MetaclinicMetaclinic

Legal

Privacy policy

Metaclinic holds diagnostic data on behalf of the laboratories and practices it serves. For almost everything in a patient's record, those organizations are the covered entities and Metaclinic is their business associate, acting on their instructions and under an executed agreement. This policy says what that means, what Metaclinic does with information from this website, and how a person exercises their rights.

Effective 19 August 2026 · version 2.0

This version supersedes all earlier ones. Material changes are published here with a new effective date and the prior version's date recorded below, so it is always possible to establish which policy was in force on a given day. Continued use after an effective date is not treated as agreement to a material change that reduces anyone's rights.

The two things this policy covers

scope

They are governed differently and it matters which one is in play.

The platform, and the records in it
Protected health information and the operational data around it, processed for a customer. Metaclinic does not decide the purposes for which this data is used. The customer does, as the covered entity, and Metaclinic acts on its instructions under a business associate agreement and under HIPAA directly. A patient's rights in this data are exercised through the provider that holds the relationship, and Metaclinic's obligation is to make that possible rather than to stand between them.
This website
metaclinic.com is a set of static pages. It sets no cookies, runs no analytics, loads nothing from a third-party host, and has no advertising of any kind. There is no tracking to opt out of because there is no tracking. The only information Metaclinic receives from a visit is what a person deliberately sends: an email to the published address, a form or agreement they choose to execute, or a meeting they choose to book through the scheduling link.

What the platform does with a record

the business associate relationship

A business associate agreement is executed with each customer before any data moves, and Metaclinic's subcontractors are business associates in turn under their own agreements. Obligations flow down that chain by contract and by regulation. Metaclinic uses protected health information only to provide the services the agreement describes, for its own required operations, and as law requires.

  • Metaclinic does not sell personal information or protected health information, and has no arrangement under which it could.
  • Metaclinic does not use protected health information for advertising or marketing, and does not use it to train models offered to anyone else.
  • Metaclinic does not interpret results, generate diagnoses, alter a laboratory's reference intervals, or act as the laboratory of record for any test.
  • De-identified or aggregated data is used only where it has been de-identified to the standard HIPAA sets and where the governing agreement permits it.

Who controls the release rules

The platform ships with a documented default configuration for what each class of stakeholder receives, available to any customer or patient on request. Those defaults are Metaclinic's, and a customer can narrow them for its own tenant. Saying the customer has “full control” of the data would be imprecise: the customer controls the purposes and can restrict the defaults, and Metaclinic is responsible for the software that enforces whatever is configured.

Compulsory process and law enforcement

when someone with authority asks

A subpoena, court order, warrant, or other compulsory process directed at Metaclinic is evaluated against the law that governs it and against the governing business associate agreement. Where a demand reaches a customer's protected health information, Metaclinic notifies that customer unless it is prohibited from doing so, so the covered entity can assert its own objections. The platform's default release configuration does not narrow what lawful compulsory process reaches, and where a response is incomplete the basis for that is stated rather than left as a silent gap.

Retention

how long

Records in the platform are retained for the period the governing agreement and the longest applicable legal requirement set, which for clinical and billing records is generally fixed by state record-retention law, CLIA, and the terms of the customer's own obligations rather than by Metaclinic's preference. On termination, data is returned or destroyed as the agreement directs. Disclosure and attestation records are retained on the schedule the longest applicable requirement sets, because their value is that they can be produced years later.

Correspondence sent to Metaclinic's published address, and records of executed agreements, are kept for as long as needed for the purpose they were sent for and for the period applicable law requires.

Security

and what is not claimed
  • Encryption in transit and at rest, with key management separated from application credentials.
  • Least privilege by default, and no standing administrative read access to clinical data.
  • Append-only audit logging of access and disclosure — entries are written once and never updated or deleted in place, corrections are recorded as further entries, and the log is retained on the schedule the longest applicable requirement sets.
  • Tenancy isolation enforced in the database rather than in application logic.
  • Subcontractor review before any new processor touches protected health information.

