1. Overview
Dental Continuity LLC ("Continuity," "we," "us," or "our") is committed to protecting the privacy and security of information we receive through the Continuity platform and website. This Privacy Policy explains what information we collect, how we use it, and your rights regarding that information.
This policy applies to:
- Our public marketing website at dentalcontinuity.com
- The authenticated Continuity platform (app.dentalcontinuity.com)
- All related services, mobile applications, and communications
2. Who We Are
Dental Continuity LLC is a California limited liability company that provides dental referral management software as a service. In the context of HIPAA, Continuity operates as a Business Associate to dental practices (Covered Entities) that subscribe to our platform. We are not a Covered Entity ourselves.
For questions about this Privacy Policy, contact our Privacy Officer at privacy@dentalcontinuity.com.
3. Information We Collect
A. Information You Provide Directly
| Type of Information | Where Collected | Purpose |
|---|---|---|
| Contact information (name, email, phone, practice name) | Beta application form, contact form | Respond to inquiries, onboarding |
| Account information (name, email, role, practice) | Platform registration | Create and manage your account |
| Billing information (payment method, billing address) | Subscription checkout | Process subscription payments |
| Clinical content (referral details, messages, files) | Authenticated platform portal | Provide the referral management service |
| Support communications (emails, support tickets) | Email, in-app support | Resolve issues and improve the service |
B. Information Collected Automatically
| Type | Examples | Purpose |
|---|---|---|
| Log data | IP address, browser type, pages visited, timestamps | Security monitoring, troubleshooting |
| Usage data | Features used, referrals created, session duration | Improve the platform, identify issues |
| Device information | Browser version, operating system, screen size | Optimize display and performance |
| Audit logs | Who accessed what record and when | HIPAA compliance, security monitoring |
C. Information We Do NOT Collect
- We do not collect PHI through our public marketing website
- We do not purchase data about you from third-party data brokers
- We do not collect Social Security numbers
- We do not collect sensitive personal information beyond what is necessary to provide the Service
4. Protected Health Information (PHI)
PHI entered into the Continuity platform by subscribing dental practices may include:
- Patient names, dates of birth, contact information
- Clinical notes, diagnoses, treatment information
- Medical alert flags and medication information
- Radiographs, CT scans, and clinical photographs
- Insurance information and authorization status
- Treatment reports and specialist correspondence
How PHI is Handled
- Storage: All PHI is stored encrypted at rest using AES-256 encryption on AWS infrastructure covered by an AWS Business Associate Agreement
- Transmission: All PHI is transmitted over encrypted HTTPS connections โ never in unencrypted email or unprotected channels
- Access: PHI is accessible only to authenticated, authorized users within the subscribing dental practice and the specific specialist office associated with each referral
- Email notifications: Email notifications sent by Continuity do not contain PHI โ they notify users to log in to view details securely
- Staff access: Continuity staff access to PHI is strictly limited and logged, and only occurs as necessary to provide technical support or as required by law
- No secondary use: We never use PHI for marketing, advertising, or any purpose other than providing the Service
5. How We Use Information
We use the information we collect to:
- Provide, maintain, and improve the Continuity platform and Service
- Process and manage your account and subscription
- Send service communications including notifications, receipts, and support responses
- Monitor and ensure the security of the Service and detect unauthorized access
- Comply with our legal obligations including HIPAA requirements
- Respond to your inquiries and provide customer support
- Analyze aggregate usage patterns to improve the platform (using de-identified data only)
- Send you updates about the Service, new features, and important notices
We do not use PHI or any individually identifiable health information for marketing, advertising, or analytics purposes.
6. How We Share Information
We do not sell your personal information or PHI to any third party under any circumstances.
We may share information in the following limited circumstances:
Service Providers (Sub-processors)
We work with trusted third-party service providers who help us operate the Service. These providers are contractually required to protect your information and may only use it to provide services to us:
| Provider | Purpose | Data Shared | BAA in Place |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting, database, file storage | All platform data including PHI | Yes |
| Mailgun | Transactional email notifications | Email addresses, notification content (no PHI) | Yes |
Legal Requirements
We may disclose information if required to do so by law, court order, or government authority, or if we believe in good faith that disclosure is necessary to protect the rights, property, or safety of Continuity, our users, or the public.
Business Transfers
In the event of a merger, acquisition, or sale of all or substantially all of our assets, your information may be transferred as part of that transaction. We will notify you of any such transfer and any material changes to how your information is handled.
With Your Consent
We may share information with your consent for purposes not described in this Privacy Policy.
7. Data Security
We implement administrative, technical, and physical safeguards designed to protect your information consistent with HIPAA's Security Rule requirements, including:
- Encryption at rest: All data stored in AWS is encrypted using AES-256 encryption
- Encryption in transit: All data transmitted to and from the Service uses TLS 1.2 or higher (HTTPS)
- Access controls: Role-based access control limits what each user can see and do based on their role
- Audit logging: All access to PHI is logged with user identity, timestamp, and action taken
- Automatic session timeout: Sessions expire after periods of inactivity
- Database security: The database is not publicly accessible and requires authenticated connections
- Backup and recovery: Automated daily backups with point-in-time recovery capability
- Monitoring: Continuous monitoring for unauthorized access and anomalous activity
No method of electronic transmission or storage is 100% secure. While we implement industry-standard safeguards, we cannot guarantee absolute security. You are responsible for maintaining the security of your account credentials.
