1.Introduction and Scope
Virtu Medical ("Virtu Medical," "we," "us," or "our") is a United States–based healthcare technology company committed to protecting the privacy, confidentiality, and integrity of all personal information, including Protected Health Information ("PHI"), collected, processed, stored, or transmitted through our software products and services.
This Privacy Policy applies to the following Virtu Medical platforms:
- VirtuCares EHR — an Electronic Health Records system designed for healthcare providers and their patients.
- Virtu Analytica — an analytics and business intelligence platform that processes health data on behalf of covered entity clients.
This Policy governs our collection, use, disclosure, and protection of information relating to patients, authorized users, and visitors. It has been designed to comply with applicable United States federal and state privacy laws, including the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), the Health Information Technology for Economic and Clinical Health Act ("HITECH"), and applicable state privacy statutes.
By accessing or using our platforms, you acknowledge that you have read, understood, and agree to the terms of this Privacy Policy.
2.Definitions
For purposes of this Privacy Policy, the following terms have the meanings set forth below:
- Protected Health Information (PHI): Individually identifiable health information created, received, maintained, or transmitted by a Covered Entity or Business Associate, as defined under 45 C.F.R. § 160.103.
- Electronic Protected Health Information (ePHI): PHI that is created, stored, transmitted, or received in electronic form.
- Covered Entity: A healthcare provider, health plan, or healthcare clearinghouse that transmits health information in electronic form in connection with a HIPAA-covered transaction.
- Business Associate: A person or entity that performs functions or activities on behalf of a Covered Entity that involve the use or disclosure of PHI.
- Authorized User: A licensed healthcare professional, administrator, or staff member granted access to the Virtu Medical platforms by an authorized Covered Entity.
- Patient: An individual whose health information is collected, stored, or processed through the Virtu Medical platforms.
- De-identified Data: Health information from which all 18 HIPAA identifiers have been removed in accordance with 45 C.F.R. § 164.514(b).
3.Information We Collect
3.1 Patient Health Information
Through the VirtuCares EHR and Virtu Analytica platforms, we collect and process the following categories of patient information, exclusively on behalf of and as directed by Covered Entity clients:
- Demographic information: full name, date of birth, gender, address, contact information, and national identifiers.
- Clinical information: diagnoses (ICD-10 coded), medications, allergies, laboratory results, vital signs, immunization records, and clinical notes.
- Insurance and billing information: health plan identifiers, member IDs, and coverage details.
- Encounter and visit records: dates of service, treating providers, facility identifiers, and care episode summaries.
- Behavioral and mental health information: screening assessment results, risk scores, and referral records.
- Substance use information: screening results and treatment program enrollment records.
3.2 Authorized User Account Information
We collect the following information from Authorized Users who access our platforms:
- Full name, professional credentials, and job title.
- Work email address and contact information.
- Authentication credentials (stored in hashed form; plaintext passwords are never stored).
- Access logs, session timestamps, and audit trail records.
- Role-based access configuration and permission assignments.
3.3 Technical and Usage Data
We automatically collect certain technical data when Authorized Users access our platforms:
- IP addresses and device identifiers.
- Browser type, operating system, and session metadata.
- Application access logs and audit events.
- Error reports and performance diagnostic data.
3.4 Information We Do Not Collect
Virtu Medical does not collect the following:
- Payment card numbers or financial account credentials (payment processing is handled by compliant third-party processors).
- Social media data or third-party advertising identifiers.
- PHI from individuals who are not patients of Covered Entity clients.
4.How We Use Information
4.1 PHI — Use Limited to Client Directives
Virtu Medical acts as a Business Associate with respect to PHI. We use PHI solely as directed by our Covered Entity clients and as permitted under applicable Business Associate Agreements ("BAAs") and HIPAA. Permissible purposes include:
- Treatment: Facilitating the provision of clinical care by authorized healthcare providers.
- Healthcare operations: Supporting quality improvement, care coordination, and population health analytics.
- Payment: Processing billing and claims information on behalf of clients.
- Legal compliance: Disclosing PHI as required by applicable law, court order, or regulatory mandate.
4.2 Authorized User Data — Operational Purposes
We use Authorized User information for the following operational purposes:
- Authenticating users and enforcing role-based access controls.
