Privacy Policy
Effective Date: March 1, 2021
Last Updated: July 26, 2026
InstaMD Inc (“InstaMD,” “we,” “us,” or “our”) provides fully managed remote patient monitoring and related care management services to healthcare organizations. We value your privacy and are committed to protecting your information.
This Privacy Policy (“Policy”) explains how we collect, use, share, and safeguard information, and outlines your rights under California law, including the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA). It applies to our website at https://instamd.co (the “Website”), to the InstaMD platform and related services (the “Services”), and to the InstaMD RPM browser extension (the “Extension”), which is distributed through the Chrome Web Store and described in Section 2.
Protected health information. The Services and the Extension handle protected health information (“PHI”) on behalf of healthcare organizations (“Practices”). The Practice is the covered entity, and InstaMD acts as a business associate under a Business Associate Agreement (“BAA”) with that Practice. Our handling of PHI is governed by that agreement and by HIPAA in addition to this Policy. Where this Policy and an executed BAA differ with respect to PHI, the BAA controls.
1. Information We Collect
1.1 Categories of Information
The categories below use the definitions applied by the Chrome Web Store and reflect the disclosures made on our Chrome Web Store listing for the Extension. We collect:
- Personally identifiable information — the patient identifier and patient name used to retrieve and label the correct monitoring record, and the name, email address and telephone number you submit on the Website
- Health information — enrollment status, adherence for the current monitoring cycle, recent physiologic readings such as blood pressure and heart rate, open alerts, and connected devices
- Authentication information — the OAuth token or session reference issued at setup, used to authenticate requests and scope them to a single Practice; no user passwords are stored
- Website content — the patient identifier read from the electronic health record chart page a user has open; no other page content is read or transmitted
- User activity — records that an authorized user viewed a given patient record, and when, in support of the Practice’s audit obligations; we do not perform keystroke, mouse, scroll, or network monitoring
We do not collect:
- Financial or payment information
- Personal communications
- Location information
- Web history — the Extension does not track browsing or navigation activity
1.2 Information You Provide
- Name, email address, and telephone number
- Business or practice details
- Information submitted through forms, demonstration requests, or customer support
- Account information, where applicable
1.3 Information Collected Automatically on the Website
- IP address, device type, and browser type
- Pages visited, time spent, and referring URLs
- Cookie and tracking technology data
This automatic collection applies to the Website only. The Extension does not use cookies or tracking technologies and does not collect browsing or navigation history.
1.4 Health Information
The Services and the Extension handle personal health information, including enrollment status, adherence, and physiologic readings. This information is handled under HIPAA and the applicable BAA. Browsing the Website alone does not create a provider–patient relationship and does not involve PHI.
2. The InstaMD RPM Browser Extension
2.1 Single Purpose
The Extension has one purpose: to display a patient’s existing remote patient monitoring record, drawn from the Practice’s own InstaMD account, alongside the patient chart the user already has open in a supported electronic health record (“EHR”) web application.
It is a workforce tool for personnel of Practices holding an active InstaMD account, and is not made available to patients or to the general public. It is read-only with respect to the EHR: it does not write to, modify, or submit data into the EHR.
2.2 What the Extension Accesses
- Patient identifier from the page being viewed. When an authorized user invokes the Extension on a patient chart, a content script reads the patient identifier shown on that page in order to request the correct record. This happens only on the tab where the user invokes the Extension, and only on the origins listed in Section 2.4. No other page content is read or transmitted.
- Monitoring record from the Practice’s InstaMD account. Using that identifier, the Extension retrieves the patient’s monitoring summary: patient name, enrollment status, adherence for the current monitoring cycle, recent physiologic readings such as blood pressure and heart rate, open alerts, and connected devices.
- Practice and authorization information. At one-time setup, the Extension collects the Practice identifier entered by the user and, through a standard OAuth authorization flow, receives a token or session reference used to authenticate subsequent requests and scope them to that Practice.
