Version 2.0 · Effective August 10, 2026
Sanasign Privacy Policy
Effective date: August 10, 2026
Introduction
Sanasign, Inc. ("Sanasign," "we," "our," or "us") builds software that moves orders for care delivered in the home — plans of care, initial certifications and recertifications, supplemental and change orders, and therapy and wound care orders — from the agency that prepares them to the provider who signs them, and back again with a complete, auditable record.
This Privacy Policy (this "Policy") explains how we collect, use, and share information in connection with our website at www.sanasign.com, the Sanasign application (including its demonstration environment), and the emails and notifications we send in connection with them (together, the "Services"). It does not apply to any other website or service, including those operated by our customers or by third parties.
Please read the next section carefully. It explains why most of the health information in Sanasign is not governed by this Policy.
Two Different Roles, Two Different Rulebooks
Sanasign handles two categories of information, and different rules apply to each.
1. Information we hold for our customers ("Customer Data"). Home health agencies, hospices, medical practices, and similar organizations use the production Sanasign service to create, send, review, and sign clinical documents. Those documents contain protected health information about patients, as defined under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations, as amended ("HIPAA").
When we handle that information, we do so as a business associate of the customer organization. Every organization using the production service accepts the Sanasign Healthcare Provider User Agreement, which incorporates our Business Associate Agreement (the "BAA") — both published on our website. Customer Data is handled under those agreements, not under this Policy. They restrict what we may do with it: in general, we may use and disclose it only to provide the service and as the customer directs, only for permitted purposes, and only in ways the customer itself would be permitted to use and disclose it. We are required to maintain administrative, physical, and technical safeguards protecting its confidentiality, integrity, and availability, and to notify the customer of any breach of unsecured protected health information. We do not sell identifiable customer or patient data to anyone.
If you are a patient and want to know how your health information is used, or want to exercise your HIPAA rights to access or amend your records, contact the agency, hospice, or medical practice that provides your care. They control those records; we hold them on that organization's behalf. If you contact us directly about a patient record, we will refer you to the responsible organization, because we are not permitted to act on such a request without its instruction.
2. Information we hold for ourselves ("Personal Information"). This Policy governs the information we collect and use on our own behalf: information about visitors to our website, people who request a demo, users of the demonstration environment, the professionals who hold Sanasign accounts, providers who receive documents through Sanasign, and people who contact us. This includes account and contact details, usage and device information, and support correspondence.
Where a single piece of information falls into both categories, the BAA and the User Agreement control.
The Demonstration Environment
We maintain a demonstration environment that runs on sample data so prospective customers can evaluate Sanasign. Do not enter information about real patients into the demonstration. It is not the production service, no business associate agreement covers it, and it is not configured to receive protected health information. Our team can view demonstration data in the ordinary course of building and supporting the product, and demonstration data is reset and deleted on no fixed schedule. If patient information is entered into the demonstration, tell us at [email protected] and we will delete it promptly and confirm. The Terms of Use state the demonstration rules in full.
Information We Collect
Information You Provide
We collect information you give us when you:
- Request a demonstration, subscribe to updates, or fill out a form on our website;
- Register for a Sanasign account or claim an organization, or have an account created for you by your organization's administrator — including your name, credential, National Provider Identifier ("NPI"), specialty, organization, work email address, and work telephone or fax number;
- Create, upload, edit, comment on, send, review, decline, or sign a document within the Services;
- Contact support, attend a training or onboarding session, or respond to a survey; or
- Correspond with us about a business relationship, a job opening, or any other matter.
Information About Guest Signers
Sanasign allows an agency to send a document to a provider who does not hold an account, so the provider can review and sign through a secure link. We receive the provider's name, credential, NPI, practice affiliation, and contact details from the sending agency and from public registries, and we collect information about how the link is used — when it was opened, from what device, and what action was taken. We use this to deliver the document, authenticate the signer, maintain the audit record, and report status to the sending organization. Guest signers accept the Signer Terms at the time they act on a document.
Information We Collect Automatically
When you visit our website or use the Services, we and our service providers automatically collect device and connection information (IP address, browser type and version, operating system, device type, screen characteristics, language settings, referring and exit pages, and the pages and features you interact with), usage information (sign-in times, session activity, actions taken on documents, and their timing and sequence), and email engagement information (whether a notification was delivered and opened and whether links were followed — this is how a sending organization knows a signature request reached its destination). Some of this information is also part of the audit trail associated with a document; where that is the case, it is Customer Data.