Designed for HIPAA compliance; not certified against any standard

Metaclinic is designed and operated for HIPAA compliance and acts as a business associate under agreement. It holds no third-party certification or accreditation: there is no completed SOC 2, no HITRUST certification, no CAP accreditation of the software, and no FDA clearance, and none is claimed. That is a statement about construction rather than about audit. No system is immune from compromise, and any claim otherwise should be read with suspicion.

If there is a breach

notification

Metaclinic reports a discovered breach of unsecured protected health information to the affected customer without unreasonable delay and within the period the governing agreement and the HIPAA breach notification rule require, with the information that rule requires the covered entity to have. Notification to patients is made by the covered entity, which holds the relationship, with Metaclinic supporting it. For information Metaclinic holds in its own right, it notifies affected people as applicable law requires.

A patient's rights in their own record

and where to exercise them

The right of access is an obligation with a clock rather than a feature, and it is described in full on the patient access page: records provided in the form requested where they are producible that way, within thirty days, with an outstanding balance no reason to withhold anything. A request is made to the provider or laboratory that holds the relationship, and Metaclinic's part is to make that request answerable rather than to answer it in their place. A person who cannot get an answer from their provider can write to Metaclinic and Metaclinic will route it.

State privacy rights

and how HIPAA interacts with them

Protected health information held by a covered entity or its business associate is exempt from most state consumer privacy statutes, including the California Consumer Privacy Act as amended, because HIPAA governs it instead. That exemption covers the records in the platform. It does not cover information a person sends Metaclinic directly as a visitor or a prospective customer, and for that information the rights below apply wherever a person's state grants them.

  • To know what personal information Metaclinic holds about you, where it came from, and why it is held.
  • To have it corrected, or deleted where no legal obligation requires it to be kept.
  • To receive a copy in a portable form.
  • Not to be discriminated against for exercising any of these.
  • To opt out of sale or of sharing for cross-context behavioral advertising — neither of which occurs, so there is nothing to opt out of.

Write to service@meta.clinic to exercise any of these. Metaclinic responds within the period the applicable statute sets and will say what it is doing and why. There is no charge, and no account is required.

Where the data is

processing location

Metaclinic processes and stores data in the United States. It does not offer the platform for use in the European Economic Area or the United Kingdom, and does not rely on a cross-border transfer mechanism for those jurisdictions. If that changes, this policy changes first.

Children

not a consumer service

This website and the platform are sold to and operated by organizations, and neither is directed to children. Accounts exist for the clinicians, laboratory staff, billers, and firms a customer authorizes, never for patients and never for the general public. Records concerning a minor patient are handled as the minor's own protected health information under HIPAA and applicable state law, including the state rules that govern when a parent or guardian may and may not access them — which is a clinical and legal determination held by the provider, not a website setting.

Changes to this policy

and the record of them

Metaclinic will follow this policy while it is in effect. A change that is material is published here with a new effective date and version before it applies, and the superseded version's dates are recorded so the policy in force on any given day can be established. Non-material corrections may be made without a version change.

Version history
VersionEffectiveWhat changed
2.019 August 2026Replaced the previous policy in full. Added an effective date and version history; made the business associate relationship the spine; stated retention, breach notification, compulsory process, and state privacy rights; recorded that no certification is held; removed sections carried over from a consumer product that did not describe this service.
Before 19 August 2026An undated policy inherited from an earlier product. It contained no effective date, described advertising cookies and children's accounts that do not exist here, and relied on a cross-border framework that no longer exists.

Questions, or a complaint

one address

Write to service@meta.clinic. It reaches us for anything specific to this policy and for anything else. A person who wants to complain to a regulator rather than to us may do so; for protected health information in the United States that is the Office for Civil Rights at the Department of Health and Human Services, and nothing here is a condition on that right.

This policy, and the engineering behind it

This policy governs the website and the platform. It rests on engineering commitments — tenancy isolation, release scoping, and attestation — that are described elsewhere on this site as design documentation rather than as legal instruments. Where this policy and any such description differ, this policy governs; where this policy and your executed agreements differ, the agreements control.