Privacy Policy

Effective Date: September 28, 2026 

THE SITE IS INTENDED FOR INDIVIDUALS LOCATED IN THE UNITED STATES. IT IS NOT INTENDED FOR INDIVIDUALS LOCATED IN OTHER COUNTRIES.

Proven Software, Inc. (“Proven,” “we,” “us,” or “our”) respects your privacy and is committed to protecting personal information.

This Privacy Policy explains how we collect, use, and protect information when you interact with our website and services.

This Privacy Policy (the “Policy”) describes our online and offline practices regarding your personal information and the rights you have regarding your personal information. We collect and process personal information online via our website (the “Site”) and via our social media channels. Except as described in the “Proven EHR Mobile App” section below, this policy does not apply to employment-related information or information that we host on behalf of our customers. When we are providing services for a “Covered Entity” customer (for example, a health care provider) under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), we act as a “Business Associate,” and we use and disclose Protected Health Information (“PHI”) only as permitted or required under applicable law and our Business Associate Agreements. The Covered Entity’s notice of privacy practices describes and controls how we use and disclose PHI.

Information we collect

Information You Provide

We may collect information when you submit contact forms, request product demonstrations, create an account, log into the platform and/or communicate with us.

This information may include your name, role/title, email address, organization, phone number and/or login credentials.

Automatically Collected Information

When you visit our Website we may automatically collect your IP address, browser type, device information, pages visited and/or referring URLs.

This data helps improve performance and usability.

How We Use Information

We may use collected information to operate and maintain our Website, respond to inquiries and demo requests, provide and support our services, improve functionality and security, analyze website usage and comply with legal obligations.

Healthcare data and HIPAA

The Website is not intended for submission of Protected Health Information (PHI).

Healthcare information processed within the Proven platform is governed by:

  • HIPAA requirements
  • customer agreements
  • Business Associate Agreements (BAAs)
  • Business Services Agreements (BSAs)

Proven EHR Mobile App

This section applies to the Proven EHR mobile app for iPhone and Android devices (the “App”). It adds to the rest of this Policy. If anything in this section differs from the rest of the Policy, this section controls the App.

Who uses the App. The App is used by employees and other authorized staff of health care organizations that use Proven EHR (“Customers”). Your organization creates and manages your account; you can’t create an account in the App. You must be 18 or older to use the App.

How the App relates to HIPAA. Most information in the App is information we host on behalf of Customers, including patients’ Protected Health Information (“PHI”). We handle it as the Customer’s Business Associate, as described above, and the Customer controls it. This section explains what the App collects and how that information is handled.

Information the App collects

  • Account and sign-in information: your name, work email address, employee ID and organization; your password, which we store only in hashed form; your sign-in method, such as an authenticator app or a phone number for text-message codes; and a record of your sign-ins (date, time, IP address and the device or browser used).
  • Patient and health information: the information you view, enter or capture about patients, such as demographics, contact and insurance details, visit records, clinical notes, forms, treatment plans and signatures. In the App’s kiosk mode, a patient or their representative can also complete forms and sign documents on your device.
  • Location, only while you are using the App:
    • your precise location when you check in to, check out of or submit a visit that your organization verifies (electronic visit verification), and when you record mileage;
    • your approximate location, rounded to about 100 meters, if you turn on location sharing with your team; and
    • your location while the App shows the drive time to an upcoming visit, if your organization turns that feature on.
    • The App does not collect your location in the background.
  • Audio: recordings you choose to make, such as dictated voice notes and, if your organization turns it on, ambient scribe recordings of a visit. A scribe recording continues while your screen is locked, until you stop it.
  • Photos: photos you take or choose, such as insurance cards and documents. The App can access only the photos you select.
  • Messages: chat messages you send to and receive from colleagues.
  • Device information: an identifier the App creates for your installation, your device’s name, your platform (iOS or Android), the App version and, if notifications are turned on, a push notification token.
  • Diagnostics: if you send a problem report, your description, your device model, operating system and App version, and recent entries from the App’s diagnostic log (you can leave the log out).
  • Activity records: as HIPAA requires, which patient records you view, create or change, and when.

The App does not access your contacts or calendar, does not use advertising identifiers, and does not show ads or contain third-party advertising, analytics or tracking software. Face ID, Touch ID and fingerprint checks happen on your device, and the App never receives your biometric data. The App’s unlock PIN never leaves your device.

How the App uses information

We use this information to:

  • provide the App’s features to you and your organization, such as documentation, scheduling, visit verification, mileage, messaging and working offline;
  • secure your account and device, including multi-factor sign-in, the app lock and remote wipe;
  • provide the optional AI features described below;
  • provide support;
  • keep the audit records HIPAA requires;
  • measure how features are used, so we can operate and improve our services; and
  • comply with the law.

AI features

If your organization turns them on, the App’s AI features transcribe voice notes and visit recordings, draft notes and summaries, and answer questions about a patient’s chart. A clinician reviews AI output before relying on it. Recordings and chart information go from the App to our servers, and then to our AI service providers. Those providers process them under agreements, including Business Associate Agreements, that restrict their use of the information to providing services to us. As stated above, Proven does not train AI models using customer or patient data.

