Privacy policy
Cync is referral coordination software for healthcare practices. It is owned and operated by Hyper Expert, LLC, a Washington limited liability company ("Hyper Expert", "we", "us", "our"). This policy explains what information we collect through the Cync application and this website, where it comes from, how we use it, who we share it with, how long we keep it, how we protect it, and the choices and rights you have.
Cync is offered in the United States only, and this policy is written for United States law.
On this page
01Summary 02Who this policy is for 03The two roles we act in 04Information we collect 05Where information comes from 06How we use information 07Automated processing and artificial intelligence 08Text messaging and mobile information 09Protected health information 10How we share information 11We do not sell or share personal information 12Cookies and tracking 13Security 14Security incidents 15How long we keep information 16Your rights and choices 17Children 18Where information is held 19Links to other sites 20Changes to this policy 21Contact us01Summary
This summary is for orientation. The sections below govern.
- Practices put referral information into Cync. For that information we act on the practice's behalf, not our own, and the practice remains the custodian of the patient record.
- We contact patients by text message, telephone and fax on a practice's behalf, about a referral their own provider initiated. We never send marketing.
- No clinical information is ever included in a text message.
- We use automated processing, including a third party artificial intelligence service, to read referral documents and to answer questions inside the application. Section 7 explains this in full.
- We do not sell personal information, and we do not share it for advertising.
- An opt out from text messages is recorded against the mobile number, applies across every practice using Cync, and does not expire.
02Who this policy is for
- Practice users. Staff at a healthcare practice who sign in to Cync: coordinators, administrators and clinicians.
- Patients. People whose referrals a practice manages in Cync, and who may receive a text message or telephone call from us on that practice's behalf.
- Referring and receiving practices. Other practices we exchange referral documents and closure notices with by fax.
- Website visitors. Anyone who visits this site without signing in.
03The two roles we act in
This distinction decides who controls information about you and who you should contact about it.
For patient and referral information we act on behalf of the practice. The practice decides what to put into Cync and what to do with it. We process it only to provide the service to that practice and on its instructions. Where it is protected health information, we do so as a business associate under a Business Associate Agreement. Under privacy laws that use the terms, the practice is the controller or business and we are the processor or service provider.
For everything else we act for ourselves. Practice user accounts, billing records, support conversations and website analytics are ours, and this policy governs them directly.
04Information we collect
The categories below use the wording of the California Consumer Privacy Act so the disclosure is directly comparable, and they apply to every user regardless of where they live.
| Category | Examples we actually collect | Why |
|---|---|---|
| Identifiers | Name, work email, telephone number, account identifier, IP address | Accounts, authentication, support, security |
| Customer records | Job title, role, practice, time zone, profile photograph, billing contact | Operating the workspace and billing |
| Protected classifications | Patient date of birth and, where a referral document states it, sex or age | Only as part of a practice's referral record |
| Commercial information | Subscription, plan and payment history | Billing and account management |
| Internet activity | Pages viewed, features used, device and browser characteristics, referring URL | Operating, securing and improving the service |
| Geolocation | Approximate city level location derived from IP address | Security and fraud prevention only. We do not collect precise location |
| Audio and electronic information | Text messages sent and received, telephone call metadata, fax documents | Contacting patients and closing referral loops on a practice's behalf |
| Professional information | Referring provider name, practice, NPI where a document states it | Routing referrals and closure notices |
| Health information | Reason for referral, clinical notes, insurance details, and other content of referral documents | Provided by the practice; processed only on its behalf |
| Inferences | Fields extracted from a referral document, with a confidence indicator | Reducing manual entry. See section 7 |
Health information, and in some states a mobile telephone number, are treated as sensitive. We use sensitive information only to provide the service and for the purposes described in this policy. We do not use it to infer characteristics about anyone.
We do not record telephone calls, and we do not transcribe them.
05Where information comes from
- From the practice. Account details, and every referral document it faxes, uploads or creates.
- From referring practices. Referral documents arriving on a practice's Cync fax number.