Information From Other Sources
We supplement provider and practice records with information from public and licensed sources, including the National Plan and Provider Enumeration System (NPPES), the CMS home health provider datasets, state licensing boards, and similar registries, so that professionals can be matched accurately and documents reach the right recipient. We may also receive information from our customers, from partners, and from fraud-prevention and security vendors.
Payment Information
If your organization purchases a subscription, we collect billing contact details and, through a third-party payment processor, the payment method used. We do not store full payment card numbers; our processor handles them under its own terms and is contractually required to protect them.
Cookies and Similar Technologies
We and our service providers use cookies and similar technologies on our website and in the application:
- Strictly necessary. Required to operate the Services — keeping you signed in, maintaining sessions, routing requests, and protecting against fraud and abuse. These cannot be turned off.
- Performance and analytics. Used to understand in aggregate how the Services are used, so we can find problems and improve them.
- Preferences. Used to remember choices you have made, such as display settings.
We do not use cookies or similar technologies for cross-context behavioral advertising, we do not permit third parties to do so in our Services, and we do not display third-party advertising anywhere in the Services.
Most browsers let you refuse or delete cookies; because some are necessary, disabling them may break parts of the Services. Where applicable law requires it, we present a cookie preference control and honor the Global Privacy Control (GPC) signal. A GPC signal applies only to the browser or device that sends it.
How We Use Information
We use the information described above to: provide, operate, secure, and maintain the Services; create and administer accounts, verify professional identity and credentials, authenticate users, and enforce access controls, including multi-factor authentication; deliver documents and notifications to their intended recipients and report delivery and signature status to the sending organization; maintain audit trails and generate completion packages; respond to support requests, resolve technical problems, and communicate with you about your account; deliver service announcements, security notices, and administrative communications; understand how the Services are used and improve their design, performance, and reliability, and develop new features; send marketing communications about Sanasign, subject to the choices below; detect, investigate, and prevent fraud, security incidents, abuse, and violations of our terms or the law; comply with our legal obligations and enforce our agreements; and carry out any other purpose described to you at collection or for which you give permission.
Our use of Customer Data is separately and more narrowly limited by the BAA and the User Agreement.
Artificial Intelligence and Model Training
We do not provide Customer Data or Personal Information to third parties for the training of their artificial intelligence models, and we contractually require vendors processing data on our behalf to commit to zero retention for their own training purposes. Where we use machine learning or automated processing within the Services — for example, to extract structured fields from an uploaded document or to flag potential gaps for user review — we do so to provide and improve the Services. We may use de-identified data, created in accordance with HIPAA's de-identification standard and the BAA, to develop and improve these features.
De-Identified and Aggregated Information
We may create de-identified and aggregated information from data in the Services, in accordance with HIPAA's de-identification standard where the underlying data is protected health information and as permitted by the BAA and the User Agreement. We use this information to operate, evaluate, and improve the Services and to produce benchmarks and industry-level statistics that do not identify any customer or patient. We do not attempt to re-identify it and require the same of anyone who receives it.
How Information Is Shared
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising, as those terms are used in the California Consumer Privacy Act and comparable state laws. We do not sell identifiable Customer Data to anyone.
We share information in the following circumstances:
Within your organization. Administrators can see account and activity information for the users they administer and can manage those accounts. Users within an organization can see documents and activity within the scope their organization grants them.
With counterparties to a document. Sanasign is a two-sided service. When an organization sends a document, the sender sees who received it, when it was opened, and what action was taken; the recipient sees the document and the identity of the sending organization and author. Sending a document to a recipient necessarily discloses information to that recipient.
In our directory. Professional and practice information may appear in the directory described below.
With service providers. We use vendors to host and operate the Services and run our business — cloud infrastructure, authentication, email and notification delivery, error monitoring, analytics, support, and payment processing. They may access information only as needed to perform work for us, are bound by written contracts including, where applicable, business associate agreements, and may not use it for their own purposes.
For legal and safety reasons. We may disclose information when we believe in good faith it is required by law or legal process; to establish, exercise, or defend legal claims; to investigate suspected fraud, security incidents, or violations of our agreements; or to protect the rights, property, or safety of Sanasign, our users, or the public. Where the information is protected health information, we handle such requests in accordance with HIPAA and the BAA, which in most cases means notifying the customer and directing the requesting party to it.
In a corporate transaction. If Sanasign is involved in a merger, acquisition, financing, reorganization, or sale of all or part of its business or assets, information may be transferred as part of that transaction or the diligence preceding it, subject to confidentiality obligations. Protected health information will be transferred only as permitted by HIPAA and the BAA. Personal Information transferred remains subject to this Policy until the recipient provides notice of a different one.
