Skip to content
NNotiva
Log in

Legal

Privacy Policy

Notiva sells software to medical practices. This policy explains what we collect from visitors and customers — and, just as importantly, how patient information is handled under a different set of rules.

Effective August 12, 2026

The short version

  • This website sets no cookies and carries no advertising or cross-site tracking. Our host counts page views and load times without storing anything on your device.
  • The only personal information the website collects is what you type into the request-access form.
  • Patient information never passes through this website. Inside the Notiva application it is handled as a HIPAA Business Associate, under a signed agreement with your practice.
  • We do not sell personal information, and we never use patient data to train AI models.

1. Who this policy covers

Notiva, Inc. (“Notiva,” “we,” “us”) provides clinical documentation software to medical practices. This policy applies to notivamed.com and to the Notiva application at app.notivamed.com.

It does not govern patient health information. When a practice uses Notiva, we act as a Business Associateunder HIPAA: we handle protected health information (PHI) only on that practice's instructions, under a signed Business Associate Agreement (BAA). That relationship — not this policy — determines how PHI is used and disclosed.

If you are a patient and want to know how your health information is used, or want to exercise a HIPAA right such as access or amendment, contact your medical practice. Their Notice of Privacy Practices governs, and we support their requests rather than acting on our own.

2. The website

We deliberately kept this site plain. It sets no cookies, carries no advertising or social media tracking tags, and records no sessions. Typefaces are served from our own domain rather than a font CDN.

The one measurement we keep is the web analytics built into Cloudflare, our hosting provider: how many people viewed a page, roughly where in the world they were, and how quickly the page loaded. It is cookieless — it stores nothing on your device and uses no identifier that follows you between visits or across other sites. The small script that reports it is served by Cloudflare. Because nothing here sets a cookie or tracks you across sites, there is no cookie banner to dismiss.

Request early access

If you fill in the request-access form, we receive what you enter: practice name, your name, your email address, the number of physicians in your practice, which EHR you use, and any optional notes. It is delivered to an internal team notification channel and used for one purpose — to contact you about Notiva. We do not sell it, rent it, or add it to an advertising audience.

Please do not include patient information in that form. It is a sales enquiry channel, not a secure route for PHI.

Server logs

Our website host processes each request and keeps standard operational logs — IP address, timestamp, requested path, and user agent — to serve the page, keep the site available, and defend against abuse. These logs are not used to build a profile of you.

3. The application

This section applies to clinicians and staff at customer practices who sign in to Notiva.

  • Account information. Name, work email, role, and practice membership. Sign-in and multi-factor authentication are handled through Google Identity Platform.
  • Strictly necessary cookies. The application sets a signed session cookie so you stay logged in, and applies an idle timeout. There are no advertising or cross-site tracking cookies.
  • Product analytics. We run our own analytics software on our own infrastructure — no third-party analytics vendor receives anything. Events are limited to a fixed, reviewed list of names and enumerated properties: no patient identifiers, no free text, and no note content. IP addresses are not stored, and session replay and heatmap features are disabled.
  • Audit records. HIPAA requires us to record who accessed what, and when. Audit entries reference patients by an internal surrogate identifier — never by name, medical record number, or date of birth.

4. Patient information

Notiva reads patient data from your EHR through SMART-on-FHIR and stores the clinical notes your clinicians compose. We do this as your Business Associate, at your direction. Our commitments:

  • Minimum necessary. We request the narrowest EHR permissions a feature needs and fetch only the fields it uses. There is no speculative caching of whole charts.
  • Encrypted throughout. TLS 1.2 or better for every connection carrying PHI, and encryption at rest. Note text and EHR tokens are additionally wrapped with keys held in a managed key service.
  • Never used to train models.Patient data is not used to train or fine-tune any AI or machine-learning model, ours or anyone else's.
  • Never sold, never advertised against. We do not sell PHI, share it for advertising, or disclose it except as your BAA permits or the law requires.
  • No vendor without an agreement. No third party receives PHI unless it has signed a BAA with us first.
  • Access is enforced and logged. The server checks on every request that the clinician is permitted to see that patient, and writes an audit record.

5. Service providers

We keep this list short on purpose. Every vendor that could come into contact with patient data has a signed BAA in place before it is used.

ProviderWhat it doesPatient data?
Google CloudApplication hosting, identity and sign-in, secret and encryption-key managementYes — under BAA
NeonManaged PostgreSQL databaseYes — under BAA
CloudflareHosting and delivery of notivamed.com, and cookieless traffic measurementNo
SlackInternal notification of request-access submissionsNo

Your EHR vendor is not our subcontractor. It acts on behalf of your practice, and our access to it is governed by the agreement between your practice and Notiva.

6. How long we keep things

  • Request-access submissions — while we are in contact with you and for a reasonable period afterwards. Ask us and we will delete them.
  • Website server logs — a short operational retention window set by our host.
  • Customer account records — for the term of the agreement with the practice, plus any period the agreement requires.
  • Patient information — as directed by the practice and its BAA, including return or destruction at termination where feasible. HIPAA audit records are retained for at least six years.

7. Security

Notiva is built around a written HIPAA compliance program with a named Security Officer. In practice that means encryption in transit and at rest, multi-factor authentication for administrative access, least-privilege credentials, server-side authorization on every request that touches patient data, separated production and development environments, and audit logging that cannot be quietly switched off. No system is perfectly secure, but we will tell you plainly if something goes wrong: our agreements commit us to breach notification, and we maintain an incident response process.

8. Your choices

  • Contact information. Email us to see, correct, or delete what you have sent us through this website.
  • Email from us. Reply and ask to be removed, and we will stop.
  • Health information. Requests for access, amendment, restriction, or an accounting of disclosures go through your practice as the covered entity. We will assist them.

9. State privacy rights

We do not sell personal information, and we do not share it for cross-context behavioral advertising — we run no advertising technology at all. Depending on where you live, you may have rights to access, correct, delete, or port the personal information we hold, and to appeal a decision. Email us and we will honor those rights without charging you or treating you differently for asking. Note that information we hold as a Business Associate under HIPAA is generally exempt from these state laws and is handled through your practice instead.

10. Children

This website and the Notiva application are for healthcare professionals and practice staff. We do not knowingly collect personal information from children through this website. Patient records handled inside the application may of course relate to patients of any age; that information is governed by the practice's BAA and HIPAA, not by this section.

11. Changes to this policy

If this policy changes we will post the new version here and update the effective date above. Where a change materially affects how we handle customer or patient information, we will notify affected practices directly rather than relying on you to notice.

12. Contact us

Privacy and security questions reach a real person — Notiva's Security Officer, Max Rice.

Notiva, Inc.
hello@notivamed.com
6970 S Red Barn Road
South Weber, Utah 84405

NNotiva
A note writer for private practice OB/GYNs. Close the chart in the room.
How it worksNot a templateFAQ
hello@notivamed.com
© 2026 Notiva, Inc.
PrivacyTerms