Privacy Policy
Privacy Policy
Version 1.0
Effective date: September 9, 2026
Last updated: September 9, 2026
OmniPACS Healthcare Technologies LLC, a New Jersey limited liability company (“OmniPACS,” “we,” “us,” “our“), provides cloud medical imaging software — DICOM study ingestion, storage, worklist, sharing, reporting and distribution — to imaging centers, mobile imaging providers, radiology groups and hospitals in the United States.
This Privacy Policy explains what personal information we collect and control, why, who receives it, how long we keep it, and the rights you have. It is written to be read, not to be survived. Our commercial terms are published separately at https://omnipacs.com/legal/agreement.
1. Scope — and the most important thing on this page
OmniPACS handles two fundamentally different kinds of information, under two fundamentally different sets of rules. This Privacy Policy governs only the second.
1.1 What this Policy does NOT cover: Protected Health Information we hold as a Business Associate
DICOM imaging studies, embedded patient identifiers, radiology reports, patient records, worklist entries, study share activity, and every other item of patient information inside the OmniPACS platform are Protected Health Information (“PHI”) that we receive, maintain, transmit and process solely on behalf of and at the direction of our healthcare-organization customers, each of which is a HIPAA covered entity or a business associate of one.
With respect to that information:
OmniPACS acts as a HIPAA Business Associate, not as an independent controller of the data. We do not decide what happens to it; our customer does.
Our handling of it is governed by the Health Insurance Portability and Accountability Act (“HIPAA”), by the Business Associate Agreement (“BAA”) we have entered into with that customer, and by our services agreement — not by this Privacy Policy.
As to the individual patient, the applicable notice is the covered entity’s own HIPAA Notice of Privacy Practices. If that Notice of Privacy Practices conflicts with anything in this Privacy Policy, the covered entity’s Notice of Privacy Practices controls.
We do not use PHI for our own marketing, advertising, or product-promotion purposes, and we do not sell it. We do not disclose PHI to advertising networks or advertising analytics providers. Ever.
Because this information is regulated by HIPAA, it is exempt in whole or in part from a number of U.S. state consumer privacy laws.
📌 A plain-language note for patients
If you are a patient and you are looking for your images, your records, or your rights over them, OmniPACS is not the right place to start — your healthcare provider is.
We are the software vendor that your imaging center, radiology group or hospital uses to store and move your images. Patients see images through OmniPACS only where a health care provider chooses to make them available through the platform. When that happens, those images are still your provider’s records, they are still PHI under HIPAA, and your provider’s Notice of Privacy Practices governs them. There is no OmniPACS sign-up for patients, and there is no patient-controlled OmniPACS account that exists without a provider relationship. Where a provider has given you access, you may also upload your own prior imaging into that access, and we handle what you upload as PHI for your provider in exactly the same way — see Section 2.
We hold your images for your provider, under a contract, and we are not permitted to act on your images without their instruction. We cannot verify your identity, we cannot confirm whether a particular study exists, and we are not able to grant, amend, restrict or delete access to your medical record on our own authority.
Please contact the imaging center, hospital, or physician practice that performed or ordered your imaging. Ask for their Privacy Officer or their Health Information Management / Medical Records department. Their Notice of Privacy Practices describes your HIPAA rights — including access, amendment, an accounting of disclosures, and restrictions — and how to exercise them.
If you contact us anyway, we will do our best to route you to the right provider, and we will tell your provider that you asked. We will not release medical information to you directly. Patients are never charged for any of this.
1.2 What this Policy does cover: personal information OmniPACS controls in its own right
This Privacy Policy applies to personal information that OmniPACS collects and controls for its own business purposes, across:
our marketing website at https://omnipacs.com and any subdomains or campaign landing pages we operate;
our logged-in application at https://app.omnipacs.com, to the limited extent the information concerns the account and the named user rather than a patient (for example, a radiologist’s work email address, their login events, or their support ticket) rather than the clinical content they are working on;
our companion and adjacent products to the extent they collect the same account-level information — UDE (Universal Diagnostic Environment iPad app), EPS-Pi (Enterprise PACS Server), OmniRouter (local DICOM relay agent) and OmniMonitor (synthetic monitoring);
our sales, marketing, billing, support and recruiting operations.
