Privacy Notice
Last updated: August 15, 2026
1. Introduction
Optimize AI Tech ("Optimize AI", "we") builds Medical Copilot, a Clinical Documentation & Coding Intelligence platform for healthcare organizations. This notice explains what information we process, why, and the rights available to you. It covers both visitors to this website and the data we process on behalf of our healthcare clients through the Medical Copilot platform.
2. Data We Process on Behalf of Healthcare Clients
Medical Copilot processes clinical encounter documentation on behalf of healthcare organizations, under written agreements with those organizations. Where United States law applies, we act as a Business Associate under HIPAA and execute Business Associate Agreements with our clients. If a Business Associate Agreement, client agreement, or data-processing agreement applies and conflicts with this notice, that agreement controls for the covered client data.
We follow strict data minimization. To perform documentation and coding review, the platform processes:
- Clinical encounter documentation, orders, results, and service descriptions provided by the client's system
- Encounter identifiers, which are encrypted at rest
- Limited demographic details needed for correct coding, such as date of birth or age and sex
- Audio, transcripts, draft notes, session artifacts, and encounter context when an ambient documentation feature is enabled by the client
We do not deliberately collect or store patient names, addresses, contact details, social security or national identity numbers, or medical record numbers. Where clinical free text, audio, transcripts, or encounter materials supplied by a client contain identifying details, that information is protected with the same safeguards as all clinical data.
3. Ambient Documentation, Audio, and Consent
When a healthcare client enables ambient scribe or encounter-listening features, Medical Copilot may process audio or conversation content from an encounter to generate draft transcripts, summaries, notes, documentation suggestions, coding-related context, or other encounter-support output. Audio processing may be transient during a live session. Temporary encrypted transcripts, draft notes, session artifacts, or processing logs may be retained only as needed to provide, secure, troubleshoot, audit, or support the service, and according to the applicable client agreement, Business Associate Agreement, product configuration, or retention setting.
The healthcare client is responsible for determining when patient notice, patient consent, participant consent, staff consent, or other authorization is required for recording, transcription, ambient listening, or AI-assisted documentation, and for obtaining and documenting that notice or consent before using ambient features. Medical Copilot may provide consent prompts, status indicators, logs, configuration settings, or other consent-support tooling, but those tools support the client's workflow and do not replace the client's legal responsibility.
Ambient output is draft documentation support. The client is responsible for clinician review, editing, approval, and inclusion in the medical record. The service does not have autonomous clinical authority and does not independently diagnose, treat, prescribe, order care, submit claims, or make final clinical, coding, billing, or payer-submission decisions.
Encounter audio or transcripts may include information from patients, clinicians, interpreters, family members, caregivers, trainees, and other participants. The client is responsible for addressing the rights and expectations of those participants under applicable law and policy.
4. Safeguards
All clinical data is protected through:
- Encryption in transit and encryption of stored identifiers, transcripts, draft notes, session artifacts, and other retained clinical materials at rest where applicable
- Role-based access controls, user-session security, and organization-level data isolation
- A per-access audit log of every access to protected health information, recorded with hashed identifiers
- A complete decision audit trail covering queries, responses, warnings, overrides, and reviewer actions where supported by the applicable service configuration
- Regular security assessment of our practices
5. Artificial Intelligence Processing
Medical Copilot uses artificial intelligence to analyze documentation and suggest clarifications, draft notes, summaries, and codes. AI output is advisory: it is reviewed and confirmed by qualified professionals at the client before any use, and every recommendation carries its source text and rationale where supported by the applicable feature. We do not use identifiable protected health information from client clinical data to train generalized models for other clients, and processing by any technology subcontractor takes place under data-protection agreements consistent with this notice and any applicable Business Associate Agreement.
We may use de-identified, aggregated, or operational information to maintain security, measure system performance, improve reliability, evaluate accuracy, troubleshoot issues, and improve the service, subject to applicable agreements and law. We minimize data used for these purposes and do not use identifiable client PHI for generalized model training unless expressly permitted by the applicable written agreement and law.
6. Website Data We Collect Directly
On this website we collect:
- Contact and demo requests. When you submit our contact form, we store the details you provide (such as name, work email, phone, and company) and receive them by email, in order to respond to you.
- Scheduling. Demo bookings are scheduled through Microsoft Bookings, which processes the details you enter under Microsoft's privacy terms.
- Analytics and security. We use Google Analytics to understand site usage and Google reCAPTCHA to protect our forms. These services set cookies and process technical data such as IP address and browser information under Google's privacy terms. We do not run advertising or social-media tracking pixels on this site.
- Business contact information. We process professional contact details of prospective clients for business-to-business communication. You may opt out of marketing communication at any time using the unsubscribe option in our messages or by contacting us.
7. How We Use Information
- Provide documentation review, ambient documentation, draft notes, clarification queries, and coding support to our clients
- Maintain audit trails required for compliance, appeal, and payer review
- Improve the reliability, safety, security, and accuracy of the platform
- Respond to enquiries and manage client relationships
- Meet our legal and contractual obligations
8. Data Retention
Clinical data processed for clients is retained according to the client agreement, Business Associate Agreement, product configuration, and applicable healthcare regulations, and is returned or deleted when the agreement ends. Ambient audio may be processed transiently, while encrypted transcripts, draft notes, session artifacts, logs, and audit records may be retained temporarily or for the period configured or agreed for clinical, support, audit, compliance, or legal purposes. Website enquiry data is kept only as long as needed to handle the enquiry and any resulting relationship.
9. Legal Frameworks and Your Rights
We align our practices with the privacy laws of the markets we serve, including HIPAA in the United States, the EU and UK GDPR, the Saudi Personal Data Protection Law (PDPL), the UAE Personal Data Protection Law, and applicable US state privacy laws such as the California Consumer Privacy Act.
Depending on the law that applies to you, you may have the right to:
- Access the personal data we hold about you
- Request correction or deletion of your data
- Object to or restrict processing
- Receive your data in a portable format
- Withdraw consent where processing is based on consent
- Lodge a complaint with your supervisory authority
For patient data processed on behalf of a healthcare client, requests should be directed to that healthcare organization, which controls the data; we support our clients in fulfilling them.
10. Contact Information
For privacy-related inquiries, contact our Data Protection Officer at: privacy@medcopilot.co