- Generating audit trails and access logs required for HIPAA compliance.
- Providing technical support and platform maintenance.
- Communicating service updates, security advisories, and policy changes.
4.3 Technical Data — Platform Improvement
Technical and usage data is used solely for:
- Monitoring platform availability, performance, and security.
- Detecting, investigating, and responding to security incidents.
- Improving system reliability and user experience in aggregate, anonymized form.
5.Disclosure of Information
5.1 Disclosures Permitted Under HIPAA
As a Business Associate, Virtu Medical may disclose PHI only in the following circumstances:
- As directed in writing by the Covered Entity client.
- As required to fulfill our obligations under a signed BAA.
- As required by applicable law, including disclosures to public health authorities, law enforcement (with appropriate legal process), or in response to a court order.
- In connection with the patient's treatment, where disclosure has been authorized by the Covered Entity.
5.2 Service Providers and Subcontractors
We engage third-party service providers ("Subcontractors") who may access PHI or ePHI solely to support our platform operations. All Subcontractors with access to PHI are required to execute a Business Associate Agreement and are contractually obligated to implement equivalent privacy and security safeguards. Current categories of Subcontractors include:
- Cloud infrastructure and hosting providers (e.g., Microsoft Azure).
- Identity and authentication providers.
- Audit logging and security monitoring services.
5.3 Disclosures We Will Never Make
6.Data Security
6.1 Administrative Safeguards
- A comprehensive HIPAA Security Program with designated Security Officer and Privacy Officer roles.
- Role-based access control (RBAC) enforcing minimum necessary access standards.
- Mandatory workforce training on privacy and security policies prior to system access.
- Background screening procedures for personnel with access to PHI.
- Business Associate Agreements with all Subcontractors handling PHI.
- Incident response and breach notification procedures aligned with 45 C.F.R. §§ 164.400–164.414.
6.2 Technical Safeguards
- Encryption of ePHI in transit using TLS 1.2 or higher.
- Encryption of ePHI at rest using AES-256 or equivalent industry-standard encryption.
- Multi-factor authentication (MFA) required for all Authorized User access.
- Automated session timeouts and idle session termination.
- Comprehensive audit logging of all access, modification, and disclosure events.
- Intrusion detection systems and continuous security monitoring.
- Vulnerability management program including regular penetration testing.
6.3 Physical Safeguards
- Hosting on SOC 2 Type II certified cloud infrastructure with physical access controls.
- No on-premises storage of ePHI on portable or removable media without encryption.
- Workstation use policies restricting access to ePHI on authorized devices only.
6.4 SOC 2 Compliance
Virtu Medical is actively pursuing SOC 2 Type II certification covering the Trust Services Criteria for Security, Availability, and Confidentiality. Upon certification, audit reports will be available to clients under NDA upon written request.
7.Patient Rights Under HIPAA
As a Business Associate, Virtu Medical supports Covered Entities in fulfilling their obligations to patients under the HIPAA Privacy Rule (45 C.F.R. Part 164, Subpart E). Patients have the following rights with respect to their PHI, which must be exercised directly with the Covered Entity:
- Right of Access: Patients have the right to inspect and obtain a copy of their PHI maintained in a designated record set. (45 C.F.R. § 164.524)
- Right to Amend: Patients may request amendments to their PHI if they believe the information is inaccurate or incomplete. (45 C.F.R. § 164.526)
- Right to an Accounting of Disclosures: Patients may request a list of disclosures of their PHI made by the Covered Entity during the prior six years. (45 C.F.R. § 164.528)
- Right to Request Restrictions: Patients may request restrictions on certain uses and disclosures of their PHI. (45 C.F.R. § 164.522)
- Right to Confidential Communications: Patients may request that communications about their PHI be made through alternative means or at alternative locations. (45 C.F.R. § 164.522)
- Right to a Notice of Privacy Practices: Patients have the right to receive a Notice of Privacy Practices from their Covered Entity describing how PHI is used and disclosed.
To exercise any of the above rights, patients must contact the Covered Entity (their healthcare provider) directly. Virtu Medical will cooperate with Covered Entities in facilitating these requests in accordance with applicable BAAs and regulatory requirements.