Specifically, it covers:
| Population | Examples of what we control |
|---|---|
| Website visitors | IP address, device and browser data, pages viewed, referral source, cookie and analytics identifiers |
| Prospects and lead-form submitters | Name, work email, phone, organization, role, stated imaging volume, free-text notes, demo requests |
| Account holders and named end users | Work contact details, role and permissions, authentication identifiers, login and session records |
| Billing contacts | Billing name and address, purchase-order and invoice data, payment method tokens, usage and overage records |
| Support requesters | Ticket contents, correspondence, screenshots you send us, in-app chat transcripts, call notes |
| Product telemetry | Feature usage, performance and error data from the application, tied to a user or account rather than to a patient |
1.3 The line, restated
The clinical layer is your provider’s data, held by us under a BAA. The commercial layer — who visited our site, who asked for a demo, who logs in, who pays the invoice, and whether the app threw an error — is ours, and this Policy governs it.
Where the two layers touch — for example, a support ticket in which a customer’s staff member pastes a patient identifier while describing a bug — we treat the whole record as PHI and handle it under the BAA and our HIPAA safeguards, not under this Policy. We ask our customers and their users not to place patient information in support tickets or chats.
1.4 What else this Policy does not cover
Our customers’ own privacy practices. Each healthcare organization decides how it configures OmniPACS, who it grants access to, and to whom it shares studies. We are not responsible for those decisions.
Third-party services reached from ours, including the CHILI diagnostic viewer, which is launched from OmniPACS by time-limited signed ticket URL, is supplied and operated by CHILI GmbH under separate terms, and is not part of the OmniPACS platform.
Employment and job-applicant data, which is handled separately and is not covered by this Policy.
2. Categories of personal information we collect, our sources, and why
The table below is our notice at collection for purposes of the California Consumer Privacy Act, as amended (“CCPA”), and addresses the equivalent disclosure duties in other states.
| Category (CCPA framing) | What it includes | Sources | Why we collect it |
|---|---|---|---|
| Identifiers | Name, work email, work phone, employer, job title, account username, Firebase user identifier, IP address, device identifiers, cookie IDs | Directly from you; from our customer when it provisions your account; automatically from your device | Create and administer accounts; authenticate; respond to inquiries; deliver the service; security |
| Professional or employment information | Role (radiologist, technologist, administrator), department, credentialing-adjacent details you volunteer, referring-physician and institution affiliation as it appears in account and contact records | Directly from you; from our customer; from publicly available business sources and business-contact providers | Provision correct permissions; sell and support the product; route support |
| Commercial information | Subscription plan and tier, contract and renewal data, study-volume and overage usage counts, invoices, payment history, purchase orders | From our customer; generated by our billing systems | Billing and collections; contract administration; revenue reporting |
| Financial / payment information | Billing address, payment-method tokens and the last four digits of a card, bank remittance details | Directly from you or your organization, via our payment processors | Take payment. We do not store full payment card numbers; card data is captured and held by Stripe and our subscription-billing provider Maxio / Chargify |
| Internet or other electronic network activity | Pages and screens viewed, referral URL, search terms on the marketing site, clicks, session duration, feature usage, API call metadata, error and crash traces, performance traces | Automatically, via cookies, SDKs and server logs | Operate, secure, debug and improve the service; measure marketing on the public site |
| Geolocation (coarse only) | City, region and country inferred from IP address | Automatically | Security and fraud signals; routing; aggregate marketing analytics. We do not collect precise geolocation, and we do not operate geofences. See Section 11.4 |
| Audio, electronic, visual information | Support call notes; screenshots and screen-share sessions you provide; in-app chat transcripts | Directly from you during support | Troubleshoot and document issues |
| Communications content | Emails to our sales and support addresses; lead-form free text; ticket bodies; notification preferences | Directly from you | Respond; keep a record; improve documentation |
| Sensitive personal information | Account log-in credentials and authentication secrets; any health-related information that you volunteer outside the clinical platform (see Section 3) | Directly from you | Authenticate you; respond to what you asked us about |
| Inferences | Lead scoring, product-interest and fit signals, engagement scores derived from marketing and product activity | Derived by us and by our CRM | Prioritize sales outreach; tailor first-party marketing. We do not build advertising profiles and we do not infer anything about any individual’s health. |
Categories of sources, stated plainly: (a) directly from you, when you fill in a form, email us, open a ticket, or use the application; (b) from our healthcare-organization customer, when it provisions or manages your user account; (c) automatically from your device and browser when you use our sites and app; (d) from service providers acting for us; and (e) from public and commercial business-information sources used for business-to-business prospecting.
