Privacy Policy and Notice of Privacy Practices
Version 1.2. Effective July 15, 2026. Last updated July 15, 2026.
Who we are
Scriptura Health LLC (Scriptura, we, us, our) is a Texas limited liability company. We operate a clinical decision support platform that helps licensed prescribers and their authorized staff generate, review, and deliver personalized care protocols. Our founder and the person responsible for privacy questions is John Murray. This policy describes how we collect, use, protect, and share personal information and protected health information (PHI) when you visit our public website or use our platform. It also serves as the Notice of Privacy Practices required by the Health Insurance Portability and Accountability Act (HIPAA) when we operate as a business associate to a covered entity practice. You can reach us at any time at privacy@scriptura.health.
Our role and yours
When a licensed clinic or practitioner engages Scriptura, that clinic is the covered entity under HIPAA. Scriptura is a business associate. The clinic sets the direction for how patient data is used. Scriptura provides the technology and follows the clinic instructions and the business associate agreement (BAA) that governs the relationship. Patients seeking their own records should first contact their clinic. If you are a patient using our patient portal, the clinic that invited you controls your record.
Information we collect
We collect four kinds of information.
- Account information. Name, email address, professional role, and license number for practitioners and their delegated staff. Practitioners provide this when they apply, are invited to a clinic, or complete onboarding.
- Patient records (PHI). Demographic details, clinical intake responses, laboratory results, and the protocol requests a prescriber makes along with the protocol responses the platform returns. Patients provide this by answering the intake or by uploading records, and clinics provide it when they add a patient to their roster.
- Device and log data. Device and browser details, IP address, and timestamps of actions on the platform. We collect this to run the service, keep audit logs, and defend against abuse.
- Cookies. We use a small number of strictly necessary cookies to keep you signed in and to protect the service. We do not run behavioral advertising trackers on any page that handles PHI, and we do not sell any of this information.
Our legal basis
We process PHI as a business associate under HIPAA, specifically the Security Rule and the Privacy Rule obligations that apply to business associates at 45 CFR Part 164 Subpart C. The second basis is contract: we act on the written instructions of the clinician's clinic under the BAA between that clinic and Scriptura. We do not process PHI for any purpose outside those instructions and our legal obligations.
How we use information
We use the information you and your clinic provide to run the service you asked for. That includes:
- Providing clinical decision support: generating and delivering care protocols requested by a licensed prescriber, and storing patient intake, laboratory results, and protocol history so the treating clinic can review them.
- Keeping the platform secure and reliable, including sign-in, multi-factor authentication, audit logging, and abuse prevention.
- Sending transactional email tied to your account and your clinic, such as invites, sign-in verification, and protocol notifications.
- Making disclosures required by law, including responses to lawful requests and reporting obligations under state and federal law.
We do not use PHI to train external artificial intelligence models. We do not sell PHI. We do not share PHI for advertising.
Sub-processors
We use a small set of vendors, called sub-processors, to run the platform. Each sub-processor that can handle PHI is under a signed business associate agreement with us and is contractually restricted to processing data on our behalf. The current list is:
- Amazon Web Services (US East 2 region). Hosting and compute (ECS Fargate), database backups (S3), and object storage for uploaded files. This is our primary infrastructure.
- AWS Cognito. Sign-in and multi-factor authentication for practitioner and patient accounts.
- Sentry. Error and performance monitoring. Data sent to Sentry is scrubbed of PHI before it leaves our servers.
- Fly.io. Hosts the Sequence Method decision support engine that produces protocol recommendations.
- AWS RDS. Managed Postgres database that stores practitioner and patient records.
- A large language model provider (for example Anthropic, OpenAI, or an equivalent). No PHI leaves the engine layer. Only structured feature vectors, which do not identify a patient, are sent to the language model provider.
How the Sequence Method uses artificial intelligence
The Sequence Method is a clinician-facing decision support tool. It is not a diagnostic device. It does not diagnose, prescribe, or make a care decision on its own. Every output the Sequence Method produces is reviewed by the ordering clinician before it reaches a patient. The clinician is responsible for the final care decision. As noted in the sub-processor list, patient-identifying information never leaves the engine layer: only structured feature vectors reach any external language model.
