Skip to content

BetaVadia is still being built. You will find rough edges — we would rather you found them than your patients did. Report something broken

Privacy Policy

Last updated: August 20, 2026

Vadia Health is operated by Pragmatic Business Solutions, LLC, a Texas limited liability company in Rio Grande City, Texas. This policy explains how we handle information about the practices that use Vadia, the clinicians and staff who work in them, the clients they serve, and visitors to our website. It applies to vadiahealth.com, the Vadia Health application, the client portal, and our mobile apps.

1. The two roles, and why the difference matters

Vadia plays two distinct roles, and which one applies determines who you go to with a request. When a practice uses Vadia to schedule, chart, message, or bill, the practice decides what is collected and why — the practice is the covered entity under HIPAA and the owner of the clinical record, and Vadia is its business associate and service provider, acting only on the practice's documented instructions. We do not decide what goes in a client's chart, we do not use a client's clinical information for our own purposes, and we do not respond directly to requests about a client's health record. Separately, for our own account, billing, support, and marketing-website data — the information we need to run Vadia as a business — we act for ourselves and this policy governs directly. If you are a client of a practice, direct requests about your health record to that practice; see the section on rights in your health record below.

2. Information we handle for practices

On behalf of a practice, the Service handles whatever that practice puts into it. In ordinary use that includes client identity and contact details; appointment and scheduling data; clinical documentation such as intake forms, assessments, progress notes, treatment plans, diagnoses, and mood entries; telehealth session metadata and, where the practice enables and consent is obtained, session recordings and transcripts; secure messages between the care team and clients; e-signatures and signed consent artifacts; insurance, eligibility, claims, and payment records; and communications sent by email, SMS, voice, or fax. Almost all of this is protected health information (PHI). It belongs to the practice and its clients, not to Vadia.

3. Information we handle for ourselves

For our own purposes we handle: account information for the people who use Vadia (name, work email, role, organization, language and interface preferences, authentication and multi-factor credentials); practice and business information (clinic name, subdomain, plan, add-ons, seat counts, and billing history); support correspondence; security and audit records (sign-in events, IP address, device and browser information, and an append-only audit trail of actions taken in the Service); and, on our public website, the limited analytics described in our Cookie Policy. Payment card details are handled by our payment processor and never reach our servers.

4. Where information comes from

Most information reaches us from you: from a practice and its staff as they use the Service, and from clients and guardians who complete forms or use the client portal at their practice's invitation. Some reaches us from third parties acting for a practice — for example eligibility and claim responses returned by a clearinghouse or payer, delivery receipts from our communications provider, and payment status from our payment processor. Our website collects only what your browser sends and what the cookie categories you have consented to permit.

5. Why we use information

We use information to provide, secure, and support the Service: to authenticate users and enforce roles and permissions; to deliver scheduling, documentation, telehealth, messaging, forms, billing, and communications features; to detect, investigate, and prevent fraud, abuse, and security incidents; to keep the audit trail required of a business associate; to bill for the Service and collect payment; to respond to support requests; to meet legal, regulatory, and professional-record obligations; and to maintain and improve reliability, performance, and safety. We use PHI only as the Business Associate Agreement and HIPAA permit — to provide the Service to the practice, for our own limited management and administration, and to carry out our legal responsibilities.

6. We do not sell personal information

We do not sell personal data, and we do not sell, share, or process personal data for targeted advertising or cross-context behavioral advertising. We do not sell sensitive personal data, including health data or biometric data, and we do not use client PHI for advertising, for profiling that produces legal or similarly significant effects, or to train general-purpose artificial-intelligence models. Because we do not carry on that processing at all, there is nothing for a universal opt-out preference signal such as Global Privacy Control to switch off; our marketing site sets no advertising cookies.

7. Protected health information and HIPAA

Where we handle PHI we do so as a business associate under the Health Insurance Portability and Accountability Act and the HITECH Act, on the terms of our Business Associate Agreement, which is offered to every practice and incorporated into our Terms of Service. That agreement — not this policy — governs our permitted uses and disclosures of PHI, our safeguards, our duty to report security incidents and breaches, the flow-down of those duties to subcontractors, and what happens to PHI when the relationship ends. Where this policy and the Business Associate Agreement conflict as to PHI, the Business Associate Agreement controls.

8. Texas medical-records and mental-health confidentiality law

Vadia is built for Texas behavioral health, and Texas imposes duties beyond HIPAA. As a person who comes into possession of protected health information in the course of business, Vadia is a covered entity in the broad sense used by the Texas Medical Records Privacy Act (Texas Health and Safety Code Chapter 181, added by HB 300), and we handle information accordingly: we do not disclose PHI for marketing without the authorization that statute requires, we train our workforce on the state and federal law applicable to the PHI they handle, and we support the electronic-disclosure notice and standard authorization obligations that fall on practices. Communications between a mental-health professional and a client, and the records of the identity, diagnosis, evaluation, or treatment of a client, are separately confidential under Texas Health and Safety Code Chapter 611; the Service is designed so that access to those records is limited to the practice's own workforce on a least-privilege basis, and so that a practice can act on a client's statutory right of access and the narrow grounds on which a professional may deny it.