Patient-uploaded imaging. Where a health care provider has given a patient access to the platform, that patient may also upload their own prior imaging and related records — typically from a CD or other portable media — into that provider-linked access. OmniPACS does not offer a standalone, patient-controlled account that exists independently of a health care provider relationship, and a patient cannot obtain platform access without one. Content a patient uploads is received into the provider-linked access and is handled as PHI under our Business Associate Agreement with that provider, subject to the same safeguards, access controls, audit logging and breach obligations as provider-supplied studies. OmniPACS does not review, validate, verify, interpret, correct or confirm the accuracy, completeness, provenance or clinical relevance of anything a patient uploads, and uploaded content does not become part of the provider’s legal medical record unless the provider accepts it. Section 1.1 governs that content; this Policy does not.
Because OmniPACS handles patient-uploaded content as a business associate under HIPAA rather than as a direct-to-consumer health service, the FTC Health Breach Notification Rule at 16 CFR Part 318, the Washington My Health My Data Act and Nevada SB 370 do not apply to it.
Payment card data. Payment card transactions are processed by Stripe, Inc., a PCI DSS Level 1 certified service provider. OmniPACS does not collect, transmit, process or store full payment card numbers, card verification values or magnetic-stripe data, and cardholder data does not traverse or reside on the platform. OmniPACS does not itself hold a PCI DSS attestation of compliance and makes no representation that it does. OmniPACS receives from Stripe only limited transaction metadata, such as the card brand, the last four digits, the expiration date, the billing contact and the transaction result.
Purposes, stated plainly: provide and operate the Services; authenticate and secure accounts; provide support; meter and bill usage; administer contracts; send transactional and service notifications; send business-to-business marketing to business contacts, with opt-out in every message; debug, monitor and improve the product; produce internal and aggregate analytics; comply with law and enforce our terms; and effect corporate transactions. We do not use personal information for purposes materially different from these without giving you notice, and — where the law requires it — obtaining your consent.
3. Sensitive personal information
Under the CCPA, “sensitive personal information” includes account log-in credentials, precise geolocation, biometric information processed to uniquely identify a person, and “personal information collected and analyzed concerning a consumer’s health.”
What we actually collect in this category, outside of PHI:
| Sensitive category | Do we collect it? | Detail |
|---|---|---|
| Account log-in / authentication credentials | Yes | Managed through Firebase Authentication with signed JSON Web Tokens. Collected and used only to authenticate you and secure the account |
| Precise geolocation | No | We infer only coarse city and region from IP address |
| Biometric information used to identify a person | No | We do not offer biometric login. Note: DICOM images — X-ray, CT, MRI, PET, mammography and similar diagnostic images — are expressly excluded from the definition of “biometric identifier” under the Illinois Biometric Information Privacy Act, 740 ILCS 14/10, and under Washington’s biometric statute, RCW 19.375. If we later add fingerprint or face login for clinical users, that would be biometric data, and we will publish a separate written retention-and-destruction schedule before launching it |
| Health information | Only incidentally, and we ask you not to send it | Clinical health information reaches us as PHI under a BAA and is outside this Policy. Separately, someone may volunteer health information in a lead form, an email or a support ticket. We do not solicit it, we do not analyze it to infer anyone’s health status, and we do not use it for marketing. Where we identify it, we minimize or delete it |
| Racial or ethnic origin, religion, union membership, immigration status, sex life or sexual orientation, genetic data, neural data, contents of communications where we are not the intended recipient | No | Not collected |
We do not use or disclose sensitive personal information for any purpose other than those permitted by CCPA § 1798.121 — essentially, performing the service you asked for, security, and legally required functions. Because of that, the CCPA’s “Limit the Use of My Sensitive Personal Information” right does not change how we handle your data — but you may still submit the request, and we will honor it and confirm in writing. See Section 9.
4. Cookies and tracking technologies
4.1 The hard commitment, first
We do not deploy advertising pixels, advertising tags, or third-party advertising analytics on:
any authenticated page of app.omnipacs.com;
the login page or any registration, password-reset or invitation-acceptance page;
any study viewer, share-link landing page, or other page on which imaging studies, reports, patient records or worklists may be displayed; or
any page or screen where PHI may otherwise be present.
