Long Health Privacy Policy

Effective Date: September 22, 2026 Last Reviewed: September 22, 2026 Version: 2.1

Long Health, Inc. (“Long Health,” “we,” “us,” or “our”) respects your privacy and is committed to protecting Personal Information entrusted to us.

This Privacy Policy describes how Long Health collects, uses, discloses, and protects Personal Information in connection with our public websites, business relationships, communications, mobile applications, and healthcare technology services.

Long Health also provides healthcare interoperability services and is a California-designated Qualified Health Information Organization (“QHIO”). Privacy practices specifically applicable to Long Health’s QHIO and California Data Exchange Framework (“DxF”) services are described separately in our Long Health QHIO Privacy Policy.

1. Scope

This Privacy Policy applies to Personal Information Long Health collects or processes in connection with:

  • our public websites;
  • our mobile applications;
  • inquiries submitted to Long Health;
  • customers and prospective customers;
  • business partners;
  • vendors and contractors;
  • authorized users of Long Health technology platforms;
  • sales and marketing activities;
  • customer support; and
  • general business operations.

This Privacy Policy does not replace the Notice of Privacy Practices of a healthcare provider, health plan, or other healthcare organization.

Protected Health Information (“PHI”) and other health information that Long Health processes on behalf of healthcare organizations may also be governed by HIPAA, Business Associate Agreements, interoperability agreements, the DxF, and other applicable requirements.

2. About Long Health

Long Health provides healthcare technology, interoperability, health information exchange, clinical workflow, data integration, documentation, transcription, and related services to healthcare providers, health plans, medical groups, hospitals, clinics, laboratories, and other authorized organizations.

Long Health does not provide medical diagnosis or treatment directly to patients.

Long Health does not currently operate a general direct-to-consumer patient portal through which individuals independently access, download, amend, delete, or manage their medical records.

When Long Health processes health information on behalf of a healthcare organization, the applicable healthcare organization remains responsible for the underlying medical record and its applicable patient privacy obligations.

For additional information concerning Long Health’s QHIO and health information exchange activities, please review our QHIO Privacy Policy.

3. Personal Information We Collect

The information we collect depends upon how an individual or organization interacts with Long Health.

Business and Contact Information

We may collect:

  • name;
  • company or organization;
  • job title;
  • business email address;
  • telephone number;
  • mailing address;
  • information submitted through contact forms;
  • correspondence; and
  • other information provided to us in connection with a business relationship.

Account and Authorized User Information

For individuals authorized by their organizations to use Long Health services, we may collect:

  • name;
  • business contact information;
  • organization;
  • username or account identifier;
  • authentication information;
  • permissions and role information;
  • application activity; and
  • support information.

Audio Recordings and Transcription Data

Certain Long Health services allow authorized users to record and submit audio through the Long Health mobile application.

When an authorized user records and submits audio through the mobile application, Long Health may collect and process:

  • the submitted audio recording;
  • information associated with the recording, including the authorized user, organization, case, encounter, or other applicable service information; and
  • a transcription generated from the submitted audio.

Audio recordings may contain Personal Information, PHI, or other sensitive information depending on the content of the recorded session.

The mobile application is used to capture and securely submit audio to Long Health. After submission, the audio may be processed as part of Long Health’s transcription and documentation services as described in this Privacy Policy.

Website and Technical Information

When someone visits our website or uses our services, we may automatically collect certain technical information, such as:

  • Internet Protocol address;
  • browser type;
  • device type;
  • operating system;
  • referring website;
  • pages viewed;
  • date and time of access;
  • approximate geographic information derived from an IP address;
  • application or website activity;
  • cookies or similar technology identifiers; and
  • security and system logs.

Customer and Transaction Information

We may collect information relating to:

  • contracts;
  • subscriptions;
  • invoices;
  • payments;
  • services purchased;
  • implementation activities;
  • customer support; and
  • other business transactions.

Payment information may be processed by third-party payment processors and may not be stored directly by Long Health.