9. Substance use disorder records

Records of the identity, diagnosis, prognosis, or treatment of a client maintained in connection with a federally assisted substance use disorder program receive additional protection under 42 U.S.C. § 290dd-2 and 42 CFR Part 2, including limits on redisclosure that survive the disclosure itself. Where a practice tells us it operates a Part 2 program, we handle those records under the segmentation and consent-tracking controls the Service provides. Whether a given record is a Part 2 record, and whether a valid consent exists for a particular disclosure, is determined by the practice.

10. Minors, guardians, and legally authorized representatives

The Service supports minor clients and the parents, conservators, guardians, and other legally authorized representatives who act for them. Who may see a minor's record, and what a minor may consent to on their own, is set by law and by the practice — not by Vadia. In Texas that includes the parental right of access to a child's records under the Texas Family Code, a minor's ability to consent to counseling in certain circumstances, and the professional's judgment about disclosure. A guardian linked to a ward receives that ward's notifications and can act in the portal on the ward's behalf to the extent the practice permits; the underlying record remains the ward's. Vadia does not knowingly collect information directly from children through our marketing website.

11. Artificial intelligence

AI features are optional, off unless a practice turns them on, and designed to assist rather than decide. Every AI-assisted output — a drafted note, a suggested code, a summary — is decision support that must be reviewed, corrected, and signed by a licensed professional before it becomes part of a record or is relied upon in care. Vadia does not use client PHI to train general-purpose or third-party models, and our AI subprocessor is engaged under terms that prohibit training on our data and require zero retention. We disclose AI assistance in the record so a reviewer can see it, and no AI feature may be enabled for PHI until a business associate agreement with the model provider is in place. See our Subprocessors page for who processes what.

12. De-identified and aggregate data

We create de-identified and aggregate data from use of the Service. We de-identify in accordance with the HIPAA de-identification standard at 45 CFR § 164.514, using Safe Harbor (removal of the eighteen categories of identifiers) and/or Expert Determination. De-identified data is not PHI and does not identify you, any client, or any practice. We use it to operate, secure, and improve the Service, and — where a practice has not opted out — to publish public-health and research statistics, including through an open-data interface. Two safeguards apply: any published figure derived from fewer than eleven individuals is suppressed, and we will not attempt to re-identify anyone, nor authorize anyone else to. This is described in full in section 9 of our Terms of Service.

13. How we protect information

Every tenant's data is isolated at the database level by row-level security, so one practice's records are unreachable from another's session rather than merely unrequested by the application. We encrypt data in transit and at rest, require multi-factor authentication for privileged access and step-up verification for sensitive administrative actions, enforce least-privilege roles, and maintain a tamper-evident, hash-chained audit trail of access and changes. Protected health information is kept out of application logs, URLs, error reports, and analytics by design, and out of systems that have no business seeing it — our payment processor receives opaque identifiers and never clinical data. We take backups, test restoration, and maintain a contingency plan. No system is perfectly secure, and we do not claim otherwise.

14. Where information is stored

Vadia stores customer data, including protected health information and backups, on infrastructure located in the United States, consistent with Texas requirements for the storage of electronic medical records. Certain subprocessors operate globally distributed networks; where that is the case we say so on our Subprocessors page, and we contract for United States processing and storage of PHI. We do not transfer PHI outside the United States for our own purposes.

15. How long we keep information

A practice's records belong to the practice and are kept for as long as the practice's account is active, and thereafter as the Business Associate Agreement, the Terms, and law require. Retention periods for clinical records are set by professional and state law and by the practice, not by Vadia; Texas licensing rules require behavioral health records to be retained for defined periods, and Vadia does not delete a record simply because a subscription ended. On termination we make customer data available for export for a limited period, after which we delete or de-identify it in the ordinary course, subject to legal-hold and retention obligations. Audit and security records are kept for the period HIPAA requires. Backups age out on a fixed schedule, so deletion of a live record is reflected in backups over that cycle rather than instantly.