We do not disclose PHI, imaging content, report content, form-field contents, uploaded file contents, or on-screen clinical data to any advertising, marketing or tag-management vendor. No advertising pixel, advertising SDK, ad-network tag, or marketing tag manager is deployed behind login or on any clinical or share page. These are standing policy commitments, and they apply to how we build and operate the platform.
Why we state it this way: the HHS Office for Civil Rights has taken the position that tracking technologies on user-authenticated webpages generally have access to PHI, that regulated entities may not use tracking technologies in a way that results in impermissible disclosures of PHI, and that tracking code on a portal login or registration page that captures login or registration information is itself a disclosure of PHI. That position governs a logged-in PACS, and we have written our commitment to match it.
4.2 What runs on the marketing site instead
On omnipacs.com — an unauthenticated business-to-business marketing site with no PHI on it — we use a deliberately small set of technologies, in categories, with non-essential categories off by default until you choose:
| Category | On by default? | What it does | Who operates it |
|---|---|---|---|
| Strictly necessary | Yes (cannot be switched off) | Load-balancing and routing, request-forgery and abuse protection, remembering your cookie choices | First-party; our cloud infrastructure provider |
| Functional | No | Form pre-fill and submission handling, region and language preference, embedded content playback | First-party; GoHighLevel / LeadConnector (form and lead capture) |
| Analytics | No | Aggregate traffic and page-performance measurement, so we know which pages are useful | First-party, aggregate measurement only. No third-party advertising analytics |
| Marketing / advertising | No — not enabled | Campaign attribution, measured first-party from referral and campaign parameters in the URL | First-party. No advertising or retargeting tag is deployed |
| Chat and engagement | No — not until you open it | Sales and support chat, product tours, in-app messaging | Intercom (see Section 5.2) |
We use a consent banner with genuine accept-all, reject-all and category-level choices, and a persistent “Cookie preferences” link lets you change your mind at any time.
Do Not Track. There is no common industry standard for legacy “Do Not Track” browser headers, and we do not respond to them. We do honor Global Privacy Control — see Section 9.5.
Cross-site tracking over time. Except as disclosed in the table above and subject to your choices, we do not permit third parties to collect information about you over time and across different websites or online services through our properties. On authenticated and clinical pages, no third party does so at all.
5. Disclosures — who receives personal information, and why
We disclose personal information to the categories of recipients below. We do not disclose PHI to any of them except where a Business Associate Agreement or equivalent HIPAA-permissible arrangement is in place.
5.1 Categories of recipients
| Category of recipient | Purpose | What they receive |
|---|---|---|
| Cloud hosting and infrastructure | Run the Services | Account data, application data, logs; PHI under BAA |
| Authentication and messaging | Log you in; deliver notifications | Account identifiers, email, device push tokens |
| Error, performance and uptime monitoring | Keep the product working | Technical telemetry, error traces, stack context, user and account identifiers |
| Support and in-app engagement | Answer your tickets and chats | Contact details, ticket and chat content, product usage context |
| Payments and subscription billing | Charge and invoice | Billing contact, payment tokens, usage and overage counts |
| CRM and marketing operations | Manage leads and business-to-business outreach | Lead-form data, contact details, engagement history |
| Diagnostic viewing | Diagnostic image interpretation | Session tickets and the study data required to render it — clinical data, under contract |
| Email and productivity | Transactional and business email | Recipient addresses and message content |
| Professional advisers | Legal, accounting, audit | As needed, minimized |
| Our customer, the covered entity | It is the controller of the clinical record | Account, usage, audit and billing information about its own users and studies |
| Corporate transactions | Diligence, financing, merger, acquisition or sale of assets | Under confidentiality; PHI only as HIPAA permits |
| Law enforcement, regulators, courts | Legal compulsion, safety, defense of claims | The minimum required |
We also disclose information at your direction — for example, when a user in the application shares a study with an external recipient, that sharing is initiated and controlled by our customer and its users, not by us.
Affiliates. Where a corporate affiliate of OmniPACS receives personal information, it receives it only for the purposes described in this Policy and under the same restrictions that apply to us, and it receives PHI only as HIPAA and the applicable BAA permit.
