Privacy Policy
This Privacy Policy explains how AIRSM LLC, doing business as ChronMD ("ChronMD," "we," "us"), collects and uses information through the chronmd.com website and the ChronMD medical-record review service. It is written for our clients — law firms and legal professionals — and for visitors to this website.
1. Two very different kinds of data
We deliberately separate the marketing website from the case-processing service:
- Website data (chronmd.com). This website is a static marketing site. It does not accept file uploads, does not host a login, and never receives, stores, or transmits medical records or protected health information (PHI).
- Case data (the service). Medical records you send us for review are transferred only through private, expiring, encrypted upload links into our access-controlled Amazon Web Services (AWS) environment. Case data never touches the marketing website or its hosting provider.
2. Information we collect on this website
- Contact information you send us — if you email intake@chronmd.com, we receive your name, email address, firm, and whatever you include in the message.
- Payment information — payments are processed by Stripe. We receive your name, email, firm/billing details and payment status; we never see or store full card numbers.
- Server logs — our hosting provider records standard access logs (IP address, user agent, pages requested) for security and operations.
- Cookies/analytics — this website uses Google Analytics 4 with Consent Mode defaulting to "denied": no analytics cookies are set and no analytics identifiers are stored unless consent is granted. IP addresses are anonymized. No advertising or cross-site tracking is used.
3. Information we process as part of the service
When a client engages us, we process the medical records and related case materials the client provides, which typically contain PHI (names, dates of birth, diagnoses, treatment notes, billing data). We process this information solely to produce the work product the client ordered (chronologies, narratives, demand letters, billing summaries, special reports and related quality-control artifacts). We act on the client's instructions and, where required, under a Business Associate Agreement (BAA) — see our HIPAA Notice.
4. How we use information
- To deliver, invoice, and support the services a client ordered;
- To send transactional messages (upload links, delivery links, receipts, status updates);
- To secure and audit the service, including per-case cryptographic ledgers of file hashes and processing steps;
- To improve our quality-control thresholds and formatting profiles. Client work product is used for the client's own matters; we do not sell client data or use PHI for advertising.
5. Subprocessors
| Provider | Purpose | Data involved |
|---|---|---|
| Amazon Web Services (AWS), US regions | Case file storage, OCR (Textract), AI processing (Bedrock), job queue, delivery, email notifications | Case files / PHI — encrypted at rest and in transit; HIPAA-eligible services under the AWS BAA |
| Stripe, Inc. | Payment processing | Billing contact and payment data only. No PHI is ever included in Stripe checkout, products, or metadata. |
| Hostinger | Hosting of this marketing website and the intake@chronmd.com mailbox | Website logs and business email. No PHI — clients are instructed never to attach records to email; records move only via secure upload links. |
| Google LLC (Google Analytics 4) | Privacy-safe website analytics (consent-gated) | Anonymized website usage data only. No PHI, no case data, no advertising use. |
6. Retention
- Case files and deliverables: retained for 90 days after delivery (or a shorter period agreed with the client), then deleted from active storage; the client may request earlier deletion at any time.
- Case ledgers (hashes and QC scores, no medical content): retained as a long-term integrity record.
- Billing records: retained as required by tax and accounting law.
7. Security
Case data is encrypted in transit (TLS) and at rest (server-side encryption with AWS KMS keys), stored in non-public buckets with access logging, and reachable only through short-lived signed URLs and least-privilege credentials. Every case is sealed with a SHA256 audit ledger so any later modification is detectable. No method of transmission or storage is perfectly secure, but we design so that a compromise of the public website cannot expose case data.
8. Your rights and choices
Clients may request access to, correction of, or deletion of their case data at any time by emailing intake@chronmd.com. Individuals whose PHI appears in records we process for a law firm should direct requests to that firm (our client), which controls the records; we will assist the client in fulfilling such requests. California residents: we do not sell or share personal information as defined by the CCPA/CPRA, and we process client-provided case records solely as a service provider acting on our clients' documented instructions; you may exercise your rights to access, correct, or delete personal information by emailing intake@chronmd.com, and we will not discriminate against you for doing so. We do not sell personal information.
9. Children
This website and service are for legal professionals and are not directed to children under 16. Records processed on behalf of clients may concern minors; such records are handled exclusively under the client's instructions and applicable law.
10. Changes
We will post any changes to this policy on this page and update the "last updated" date. Material changes affecting active clients will be notified by email.
11. Contact
AIRSM LLC, doing business as ChronMD · Jacksonville, Florida · intake@chronmd.com. Our registered mailing address is provided in executed agreements and on request.