OmniMD Privacy Policy
Last Updated: 09/25/2026
At OmniMD, we’re committed to protecting your privacy and handling your data carefully. As a trusted provider of Electronic Health Records (EHR), Revenue Cycle Management (RCM), and cloud-based health solutions, we know how important it is to keep your information safe and private. This Privacy Policy explains what types of information we collect, how we use it, and the steps we take to keep it secure. It also outlines your rights when it comes to your data.
This Statement of Privacy applies to omnimd.com and OmniMD and governs data collection and usage. For the purposes of this Privacy Policy, unless otherwise noted, all references to OmniMD include omnimd.com and parent company, OmniMD, Inc. By using the OmniMD website, you consent to the data practices described in this statement.
Scope of This Policy
This Privacy Policy governs personal information collected through the omnimd.com website – such as information you provide when requesting a demo, downloading a resource, or contacting us.
It does not govern Protected Health Information (PHI) processed through OmniMD’s software products on behalf of our healthcare provider customers. That data is governed by HIPAA and the Business Associate Agreement (BAA) executed between OmniMD and the applicable healthcare provider. If you are a patient with questions about your health information, please contact your healthcare provider directly, as they control that data as the HIPAA Covered Entity.
Collection of Personal Information & How we Use it!
We only collect personal information from you with your explicit consent, such as when you fill out a form to access our resources. OmniMD keeps your information secure and will never share, sell, or trade your contact information with anyone outside our company.
Cookies and Tracking Technologies
We use cookies and similar technologies, including analytics and advertising pixels (such as Meta/Facebook Pixel), to understand site usage and deliver relevant advertising. You can manage cookie preferences through your browser settings or by using our cookie consent tool [link once built]. We do not knowingly sell or share data collected via these technologies with third parties for cross-context behavioral advertising without an opt-out mechanism as required by applicable law.
Health Data
As part of our services, we collect and securely store certain health-related information to provide accurate and effective healthcare support.
You may choose to enter in the app the following health and medical data:
- Vital signs (body temperature, blood pressure, heart rate, respiratory rate, blood glucose, Oxygen Saturation, Sleep)
- Body measurements
- Blood type
- Health conditions
- Symtpoms
- Treatments and medications
- Allergies
- Laboratory tests and results
- Images
- Written information (messages) you exchange with doctors
- Billing Details
This data is processed on behalf of your healthcare provider under a Business Associate Agreement between OmniMD and that provider, and is governed by HIPAA, not by this website Privacy Policy. Your provider’s own Notice of Privacy Practices explains your rights regarding this information.
Health Devices
If you connect health devices to our platform, we may collect data from those devices. This data, which might include activity levels and health metrics, helps us provide a more tailored healthcare experience. Rest assured, this information is used only to support your health and is protected by our data security standards.
Consumer Health Data (Washington and Nevada Residents)
If you are a resident of Washington or Nevada, certain health-related information we collect through our website may qualify as “Consumer Health Data” under the Washington My Health My Data Act or Nevada’s consumer health data law. For this data, we:
- Obtain your consent before collecting Consumer Health Data, and separate, prior consent before sharing it with any third party
- Do not sell Consumer Health Data without your valid, separate authorization
- Do not use geofencing technology around healthcare facilities to identify, track, or send messages to individuals seeking health care services
- Allow you to withdraw consent and request deletion of your Consumer Health Data at any time by contacting privacy@omnimd.com
[Attorney note: WA MHMDA requires a separate, standalone “Consumer Health Data Privacy Policy” linked from the homepage, not just a section within a general privacy policy — confirm with counsel whether a standalone document is required for your specific data practices.]
Data Security and Data Retention
How We Use and Protect Your Data
At OmniMD, we respect your privacy and handle your data responsibly. We only process your information to provide the services you’ve chosen, such as using our healthcare technology to manage your records and treatments. When you choose to use our services and share your data, you give us consent to securely process that information.
For sensitive health data, like your medical history or treatment details, we rely on your explicit consent. While this information is only accessible by you and the healthcare providers you trust, we ensure its encrypted and safely stored in our system to protect your privacy and meet your healthcare needs.
We also use data to improve our products, enhance our services, and develop new features that make your experience better. This is part of our ongoing commitment to innovating and providing the best possible solutions to support your health journey.
Data Security Measures
We protect your data using advanced security tools and practices, such as firewalls, encryption, intrusion detection, and regular security checks. Our team constantly updates our security to keep up with the latest standards and protect against threats.
Data Retention
We keep your data only as long as necessary to provide our services and comply with legal requirements. Once data is no longer needed, we delete or anonymize it in a secure manner.
Compliance and Security Standards
Your Privacy Rights (California and Other States)
If you are a California resident, you have the right to:
- Know what personal information we collect, use, and disclose
- Request deletion of your personal information
- Correct inaccurate personal information
- Opt out of the sale or sharing of your personal information (OmniMD does not sell personal information)
- Limit the use of sensitive personal information
- Not be discriminated against for exercising these rights
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and other states with comprehensive privacy laws have similar rights. To exercise any of these rights, contact privacy@omnimd.com. We will verify your identity before processing your request and will respond within the timeframe required by applicable law.
We honor Global Privacy Control (GPC) signals as a valid opt-out request where required by law.
[Attorney note: confirm whether GDPR applies based on your actual EU visitor traffic — if it doesn’t, remove the GDPR reference entirely rather than leaving it as an unsubstantiated claim.]
Updates to Our Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or in response to customer feedback. We encourage you to check back occasionally to stay informed about how we’re working to protect your information and maintain your privacy.
Google API Data Usage
OmniMD integrates with Google Calendar API to provide seamless scheduling and Google Meet functionality. Specifically, we use Google APIs to:
- Create, view, and manage Google Calendar events on your behalf.
- Generate Google Meet links for scheduled meetings.
- Retrieve your email address and profile name for authentication and personalization.
How We Handle Your Google Data
We only request the minimum permissions necessary (https://www.googleapis.com/auth/calendar).
We do not store Google Calendar event details outside of your Google account.
We do not share, sell, or use Google user data for advertising.
All API requests are securely made using OAuth 2.0 authentication.
Google API Limited Use Policy Compliance
OmniMD follows Google’s API Services User Data Policy, including the Limited Use requirements:
- No Sharing or Selling: We do not share, sell, or transfer Google user data to third parties.
- No Ads: Google user data is never used for advertising.
- No Unnecessary Data Collection: We only access Google data required for core service functionality.
Children’s Privacy
Our website is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact us at privacy@omnimd.com and we will delete it.
Opt In Process Statement
The opt in process for this campaign is available only to authenticated users behind a secure login and is not accessible through a public URL. For security and privacy reasons, a publicly accessible link cannot be accessed without authorized login. Screenshots of the opt in workflow have been included as evidence to demonstrate the complete user experience and to verify compliance with applicable messaging requirements. https://omnione.omnimd.com/

Contact Information
If you have questions about this Privacy Policy or would like to exercise your rights, please reach out to us:
Email: privacy@OmniMD.com
Mailing Address: OmniMD, 245 Saw Mill River Road, Suite 301, Hawthorne, NY 10532