5.2 The subprocessors we actually use
We believe in naming names. Our current material subprocessors:
| Subprocessor | Role | Data involved |
|---|---|---|
| Amazon Web Services | Cloud hosting, storage, compute and queueing, including study export and CD/ISO generation | All application data, including PHI, under a BAA |
| Google — Firebase | Firebase Authentication (identity, signed token issuance) and Firebase Cloud Messaging (push notifications) | Account identifiers, email, device push tokens |
| Sentry | Application error and exception tracking | Error traces, technical telemetry, user and account identifiers |
| New Relic | Application performance monitoring | Performance and transaction telemetry, technical identifiers |
| Intercom | Support widget and in-app engagement | Contact details, chat and ticket content, product usage events |
| Stripe | Payment processing | Billing contact, payment credentials (held by Stripe), transaction records |
| Maxio / Chargify | Subscription management, metered billing, invoicing | Billing contacts, subscription and usage data, invoices |
| GoHighLevel / LeadConnector | CRM; marketing-site and signup lead capture and sync | Lead-form submissions, contact details, marketing engagement, lead source labels |
| CHILI | Third-party diagnostic viewer, launched by time-limited signed ticket URL | Study data required for diagnostic display |
| Google Workspace | Business and transactional email delivery | Message content and recipient addresses |
The current list is maintained at https://omnipacs.com/legal/subprocessors. We will update that page and provide at least thirty (30) days’ notice of a material change to this list before the new subprocessor begins processing.
Each subprocessor is engaged under a written contract that limits it to processing on our instructions, prohibits use of the data for its own purposes, and — where PHI is or may be involved — includes a Business Associate Agreement.
6. Sale, sharing, and targeted advertising
We do not sell personal information. We have not sold personal information in the preceding twelve months, and we do not intend to.
We do not share personal information for cross-context behavioral advertising, and we do not use it to serve targeted advertising to you.
We never use, disclose, or make available PHI for marketing, advertising, or the promotion of our own products, and we never disclose PHI to advertising or advertising analytics vendors.
We do not sell consumer health data, and we do not offer it for sale.
We do not use Customer Data or PHI to train artificial-intelligence or machine-learning models, and we do not disclose it to third parties for that purpose.
We do not de-identify Customer Data or PHI for our own purposes. OmniPACS reserves no right to do so. De-identification occurs only on a customer’s documented instruction, or as HIPAA otherwise permits at the customer’s direction.
If any statement above ever ceases to be true, we will update this Policy, publish the required opt-out links and mechanisms, and honor opt-outs before the practice begins.
7. How long we keep information
We keep personal information only as long as reasonably necessary for the purpose for which we collected it, and no longer. The periods and criteria below apply to the data we control. PHI retention is governed by the customer agreement and BAA, and is directed by the customer, not by this table.
| Category | Retention period or criteria | Basis / notes |
|---|---|---|
| Marketing-site analytics and aggregated traffic data | Kept in aggregate form only, for as long as needed for traffic and performance reporting | No identified individual profile |
| Cookie and consent records | Cookie lifetimes are shown in the preference center; a record of the choice you made is kept while it remains evidence of that choice | Evidence of the choice you made |
| Lead and prospect records (unconverted) | Kept while the sales relationship remains active, then deleted or anonymized when follow-up is no longer reasonably foreseeable | Sales follow-up |
| Marketing suppression / do-not-contact list | Retained indefinitely, in minimized form (email hash only) | We must keep this to keep honoring your opt-out |
| Account and named-user records (contact details, role, permissions) | For the life of the customer account, then deleted subject to the customer’s own instruction and to our legal-hold obligations | Service delivery |
| Authentication records and session and refresh tokens | Tokens expire automatically according to their configured lifetime | Security |
| Security, access and audit logs | Six (6) years | HIPAA documentation retention and incident investigation |
| Backups | Thirty-five (35) days, after which they expire | Recovery |
| Application error and performance telemetry | Kept per the retention configured in our monitoring tools, for as long as needed to diagnose and fix the issue | Debugging |
| Support tickets and chat transcripts | Kept as a service and dispute record for as long as a claim or question about the engagement remains reasonably foreseeable | Service history and dispute resolution |
| Billing, invoicing and usage records | Kept for the period our tax, accounting and audit obligations require | Tax, accounting and audit obligations |
| Contracts, BAAs and legal records | Term plus the applicable statute-of-limitations period | Statutes of limitation |
| Customer Data and PHI in the platform | For the duration of the subscription. After termination or expiration there is a thirty (30) day window during which the customer may retrieve its data at no charge. OmniPACS may delete Customer Data sixty (60) days after termination or expiration, and will do so on written instruction, subject to expiry of backups within the thirty-five (35) day backup period | Governed by the customer agreement and BAA, at the customer’s direction |
Where an exact period cannot be stated, our criteria are: how long we need the information for the disclosed purpose; how long a legal, tax, accounting or HIPAA documentation obligation requires; and how long any claim or investigation remains reasonably foreseeable. We do not retain personal information indefinitely, with the single exception of minimized suppression-list entries that exist to honor your own opt-out.
