Privacy Policy
Last Updated: April 7, 2026
Welcome to Visit Confirmed, Inc. (“VisitConfirmed,” “we,” “our,” or “us”).
VisitConfirmed provides AI-powered patient engagement tools, including appointment reminders, confirmations, and rescheduling support via SMS, email, and voice communication (the “Services”).
Your privacy is important to us. This Privacy Policy explains how we collect, use, disclose, and safeguard your information.
1. Scope of This Policy
This Privacy Policy applies to:
- Visitors to visitconfirmed.com
- Healthcare organizations and business customers (“Customers”)
- Patients and end users who receive communications through our Services
If you are a patient receiving a reminder or message from VisitConfirmed on behalf of your healthcare provider, your healthcare provider may also have its own privacy policy governing your information.
2. Information We Collect
We collect information in three primary ways:
A. Information Provided by Customers (Healthcare Organizations)
Our Customers may provide:
- Patient name
- Phone number
- Email address
- Appointment date/time
- Appointment type
- Provider name
- Communication preferences
- Message history and responses (RSVPs, confirmations, cancellations)
In some cases, this information may include Protected Health Information (“PHI”) as defined under HIPAA.
Phone Numbers
We collect phone numbers provided by healthcare providers on behalf of their patients. Phone numbers are used solely to send appointment-related SMS messages. We do not sell or share phone numbers with third parties for marketing purposes.
B. Information Automatically Collected
When you use our website:
- IP address
- Browser type
- Device type
- Pages visited
- Referring URL
- Cookies and analytics data
We use cookies and similar technologies to improve performance and understand usage.
C. Communications Data
When patients interact with VisitConfirmed messages:
- SMS replies
- Email replies
- Voice responses (DTMF tones or speech-to-text where enabled)
- Delivery status and timestamps
Voice calls may be recorded or transcribed if enabled by the Customer and permitted by law.
3. How We Use Information
We use collected information to:
- Send appointment reminders and confirmations
- Process RSVP responses
- Facilitate rescheduling workflows
- Provide SMS, email, and voice communication
- Improve reminder effectiveness using AI tools
- Provide analytics to Customers
- Maintain system security and reliability
- Comply with legal obligations
We do not sell patient data.
4. HIPAA & Protected Health Information
VisitConfirmed may act as a Business Associate under the Health Insurance Portability and Accountability Act (“HIPAA”) when handling PHI on behalf of healthcare Customers.
Where applicable:
- We enter into Business Associate Agreements (BAAs) with Customers.
- We implement administrative, technical, and physical safeguards designed to protect PHI.
- We limit access to PHI to authorized personnel.
If you are a patient, your healthcare provider controls your medical information and is responsible for HIPAA compliance related to your care.
5. SMS & Voice Communications
By providing a phone number to your healthcare provider, you consent to receive appointment-related messages via:
- SMS/text message
- Automated voice calls
- AI-assisted voice reminders
Standard message and data rates may apply.
You may opt out of SMS messages at any time by replying “STOP.” Voice call opt-out instructions will be provided during calls where applicable.
6. Email Communications
Appointment-related emails are transactional in nature. You may manage communication preferences through your provider when available.
7. AI & Automation
VisitConfirmed may use AI tools to:
- Personalize reminder language
- Optimize timing
- Interpret patient replies
- Assist with scheduling workflows
AI tools operate within strict privacy and security safeguards. We do not use PHI to train public AI models.
8. How We Share Information
We may share information with:
- Telecommunications providers (e.g., SMS and voice carriers)
- Email delivery providers
- Cloud hosting providers
- Analytics providers
- Subprocessors supporting our infrastructure
All service providers are contractually obligated to safeguard information.
We do not sell personal information.
We may disclose information:
- To comply with legal requirements
- To protect rights and safety
- In connection with a merger, acquisition, or corporate transaction
9. Data Security
We implement reasonable administrative, technical, and physical safeguards including:
- Encryption in transit (TLS)
- Encryption at rest
- Role-based access controls
- Audit logging
- Regular security reviews
No system can be guaranteed 100% secure.
10. Data Retention
We retain information:
- As required to provide Services
- As required by law
- As defined in Customer agreements
PHI retention is governed by agreements with healthcare Customers.
11. Your Rights
Depending on your location, you may have rights to:
- Access your personal information
- Request correction
- Request deletion (where applicable)
- Restrict certain processing
Patients should direct privacy-related requests to their healthcare provider first.
12. Cookies & Analytics
Necessary Cookies
We set a small number of cookies that are required for our website to function. These do not require your consent:
- Session cookie — maintains your login session when you are signed in
- CSRF cookie — protects form submissions against cross-site request forgery
- Cookie consent cookie — remembers whether you accepted or rejected non-essential cookies
Analytics Cookies
With your consent, we may use analytics tools to understand how visitors use our website, including pages visited, time on site, and referral sources. These cookies are only set after you click “Accept” on our cookie consent banner.
If you reject non-essential cookies, no analytics data is collected.
Managing Your Preferences
You can change your cookie preferences at any time by clicking the “Cookie Settings” link in the footer of any page. You may also disable cookies through your browser settings.
Global Privacy Control
We honor the Global Privacy Control (GPC) signal. If your browser sends a GPC signal, we treat it as a request to reject non-essential cookies and will not load analytics tracking.
13. Children’s Privacy
Our Services are not directed to children under 13. Healthcare Customers are responsible for appropriate parental consent where required.
14. International Users
Our Services are intended for use in the United States. If you access the Services from outside the U.S., your information may be transferred to the United States.
15. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated version with a revised “Last Updated” date.
16. Contact Us
Visit Confirmed, Inc.
#1010
8 Gurnet Rd, Suite 7
Brunswick, ME 04011
United States
Email: privacy@visitconfirmed.com
Website: https://visitconfirmed.com