Who we share information with

  • Your organization. It controls the information and can see your account, activity, visit locations, mileage, messages and, if you turn location sharing on, your shared location.
  • Our service providers. They process information only on our behalf. Our contracts with them, including Business Associate Agreements where they handle PHI, require them to protect it at least as well as this Policy describes. They are Microsoft Azure (hosting and storage, maps and drive times, document reading, email, text messages, chat and push notifications), Deepgram (speech-to-text), OpenAI and Amazon Web Services (AI features), and Apple and Google (delivering push notifications).
  • Other organizations your organization connects to Proven EHR, such as e-prescribing services and insurance payers, at your organization’s direction.
  • Government authorities or others, when the law requires it and HIPAA permits it.

We do not sell personal information or share it for advertising. When you choose to get directions or call a phone number, the App opens your device’s maps or phone app, and that app’s own privacy policy applies.

How the App protects information

  • Information the App stores on your device is encrypted, and the keys are held in your device’s secure storage.
  • The App requires a 6-digit PIN (you can also use Face ID, Touch ID or a fingerprint), locks after a period of inactivity and hides its contents in the app switcher.
  • The App connects only to Proven’s servers, over encrypted connections.
  • Sign-in requires multi-factor authentication, apart from limited exceptions approved by an administrator.
  • Your organization can turn off your mobile access and remotely wipe the App’s data from your device.

How long information is kept, and how to delete it

  • On your device: The App keeps some information so you can work offline. Information about patients who are no longer on your schedule is removed automatically, unless you starred them or still have unsent work for them. Signing out ends your session but does not remove information already stored in the App. Deleting the App removes it, and your organization can also wipe it remotely.
  • On our servers: Information your organization keeps in Proven EHR is kept while its agreement with us is in effect, and then returned or deleted as that agreement requires. Visit recordings are deleted once the transcript and note are created, unless your organization chooses to keep them. Turning off location sharing erases your shared location. Sign-in and audit records are kept as long as needed for security and legal purposes.
  • Requesting deletion: To delete your account or your personal information, contact your organization’s administrator or email us at partners@provensoftware.com. We will delete or de-identify the information we aren’t required to keep by law, by HIPAA or under our agreements with your organization.

Your choices

You can allow or deny the App’s access to your location, microphone, camera, photos and notifications at any time in your device settings, and you can turn location sharing on or off in the App. If you deny a permission, the features that need it won’t work. Each time you send a problem report, you can choose whether to include diagnostic logs.

Questions about the App

Email partners@provensoftware.com.

Eligibility

Our Site and services are not directed to children under the age of 13, and we do not knowingly collect information online from children under the age of 13. No one under the age of 13 may access, browse, or use the Site or provide any information to us online. If we learn that we have collected or received personal information from a child under the age of 13 online without a parent’s or legal guardian’s consent, we will take steps to stop collecting that information and to delete it. If you believe we have received any information from a child under the age of 13 online, please contact us using the “Contact Us” details provided at the end of this Policy.

For information about the Children’s Online Privacy Protection Act, please visit the Federal Trade Commission’s website.

Artificial intelligence and data use

Proven’s platform may include artificial intelligence features designed to support healthcare workflows.

Proven does not train AI models using customer or patient data.

Customer data remains under the control of the healthcare organization using the platform.

Cookies and analytics

What are cookies?

Cookies are small text files that are used to store small pieces of information. They are stored on your device when the website is loaded on your browser. These cookies help us make the website function properly, make it more secure, provide better user experience, and understand how the website performs and to analyze what works and where it needs improvement.

How do we use cookies?

As most of the online services, our website uses first-party and third-party cookies for several purposes. First-party cookies are mostly necessary for the website to function the right way, and they do not collect any of your personally identifiable data.

The third-party cookies used on our website are mainly for understanding how the website performs, how you interact with our website, keeping our services secure, providing advertisements that are relevant to you, and all in all providing you with a better and improved user experience and help speed up your future interactions with our website.

Sharing of information

We do not sell personal information.

Proven may engage trusted third-party service providers to support website operations, infrastructure, analytics, and service delivery. These providers are contractually obligated to protect the confidentiality and security of information processed on our behalf.

Information may be shared with service providers supporting website operations, analytics providers and/or legal authorities when required by law.

Data security

We implement administrative, technical, and physical safeguards designed to protect personal information. From time to time, we review our security procedures and consider new technologies and methods.

But, no security system is perfect, and no data transmission is 100% secure. Although we strive to protect personal information, we cannot guarantee or warrant the security of any information transmitted to or from the Site. Your use of the Site is at your own risk. We cannot guarantee that your data will remain secure in all circumstances.

The safety and security of your personal information also depends on you. Where you use a password for access to restricted parts of the Site, you are responsible for keeping the password confidential. Do not share your password with anyone.

If a data breach compromises your personal information, we will notify you and any applicable regulator when we are required to do so by applicable law.

Data retention

We retain personal information only as long as necessary to, provide services, comply with legal obligations, resolve disputes and/or enforce agreements.

Children’s privacy

Our Site and services are not directed to children under the age of 13, and we do not knowingly collect information online from children under the age of 13. No one under the age of 13 may access, browse, or use the Site or provide any information to us online. If we learn that we have collected or received personal information from a child under the age of 13 online without a parent’s or legal guardian’s consent, we will take steps to stop collecting that information and to delete it. If you believe we have received any information from a child under the age of 13 online, please contact us using the “Contact Us” details provided at the end of this Policy.

For information about the Children’s Online Privacy Protection Act, please visit the Federal Trade Commission’s website.

Changes to this policy

We may update this Privacy Policy periodically. Updates will be posted with a revised effective date.

Contact

Privacy inquiries may be directed to partners@provensoftware.com