Privacy Policy
Effective date: August 6, 2026
Last updated: August 6, 2026
1. Who we are
Authos Health, Inc. (“Authos,” “we,” “us”) is a Delaware corporation registered to do business in Utah. We build AuthLogic, prior authorization software for ophthalmology practices.
This policy explains how we handle information in two distinct contexts, which are governed very differently:
- Our website at authos.health, which anyone can visit.
- The AuthLogic service, which we provide to healthcare practices under contract.
If you are a patient, the short version is in Section 6.
2. Our role, and why it matters
For the AuthLogic service, Authos is a Business Associate as that term is defined under HIPAA. We are not a Covered Entity. We do not have a direct relationship with patients and we do not decide what happens to a patient's medical record.
The practice or health system that uses AuthLogic is the Covered Entity. They control the record. We process protected health information (“PHI”) only on their instruction and only as permitted by the Business Associate Agreement we sign with them. Where this policy and an executed BAA differ with respect to PHI, the BAA governs.
3. Information we collect from website visitors
The website is informational. We do not require an account and we do not sell anything through it.
What you give us. If you submit our contact form, we receive what you type into it: typically your name, email address, organization, and message. We use it to respond to you and to keep a record of the conversation.
What is collected automatically. Our hosting provider records standard technical information about requests, including IP address, browser type, referring page, and timestamp. This is used to serve the site, keep it available, and protect it from abuse.
Do not send us patient information through the website. The contact form is not a secure channel for PHI and should not be used for it. If you need to discuss a specific patient, tell us and we will move to an appropriate channel.
We do not use advertising cookies, we do not run third-party ad trackers, and we do not build advertising profiles.
4. Information we process in the AuthLogic service
AuthLogic exists to prepare prior authorization requests. To do that it processes clinical and administrative information about patients whose authorizations a practice is submitting. Depending on the case, that can include:
- Patient identifiers and demographics
- Coverage, plan, and payer information
- Diagnosis codes and clinical conditions
- Medication and procedure orders, and prior therapy history
- Clinical documentation and imaging reports, including measurements recorded in them
- The identity of the practice staff member who took an action on a case
How it reaches us. AuthLogic reads from the practice's electronic health record over the interface the EHR vendor publishes, using credentials the practice authorizes. We request read access only, scoped to the resources listed above. AuthLogic does not write to, modify, or delete anything in the EHR, and it does not run inside the practice's clinical database.
What we do with it. We use it to assemble the authorization, evaluate the case against the payer's published criteria, produce a verdict, support submission by practice staff, and record the outcome. Every action on a case is written to an append-only audit log that cannot be edited after the fact.
What we do not do with it. We do not sell it. We do not share it for advertising. We do not use it to train publicly available AI models. We do not use one customer's patient data to serve another customer.
De-identified information. We may derive de-identified and aggregated information from service data to operate, secure, and improve the service, consistent with HIPAA's de-identification standard and with our agreements. De-identified information is not re-identified.
5. Artificial intelligence
AuthLogic uses AI models in two places, and they are kept separate on purpose.
Reasoning about a case. Where a model processes PHI, that processing runs on infrastructure covered by a Business Associate Agreement with the infrastructure provider. Inputs and outputs are not used to train the provider's models and are not retained by the provider for that purpose.
Reading payer policies. Payer authorization criteria are extracted from documents the payers publish publicly. That process runs entirely separately and never receives patient information.
Models do not make the authorization decision. Criteria are evaluated by deterministic rules, and a person at the practice reviews and submits every authorization.
6. If you are a patient
We do not have a direct relationship with you, and we cannot verify your identity or act on your record on our own authority.
Your rights under HIPAA, to access your records, request a correction, or ask for an accounting of disclosures, run through your healthcare provider, who is the Covered Entity. Contact them and they will contact us if our records are involved. We will support them promptly.
7. Service providers
We use a small number of vendors to run the service and the website. Vendors that may process PHI do so under an executed Business Associate Agreement.
| Purpose | Provider | May process PHI |
|---|---|---|
| Cloud infrastructure and databases | Amazon Web Services (US) | Yes, under BAA |
| AI inference on case data | Amazon Bedrock (US) | Yes, under BAA |
| Website hosting and network security | Cloudflare | No |
| Contact form delivery | Web3Forms | No |
| Business email and documents | Google Workspace (US) | Yes, under BAA |
| AI inference on public payer policy documents | Anthropic | No |
Service data is stored and processed in the United States.
8. Security
We maintain administrative, physical, and technical safeguards appropriate to the information we handle. In practice that includes: encryption of data in transit and at rest, databases that are not reachable from the public internet, individual named accounts for every user rather than shared credentials, least-privilege access, an append-only audit log of activity on every case, centralized logging with alerting, and formal agreements with every vendor that touches protected information.
No system is perfectly secure. If we become aware of a breach of unsecured PHI, we will notify the affected Covered Entity as required by HIPAA and by our agreement with them.
9. Retention
Website. Contact form submissions are kept as long as needed to respond and maintain a record of the correspondence. Server logs are kept for a limited period for security and reliability purposes.
Service. Service data, including PHI, is retained for the term of our agreement with the practice and for the period that agreement specifies. On termination we return or destroy PHI as directed, subject to any legally required retention. Audit logs are retained for six years, consistent with the HIPAA documentation retention requirement at 45 CFR 164.316(b)(2)(i).
10. Children
The website is not directed to children and we do not knowingly collect information from children through it. AuthLogic may process information about patients of any age, including minors, as part of the authorization a practice is submitting on their behalf, under the practice's direction and its agreement with us.
11. Changes
We may update this policy. When we do, the effective date above changes. If a change materially affects how we handle service data, we will notify affected practices directly rather than relying on this page.
12. Contact
Authos Health, Inc., a Delaware corporation registered in Utah
privacy@authos.health