Privacy Policy

Effective date: July 2, 2026 · Last updated: July 2, 2026

This Privacy Policy explains how AIRSM LLC, doing business as ChronMD ("ChronMD," "we," "us"), collects and uses information through the chronmd.com website and the ChronMD medical-record review service. It is written for our clients — law firms and legal professionals — and for visitors to this website.

1. Two very different kinds of data

We deliberately separate the marketing website from the case-processing service:

2. Information we collect on this website

3. Information we process as part of the service

When a client engages us, we process the medical records and related case materials the client provides, which typically contain PHI (names, dates of birth, diagnoses, treatment notes, billing data). We process this information solely to produce the work product the client ordered (chronologies, narratives, demand letters, billing summaries, special reports and related quality-control artifacts). We act on the client's instructions and, where required, under a Business Associate Agreement (BAA) — see our HIPAA Notice.

4. How we use information

5. Subprocessors

ProviderPurposeData involved
Amazon Web Services (AWS), US regionsCase file storage, OCR (Textract), AI processing (Bedrock), job queue, delivery, email notificationsCase files / PHI — encrypted at rest and in transit; HIPAA-eligible services under the AWS BAA
Stripe, Inc.Payment processingBilling contact and payment data only. No PHI is ever included in Stripe checkout, products, or metadata.
HostingerHosting of this marketing website and the intake@chronmd.com mailboxWebsite logs and business email. No PHI — clients are instructed never to attach records to email; records move only via secure upload links.
Google LLC (Google Analytics 4)Privacy-safe website analytics (consent-gated)Anonymized website usage data only. No PHI, no case data, no advertising use.

6. Retention

7. Security

Case data is encrypted in transit (TLS) and at rest (server-side encryption with AWS KMS keys), stored in non-public buckets with access logging, and reachable only through short-lived signed URLs and least-privilege credentials. Every case is sealed with a SHA256 audit ledger so any later modification is detectable. No method of transmission or storage is perfectly secure, but we design so that a compromise of the public website cannot expose case data.

8. Your rights and choices

Clients may request access to, correction of, or deletion of their case data at any time by emailing intake@chronmd.com. Individuals whose PHI appears in records we process for a law firm should direct requests to that firm (our client), which controls the records; we will assist the client in fulfilling such requests. California residents: we do not sell or share personal information as defined by the CCPA/CPRA, and we process client-provided case records solely as a service provider acting on our clients' documented instructions; you may exercise your rights to access, correct, or delete personal information by emailing intake@chronmd.com, and we will not discriminate against you for doing so. We do not sell personal information.

9. Children

This website and service are for legal professionals and are not directed to children under 16. Records processed on behalf of clients may concern minors; such records are handled exclusively under the client's instructions and applicable law.

10. Changes

We will post any changes to this policy on this page and update the "last updated" date. Material changes affecting active clients will be notified by email.

11. Contact

AIRSM LLC, doing business as ChronMD · Jacksonville, Florida · intake@chronmd.com. Our registered mailing address is provided in executed agreements and on request.