8.Data Retention and Destruction
8.1 Retention Periods
- PHI and ePHI: Retained for the period specified in the applicable BAA, or as required by federal and state law. Where no client contract specifies a retention period, PHI is retained for a minimum of six (6) years from the date of creation or the date when the record was last in effect, consistent with HIPAA requirements.
- Audit logs and access records: Retained for a minimum of six (6) years to support HIPAA compliance and audit purposes.
- Authorized User data: Retained for the duration of the engagement and for a minimum of three (3) years following termination of the relationship.
8.2 Secure Destruction
Upon expiration of applicable retention periods or upon written request from a Covered Entity following contract termination, Virtu Medical will destroy PHI and ePHI using methods that render the data unreadable and indecipherable, in accordance with NIST SP 800-88 guidelines. A certificate of destruction will be provided upon request.
9.Breach Notification
In the event of a Security Incident or Breach of Unsecured PHI as defined under 45 C.F.R. § 164.402, Virtu Medical will:
- Notify the applicable Covered Entity of a confirmed breach without unreasonable delay, and in no event later than sixty (60) calendar days following discovery of the breach, consistent with 45 C.F.R. § 164.410.
- Provide the Covered Entity with all information required to fulfill its own breach notification obligations to affected patients and the U.S. Department of Health and Human Services (HHS).
- Cooperate fully with the Covered Entity's investigation and remediation efforts.
- Implement corrective measures to prevent recurrence of the incident.
Virtu Medical maintains a documented Incident Response Plan that is tested and reviewed annually. Suspected security incidents or breaches should be reported immediately to security@virtumedical.com.
10.Cookies and Tracking Technologies
Our platforms use limited session-based technologies strictly for operational purposes:
- Session cookies: Required to maintain authenticated user sessions. These cookies are not used for advertising or cross-site tracking and expire upon browser closure or session timeout.
- Security tokens: Used for CSRF protection and authentication integrity.
Virtu Medical does not use third-party advertising trackers, behavioral analytics cookies, or fingerprinting technologies. Our platforms are not designed for use by individuals under the age of 18 and we do not knowingly collect data from minors outside of a clinical care context authorized by a Covered Entity.
11.Third-Party Links and Integrations
Our platforms may integrate with or link to third-party systems (including but not limited to laboratory information systems, state immunization registries, and interoperability endpoints). These integrations are executed pursuant to data exchange agreements and applicable regulatory requirements. Virtu Medical is not responsible for the privacy practices of third-party systems accessed outside of our platforms. Users should review the privacy policies of any third-party services independently.
12.International Considerations
Virtu Medical is a United States–based company and all PHI is stored and processed within United States–based, HIPAA-compliant cloud infrastructure. We do not transfer PHI outside the United States without the explicit written authorization of the applicable Covered Entity and compliance with all applicable data transfer frameworks.
Clients with operations or patient populations outside the United States should contact Virtu Medical to discuss jurisdictional compliance requirements, including applicability of the European Union's General Data Protection Regulation (GDPR) or other regional privacy frameworks.
13.Changes to This Privacy Policy
Virtu Medical reserves the right to modify this Privacy Policy at any time. Material changes will be communicated to Covered Entity clients and Authorized Users via email notification and in-platform notice no less than thirty (30) days prior to the effective date of the change, except where a shorter period is required by law.
All previous versions of this Policy will be archived and made available upon request. Continued use of the platforms following the effective date of any modification constitutes acceptance of the updated Policy.
14.Contact Information
Virtu Medical — Privacy Office
Privacy inquiries: privacy@virtumedical.com
Security incidents: security@virtumedical.com
Website: www.virtumedical.com
To report a suspected privacy violation or to exercise rights under HIPAA, please contact your Covered Entity (healthcare provider) directly. Patients may also file a complaint with the U.S. Department of Health and Human Services, Office for Civil Rights (OCR): 200 Independence Avenue, S.W., Washington, D.C. 20201 · Toll-free 1-800-368-1019 · www.hhs.gov/ocr.
This Privacy Policy is effective as of June 15, 2026. Version 1.0 · Virtu Medical.