With your permission, or as otherwise described at the time.
Provider and Practice Directory
Sanasign maintains a directory of providers and practices so an agency can find the right signer. It includes professional information only — name, credential, NPI, practice affiliation, and work contact details — drawn from public registries and information supplied by users and their organizations, and it is visible to other organizations using the Services for the purpose of directing documents. It is not a public consumer-facing directory, contains no ratings or reviews, is not open to the general public, and contains no patient information. If your information is inaccurate, you or your administrator can correct it in the application, or write to [email protected].
Communications From Us
Some communications are part of the Services and cannot be turned off while you have an account or an active signature request — signature requests, document status notifications, security alerts, authentication messages, and notices about changes to our terms. Marketing communications are optional: opt out any time using the unsubscribe link or by writing to [email protected]. Opting out of marketing does not stop service messages.
Security
We use administrative, physical, and technical safeguards designed to protect the information we hold, including encryption of data in transit and at rest, role-based access controls, organization-level data isolation enforced at the database layer, multi-factor authentication, logging and monitoring, and confidentiality obligations for personnel with access to production systems. Where we act as a business associate, we implement the safeguards required by the HIPAA Security Rule and our BAA.
No system is perfectly secure, and we cannot guarantee that information will never be accessed, disclosed, altered, or destroyed in breach of our safeguards. Keep your credentials confidential, enable multi-factor authentication, do not share accounts, and tell us promptly at [email protected] if you believe an account has been compromised.
Data Retention
We retain Customer Data as the User Agreement and BAA provide: following termination, customers have a sixty (60)-day window to export their documents and completion packages, after which we return or destroy protected health information in accordance with the BAA, subject to retention required by law and backup copies pending routine deletion. Healthcare organizations frequently have independent legal obligations to retain clinical records for extended periods; those obligations are the customer's to meet, and Sanasign is not a system of record.
Demonstration data is not retained and may be reset or deleted at any time. We retain other Personal Information — demo requests, correspondence, account records, marketing preferences, and security and usage logs — as long as needed for the purposes in this Policy and to meet our legal, tax, audit, and recordkeeping obligations, resolve disputes, and enforce our agreements.
Your Choices and Rights
Access and correction. You can view and update much of your account and profile information by signing in. If you cannot make a change yourself, your organization's administrator may be able to, or write to [email protected].
Limits. You cannot access, change, or delete another user's account, another organization's records, or information a different user or organization submitted about you. You cannot delete a document you have sent to someone else, and you cannot alter the audit trail — its integrity is the point of the product.
Patient records. As described above, requests to access, amend, restrict, or receive an accounting of disclosures of protected health information should go to the healthcare organization that maintains the record.
State privacy rights. Residents of California, Colorado, Connecticut, Virginia, Texas, and other states with comprehensive privacy laws may have rights to know what personal information we hold, obtain a copy, correct it, delete it, and appeal a denial, subject to the exceptions in the applicable law. We do not sell personal information, do not share it for cross-context behavioral advertising, and do not use it for profiling that produces legal or similarly significant effects, so there is nothing to opt out of in those categories. Protected health information handled under HIPAA, and information used solely in a business-to-business or employment context, is exempt from most of these laws; where an exemption applies, we will tell you. To make a request, write to [email protected]. We will verify your identity before acting, will not discriminate against you for making a request, and will respond within the period the applicable law requires. An authorized agent may submit a request with proof of authorization.
Children's Privacy
The Services are professional tools intended only for adults acting in a professional capacity. You must be at least 18 years old to use them, and we do not knowingly collect personal information directly from children. Clinical documents in Sanasign may concern patients who are minors — pediatric home health is a real part of this industry. That information is protected health information, is Customer Data, and is handled under HIPAA and the BAA rather than under this Policy.
Third-Party Websites and Services
Our website and the Services may link to sites and services we do not operate. This Policy does not apply to them; review their privacy policies before providing information. If your organization connects Sanasign to a third-party system, information you direct us to send to that system is handled under your agreement with that provider.
United States Only
The Services are operated in and intended for use in the United States. If you access them from outside the United States, you do so on your own initiative, are responsible for compliance with local law, and understand that your information will be processed in the United States.
Changes to This Policy
We will update this Policy as our business and the law change. When we do, we will revise the effective date above and post the updated Policy on our website. If a change materially affects how we handle Personal Information, we will provide additional notice — by email, in the application, or prominently on our website — before it takes effect. Continued use of the Services after a change takes effect means you accept it.
Contact Us
Questions about this Policy, how we handle information, or a privacy request:
Email: [email protected]
We will respond as promptly as we can.