8. Security
We maintain an information security program with administrative, physical and technical safeguards designed to be appropriate to the sensitivity of the data we handle, including a HIPAA Security Rule risk analysis and risk-management process for systems that touch electronic PHI.
The controls we maintain are:
Encryption in transit using TLS 1.2 or higher across our web, API and application surfaces.
Encryption at rest for stored imaging studies, customer data and backups, using platform-managed encryption on the underlying cloud infrastructure.
Unique credentials for each individual user. No shared or generic accounts. Credential provisioning and de-provisioning are controlled by the customer’s own administrators.
Role-based access control and configurable sharing controls, configured by the customer.
Audit logging of access to and disclosure of PHI, retained for six (6) years.
Least-privilege administrative access for OmniPACS personnel, limited to what is necessary to operate and support the platform.
Workforce training on HIPAA and information security, and a workforce sanctions policy.
Written agreements, including business associate agreements where required, with subprocessors that process PHI.
A documented incident response process, including HIPAA breach-notification obligations to the covered entity under the BAA.
Backups, retained for thirty-five (35) days.
Time-limited, cryptographically signed URLs for the diagnostic viewer hand-off.
Authentication. Authentication is performed through Firebase Authentication using signed tokens. OmniPACS requires verification by a one-time passcode, sent to the email address or mobile number on file, when an account is created and when a password is reset. OmniPACS does not currently enforce multi-factor authentication on every routine sign-in. Subscribers remain responsible for evaluating whether that is sufficient for their environment and for applying compensating controls, including device management, network controls and session policy, where their own risk assessment requires them.
Certifications. OmniPACS does not currently hold a SOC 2 Type I or Type II report, a HITRUST CSF certification, an ISO/IEC 27001 certificate, an AT-C 315 HIPAA compliance examination report, a PCI DSS attestation of compliance, or any other independent third-party attestation covering OmniPACS’ own controls, and makes no representation that it does.
The platform is hosted on Amazon Web Services, which maintains its own independent third-party audit reports and certifications, including SOC 1, SOC 2 and SOC 3 reports and ISO/IEC 27001 certification, and which offers a HIPAA Business Associate Addendum covering HIPAA-eligible services. Those reports are obtained from AWS and are made available by AWS through AWS Artifact. They attest to the controls AWS operates for its own infrastructure and services. They are not an attestation of OmniPACS’ controls, they do not cover the OmniPACS application layer, and a Subscriber may not treat them as a substitute for a SOC 2 report covering OmniPACS.
What we do not promise. We perform security testing at intervals we determine appropriate, and we do not commit to any testing cadence or to sharing results. We maintain backups and will use commercially reasonable efforts to restore service and data as promptly as practicable, but we do not warrant any recovery point objective or recovery time objective.
No method of transmission or storage is completely secure. While we work to protect your information, we cannot guarantee its absolute security. If you believe your account has been compromised, or you become aware of a security vulnerability or unauthorized use, email support@omnipacs.com with the subject line “SECURITY.”
9. Your rights and how to exercise them
Depending on where you live, you may have some or all of the following rights over the personal information we control (rights over PHI run through your healthcare provider — see Section 1):
Know / access — what we collect, the sources, the purposes, the categories of recipients, and a copy of the specific pieces we hold about you.
Correct inaccurate personal information.
Delete personal information, subject to legal and contractual exceptions.
Portability — a copy in a portable, readily usable format.
Opt out of sale, sharing and targeted advertising — see Section 6; we do not engage in these, and we will confirm that in response to any request.
Limit the use and disclosure of sensitive personal information — see Section 3.
Opt out of profiling in furtherance of decisions producing legal or similarly significant effects. We do not engage in such profiling or automated decision-making about individuals.
