Privacy Policy

Effective Date: March 1, 2021

Last Updated: July 26, 2026

InstaMD Inc (“InstaMD,” “we,” “us,” or “our”) provides fully managed remote patient monitoring and related care management services to healthcare organizations. We value your privacy and are committed to protecting your information.

This Privacy Policy (“Policy”) explains how we collect, use, share, and safeguard information, and outlines your rights under California law, including the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA). It applies to our website at https://instamd.co (the “Website”), to the InstaMD platform and related services (the “Services”), and to the InstaMD RPM browser extension (the “Extension”), which is distributed through the Chrome Web Store and described in Section 2.

Protected health information. The Services and the Extension handle protected health information (“PHI”) on behalf of healthcare organizations (“Practices”). The Practice is the covered entity, and InstaMD acts as a business associate under a Business Associate Agreement (“BAA”) with that Practice. Our handling of PHI is governed by that agreement and by HIPAA in addition to this Policy. Where this Policy and an executed BAA differ with respect to PHI, the BAA controls.

1. Information We Collect

1.1 Categories of Information

The categories below use the definitions applied by the Chrome Web Store and reflect the disclosures made on our Chrome Web Store listing for the Extension. We collect:

We do not collect:

1.2 Information You Provide

1.3 Information Collected Automatically on the Website

This automatic collection applies to the Website only. The Extension does not use cookies or tracking technologies and does not collect browsing or navigation history.

1.4 Health Information

The Services and the Extension handle personal health information, including enrollment status, adherence, and physiologic readings. This information is handled under HIPAA and the applicable BAA. Browsing the Website alone does not create a provider–patient relationship and does not involve PHI.

2. The InstaMD RPM Browser Extension

2.1 Single Purpose

The Extension has one purpose: to display a patient’s existing remote patient monitoring record, drawn from the Practice’s own InstaMD account, alongside the patient chart the user already has open in a supported electronic health record (“EHR”) web application.

It is a workforce tool for personnel of Practices holding an active InstaMD account, and is not made available to patients or to the general public. It is read-only with respect to the EHR: it does not write to, modify, or submit data into the EHR.

2.2 What the Extension Accesses

2.3 What Is Stored on the Device

The Extension stores the following in browser extension storage on the local device:

Patient information is not stored by the Extension. Monitoring data is retrieved on demand and held in memory only while the panel is open. It is not written to extension storage or to any other persistent location in the browser.

2.4 Permissions

The Extension does not request access to all websites and does not run on unrelated sites. Where an EHR vendor assigns each customer its own subdomain, the corresponding entry above is scoped to that vendor’s single domain; no entry matches arbitrary domains or all URLs.

Practices operating a self-hosted EHR may grant the Extension access to their own EHR origin from the setup page. That permission is requested at the time of setup, applies only to the origin the Practice specifies, and can be revoked at any time through the browser’s extension settings.

Supported EHR applications may change as adapters are added or retired, and the address used for a given EHR can differ between hosting environments and vendor editions. The authoritative list for any release is the set of host permissions declared in that version’s package. For the EHR-specific URL that applies to your environment, or for further detail about how the Extension operates with a particular EHR, contact us at info@instamdinc.com.

2.5 Google User Data

The Extension uses the browser identity API solely to complete the OAuth authorization flow to the Practice’s InstaMD tenant. It does not request or access a user’s Google account identity, email address, or profile information, and it collects no Google user data.

2.6 Remote Code

All executable code used by the Extension is contained in the package distributed through the Chrome Web Store. The Extension does not load or execute remotely hosted code, and does not use eval(), new Function(), or dynamic import from remote URLs. Responses received from the InstaMD API are data, which the Extension parses and renders; no response is evaluated as code.