4. Health Information

In providing healthcare technology, documentation, transcription, and interoperability services, Long Health may create, receive, maintain, or transmit PHI or other health information on behalf of healthcare organizations.

Long Health processes such information only as permitted by applicable law, contractual agreements, Business Associate Agreements, interoperability requirements, customer instructions, and other requirements applicable to the services being provided.

Audio recordings submitted through Long Health services may contain PHI or other health information. Such information is processed for purposes of providing the applicable transcription, documentation, or related service.

Long Health does not use PHI received from healthcare customers for consumer behavioral or targeted advertising.

Long Health does not sell PHI.

For information regarding health information processed through Long Health’s California QHIO services, please review our Long Health QHIO Privacy Policy.

5. How We Use Personal Information

Long Health may use Personal Information to:

  • provide and operate our services;
  • receive and process audio recordings submitted by authorized users;
  • generate transcriptions and provide related documentation services;
  • establish and manage customer relationships;
  • authenticate authorized users;
  • respond to inquiries and support requests;
  • administer contracts and billing;
  • communicate with customers and business partners;
  • provide product, service, administrative, and security notices;
  • improve our websites, platforms, and services;
  • monitor performance and troubleshoot technical issues;
  • detect and prevent fraud, misuse, and cybersecurity threats;
  • maintain security and audit records;
  • comply with contractual obligations;
  • comply with applicable legal and regulatory requirements;
  • enforce our agreements;
  • protect Long Health, our customers, and others; and
  • carry out legitimate corporate and business operations.

Where required by applicable law or applicable service requirements, Long Health obtains consent or other appropriate authorization before using or disclosing Personal Information for a purpose requiring such consent or authorization.

For mobile audio submissions that are transmitted to a third-party artificial intelligence service for transcription, Long Health provides an in-application disclosure and obtains the authorized user’s affirmative permission before the recording is submitted for such processing.

6. How We Disclose Personal Information

Long Health may disclose Personal Information in the following circumstances.

Service Providers

We may provide information to vendors and service providers that assist us with functions such as:

  • cloud infrastructure;
  • website hosting;
  • cybersecurity;
  • communications;
  • customer support;
  • transcription and artificial intelligence processing;
  • analytics;
  • payment processing;
  • accounting; and
  • other business operations.

We require service providers to protect information in accordance with applicable contractual, privacy, security, and legal requirements.

When service providers process PHI on Long Health’s behalf, Long Health uses appropriate contractual arrangements, including Business Associate Agreements where required, designed to require privacy and security protections consistent with Long Health’s legal and contractual obligations.

OpenAI and AI-Assisted Transcription

Long Health uses OpenAI, L.L.C. (“OpenAI”), a third-party artificial intelligence service provider, for certain transcription-related processing.

When an authorized user elects to submit an audio recording for transcription, the recording is securely transmitted to Long Health’s infrastructure and may then be transmitted to OpenAI for the purpose of generating a transcription.

The information transmitted to OpenAI may include:

  • the submitted audio recording; and
  • Personal Information, PHI, or other information contained within the recording that is necessary to generate the transcription.

Long Health uses OpenAI for PHI processing through a HIPAA-enabled Zero Data Retention workflow governed by contractual privacy and security requirements.

Under the applicable Zero Data Retention workflow, content submitted to OpenAI:

  • is not logged for human review;
  • is not persistently stored in OpenAI’s cloud systems;
  • is not saved to disk or retained by OpenAI; and
  • may be processed temporarily in memory as necessary to perform the requested service.

Long Health uses the applicable Zero Data Retention-enabled organization and eligible OpenAI service endpoints for workflows involving PHI.

OpenAI processes PHI for Long Health pursuant to a Business Associate Agreement and applicable contractual privacy and security requirements. OpenAI is required to maintain appropriate safeguards for electronic PHI and, where applicable, require subcontractors handling PHI to be subject to corresponding restrictions and conditions.

Long Health does not disclose submitted audio recordings or resulting transcripts to OpenAI for advertising or marketing purposes.