- From patients. Replies to our text messages, and anything a patient tells a practice that the practice records.
- From you directly. Support requests and demo enquiries on this website.
- Automatically. Log, device and usage information when you use the application or this site.
- From service providers. Delivery receipts and call outcomes from communications carriers.
We do not buy personal information, and we do not acquire it from data brokers.
06How we use information
- To provide the service: tracking referrals, contacting patients on a practice's behalf, notifying referring practices when a loop closes, and keeping a record of what happened.
- To read referral documents and reduce manual entry. See section 7.
- To authenticate users, protect accounts, and detect and prevent fraud and abuse.
- To provide support and to communicate with practice users about the service.
- To monitor reliability, diagnose faults and improve the product.
- To bill for the service and keep accounting records.
- To meet legal, regulatory and contractual obligations, and to establish or defend legal claims.
We do not use patient information for advertising, and we do not use it to make decisions about a person's care. Cync records and prompts; clinicians decide.
07Automated processing and artificial intelligence
Cync uses automated processing in two places, and we describe both because a healthcare buyer is entitled to know before choosing us.
Reading referral documents
When a referral document arrives, Cync extracts the fields a coordinator would otherwise type: patient name, date of birth, telephone number, insurance, referring provider and reason for referral. Part of that extraction uses a large language model provided by a third party. The content of the document is sent to that provider for processing and a structured result is returned. Extracted fields are marked with a confidence indicator, are always shown next to the original document, and can be corrected by a coordinator at any time.
Answering questions in the application
Cync includes a feature that answers questions about a practice's own referrals in natural language. Answering a question may send the relevant referral information to the same third party provider.
How that provider is bound
- The provider is engaged under a written agreement that includes a Business Associate Agreement covering protected health information.
- Information is processed in the United States.
- The provider is not permitted to use practice or patient information to train its models, and neither do we.
- Information is retained by the provider only as long as needed to return a result and to meet its own legal obligations.
The limits we place on it
- No automated decisions with legal or similarly significant effects. Nothing in Cync decides whether a patient is seen, when, or by whom. Extraction proposes values; a person accepts or corrects them.
- Never the sole basis for clinical action. The original document is retained and remains the record.
- Always correctable. A coordinator can reset any referral to the fields exactly as they arrived.
- Bounded. Automated processing is used for reading documents and answering questions, and for nothing else. We do not profile patients and we do not score them.
If we materially change how automated processing works, or change providers, we will update this section and notify practice administrators before the change takes effect.
08Text messaging and mobile information
How contact details reach us, and on what basis we message
Patients give their mobile number to their own physician during intake and agree to be contacted about their care. When that physician refers the patient to a specialist practice, the referral, including the number, is sent to that practice. Cync then contacts the patient, on that practice’s behalf, about the appointment they were referred for. Messages are transactional and relate to an active referral that the patient's own provider initiated. They are never marketing, and we do not send promotional, political or fundraising messages of any kind.
What we send
A message identifies Cync as the sender, names the practice the patient was referred to, says a referral has been received, and asks the patient to call that practice or reply to arrange the appointment. No clinical information is ever included in a text message. The message does not state the reason for the referral, the specialty, or any diagnosis.
Frequency, cost and keywords
- Message frequency varies. A referral results in up to three approaches, sent no more than once a day, and contact stops after that whether or not the patient replies.
- Messages are sent during daytime contact hours in the practice's own time zone.
- Message and data rates may apply. We do not charge patients for messages.
- Reply STOP to opt out. Reply HELP for help. Reply START or UNSTOP to opt back in.
- Carriers are not liable for delayed or undelivered messages.
Opting out
A patient who replies STOP is opted out immediately. We record the opt out against the mobile number itself, so it applies to every message that would otherwise be sent to that number through Cync, by any practice, and it does not expire. Any attempt already queued for that number is cancelled rather than delayed. A patient can opt back in at any time by replying START, and can always contact the practice directly by telephone.
09Protected health information
Where Cync processes protected health information as defined by HIPAA, we do so as a business associate of the practice under a written Business Associate Agreement. That agreement governs our use and disclosure of it and takes precedence over this policy where the two differ.
