Atlas.md Privacy Policy

Last Updated: November 19, 2025

Scope: This Privacy Policy applies to the Atlas.md web application, mobile applications, and website (collectively, the “Services”) provided by Atlas CRM, LLC (“Atlas.md,” “we,” or “us”). It describes how we collect, use, disclose, and protect personal information. This policy covers data of our clinic customers (healthcare providers and their staff), patients whose information is managed on our platform, and visitors to our website.

Atlas.md is a specialized software for healthcare practice management, and therefore we handle sensitive personal data, including health information. We are committed to protecting your privacy and complying with applicable privacy laws. In many cases, Atlas.md acts as a “Business Associate” to healthcare providers under HIPAA, meaning we process Protected Health Information on behalf of our clinic customers. We strive to uphold the trust placed in us by implementing strong privacy and security practices.

By using our Services or by providing us with personal information, you agree to the terms of this Privacy Policy. If you do not agree, please do not use the Services. If you have any questions about this policy, you can contact us at support@atlas.md.

1. Information We Collect

We collect various types of information through our Services. In most cases, the data we collect is provided by users (either healthcare providers or patients) or generated through the use of our platform. Here are the categories of information we handle:

Special Note on Sensitive Personal Information: Because Atlas.md is used for healthcare data, much of the information in our system is sensitive personal data, including health information. We apply the highest standard of care to protecting this information (see Section 4: How We Protect Your Information). We do not use sensitive health data for any purpose other than providing our Services, except in an anonymized way to improve our tools (e.g., to refine an AI algorithm, we might analyze hundreds of lab results trends without any patient identifiers attached).

2. How We Use Your Information

Atlas.md uses the collected information for the following purposes:

We do not use personal data for any purposes not described above without obtaining consent or providing notice. In particular, we do not sell personal information to data brokers or advertisers. We do not use patient data to advertise or market third-party products to patients. Any use of data for research (for example, analyzing outcomes across clinics) would be done in an aggregated and anonymized manner unless we obtain explicit permission for a specific identifiable use.

3. How We Share and Disclose Information

Atlas.md will share personal information with third parties only in ways that are necessary to provide our Services or as required by law. Below are the circumstances and partners with whom we may share data:

No Selling of Personal Information: We want to clarify that we do not sell or rent personal information to third-party marketers. We do not share patient lists or contact information with pharmaceutical companies or the like. All sharing is only what’s needed to run our service or what is directed by our users, as outlined above.

4. Data Security: How We Protect Your Information

Atlas.md takes the security of personal and health information very seriously. We have implemented a comprehensive security program with administrative, technical, and physical safeguards designed to protect your data from unauthorized access, disclosure, or alteration. Here are key aspects of our security approach:

Despite our efforts, it’s important to acknowledge that no security measure is foolproof. The healthcare industry can be a target for cyber threats, and while we do everything reasonably possible to protect data, we cannot guarantee absolute security. Users should also play their part in security (see the “Your Security Responsibilities” under Terms of Service). If you have reason to believe that your data or account has been compromised, please contact us immediately.

5. Data Retention

We retain personal information for as long as necessary to fulfill the purposes for which it was collected, or as required by law, or as otherwise stated in this Privacy Policy.

Legal Hold: Note that if we are under a legal obligation to preserve data (e.g., a litigation hold, government investigation, or specific law requiring certain data retention), we will suspend routine deletion until that obligation is fulfilled.

When we do dispose of personal data, we take care to do so securely. For example, digital data deletion involves deleting from databases and overwriting or encrypting backups when they cycle out, and physical media (if any) would be shredded or destroyed.

6. Individual Rights and Choices

Depending on who you are (patient, provider, website visitor) and applicable laws, you may have certain rights regarding your personal information. We are committed to honoring applicable rights requests in a timely manner. Below are ways you can control your information and exercise rights:

If you have any questions about your rights or how to exercise them, please contact us at support@atlas.md. We will be happy to explain and help with the process. In many cases, because of the nature of our service, we will advise you to also speak with your healthcare provider (for anything related to your health record) to ensure proper handling under medical privacy rules.

7. Children’s Privacy

Atlas.md is not directed to children for direct sign-up. However, it does store personal information about children in a healthcare context (for example, pediatric patients of a clinic will have records in the system). Any such data is provided by the child’s parent or guardian and the healthcare provider, and is used only for the purposes of healthcare services for that child. We do not knowingly collect personal information from children under 13 directly through any public-facing portal without parental consent. If a patient under 13 is given access to, say, a messaging app by their parent/guardian, it is assumed the parent/guardian supervised that and consented.

If you are a parent or guardian and believe that a minor’s personal information has been provided to us without proper consent, please contact us. We will work with you and the clinic to address any concerns, including deleting any inadvertent unauthorized information. In practice, since we operate through clinics, the clinic obtains parental consent for treating minors and for using Atlas.md as part of that service.

8. International Users

Atlas.md is designed for use by clinics and patients in the United States. Our infrastructure is based in the U.S., and our operations are subject to U.S. laws. If you are accessing the Services from outside the U.S., be aware that your information will be transferred to, stored, and processed in the United States. The data protection laws of the U.S. may differ from those in your country of residence. By using our Services or providing us with your information, you acknowledge this transfer and processing in the U.S.

If you are in the European Economic Area (EEA), United Kingdom, or other regions with comprehensive data protection laws (like GDPR), please note that Atlas.md is likely not offering services to you directly (as our focus is U.S. clinics). Any personal data of EU individuals in our system would typically be there because a U.S.-based clinic entered it (which may happen if an EU citizen is a patient of a clinic here, or a user decides to use it abroad). In those cases, the clinic would be the data controller and Atlas.md a data processor. We would handle that data under the contractual instructions of the clinic (likely via a Data Processing Addendum in line with GDPR standards). If GDPR applies, individuals have rights similar to those described in Section 6, and we will assist the controller (clinic) in fulfilling those. We also ensure adequate safeguards for any EU data, such as standard contractual clauses if appropriate, and we treat all personal data with high security regardless of origin.

9. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or for other operational reasons. When we make material changes to the policy, we will notify our users in an appropriate manner:

If we were to make a change that we believe retroactively reduces your privacy rights (for example, if we decided to start using data in a new way that you didn’t originally agree to), we would either obtain your consent or give you a clear ability to opt out of that new use. Most changes are likely to be minor or clarifying. Your continued use of the Services after the effective date of a revised policy will signify your acceptance of the updated terms, to the extent permitted by law.

For any questions regarding the changes or to get the previous version of the policy, you can contact us.

10. Contact Us

If you have any questions, concerns, or comments about this Privacy Policy or our data practices, please don’t hesitate to contact us:

We will address your inquiries as promptly as possible. If you have a dispute with us regarding privacy, we will work in good faith to resolve it. If you feel we have not satisfactorily addressed your concern, you may have the right to lodge a complaint with a supervisory authority (for example, a data protection authority or the U.S. Department of Health & Human Services Office for Civil Rights, in the case of HIPAA issues). We would appreciate the chance to deal with your concerns directly first.

Your trust is vital to us. Atlas.md is built around the idea of providing personal, reliable service for direct care, and that extends to how we handle your data. We appreciate you taking the time to read this Privacy Policy.



Vulnerability Disclosure Policy