- Access records. The Extension records that an authorized user viewed a given patient record, together with the time of access, in support of the audit obligations of the Practice.
2.3 What Is Stored on the Device
The Extension stores the following in browser extension storage on the local device:
- The Practice shortname or identifier entered at setup
- An optional Practice display name
- The OAuth token or session reference established at setup
- Minor interface state, such as whether the panel is expanded
Patient information is not stored by the Extension. Monitoring data is retrieved on demand and held in memory only while the panel is open. It is not written to extension storage or to any other persistent location in the browser.
2.4 Permissions
- storage — retains the setup configuration described in Section 2.3, so staff are not asked to reconfigure or re-authenticate on every page load
- activeTab — provides access to the tab being viewed, at the moment the user invokes the Extension, in order to read the patient identifier
- scripting — injects the content script that locates the patient identifier and renders the panel into the page
- identity — completes the one-time OAuth sign-in to the Practice’s InstaMD tenant
- host permissions — the InstaMD API origin (api.myinstamd.com), which the Extension calls to retrieve monitoring data, and the EHR application origins on which the panel is designed to appear: static.practicefusion.com, app.tebra.com, pm.officeally.com, athenanet.athenahealth.com, *.pointclickcare.com, and *.eclinicalweb.com
The Extension does not request access to all websites and does not run on unrelated sites. Where an EHR vendor assigns each customer its own subdomain, the corresponding entry above is scoped to that vendor’s single domain; no entry matches arbitrary domains or all URLs.
Practices operating a self-hosted EHR may grant the Extension access to their own EHR origin from the setup page. That permission is requested at the time of setup, applies only to the origin the Practice specifies, and can be revoked at any time through the browser’s extension settings.
Supported EHR applications may change as adapters are added or retired, and the address used for a given EHR can differ between hosting environments and vendor editions. The authoritative list for any release is the set of host permissions declared in that version’s package. For the EHR-specific URL that applies to your environment, or for further detail about how the Extension operates with a particular EHR, contact us at info@instamdinc.com.
2.5 Google User Data
The Extension uses the browser identity API solely to complete the OAuth authorization flow to the Practice’s InstaMD tenant. It does not request or access a user’s Google account identity, email address, or profile information, and it collects no Google user data.
2.6 Remote Code
All executable code used by the Extension is contained in the package distributed through the Chrome Web Store. The Extension does not load or execute remotely hosted code, and does not use eval(), new Function(), or dynamic import from remote URLs. Responses received from the InstaMD API are data, which the Extension parses and renders; no response is evaluated as code.
2.7 Ending Access and Deleting Stored Information
Selecting Sign out or Reset on the Extension’s setup page clears the stored Practice identifier and authorization reference for that browser and ends that browser’s access. Uninstalling the Extension removes its local storage. Requests concerning records held in the InstaMD platform should be directed to the Practice, which is the covered entity for those records, or to us at info@instamdinc.com.
3. How We Use Information
We may use information for the following purposes:
- To display a patient’s existing monitoring record to authorized workforce members of the Practice that holds that record
- To authenticate users and scope access to the correct Practice
- To maintain access records supporting the Practice’s audit obligations
- To provide, operate, secure, and improve the Website, the Services, and the Extension
- To respond to inquiries and deliver customer support
- To process service or demonstration requests
- To analyze Website performance and usage trends
- To prevent fraud and abuse, and to comply with legal and regulatory requirements
4. Limited Use and Data Commitments
Our use and transfer of information received through the Extension adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements. Specifically:
- We do not sell user data, and we do not share it as those terms are defined by the CCPA and CPRA
- We do not transfer user data to third parties except to subprocessors acting under written agreement and, where PHI is involved, under a BAA; in connection with a business transfer as described in Section 5; or where required by law
- We do not use or transfer user data for any purpose unrelated to the single purpose stated in Section 2.1
- We do not use or transfer user data to determine creditworthiness or for lending purposes
- We do not use it for advertising, marketing, or profiling, and we do not use it to train generalized machine learning models
- We do not use sensitive personal information for purposes not permitted by California law, including the CPRA
5. How We Share Information
5.1 Service Providers and Subprocessors
We may share information with trusted vendors that assist us with services such as hosting, infrastructure, analytics, security, customer relationship management, and customer support, under written agreement and, where PHI is involved, under a BAA. These parties may use the information only to provide services to us.