- We use and disclose protected health information only as that agreement and applicable law permit.
- We require the same protections, in writing, from any subcontractor who handles it.
- We report security incidents and breaches to the practice as the agreement requires.
- We assist the practice in responding to patient requests for access, amendment, restriction and accounting of disclosures.
- On termination we return or destroy protected health information as the agreement directs.
A practice should have a Business Associate Agreement in place with us before submitting protected health information.
10How we share information
We share information in the circumstances below, and in no others.
| Recipient | What they receive | Why |
|---|---|---|
| Cloud hosting and storage | All service data, encrypted | Running the application and storing documents |
| Communications carriers | Telephone numbers, message content, fax documents | Delivering text messages, calls and faxes |
| Artificial intelligence provider | Referral document content | Field extraction and in application answers. See section 7 |
| Identity and authentication provider | Practice user account identifiers | Sign in, sessions and multi factor authentication |
| Error and performance monitoring | Technical logs | Diagnosing faults and keeping the service up |
| Payment and accounting providers | Billing contact and transaction records | Taking payment and keeping accounts |
| The practice that owns the referral | Its own records only | Practices cannot see one another's data |
| Professional advisers | Only what is necessary | Legal, audit and insurance advice, under duties of confidence |
Service providers act on our instructions, may use information only to provide their service to us, and are bound by written contracts, including Business Associate Agreements where they handle protected health information. A current list of our service providers is available to customers and prospective customers on request from the address in section 21.
We may also disclose information where we are required to by law, legal process or a government request; where it is necessary to protect the rights, property or safety of a person, our customers or the service; or in connection with a merger, acquisition or sale of assets, in which case we will notify affected practices and any recipient remains bound by this policy or one at least as protective.
11We do not sell or share personal information
We do not sell personal information, and we have not done so in the preceding twelve months. We do not share personal information for cross context behavioural advertising, and we have not done so in the preceding twelve months. We do not sell or share the personal information of anyone we know to be under sixteen. Because we do not do either, there is no opt out to offer, but you may still contact us to confirm this.
12Cookies and tracking
We use a small number of cookies and similar technologies:
- Strictly necessary. Keeping you signed in, protecting your session, remembering your interface preferences, and protecting against fraud and abuse. The service cannot work without these.
- Analytics. Understanding how this website performs, in aggregate.
We do not use advertising cookies, we do not run third party advertising trackers, and we do not participate in cross site tracking networks. You can block or delete cookies in your browser, though blocking strictly necessary cookies will prevent you from signing in.
Do Not Track. Because we do not track users across third party websites, we do not respond differently to Do Not Track or Global Privacy Control signals in the application. We honour a Global Privacy Control signal on this website as an opt out request where applicable law requires it.
13Security
We maintain administrative, technical and physical safeguards appropriate to the information we hold:
- Encryption in transit and at rest.
- Tenant isolation, so each practice workspace is separated from every other at the data layer.
- Role based access inside a workspace, and least privilege for our own staff, whose administrative access is limited to those who need it and is logged.
- Single sign on with configurable session policies, support for multi factor authentication, and the ability for a practice to end every session for a user immediately.
- An audit record of sign ins and record changes.
- Written contracts with service providers, including Business Associate Agreements where required.
- Periodic review of access, configuration and dependencies, and prompt patching of the components we run.
No system is completely secure, and no method of transmission or storage is guaranteed. You are responsible for keeping your own credentials confidential and for removing access from people who leave your practice.
14Security incidents
We maintain an incident response process covering detection, containment, investigation and notification. If a security incident affects a practice's information, we will notify that practice without unreasonable delay and, for protected health information, within the timeframe its Business Associate Agreement requires. Our notice will describe what happened, the information involved, what we have done, and what we recommend. Where the law requires us to notify individuals or a regulator directly, we will do so, and we will support a practice making its own notifications.