When we share information, and with whom
Apart from the sub-processors above, we share information only when the clinic that controls the record directs us to, or when we are required by law. The categories of recipients are:
- The clinic that controls your record. The treating clinic and its authorized staff can view and export records for patients on its roster. Patients can request access to their own records through the patient portal or by contacting their clinic.
- Law enforcement and regulators. We disclose information when required by valid legal process or when we believe in good faith that disclosure is necessary to prevent imminent harm. Where the law permits, we notify the affected clinic before making the disclosure.
- A successor entity. If Scriptura is acquired or merges with another company, information may transfer to the successor, subject to this policy and any BAAs then in force.
How we protect information
- We encrypt data in transit using TLS version 1.2 or higher.
- We encrypt stored data at rest, including database storage and object storage.
- Multi-factor authentication is available on every account, and a clinic can require it for its staff.
- We keep an append-only audit log of access to patient data, so every read and write to a per-patient record is recorded.
- We enforce tenant isolation so a practitioner in one clinic cannot see records belonging to another clinic.
- We hold a HIPAA business associate agreement with each sub-processor that can handle PHI.
An honest note on our current stage
Scriptura is pre-production. We describe our controls plainly and we do not claim certifications we do not hold. We have not completed a SOC 2 audit. We do not hold HITRUST certification. We have not yet had a third-party penetration test. We will update this page when any of these change, and we report our security posture to each clinic under contract.
Your rights
When Scriptura acts as a business associate, patients have the right to access a copy of their record, to ask that inaccurate information be corrected, and to ask that information be deleted, subject to the clinic's legal retention duties. To support these rights, the platform gives the treating clinic tools to export a single patient's record as a structured, machine-readable file and to erase a patient's record on request. Both actions are limited to the clinic that controls the record and are written to the append-only audit log. These rights are exercised through the ordering clinic that controls your record. You can start any request by contacting your clinic, or by contacting us at privacy@scriptura.health and we will route the request to the correct clinic. If you believe your privacy rights have been violated, you can also file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights. We will not retaliate against anyone for filing a complaint.
California residents
Medical information held by a HIPAA business associate is largely exempt from the California Consumer Privacy Act, because it is already covered by HIPAA and the California Confidentiality of Medical Information Act. For the limited account and website information that is not PHI, California residents have the right to know what personal information we collect, to request access to it, to request deletion, and not to be discriminated against for exercising these rights. We do not sell personal information and we do not share it for cross-context behavioral advertising. Send California requests to privacy@scriptura.health.
Texas residents
Scriptura is based in Texas. Under the Texas Data Privacy and Security Act, Texas residents have the right to confirm whether we process their personal information, to access and correct it, to request deletion, and to appeal a decision we make about a request. Protected health information handled under HIPAA is exempt from that law, so these rights apply to the account and website information that is not PHI. Send Texas requests to privacy@scriptura.health and we will respond within the time the law allows.
Data retention
We keep patient records until the treating clinic terminates its account, and for any additional minimum period required by state and federal law. Audit logs are retained for at least six years, as required by HIPAA. When a clinic terminates its agreement with us, we follow the return or destruction procedure in the BAA. Deleted records are removed from active systems immediately and from backups within the backup rotation window.
Children
Our platform is used by licensed prescribers and their patients. Patient records may include pediatric patients when the treating clinic is authorized to care for them. We do not knowingly operate a service directly with children. If a minor uses the patient portal, they do so through a treating clinic that has obtained the appropriate parental or guardian consent.
International users
Our infrastructure runs in the United States. If you access the platform from outside the United States, your information will be transferred to and processed in the United States, subject to this policy.
Changes to this policy
We may update this policy. When we make a material change we will update the version number and the dates at the top of the page. If the change affects how we use PHI, or changes the sub-processor list, we will also notify the clinics that use the platform so they can inform their patients. Prior versions are available on request.
How to reach us
Privacy questions: privacy@scriptura.health
Scriptura Health LLC, a Texas limited liability company. Attention: John Murray.