8. Data Retention
We retain information for as long as necessary to provide the Service and comply with our legal obligations:
- Account data: Retained while your account is active and for a reasonable period after termination
- PHI and referral records: Retained for a minimum of seven (7) years from the date of the referral, consistent with California dental records retention requirements under Business and Professions Code Section 1627.5, or as otherwise required by law
- Audit logs: Retained for a minimum of six (6) years consistent with HIPAA requirements
- Billing records: Retained for seven (7) years for tax and accounting purposes
- Website contact form submissions: Retained for up to two (2) years or until the relationship concludes
When a subscribing practice cancels their account, their PHI will be retained for the legally required period and then securely deleted. Practices may request a data export prior to account cancellation.
9. Your Rights
Depending on your location and applicable law, you may have the following rights regarding your information:
Rights as a Platform User (Account Data)
- Access: Request a copy of personal information we hold about you
- Correction: Update or correct inaccurate personal information
- Deletion: Request deletion of your personal information (subject to legal retention requirements)
- Portability: Request your data in a portable format
- Opt-out: Opt out of non-essential communications
Rights Regarding PHI (Patient Data)
Patient rights regarding PHI are governed by HIPAA and are exercised through the dental practice (Covered Entity), not directly through Continuity. Patients wishing to access, amend, or request an accounting of disclosures of their PHI should contact the dental practice directly.
To exercise your rights, contact us at privacy@dentalcontinuity.com. We will respond to verifiable requests within 30 days.
10. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):
- Right to Know: The categories and specific pieces of personal information we have collected about you
- Right to Delete: Deletion of personal information we have collected, subject to certain exceptions
- Right to Correct: Correction of inaccurate personal information
- Right to Opt-Out of Sale or Sharing: We do not sell or share personal information for cross-context behavioral advertising
- Right to Limit Use of Sensitive Personal Information: We only use sensitive personal information as necessary to provide the Service
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights
Note: PHI regulated by HIPAA is exempt from CCPA. CCPA rights apply to your account and contact information, not to PHI processed under our Business Associate Agreement.
To submit a California privacy request, contact us at privacy@dentalcontinuity.com with "California Privacy Request" in the subject line.
11. Cookies & Tracking Technologies
Our public website and platform use cookies and similar technologies to operate and improve the Service:
| Cookie Type | Purpose | Can Be Disabled? |
|---|---|---|
| Essential/Session | Keep you logged in, maintain your session, security (CSRF protection) | No โ required for the Service to function |
| Functional | Remember your preferences (office selection, notification settings) | Yes โ may affect functionality |
| Analytics | Understand how the platform is used to improve it (de-identified) | Yes โ via browser settings |
We do not use advertising cookies or third-party tracking pixels on the authenticated portal. You can control cookies through your browser settings. Disabling essential cookies will prevent you from using the Service.
12. Third-Party Services & Links
The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing any information.
Our current third-party service providers with access to Service data are listed in Section 6. We conduct due diligence on all service providers and require appropriate data protection agreements before granting access to any user data.
13. Data Breach Notification
In the event of a data breach affecting PHI, Continuity will comply with HIPAA's Breach Notification Rule (45 CFR Part 164, Subpart D), which requires:
- Notification to affected Covered Entities (dental practices) without unreasonable delay and no later than 60 days following discovery of the breach
- Notification to the U.S. Department of Health and Human Services
- Notification to affected individuals as directed by the Covered Entity
- In certain cases, notification to prominent media outlets in affected states
In the event of a breach affecting non-PHI personal information, Continuity will comply with California's data breach notification law (California Civil Code Section 1798.29 and 1798.82), which requires notification to affected California residents in the most expedient time possible and without unreasonable delay.
14. Children's Privacy
The Continuity platform is not directed at individuals under 18 years of age. We do not knowingly collect personal information from children under 18. If you believe we have inadvertently collected information from a minor, please contact us immediately at privacy@dentalcontinuity.com.
Note: The Service may process PHI relating to minor patients as part of dental referrals. Such processing is governed by the Business Associate Agreement and applicable HIPAA provisions, not by children's online privacy laws such as COPPA, as the processing occurs within a professional healthcare context.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by:
- Sending an email notification to the address associated with your account
- Displaying a prominent notice in the platform
- Updating the "Last updated" date at the top of this page
We will provide at least 30 days' notice before material changes take effect. Your continued use of the Service after the effective date of any changes constitutes acceptance of the updated Privacy Policy.
16. Contact Us
If you have questions, concerns, or requests related to this Privacy Policy or our data practices, please contact us:
- Privacy inquiries: privacy@dentalcontinuity.com
- General inquiries: info@dentalcontinuity.com
- HIPAA BAA requests: info@dentalcontinuity.com โ subject line "HIPAA BAA Request"
- Company: Dental Continuity LLC
- Mailing address: Available upon request
We will acknowledge your inquiry within 5 business days and respond substantively within 30 days.