Privacy
Last updated August 21, 2026
IntakeLinx processes clinical documents on behalf of healthcare suppliers. This page describes what we do with that information, and separately what this website collects, because those are different things and conflating them is how privacy policies become useless.
Two different relationships
When a supplier uses IntakeLinx to process patient documents, we act as a business associate under HIPAA. The supplier is the covered entity, the data is theirs, and our handling of it is governed by a signed business associate agreement rather than by this page. Where that agreement and this page differ, the agreement governs.
When you visit this website, you are not a patient and we are not processing protected health information. That is covered in the website section below.
Protected health information
What we process
Whatever a customer sends us: clinical document packets and the structured data extracted from them. This typically includes patient identifiers, dates of birth, addresses, insurance and payor information, diagnosis and procedure codes, prescriber details, and clinical notes contained in the documents.
Why we process it
To perform the service the customer engaged us for: turning documents into structured orders in their destination system. We do not process it for any other purpose. We do not sell it, we do not share it with anyone other than the subprocessors listed below, and we do not use it to train models.
How it is isolated
Every record carries a tenant, and isolation is enforced by row level security in the database rather than by application code. Policies are deny by default, so a query that fails to scope itself returns nothing rather than returning another customer's patients.
Logging
Protected health information does not reach application logs. A redaction layer sits between the application and every logger and works from an allowlist of permitted keys, so anything not explicitly permitted is not logged. Operational logs contain identifiers for cases and jobs, never patient data.
Audit
Access to patient data is recorded to an append only audit log. That log has no update or delete path, including for us.
Retention and deletion
Retention is configured per customer and per artifact class, because obligations differ by state and by payor contract. On deletion, the stored document object is deleted. The audit record that the document existed and was deleted is retained, because a deletion log that can itself be deleted is not a deletion log.
On termination, a customer may request return or deletion of their data as set out in their business associate agreement.
Subprocessors
We use a small number of subprocessors, each under a business associate agreement:
- Application hosting and delivery.
- Managed database and object storage.
- Model inference, with zero retention enabled so document content is not retained after the response.
The current list with named vendors is provided to customers on request and before signature, and customers are notified before a new subprocessor is added.
Breach notification
If we discover a breach of unsecured protected health information, we notify the affected customer without unreasonable delay and within the timeframe set out in the business associate agreement, with the information they need to meet their own notification obligations.
This website
The marketing pages of this website do not use advertising trackers, do not set analytics cookies, and do not build a profile of you. Our hosting provider records standard request logs, including IP address and user agent, for security and reliability. Those logs are retained for a short operational period.
If you email us, we keep that correspondence so we can respond to it. Please do not send patient documents by email.
The signed in application sets a session cookie. It is strictly necessary for authentication and is not used for tracking.
Your rights
If you are a patient whose documents were processed through IntakeLinx, your rights of access, amendment and accounting run through the supplier who holds your record, not through us. We support that supplier in responding to you. If you contact us directly we will refer you to them, because we cannot verify your identity against a record we hold on someone else's behalf.
Contact
Privacy questions: privacy@intakelinx.com