Privacy Policy

1. Overview

MontoHealth (“we,” “us,” or “our”) provides an AI-powered patient communication and workflow automation platform for healthcare organizations (the “Services”). This Policy explains how we collect, use, and protect personal information in connection with the Services.

A healthcare practice, clinic, or healthcare organization that registers to use the Services holds an account (an “Organization”). An Organization may add authorized users (“Users”) to its account and control what each User can access. Patients who interact with the Services on behalf of an Organization — by phone, text message, or other supported channel — do not hold an account and take part only because the Organization has made the Services available to them (“Patients”).

For Patient information, including Protected Health Information (“PHI”), we act as a **Business Associate** to the Organization under the Health Insurance Portability and Accountability Act (“HIPAA”), and we process it under the terms of a Business Associate Agreement (“BAA”) entered into with each Organization, and on the Organization’s instructions. The Organization, as a HIPAA Covered Entity (or as a Business Associate of one), is responsible for obtaining any consents and providing any notices required by law before submitting Patient information to, or communicating with a Patient through, the Services.

The Services are offered only in the United States. If you do not agree with this Policy, do not register for an account or use the Services.

**If you are a Patient experiencing a medical emergency, do not use this platform. Call 911 or go to your nearest emergency room.**

2. Information We Collect

CategoryExamples
AccountName, business email, phone number, Organization name, job title
Practice ConfigurationCall routing rules, scheduling preferences, service scripts, notification settings
Patient InformationName, date of birth, contact details, insurance information, and other information necessary to schedule appointments, process refill requests, or respond to routine inquiries
Protected Health Information (PHI)Information relating to a Patient’s health condition, treatment, or payment for care that is shared during an interaction, to the extent disclosed by the Patient or the Organization
Interaction DataCall recordings, voice transcripts, SMS message threads, and AI-generated summaries of Patient interactions
Billing & TechnicalBilling contact and address. Card payments are handled by our payment processor; we do not receive or store full card numbers & Technical:  IP address, device and browser type, session and usage activity, cookies

We collect this information directly from Organization Users, from Organizations about the Patients they serve, from Patients during an interaction with the Services, and automatically from the devices used to access the Services. Interaction Data — including transcripts and AI-generated summaries — is generated by the Services and can be reviewed or edited by the Organization.

We do not use facial recognition, voiceprint matching, or any other biometric identification technique.

You can disable non-essential cookies through our cookie banner or your browser settings.

3. How We Use Information

We use information to: deliver and support the Services, including answering calls, scheduling appointments, and routing refill or referral requests; generate transcripts and summaries of Patient interactions; manage Organization accounts and billing; secure the platform and prevent fraud; improve reliability using de-identified or aggregated data; meet legal and regulatory obligations; and, where an Organization User has opted in, send product updates. We never use Patient contact details for marketing.

4. AI Processing

We use third-party AI providers for language processing, voice, and transcription. Where PHI may be processed, we only use subprocessors that have agreed to a Business Associate Agreement or equivalent HIPAA-compliant terms, and whose commercial terms provide that content submitted through their API is not used to train the provider’s models. We have not opted in to any program that would allow this.

We do not use Interaction Data or PHI to train or fine-tune AI models.

AI-generated transcripts, summaries, and responses are intended to support — not replace — clinical and administrative judgment. They may be inaccurate or incomplete and should be reviewed by Organization staff where they inform a care-related decision.

5. HIPAA and Protected Health Information

Where the Services involve the creation, receipt, maintenance, or transmission of PHI on behalf of an Organization that is a HIPAA Covered Entity, we enter into a Business Associate Agreement with that Organization governing our use and disclosure of PHI. In the event of any conflict between this Policy and an applicable BAA, the BAA controls with respect to PHI.

We maintain administrative, physical, and technical safeguards designed to protect PHI in accordance with the HIPAA Security Rule, including encryption, access controls, and audit logging.

If you are a Patient and have questions about how your health information is used, please contact the healthcare Organization that provided you with access to the Services — they are the Covered Entity responsible for your health information.

6. Text Messaging

Where enabled by an Organization, we deliver SMS messages on behalf of that Organization relating to a Patient’s care: appointment reminders and confirmations, rescheduling notices, refill status updates, and Patient responses sent during a text-based interaction. We do not send marketing messages to Patients.

Patients provide their mobile number and consent to the Organization that initiates contact.

No mobile information is shared with third parties or affiliates for marketing or promotional purposes. Sharing with subcontractors that support message delivery and customer support is permitted for that limited purpose. Text messaging originator opt-in data and consent are not shared with any third party except as described in this section.

Message frequency varies. Message and data rates may apply. Reply STOP to opt out, or HELP for help. Carriers are not liable for delayed or undelivered messages.

7. Sharing

We do not sell personal information or share it for cross-context behavioral advertising. We share information with:

  • Service providers for hosting, message delivery, AI processing, analytics, and payments, engaged under terms — including BAAs where PHI is involved — that permit them to use it only to provide their service to us.
  • The Organization that a Patient interacted with, which receives that Patient’s Interaction Data and any related PHI.
  • Systems an Organization connects to the Services (such as an EHR or practice management system), as that Organization directs.
  • Authorities or others where required by law, or to enforce our Terms of Service or protect rights, property, and safety.
  • A successor entity in a merger, acquisition, or sale of assets, subject to continued protection of PHI as required by HIPAA.

8. Retention

We keep personal information, including PHI, for as long as reasonably necessary for the purposes described in this Policy and any applicable BAA, then delete or de-identify it. Retention periods depend on the type of information, its purpose, and any legal, regulatory, or contractual requirement — including any minimum retention period specified by an Organization’s BAA.

Information in backups is removed on our normal backup cycle after deletion from active systems.

We act on verified deletion requests within the timeframe required by applicable law, except where we are required to retain information longer.

9. Security

Information is stored and processed in United States data centers. We use industry-standard safeguards including encryption in transit and at rest, role-based access controls, audit logging, and regular security reviews, consistent with HIPAA Security Rule requirements. No system can guarantee absolute security.

10. Your Rights

Where a U.S. state privacy law applies to you, you may request access to, correction of, deletion of, or a portable copy of the personal information we hold about you, and you will not be treated differently for making a request. Because we do not sell or share personal information for advertising, no opt-out applies.

If your request concerns PHI held on behalf of a healthcare Organization, we will direct you to that Organization, as they are responsible for responding to requests regarding your health records under HIPAA.

Email [privacy@montohealth.ai](mailto:privacy@montohealth.ai). We verify identity before responding. An authorized agent may submit a request with proof of authorization.

Organization Users can manage marketing preferences in account settings or by unsubscribing. Essential service notifications continue while an account is active.

11. Age

Accounts are restricted to individuals aged 18 or over. We do not independently verify a Patient’s age; where a Patient is a minor, the Organization is responsible for any consent required under applicable law. We do not knowingly collect information from children under 13 outside of an Organization’s direction, and will delete it if we learn we have done so improperly.

12. Changes

We may update this Policy and will update the “Last Updated” date above. We review it at least once every 12 months. For material changes, we will email Organization administrators and post notice on our website before the change takes effect.

13. Contact

Privacyprivacy@montohealth .ai
Supportsupport@montohealth .ai
AddressMontoHealth, 22693 Hesperian Blvd #205, Hayward, CA 94541, United States
Phone(650) 374-4160
Ready to Transform Patient Communication?

Experience the Future of Healthcare Communication

Empower your practice with intelligent AI that never misses an opportunity to care for your patients.