to its sensitivity.

Your choices and rights

Providers may access and update their account information within the Service. Depending on where you live, you may have rights to access, correct, or delete personal information we hold about you. To make a request, contact us at the address below; we may need to verify your identity before acting.

If your request concerns a patient’s medical records, please contact the anesthesia provider or dental office that treated the patient, since that practice controls those records.

Sign in with Apple and Google

We offer Sign in with Apple and Google sign-in so you can authenticate securely. When you use one of these options, we receive the name and email associated with your account to create and secure your Vitalis account. Their handling of your information is governed by Apple’s and Google’s own privacy policies.

Children’s privacy

The Service is intended for use by anesthesia providers and their staff, not by children, and we do not knowingly collect personal information directly from children. Providers may record information about patients who are minors as part of delivering care; that information is handled as patient information under this policy and under the treating practice’s authority.

Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above and, where appropriate, provide additional notice. Your continued use of the Service after an update means you accept the revised policy.

Contact us

If you have questions about this Privacy Policy or how we handle information, contact us at assistant.drlee@elitesedation.com.