TreatPath is a web application for dental practices, operated by TreatPath Inc., a Delaware corporation. This Privacy Policy describes how TreatPath handles data collected through our website (gettreatpath.com) and our application.
When you visit gettreatpath.com, we may collect:
We do not sell, rent, or share your contact information with third parties for marketing purposes.
TreatPath stores the following on its cloud infrastructure, isolated per practice:
What TreatPath does not collect or store: date of birth, Social Security number, insurance member or subscriber ID, medical or health history, clinical notes, x-rays or images beyond the treatment-plan region you capture, and payment card details. We keep only what is needed to present and record a treatment plan.
This data is held by TreatPath on cloud infrastructure operated by our hosting and database provider under an executed Business Associate Agreement, encrypted in transit and at rest, and isolated so that no practice can read another practice's records. Your practice retains ownership of its patient data at all times; TreatPath processes it solely to provide the service and never sells it, shares it for marketing, or uses it to train AI models.
TreatPath uses Anthropic's Claude API to process screenshot images for OCR (optical character recognition). When you use the image upload feature, the captured image is transmitted to Anthropic's servers for processing and the extracted text is returned to your application.
The image may contain whatever is visible in your practice management software, including patient identifiers. This processing is covered by an executed Business Associate Agreement with Anthropic on a HIPAA-configured, zero-retention environment: the image is not retained after processing and is not used to train their models.
Aside from this and the cloud storage described above, no patient data leaves the system. Our error monitoring is configured to exclude patient information, and we verify that.
Subscriptions are billed by card through Stripe, our payment processor. When a practice subscribes, Stripe collects the card details and billing address directly on its own secure pages; TreatPath receives only a customer reference, the subscription status and invoice records, and never sees or stores card numbers. The information Stripe holds is the practice's business billing information — it does not include any patient information, and Stripe has no access to treatment plans or the application. Stripe's handling of that data is described in its own privacy policy at stripe.com/privacy.
Because TreatPath stores and processes protected health information on behalf of your practice, TreatPath acts as a business associate as defined by HIPAA. A signed Business Associate Agreement is required before a covered entity uses TreatPath with protected health information. Request one at support@gettreatpath.com.
HIPAA does not provide for certification of software, so no vendor can accurately describe itself as "HIPAA certified." TreatPath is built to support your practice's obligations: encryption in transit and at rest, per-practice data isolation, access logging, and automatic sign-out after inactivity. See our Security page for the current list of controls and their status.
TreatPath maintains executed Business Associate Agreements with its subprocessors and a documented risk analysis under its adopted security program, reviewed as the service changes. Practices with formal compliance programs are welcome to review these with their compliance officer; request the current documentation at support@gettreatpath.com.
Treatment plan data is retained for as long as your practice's account is active, so that signed plans remain available to you as a record of what the patient agreed to. A practice may request deletion of its data at any time by contacting support@gettreatpath.com. Where a signed plan forms part of your practice's own record-keeping obligations, retention is determined by your practice, not by TreatPath.
Email addresses collected through our waitlist and demo forms are retained until you request removal. To request deletion, contact us at support@gettreatpath.com.
We may update this policy as the service evolves. Material changes are notified to the email on each practice's account before they take effect, and the date at the top of this page always reflects the current version.
TreatPath Inc., a Delaware corporation. A mailing address is available on request. For any questions about this privacy policy or how TreatPath handles data, contact us at support@gettreatpath.com or (858) 215-4842.