5.2 Legal Compliance
We may disclose information to comply with applicable laws, regulations, subpoenas, or government requests, and to establish or defend our legal rights.
5.3 Business Transfers
In connection with mergers, acquisitions, financing, or sale of company assets, information may be transferred to another entity, provided the receiving party agrees to maintain protections consistent with this Policy and, for PHI, with the applicable BAA.
5.4 No Sale or Sharing
We do not sell personal information, and we do not share it as those terms are defined by the CCPA and CPRA.
6. Data Retention
We retain personal information only for as long as necessary to:
- Fulfill the purposes described in this Policy
- Meet legal, regulatory, or contractual obligations, including those in an applicable BAA
- Support our business operations
Configuration stored by the Extension persists on the device until the user signs out, resets the connection, or uninstalls the Extension. Retention of monitoring records held in the InstaMD platform is governed by the Practice’s agreement with InstaMD. When information is no longer needed, it is securely deleted, anonymized, or de-identified in accordance with applicable laws.
7. Security
We implement technical, administrative, and physical safeguards designed to protect personal information, including encryption, access controls, and secure infrastructure. Connections between the Extension and InstaMD are made over TLS. Authorization uses a standard OAuth flow, and user passwords are never stored in the Extension. Every patient lookup is scoped to the Practice identifier established at setup, so the Extension cannot return records belonging to another Practice.
Because a browser connection is established per browser rather than per individual user, Practices should manage shared workstations under their own workstation security and access policies. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. Children’s Privacy
The Website and the Extension are not intended for children, and we do not knowingly collect personal information from children through them. The Extension is a workforce tool and is not made available to patients. Where a Practice monitors a minor patient, that record is handled under the Practice’s own obligations and the applicable BAA. If you believe that a child has provided information to us, please contact us so we can take appropriate steps to remove the information.
9. Your California Privacy Rights
If you are a California resident, you may have the following rights under the CCPA and CPRA:
9.1 Right to Know
You may request that we disclose the categories and specific pieces of personal information we have collected about you, the sources of that information, the purposes for collecting it, and the categories of third parties with whom we share it.
9.2 Right to Delete
You may request that we delete personal information we collected from you, subject to certain legal and operational exceptions.
9.3 Right to Correct
You may request that we correct inaccurate personal information that we maintain about you.
9.4 Right to Opt-Out of Sale or Sharing
We do not sell or share your personal information as defined under the CCPA and CPRA.
9.5 Right to Limit Use of Sensitive Personal Information
We do not use sensitive personal information beyond permitted purposes that support our operations.
9.6 Right to Non-Discrimination
We will not discriminate against you for exercising any of your privacy rights, such as by denying services, charging different prices, or providing a different level or quality of services.
9.7 Submitting a Request
To exercise your rights, please contact us by email at info@instamdinc.com. Include your name, your state of residence, and a description of the request you are making. We may need to verify your identity before processing your request. Requests concerning medical records held by a Practice should be directed to that Practice.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, or legal requirements. When we do, we will revise the “Last Updated” date at the top of this page. Where a change affects the Extension, we will update the corresponding disclosures on our Chrome Web Store listing at the same time. Updated policies become effective upon posting on the Website.
11. Contact Us
If you have any questions about this Privacy Policy, please contact us at:
InstaMD Inc
25350 Magic Mountain Pkwy, Suite 300
Valencia, CA 91355
Email: info@instamdinc.com