16. Who we share information with

We share information with: (a) subprocessors that help us run the Service — hosting, storage, communications, telehealth, payments, clearinghouse, and AI — each engaged under contract, and each engaged under a business associate agreement where it handles PHI; (b) a practice's own designated recipients, at the practice's direction, such as a payer, clearinghouse, or referral partner; (c) professional advisors bound by confidentiality; (d) an acquirer in a merger, acquisition, financing, or sale of assets, subject to this policy and to the Business Associate Agreement; and (e) government or legal authorities where required by law or valid legal process, or where necessary to protect rights, safety, or the integrity of the Service. Where the law permits, we will tell the affected practice before disclosing its data in response to legal process, so it can seek protection. We do not share PHI for any purpose the Business Associate Agreement does not permit. The current list is on our Subprocessors page.

17. Email, text messages, and calls

The Service sends transactional messages — verification and password emails, appointment reminders, form assignments, portal notifications — by email, SMS, push, and voice. Text-message and voice contact with a client requires that client's prior express consent, captured and recorded per number, and consent is revocable at any time; replying STOP to a text stops further texts to that number, and we honor the revocation across the platform. Practices are responsible for obtaining and maintaining consent for the people they contact, and for compliance with the federal Telephone Consumer Protection Act and Texas telephone-solicitation law (Texas Business and Commerce Code Chapters 302 and 305). We do not send marketing messages to a practice's clients. Message content is kept minimal and clinically non-specific by design, because a message may be seen on a lock screen by someone other than the client.

18. Cookies and our website

Our public website uses only first-party storage and asks for consent before setting anything beyond what is strictly necessary. What each category may collect, how long it lasts, and how to change your choice at any time is described in our Cookie Policy. The signed-in application uses only the storage required to keep you authenticated and to remember interface preferences.

19. Your privacy rights

Where the Texas Data Privacy and Security Act (Texas Business and Commerce Code Chapter 541) applies to data we control, you may confirm whether we process your personal data and access it; correct inaccuracies; obtain a portable copy; delete it; and opt out of sale or targeted advertising — which, as stated above, we do not carry on. Residents of other states with comparable laws have comparable rights. To exercise a right, write to [email protected] with enough detail for us to identify your records; we will respond within the time the applicable law allows and may need to verify your identity first. If we decline, we will tell you why and how to appeal, and we will decide an appeal in writing within the statutory period; if we deny the appeal we will give you a way to complain to the Texas Attorney General. Note that most health information in the Service is exempt from these statutes because it is governed by HIPAA — and it is held for a practice, not for us, so requests about it go to the practice.

20. Rights in your health record

If you are a client of a practice that uses Vadia, your rights in your health record — to inspect and obtain a copy, to request an amendment, to receive an accounting of disclosures, to request restrictions or confidential communications, and to receive that practice's Notice of Privacy Practices — run against the practice, which holds and controls the record. Contact your practice, not Vadia. Vadia's job is to give the practice the tooling to honor those requests, and to pass along to the practice any request that reaches us by mistake. Under Texas Health and Safety Code Chapter 611 a mental-health professional may, in defined circumstances, deny access to portions of a record and must give written notice; that judgment belongs to the professional.

21. Security incidents and breach notification

If we discover a breach of unsecured protected health information, we notify the affected practice without unreasonable delay and within the window our Business Associate Agreement sets, which is shorter than the sixty-day outer limit HIPAA allows, and we give the practice the information it needs to make its own notifications under 45 CFR §§ 164.404-164.408. For personal information that is not PHI, we notify as the Texas Identity Theft Enforcement and Protection Act (Texas Business and Commerce Code Chapter 521) and other applicable breach-notification law require, including notice to the Texas Attorney General where the statute requires it. We maintain an incident-response plan and investigate every report.

22. Biometric information

Vadia does not capture or use a biometric identifier — a retina or iris scan, fingerprint, voiceprint, or record of hand or face geometry — to identify anyone, and we do not sell, lease, or otherwise disclose biometric identifiers, within the meaning of Texas Business and Commerce Code Chapter 503. Telehealth video and any session audio a practice records with consent are clinical content handled as PHI under the Business Associate Agreement; they are not used to build a biometric template.

23. Children's privacy

Our marketing website is directed to health care professionals and is not intended for children under 13, and we do not knowingly collect personal information from children through it. Minor clients receive care through a practice; information about them enters the Service through that practice and its consenting guardians, and is handled as PHI under the Business Associate Agreement rather than under this section.

24. Changes to this policy

We may update this policy. If we make a material change we will update the date above, and where the change materially affects how we handle personal information we will give reasonable advance notice through the Service or by email before it takes effect. Prior versions are available on request. Continued use of the Service after a change takes effect means you accept the updated policy.

25. Contact us

Questions, requests, and privacy complaints may be sent to [email protected] or by mail to Pragmatic Business Solutions, LLC, Rio Grande City, Texas. If you believe your health-information rights have been violated you may also complain to your practice, or to the U.S. Department of Health and Human Services Office for Civil Rights; we will not retaliate against anyone for making a complaint.