2.7 Ending Access and Deleting Stored Information

Selecting Sign out or Reset on the Extension’s setup page clears the stored Practice identifier and authorization reference for that browser and ends that browser’s access. Uninstalling the Extension removes its local storage. Requests concerning records held in the InstaMD platform should be directed to the Practice, which is the covered entity for those records, or to us at info@instamdinc.com.

3. How We Use Information

We may use information for the following purposes:

4. Limited Use and Data Commitments

Our use and transfer of information received through the Extension adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements. Specifically:

5. How We Share Information

5.1 Service Providers and Subprocessors

We may share information with trusted vendors that assist us with services such as hosting, infrastructure, analytics, security, customer relationship management, and customer support, under written agreement and, where PHI is involved, under a BAA. These parties may use the information only to provide services to us.

5.2 Legal Compliance

We may disclose information to comply with applicable laws, regulations, subpoenas, or government requests, and to establish or defend our legal rights.

5.3 Business Transfers

In connection with mergers, acquisitions, financing, or sale of company assets, information may be transferred to another entity, provided the receiving party agrees to maintain protections consistent with this Policy and, for PHI, with the applicable BAA.

5.4 No Sale or Sharing

We do not sell personal information, and we do not share it as those terms are defined by the CCPA and CPRA.

6. Data Retention

We retain personal information only for as long as necessary to:

Configuration stored by the Extension persists on the device until the user signs out, resets the connection, or uninstalls the Extension. Retention of monitoring records held in the InstaMD platform is governed by the Practice’s agreement with InstaMD. When information is no longer needed, it is securely deleted, anonymized, or de-identified in accordance with applicable laws.

7. Security

We implement technical, administrative, and physical safeguards designed to protect personal information, including encryption, access controls, and secure infrastructure. Connections between the Extension and InstaMD are made over TLS. Authorization uses a standard OAuth flow, and user passwords are never stored in the Extension. Every patient lookup is scoped to the Practice identifier established at setup, so the Extension cannot return records belonging to another Practice.

Because a browser connection is established per browser rather than per individual user, Practices should manage shared workstations under their own workstation security and access policies. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

8. Children’s Privacy

The Website and the Extension are not intended for children, and we do not knowingly collect personal information from children through them. The Extension is a workforce tool and is not made available to patients. Where a Practice monitors a minor patient, that record is handled under the Practice’s own obligations and the applicable BAA. If you believe that a child has provided information to us, please contact us so we can take appropriate steps to remove the information.

9. Your California Privacy Rights

If you are a California resident, you may have the following rights under the CCPA and CPRA:

9.1 Right to Know

You may request that we disclose the categories and specific pieces of personal information we have collected about you, the sources of that information, the purposes for collecting it, and the categories of third parties with whom we share it.

9.2 Right to Delete

You may request that we delete personal information we collected from you, subject to certain legal and operational exceptions.

9.3 Right to Correct

You may request that we correct inaccurate personal information that we maintain about you.

9.4 Right to Opt-Out of Sale or Sharing

We do not sell or share your personal information as defined under the CCPA and CPRA.

9.5 Right to Limit Use of Sensitive Personal Information

We do not use sensitive personal information beyond permitted purposes that support our operations.

9.6 Right to Non-Discrimination

We will not discriminate against you for exercising any of your privacy rights, such as by denying services, charging different prices, or providing a different level or quality of services.

9.7 Submitting a Request

To exercise your rights, please contact us by email at info@instamdinc.com. Include your name, your state of residence, and a description of the request you are making. We may need to verify your identity before processing your request. Requests concerning medical records held by a Practice should be directed to that Practice.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, or legal requirements. When we do, we will revise the “Last Updated” date at the top of this page. Where a change affects the Extension, we will update the corresponding disclosures on our Chrome Web Store listing at the same time. Updated policies become effective upon posting on the Website.

11. Contact Us

If you have any questions about this Privacy Policy, please contact us at:

InstaMD Inc
25350 Magic Mountain Pkwy, Suite 300
Valencia, CA 91355
Email: info@instamdinc.com