TreatPath is a web application for dental practices. This Privacy Policy describes how TreatPath handles data collected through our website (gettreatpath.com) and our application.
When you visit gettreatpath.com, we may collect:
We do not sell, rent, or share your contact information with third parties for marketing purposes.
TreatPath stores the following on its cloud infrastructure, isolated per practice:
None of this data is transmitted to TreatPath or stored on any TreatPath server. Your practice retains full ownership and control of all patient data at all times.
TreatPath uses Anthropic's Claude API to process screenshot images for OCR (optical character recognition). When you use the image upload feature, the captured image is transmitted to Anthropic's servers for processing and the extracted text is returned to your application.
This is the only instance in which any data leaves your local network. The image may contain procedure codes and fee information visible in your practice management software. Anthropic's data use policy governs how this data is handled on their end. Per Anthropic's policy, API data is not used to train their models.
We recommend ensuring no patient-identifying information (names, dates of birth) is visible in the captured screenshot.
Because TreatPath stores and processes protected health information on behalf of your practice, TreatPath acts as a business associate as defined by HIPAA. A signed Business Associate Agreement is required before a covered entity uses TreatPath with protected health information. Request one at support@gettreatpath.com.
HIPAA does not provide for certification of software, so no vendor can accurately describe itself as "HIPAA certified." TreatPath is built to support your practice's obligations: encryption in transit and at rest, per-practice data isolation, access logging, and automatic sign-out after inactivity. See our Security page for the current list of controls and their status.
TreatPath is in beta and is completing its Business Associate Agreements with subprocessors and its formal risk analysis ahead of general availability. Practices with formal compliance programs should review this with their compliance officer before use.
Treatment plan data is retained for as long as your practice's account is active, so that signed plans remain available to you as a record of what the patient agreed to. A practice may request deletion of its data at any time by contacting support@gettreatpath.com. Where a signed plan forms part of your practice's own record-keeping obligations, retention is determined by your practice, not by TreatPath.
Email addresses collected through our waitlist and demo forms are retained until you request removal. To request deletion, contact us at support@gettreatpath.com.
This is a prototype privacy policy for beta use. A legally verified privacy policy will replace this document before TreatPath becomes generally available. We will notify beta partners of any material changes.
For any questions about this privacy policy or how TreatPath handles data, contact us at support@gettreatpath.com.