Pre-launch draft. This document is in effect for our closed beta and will be reviewed by legal counsel before public launch. Last updated: July 1, 2026.

Privacy Policy

Effective July 1, 2026

This Privacy Policy describes how Rempli collects, uses, and protects information when you use our patient intake platform. Rempli handles Protected Health Information (PHI) as a Business Associate under HIPAA. If you are a patient, your PHI is shared with your healthcare provider as directed by you when you submit a form.

1. Information We Collect

Information from your Electronic Health Record (EHR)

When you connect your Epic MyChart account, Rempli retrieves the following categories of data via the SMART on FHIR API, with your explicit authorization:

  • Demographics: name, date of birth, gender, address, phone, email
  • Active conditions and diagnoses
  • Current medications and prescriptions
  • Allergy and intolerance records
  • Immunization history
  • Recent vital signs and laboratory results
  • Procedures and surgical history
  • Insurance coverage information
  • Emergency contacts and related persons

This data is used solely to pre-fill your intake forms. We do not access your full medical record — only the resource types listed above and only for the patient context granted during the OAuth authorization.

Information you provide directly

  • Your email address when creating a Rempli account
  • Any fields you add or edit on an intake form before submitting

Information collected automatically

  • Session cookies used to maintain your authenticated state (30-minute expiry for EHR sessions)
  • Standard server logs (IP address, browser type, pages visited) for security and debugging

2. How We Use Your Information

  • To pre-fill forms: EHR data is mapped to form fields and presented to you for review before submission.
  • To deliver submissions: When you submit a form, a completed PDF is sent to the healthcare provider you are completing the form for.
  • To store your health profile: If you create a Rempli account, your health record data is stored so future forms can be pre-filled without requiring a fresh EHR connection every visit.
  • To improve form classification: Form content (not patient data) may be analyzed using AI to help providers map uploaded forms to standard fields.
  • For authentication: Your email is used to send secure sign-in links. We do not store passwords.

3. How We Share Your Information

Rempli does not sell, rent, or trade your personal information or PHI to third parties. We share information only in the following circumstances:

  • With your healthcare provider: When you submit a form, the completed data is sent as a PDF to the provider's designated email address. This is the primary purpose of the service and occurs only with your explicit consent at submission time.
  • With service providers: We use third-party vendors to operate Rempli (hosting, database, email delivery, AI processing). Each vendor with access to PHI has executed a Business Associate Agreement with Rempli.
  • As required by law: We may disclose information if required by a valid legal process, court order, or applicable law.

4. Protected Health Information (PHI) and HIPAA

Rempli operates as a HIPAA Business Associate. We implement administrative, physical, and technical safeguards appropriate to the sensitivity of the data we handle, including:

  • Encryption of data in transit (TLS) and at rest
  • Access controls limiting PHI access to authorized personnel and systems
  • Audit logging of PHI access events
  • Short-lived EHR access tokens (30-minute sessions) that are not persisted after use

During our current beta period, Rempli operates on infrastructure that is being evaluated for HIPAA compliance. We will complete formal compliance review before general availability.

5. Data Retention

  • EHR session data: Raw FHIR data retrieved during a session is held in memory only for the duration of your session and is not written to disk.
  • Stored health profile: If you have a Rempli account, your health profile is retained until you delete it or close your account.
  • Form submissions: Submission records (including the data snapshot) are retained in the provider's submission log. Providers may request deletion; patients may request deletion by contacting us.
  • Account data: Your email address and account metadata are retained until account deletion.

6. Your Rights

Depending on your location and applicable law, you may have the right to:

  • Access: Request a copy of the personal data Rempli holds about you.
  • Correction: Update inaccurate data in your stored health profile via Account → Edit Profile.
  • Deletion: Request deletion of your account and associated data by emailing privacy@rempli.health.
  • Revoke EHR access: Revoke Rempli's access to your Epic record at any time via your MyChart account settings under Connected Apps.
  • HIPAA rights: As a patient whose PHI we process, you retain all rights afforded under HIPAA, including the right to request an accounting of disclosures.

7. Cookies and Tracking

Rempli uses only functional cookies necessary to operate the service — specifically, an authentication session cookie and a short-lived EHR session cookie. We do not use advertising cookies, tracking pixels, or third-party analytics. We do not track you across other websites.

8. Children's Privacy

Rempli accounts are restricted to users 18 and older. Forms may be completed on behalf of minors by a parent or authorized guardian, but the account holder must be an adult. We do not knowingly collect personal information directly from children under 13.

9. Changes to This Policy

We will update this Privacy Policy as our practices evolve. Material changes will be communicated to account holders by email. The effective date at the top of this page reflects the date of the most recent update.

10. Contact

For privacy questions, data requests, or to report a concern, contact our privacy team at privacy@rempli.health. For security issues, email security@rempli.health.