Legal

Effective date: June 12, 2026 · Questions: info@vigil-health.org

Privacy Policy

Vigil Health (“Vigil,” “we,” “us”) operates a cloud-based Chronic Care Management (CCM) platform for medical practices. This Privacy Policy describes how we collect, use, and protect information when you use our platform.

Information we collect

Practice information: When a practice registers, we collect the practice name, National Provider Identifier (NPI), address, and administrator contact details. This information is used to operate and invoice the account.

User account information: We collect names, email addresses, and hashed passwords for platform users (coordinators, providers, administrators). Passwords are never stored in plaintext.

Protected Health Information (PHI): Our platform stores patient PHI on behalf of enrolled medical practices, acting as a Business Associate under HIPAA. PHI includes patient names, Medicare Beneficiary Identifiers (MBI), dates of birth, addresses, phone numbers, and chronic condition information. Crown-jewel PHI fields — MBI, date of birth, and address — are encrypted at the application layer using AES-256-GCM before being written to the database. All stored data is additionally protected by Supabase's database-level encryption at rest.

Usage data: We log access events, authentication events, and system actions in an append-only audit trail for HIPAA compliance. These logs record who did what and when, without storing PHI in log fields.

Call recordings: Patient voice check-in calls are recorded and stored securely for compliance purposes. Recordings contain PHI and are subject to all PHI handling requirements.

How we use information

Practice and user information is used solely to operate the platform, communicate about the service, and invoice the practice. We do not sell, rent, or share practice or user data with third parties for marketing purposes.

PHI is used exclusively to provide the CCM platform services on behalf of the enrolled medical practice. We do not use PHI for any purpose beyond what is required to operate the service and maintain HIPAA compliance.

Data sharing

We share data only as follows:

  • Supabase: Database and authentication infrastructure. Supabase is a HIPAA-eligible provider.
  • Twilio: Voice calls and SMS messaging. Twilio is a HIPAA-eligible provider. A Business Associate Agreement (BAA) is required and in effect before any real patient data is transmitted.
  • Deepgram: Audio transcription of patient calls. Deepgram is a HIPAA-eligible provider. BAA required before production use.
  • Anthropic: AI risk scoring and clinical assistant features. BAA required before production use with real patient data.
  • Legal requirement: We may disclose information if required by law, subpoena, or court order.

Data retention

Patient records, time logs, call recordings, and audit trails are retained for a minimum of seven years in accordance with CMS documentation requirements for Medicare billing. Practice and user data is retained for the duration of the service agreement plus three years.

Your rights

Medical practices have the right to request an export or deletion of their practice data by contacting us at info@vigil-health.org. Deletion requests for data subject to Medicare retention requirements may be fulfilled only after the retention period expires.

Patient rights under HIPAA (access, amendment, accounting of disclosures) are exercised through the enrolled medical practice as the covered entity.

Terms of Service

By creating an account and using the Vigil Health platform, you (“Practice” or “you”) agree to these Terms of Service. Please read them carefully.

Eligibility and account

The platform is available to licensed medical practices authorized to bill Medicare under CPT codes for Chronic Care Management services. By registering, you represent that your practice holds the required licenses and Medicare billing privileges.

Each user account requires a valid email address and must be protected with multi-factor authentication. You are responsible for the security of all accounts within your practice. Do not share login credentials.

HIPAA obligations

You acknowledge that you are a Covered Entity under HIPAA and that Vigil Health operates as your Business Associate for the purpose of providing CCM platform services. A signed Business Associate Agreement (BAA) is required before processing real patient data through the platform. Using the platform with real patient data without an executed BAA is prohibited.

Accurate billing representations

You agree to use the platform only to document and attest to care that was actually provided. The provider attestation certifies, under penalty of perjury, that the documented CCM services were rendered as described. Submitting false claims to Medicare is a federal crime under the False Claims Act. You are solely responsible for the accuracy of your billing submissions.

Vigil Health provides tools for documentation and workflow automation. We do not guarantee that use of the platform will result in successful Medicare reimbursement. You are responsible for ensuring that your CCM program meets all applicable CMS requirements.

Acceptable use

You agree not to use the platform to: (a) submit fraudulent claims; (b) store data belonging to patients who have not provided CCM consent; (c) share PHI outside of authorized care team members; (d) attempt to reverse-engineer, scrape, or circumvent the platform's security controls; or (e) use the platform for any purpose that violates applicable law.