Before audio submitted through the Long Health mobile application is transmitted for OpenAI processing, the application informs the authorized user that the recording will be transmitted to OpenAI for transcription and requires affirmative permission to proceed.

If permission is not provided, the recording will not be submitted through that workflow for OpenAI transcription.

Customers and Authorized Organizations

Information relating to authorized users may be provided to the organization through which the user receives access to Long Health services.

Information, recordings, transcriptions, documents, and other content processed on behalf of a customer may be made available to that customer and its authorized users in accordance with the applicable service and contractual arrangements.

Professional Advisors

We may disclose information to attorneys, accountants, auditors, insurers, consultants, and other professional advisors when reasonably necessary.

Legal and Regulatory Requirements

We may disclose information when required or permitted by law, regulation, subpoena, court order, or other valid legal process.

Business Transactions

Information may be transferred as part of a merger, acquisition, financing, restructuring, sale of assets, or similar business transaction, subject to applicable privacy and confidentiality requirements.

7. Cookies and Website Technologies

Long Health may use cookies and similar technologies to:

  • operate our website;
  • maintain website security;
  • remember preferences;
  • understand website usage;
  • measure website performance; and
  • improve website functionality.

We may use service providers to assist with website analytics and related functions.

Visitors can generally manage cookies through their browser settings. Certain website features may not function properly if cookies are disabled.

Long Health does not use PHI obtained through its healthcare interoperability or healthcare technology services for website advertising or consumer behavioral advertising.

8. Marketing Communications

Long Health may use business contact information to communicate regarding our products, services, events, or other business matters.

Recipients may opt out of promotional emails using the unsubscribe mechanism contained in those communications or by contacting Long Health.

Opting out of marketing communications does not prevent Long Health from sending necessary transactional, customer-service, contractual, privacy, or security communications.

9. Data Security

Long Health maintains administrative, technical, and physical safeguards designed to protect Personal Information against unauthorized access, disclosure, alteration, destruction, or loss.

Depending upon the information and service involved, safeguards may include:

  • encryption;
  • access controls;
  • authentication;
  • network and endpoint security;
  • audit logging;
  • security monitoring;
  • vulnerability management;
  • workforce security controls;
  • incident response;
  • business continuity; and
  • vendor risk management.

Long Health uses contractual and security controls appropriate to the sensitivity of information processed by service providers.

No electronic system can be guaranteed to eliminate every security risk.

Long Health continually evaluates and updates its security measures based upon applicable requirements and identified risks.

10. Data Retention

Long Health retains Personal Information for periods reasonably necessary to:

  • provide services;
  • maintain customer relationships;
  • satisfy contractual requirements;
  • meet legal and regulatory obligations;
  • maintain required audit records;
  • protect our systems;
  • resolve disputes; and
  • enforce agreements.

Retention periods vary depending upon the type of information and applicable legal, contractual, and operational requirements.

Health information processed on behalf of a healthcare organization may be subject to separate retention requirements established by that organization, applicable agreements, or applicable law.

Audio Recordings and Transcriptions

Audio recordings and resulting transcriptions maintained by Long Health are retained in accordance with the applicable service configuration, customer instructions, contractual obligations, operational requirements, and applicable law.

The retention period applicable to information maintained by Long Health is separate from OpenAI’s processing of audio through Long Health’s Zero Data Retention workflow.

Under Long Health’s applicable OpenAI Zero Data Retention workflow, PHI and other content transmitted to OpenAI is processed transiently for the requested service and is not persistently stored, saved to disk, or retained by OpenAI after processing. Temporary in-memory processing may occur as necessary to perform the service.

Authorized users may contact Long Health regarding applicable privacy choices, withdrawal of consent for future processing, or requests concerning information processed through Long Health services.

Withdrawal of consent does not affect processing that occurred before the withdrawal and may not require deletion of information that Long Health or its customers are required or permitted to retain under applicable law, contractual requirements, or healthcare-record retention obligations.

Where Long Health processes information on behalf of a healthcare organization, certain access, correction, deletion, or other privacy requests may need to be submitted to or handled through that organization.

