Privacy Policy

Last updated: July 4, 2026

This Privacy Policy describes how Cyphelink, LLC (“Cyphelink,” “we,” “us”) handles information processed through the Cyphelink referral-triage platform (the “Service”). Cyphelink is an administrative workflow tool used by specialty clinics to organize and prioritize incoming patient referrals.

1. Our role under HIPAA

Cyphelink acts as a Business Associate to the healthcare providers and clinics that use the Service (each a Covered Entity). We process Protected Health Information (“PHI”) only on a clinic’s behalf and only as permitted by a signed Business Associate Agreement (“BAA”) between Cyphelink and that clinic. If you are a patient, your rights regarding your PHI — including access, amendment, and an accounting of disclosures — are exercised through your clinic and its Notice of Privacy Practices, not directly through Cyphelink. Cyphelink does not act on patient requests for access, amendment, or an accounting of disclosures directly; we refer any such request to the relevant clinic.

2. Information we process

  • Referral documents. The faxed or uploaded referral PDFs themselves.
  • Extracted referral data. Information our pipeline extracts from those documents, which may include patient name, date of birth, contact details, insurance information, referring-provider details, and clinical information (diagnoses, symptoms, reason for referral).
  • Account data. Clinic-staff names, email addresses, and role assignments used for authentication and access control.
  • Operational metadata. Audit logs, timestamps, and system identifiers used for security, troubleshooting, and HIPAA accountability.

3. How we use information

We use PHI solely to provide the Service to the clinic — ingesting, classifying, prioritizing, and displaying referrals — and as otherwise permitted by the BAA. We do not sell PHI or use it for advertising. We do not use PHI to train, fine-tune, or develop any AI model — whether general-purpose models or Cyphelink’s own classification. Any use of de-identified data to improve the Service is limited as described in Section 8. AI classification is performed within AWS infrastructure covered by our AWS Business Associate Addendum.

4. How we protect information

  • Encryption in transit: TLS 1.2+ on all connections.
  • Encryption at rest: AES-256 server-side encryption on stored documents; encrypted database storage.
  • Access controls: authenticated, role-based access; clinic-level data isolation enforced on every request.
  • Auditing: append-only audit logging of access to and changes in referral records.
  • Least privilege: staff and system components receive only the access required for their function.

5. Subprocessors

We use Amazon Web Services (AWS) to host and operate the Service, including compute, storage, database, authentication, and AI inference. PHI processed through these services is covered by the AWS Business Associate Addendum. Where a clinic connects a fax line to the Service, referral documents are also transmitted through the clinic’s fax provider (for example, Zoom Phone) as part of receiving or sending faxes. A current list of subprocessors is available to clinics on request at ayman@cyphelink.com.

6. Data retention

We retain PHI for the period required to provide the Service and to meet legal and regulatory obligations — including the six-year retention period applicable to HIPAA records — after which it is securely disposed of, unless the BAA or applicable law requires otherwise. Audit records are append-only and retained for the same period.

7. Breach notification

In the event of a breach of unsecured PHI, we will notify the affected clinic without unreasonable delay and no later than the timeframe specified in the applicable BAA (and in no case later than required by the HIPAA Breach Notification Rule), so the clinic can fulfill its notification obligations.

8. De-identified and aggregate data

We may create de-identified or aggregate data (which does not identify any individual and is created consistent with the HIPAA de-identification standard) to operate, secure, and improve the Service, including to evaluate and improve Cyphelink’s own classification, and only as permitted by the BAA. We do not use PHI to train AI models (see Section 3).

9. Cookies and sessions

The Service uses strictly-necessary, HttpOnly session cookies to authenticate clinic staff and maintain a secure session. We do not use advertising, analytics, or cross-site tracking cookies. The contact form on our marketing site (cyphelink.com) uses Cloudflare Turnstile to filter automated abuse. Turnstile evaluates browser signals to distinguish people from automated traffic; the contents of the form are not sent to Cloudflare.

10. California privacy (account data)

PHI handled on a clinic’s behalf is governed by HIPAA and the BAA and is exempt from the California Consumer Privacy Act. For non-PHI clinic-staff account data (names, email addresses, role assignments), we collect and use it only to operate the Service and provide access control. We do not sell or share personal information for cross-context behavioral advertising.

11. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated to clinics, and the “effective date” above will be updated.

12. Contact

Questions about this policy or our privacy practices may be directed to ayman@cyphelink.com. Patients should contact their clinic directly regarding their own health information.

Privacy Policy — Cyphelink