15How long we keep information
| Information | Kept for |
|---|---|
| Referral records, documents and messages | As long as the practice maintains its workspace. On termination, returned or deleted at the practice's direction |
| Text message opt out records | Indefinitely. Deleting one would allow a number that asked not to be contacted to be contacted again |
| Account and audit records | The life of the account, then a reasonable period for legal, security and accounting purposes |
| Billing records | As long as tax and accounting law requires |
| Technical logs | A short operational period, then deleted or aggregated |
| Website analytics | Aggregate or pseudonymous form only |
We may retain information longer where we must to comply with law, resolve disputes or enforce our agreements. Backups are deleted on their own cycle after a record is removed from the live service.
16Your rights and choices
Depending on where you live, you may have the right to know what personal information we hold, to obtain a copy in a portable form, to correct it, to delete it, to limit the use of sensitive personal information, to withdraw consent, to opt out of sale, sharing or profiling, and to appeal a decision we make. We will not discriminate against you for exercising any of these rights, and we will never require you to create an account to make a request.
Patients
Your referral record belongs to your practice, not to us. Requests to see, correct or delete it should go to the practice that arranged your care, and we will support them in answering you. You can stop text messages at any time by replying STOP, without contacting anybody.
Practice users
You can review and update your account details inside the application, or contact us using the details in section 21.
California
California residents have rights under the California Consumer Privacy Act as amended, including rights to know, access, delete, correct, opt out of sale and sharing, and limit the use of sensitive personal information. Section 4 sets out the categories we collect, section 5 the sources, section 6 the purposes and section 10 the recipients. We do not sell or share personal information as those terms are defined. Medical information governed by HIPAA, and information we process as a business associate, is exempt from that Act and is handled under the Business Associate Agreement instead.
Washington
Washington's My Health My Data Act gives Washington consumers rights over consumer health data, including the right to confirm whether we collect it, to withdraw consent, and to have it deleted. Protected health information held under HIPAA, and information we process as a business associate, falls outside that Act and is governed by the Business Associate Agreement. For anything outside that boundary you can exercise these rights using the details in section 21, and you may appeal if we decline.
Other states
Residents of states with comprehensive privacy laws, including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky and Rhode Island, have comparable rights under their own laws. We extend the rights described in this section to every United States resident regardless of state, so you do not need to work out whether your state has a law yet. Nevada residents may direct us not to sell their information; we do not sell it in any event.
Authorized agents
You may use an authorized agent to make a request. We will ask for written proof of the agent's authority and may still ask you to verify your own identity directly.
How to make a request, and what happens next
Write to [email protected]. We will acknowledge your request, verify your identity in proportion to the sensitivity of what you have asked for, and respond within forty five days, extending once by a further forty five days where the request is complex and telling you if we do. There is no charge unless a request is manifestly unfounded or excessive, in which case we will tell you before doing anything. If we decline, we will say why, and you may appeal by replying to our response; we will answer an appeal within sixty days and tell you how to contact your state attorney general if you remain unsatisfied.
17Children
Cync is a tool for healthcare practices and is not directed at children. We do not knowingly collect personal information directly from children, and this website is not intended for them. A practice may manage a referral for a patient who is a minor, in which case that information is part of the practice's record, is handled under the Business Associate Agreement, and requests about it should go to the practice or the child's parent or guardian through the practice.
18Where information is held
We store and process information in the United States, and our service providers do the same for the information they handle for us. Cync is not offered outside the United States. If you contact us from elsewhere, your information will be transferred to and handled in the United States.
19Links to other sites
This website and the application may link to sites we do not control. We are not responsible for their content or their privacy practices, and this policy does not apply to them.
20Changes to this policy
We may update this policy. The date at the top shows when it last changed. Where a change materially affects how we handle information, we will notify practice administrators before it takes effect and, where the law requires, obtain consent. Prior versions are available on request.
21Contact us
Cync is a product of Hyper Expert, LLC.
Hyper Expert, LLC
600 1st Ave, STE 100
Seattle, WA 98104
United States
Patients: the fastest way to stop text messages is to reply STOP to any message. For anything about your medical record, contact the practice that arranged your care.