11. Medical Records and Patient Requests

Long Health does not currently provide a general direct-to-consumer medical-record access service.

Individuals seeking:

  • access to medical records;
  • copies of medical records;
  • correction or amendment of medical records;
  • an accounting of disclosures; or
  • restrictions concerning an underlying medical record

should ordinarily contact the healthcare provider, health plan, or other healthcare organization responsible for that record.

Where Long Health processes information as a Business Associate or technology provider, Long Health assists the responsible healthcare organization with applicable individual rights as required by law and applicable contractual agreements.

HIPAA generally places responsibility on the Covered Entity for fulfilling an individual’s rights of access, amendment, and accounting, including where relevant information is maintained by its Business Associate.

For requests specifically concerning information exchange through Long Health’s QHIO services, please review our QHIO Privacy Policy.

12. California Privacy Rights

California residents may have certain rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA/CPRA”), to the extent those laws apply to Long Health and the particular information involved.

Depending upon the circumstances, applicable rights may include the right to:

  • know categories and specific pieces of Personal Information collected;
  • know how Personal Information is used or disclosed;
  • request correction of inaccurate Personal Information;
  • request deletion of certain Personal Information;
  • opt out of certain sales or sharing where applicable;
  • limit certain uses of Sensitive Personal Information where applicable; and
  • exercise applicable privacy rights without unlawful discrimination.

Certain information is exempt from some or all CCPA/CPRA requirements, including certain PHI and medical information subject to HIPAA and other healthcare privacy laws.

Long Health does not sell PHI.

Requests concerning Personal Information collected by Long Health for its own business purposes may be submitted to support@longhealth.io.

Long Health may verify the identity and authority of a person submitting a privacy request before acting upon it.

Requests concerning medical records maintained by a healthcare provider, health plan, or other healthcare organization should ordinarily be directed to that organization.

13. Children’s Privacy

Long Health’s public website and business services are not directed to children for the purpose of creating consumer accounts.

Long Health may process information concerning minors when such information is provided by or processed on behalf of healthcare organizations as part of authorized healthcare services.

Such information is handled in accordance with applicable privacy laws and contractual requirements.

14. Third-Party Websites

Our website may contain links to websites or services operated by third parties.

Long Health does not control and is not responsible for the privacy practices of independent third-party websites.

We encourage visitors to review the privacy policies of third-party services before providing Personal Information to them.

15. QHIO Privacy

Long Health, Inc. is a California-designated Qualified Health Information Organization.

Long Health maintains a separate Long Health QHIO Privacy Policy that describes privacy practices applicable to Long Health’s QHIO services, California Data Exchange Framework activities, health information exchange, individual access considerations, exchange restrictions, and other QHIO privacy requirements.

QHIO Privacy Policy

The QHIO Privacy Policy is maintained and published separately for purposes of Long Health’s applicable California QHIO privacy-policy requirements.

16. Changes to This Privacy Policy

Long Health may update this Privacy Policy periodically to reflect changes in:

  • our services;
  • technology;
  • business practices;
  • applicable laws or regulations; or
  • privacy and security practices.

When we make changes, we will update the Effective Date and Last Reviewed information at the beginning of this Privacy Policy.

17. Contact Us

Questions regarding this Privacy Policy, Long Health’s general privacy practices, or applicable privacy choices concerning audio and transcription processing may be submitted to:

Long Health, Inc. Privacy / Compliance

Email: contact@longhealth.io

Phone: 408-673-8215

Website: https://www.longhealth.io

Please do not send Social Security numbers, complete medical records, audio recordings, or other unnecessary sensitive health information through ordinary email.

Version History

Version 2.1 — September 22, 2026

Updated to address Long Health mobile application audio recording and submission, transcription processing, third-party artificial intelligence processing by OpenAI, user consent, Zero Data Retention, and related retention and privacy disclosures.

Version 2.0 — September 3, 2026

Comprehensive revision to reflect Long Health’s current business-to-business healthcare technology and interoperability service model and separation of the general Privacy Policy from the Long Health QHIO Privacy Policy.