Fees and payment

Platform fees consist of a one-time onboarding fee and a monthly per-enrolled-patient fee. The current starting rate is $25.00 per patient per month; fees may decrease at higher panel sizes — the applicable rate schedule is provided at the time of agreement execution. The one-time onboarding fee is $500.00 for Founding Practice participants (standard list price: $1,000.00). Invoices are generated on the 28th of each month for the coming month and are due by the 5th. Initial (onboarding) invoices are due within 3 business days of agreement execution. All payments are collected via ACH bank transfer through Melio — no credit cards accepted. Patients enrolled or disenrolled mid-month are prorated at 1/30th of the monthly per-patient rate per day; proration credits or charges appear on the following month's invoice. Vigil Health reserves the right to suspend access for invoices outstanding beyond 15 days of the due date.

Termination

Either party may terminate the service agreement with 15 days written notice. No cancellation fee applies. Upon cancellation, Vigil Health will refund any prepaid but undelivered service days via ACH within 5 business days of the cancellation effective date. Vigil Health will provide a data export of your practice's records in a standard format within 30 days of termination. Data is retained for the required retention period and then securely deleted.

Limitation of liability

To the maximum extent permitted by law, Vigil Health's liability for any claim arising from use of the platform is limited to the fees paid by the practice in the three months preceding the claim. We are not liable for indirect, incidental, or consequential damages, including lost Medicare reimbursements.

Governing law

These terms are governed by the laws of the State of Utah. Disputes shall be resolved in the state or federal courts located in Utah, and you consent to the jurisdiction of those courts.

HIPAA Notice

Vigil Health acts as a Business Associate under the Health Insurance Portability and Accountability Act (HIPAA). We do not act as a Covered Entity and do not provide healthcare services directly to patients.

Business Associate Agreement

A signed Business Associate Agreement (BAA) is required between Vigil Health and each enrolled medical practice before any real patient Protected Health Information (PHI) may be entered into the platform. To request a BAA, contact us at info@vigil-health.org with the subject “BAA Request.”

PHI safeguards

  • Crown-jewel PHI fields (MBI, date of birth, address) are encrypted at the application layer using AES-256-GCM with key rotation support, before reaching the database
  • All stored data is additionally protected by Supabase database-level encryption at rest
  • All data is encrypted in transit using TLS 1.2 or higher
  • Access to PHI requires multi-factor authentication at AAL2 level (TOTP)
  • All PHI access events are logged in an append-only, tamper-evident audit trail
  • PHI is never included in application logs, error messages, or URLs
  • Sessions expire after 15 minutes of inactivity and after 4 hours absolute
  • User accounts are scoped to the practice's own patients only (tenant isolation)

Breach notification

In the event of a suspected or confirmed breach of unsecured PHI, Vigil Health will notify the affected practice within 60 days of discovery, as required by the HIPAA Breach Notification Rule (45 CFR §164.400 et seq.).

Subcontractors

All subcontractors that handle PHI (Supabase, Twilio, Deepgram, Anthropic) are required to execute a BAA with Vigil Health before any PHI is transmitted to their systems.

Cookie Policy

Vigil Health uses a minimal set of cookies strictly necessary to operate the platform. We do not use advertising cookies, third-party tracking cookies, or analytics services that would share your data with external parties.

Cookies we use

CookiePurposeDurationType
sb-*-auth-tokenSupabase authentication session token — keeps you logged inSession / up to 4 hoursStrictly necessary
vh_session_startRecords when your session started to enforce the 4-hour absolute session capSessionStrictly necessary

No tracking or analytics

We do not use Google Analytics, Facebook Pixel, Mixpanel, Hotjar, or any other third-party analytics or advertising service. No data about your use of this platform is shared with advertising networks.

Managing cookies

The cookies listed above are strictly necessary for the platform to function. Blocking them will prevent you from logging in. You can clear all cookies for this site at any time through your browser settings, which will sign you out of your session.

Security Disclosure

Vigil Health takes the security of patient data seriously. If you believe you have discovered a security vulnerability in our platform, please report it to us responsibly.

How to report

Email info@vigil-health.org with the subject line SECURITY. Include:

  • A description of the vulnerability and the potential impact
  • Steps to reproduce the issue
  • Your contact information (optional but helpful for follow-up)

Our commitment

  • We will acknowledge receipt of your report within 48 hours
  • We will investigate and respond with our findings within 10 business days
  • We will not pursue legal action against researchers acting in good faith
  • We ask that you not access, modify, or disclose patient data during testing
  • We ask that you allow us reasonable time to remediate before public disclosure

Scope

In scope: vigil-health.org and any subdomains, the Vigil Health web application, and the Vigil Health API.

Out of scope: Social engineering attacks, physical attacks, denial of service, spam, or attacks against Supabase, Twilio, or other third-party infrastructure.

© 2026 Vigil Health. These policies were last updated on June 12, 2026. For questions, contact info@vigil-health.org.