Privacy Policy
Last updated August 19, 2026
The short version
ChartPort is clinical software sold to assisted living operators. Nearly all of the health information we handle belongs to our customers, not to us — we process it on their instructions, under a Business Associate Agreement, and for no other purpose. We do not sell data, we do not use it for advertising, and we do not use it to train anyone's AI models. The browser extension reads only the ECP screens an operator is already looking at, sends data only when that operator clicks something, and collects nothing about browsing anywhere else.
Who this covers
This policy applies to ChartPort ("ChartPort", "we", "us") — the ChartPort web application at chartport.io, the ChartPort API, and the ChartPort browser extension distributed through the Chrome Web Store.
ChartPort is used by staff at assisted living operators. It is not a consumer product, and residents do not hold ChartPort accounts.
Protected health information
ChartPort ingests clinical paperwork — prescription orders, medication lists, clinical notes, face sheets — that providers and pharmacies send to our customers. That material contains protected health information (PHI) about residents.
With respect to that information we act as a Business Associate under HIPAA. The operator is the covered entity; it remains theirs. We handle it only to provide the service, only as their agreement with us permits, and our obligations are set by the Business Associate Agreement between us — which governs over this policy wherever the two differ.
If you are a resident or a family member and want to know what a facility holds about you, or want it corrected or deleted, that request goes to the facility. We cannot act on it directly, because the record is not ours to release. We support our customers in responding to those requests.
Account and usage information
For staff who sign in, we hold a name, a work email address, the tenant they belong to, and their assigned role. Sign-in is handled through Google OAuth or Amazon Cognito; we never receive or store a password.
We keep operational logs — API requests, processing events, errors — to run the service, diagnose failures, and maintain an audit trail of who did what to a clinical record. We do not run advertising trackers, third-party analytics, session recording, or behavioral profiling in the web application or the extension. Staff activity is never sold, and never packaged into productivity metrics about individual employees.
Our public marketing pages — the home page and the get-in-touch form — do load HubSpot’s tracking script, which sets a cookie so a form submission can be tied to an existing contact and records the page and IP address the form was sent from. It runs only on those pages, never on a signed-in screen, and it never sees clinical data.
The ChartPort browser extension
The extension runs only on secure.ecp123.com, the EHR our customers already use. It exists so staff can pull a chart document into ChartPort, and see what ChartPort knows, without leaving the screen they are working in.
What it reads
Within those pages it reads the resident and medication information already displayed to the signed-in staff member, and the identity claims of that person's existing EHR session — which facility and which employee — so clinical actions can be attributed correctly. The raw EHR session token itself never leaves the browser.
What it sends, and when
Nothing is transmitted by simply having a page open. The extension sends data to the ChartPort API only in response to a deliberate action by the staff member — capturing a chart document, or requesting that a medication list be matched against ChartPort's records. Those transmissions go to ChartPort's own API and nowhere else.
What it stores on the device
The extension generates a cryptographic key pair whose private half cannot be exported from the browser, and stores it locally along with an enrolment identifier, the API address to talk to, and a cached list of which features are currently enabled. There is no password and no long-lived access token in the extension. An administrator can disconnect a browser at any time, from the extension's own popup or from ChartPort.
What it does not do
It does not read, collect, or transmit browsing history, page contents, form input, or credentials from any other site. It has no access to pages outside the two domains named in its manifest. It contains no analytics, no advertising code, and no remotely loaded scripts — all of its code ships in the package Google reviews.
Chrome Web Store Limited Use
Our use of information received from Google APIs, and all data handled by the extension, adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements. We use that data solely to provide and improve the ChartPort features described here. We do not transfer it except as required to provide those features, for security or legal reasons, or as part of a merger or acquisition with notice to affected customers. We do not use it for advertising, and we do not allow humans to read it except with the customer's explicit permission, for security or support purposes, to comply with law, or where the data has been aggregated and de-identified.
Who processes data on our behalf
We use a small number of vendors to run the service. Each handles data only to provide its function to us:
- Amazon Web Services — hosting, storage, database, sign-in, document text recognition, and AI processing. Clinical data lives here.
- Fax providers— currently Alohi's Fax.Plus, which receives inbound faxes on our customers' numbers and passes them to us.
- Google — sign-in, when a staff member chooses to authenticate with a Google account.
- NPPES— the U.S. government's public registry of healthcare providers, queried to resolve prescriber identifiers. These lookups carry provider information, never resident information.
We do not sell personal information or protected health information. We do not share it with advertising networks or data brokers. We disclose it outside these vendors only when the law requires it, and we will tell the affected customer unless we are legally prohibited from doing so.
AI processing
ChartPort uses large language models to read incoming documents — classifying them, extracting the clinical claims they carry, and matching them to residents and medications.
This runs on Amazon Bedrockinside our own AWS environment. Document content is not sent to a separate model vendor, is not retained by the model provider, and is not used to train or improve any third party's models. Model output is treated as a draft interpretation: clinical decisions stay with the staff who review it.
Security
Data is encrypted in transit with TLS and at rest in AWS. Credentials for fax providers, EHR connections, and enrolled browsers are additionally sealed with dedicated AWS-managed encryption keys. Every record is scoped to a single tenant, and access is granted by role.
No system is perfectly secure. If a breach affects protected health information, we notify affected customers as HIPAA and our Business Associate Agreements require.
Retention
Clinical records are retained for as long as the operator's account is active, because they are part of that operator's record-keeping and regulatory obligations. On termination we return or delete customer data as the Business Associate Agreement directs. Operational logs are kept on a shorter cycle sufficient for troubleshooting and audit.
Changes to this policy
If we change this policy we will update the date at the top of this page. If a change materially affects how we handle clinical information, we will notify customers directly rather than relying on this page alone.
Contact
Questions about this policy, or about data we hold, go to hayden@chartport.io.