Withdraw consent you previously gave.
Non-discrimination — we will not deny you service, charge you a different price, or provide a lesser quality of service because you exercised a privacy right.
Appeal a denial — see Section 9.3.
9.1 How to submit a request
Choose whichever is easiest:
Email support@omnipacs.com with the subject line “PRIVACY REQUEST.”
Mail to OmniPACS Healthcare Technologies LLC, 17 Griffin Street, Monmouth Beach, New Jersey 07750, United States, Attention: Privacy Request.
Telephone 813-590-0846.
Tell us what right you want to exercise and give us enough information to find your records. If you are a user of the application, submitting from the email address on your account is the fastest path.
9.2 Verification and timing
We verify requests before acting on them, using information already in our records — typically confirmation of control of the email address on file and, for access requests, one or two additional matching data points. We may ask for more where the request concerns sensitive information. We will not create new personal information about you just to verify you, and we will not use verification information for any other purpose.
| Step | Timing |
|---|---|
| Acknowledgement | Within 10 business days |
| Substantive response | Within 45 calendar days of receipt |
| Extension, with notice to you | One additional 45 days where reasonably necessary |
| Opt-out of sale, sharing or targeted advertising | Within 15 business days |
| Appeal decision | Within 45 days, extendable as described in Section 9.3 |
If we cannot verify you, or an exception applies, we will tell you which one and why. There is no charge for a reasonable request; we may decline or charge for requests that are manifestly unfounded, excessive or repetitive, and we will explain if we do.
9.3 Appeals
If we deny your request in whole or in part, you may appeal. Reply to our decision, or write to support@omnipacs.com with the subject line “PRIVACY REQUEST — APPEAL,” within sixty (60) days of our response. State what you asked for and why you believe the decision was wrong.
The appeal is reviewed by someone other than the person who made the original decision. We will respond in writing within 45 days of receipt, extendable by 60 additional days where reasonably necessary, and we will explain our reasoning.
If your appeal is denied, you may contact your state Attorney General to submit a complaint. We will provide the relevant online mechanism or contact information with our appeal decision. In California, you may also contact the California Privacy Protection Agency.
9.4 Authorized agents
You may use an authorized agent to submit a request on your behalf. We will ask the agent for either (a) written, signed permission from you, or (b) proof of a power of attorney, and we may separately contact you to confirm that you authorized the request and to verify your identity — unless the agent holds a power of attorney under state probate law. An opt-out preference signal sent by a platform, technology or mechanism on your behalf is treated as a valid request from an authorized agent and does not require additional proof.
9.5 Global Privacy Control and universal opt-out mechanisms
We recognize and honor the Global Privacy Control (“GPC”) as a valid opt-out of the sale or sharing of personal information and of targeted advertising.
We apply GPC to every visitor whose browser or extension sends the signal, without geofencing it to particular states.
Where the signal is sent from a browser we can associate with a known account, we apply the opt-out to that account as well as to the browser.
Global Privacy Control is the only universal opt-out mechanism on the Colorado Attorney General’s approved list, and recognition of opt-out preference signals is required in a growing number of states, including California, Colorado, Connecticut, Delaware, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Texas, Minnesota and Maryland.
Because we do not sell or share personal information (Section 6), the practical effect of GPC on our sites is limited — but we honor it, and it also switches off the non-essential analytics and marketing cookie categories described in Section 4.2.
10. Chat, session replay, and analytics consent
We treat website and in-app instrumentation as a communications-privacy question, not just a cookie question, because plaintiffs and regulators now do the same. California’s Invasion of Privacy Act and comparable state wiretapping and “pen register” statutes have generated extensive litigation over analytics tags, pixels, chat widgets and session-replay tools. Our position:
No session replay, keystroke capture, mouse-movement recording or screen recording runs on authenticated application pages, the login page, or any page where imaging studies, reports or patient records may appear.
On the marketing site, non-essential instrumentation does not run until you consent. Analytics and marketing categories are off by default.
Our chat widget is operated by a third party — Intercom — and we say so. When you open a chat, you are told that the conversation is transmitted to and stored by Intercom acting as our service provider, and that a transcript is retained. Opening the chat is voluntary; the widget does not capture your activity unless you open it.
Please do not enter patient information into chat. Our support workflow escalates any conversation containing patient identifiers into our HIPAA-governed support channel.
Every instrumentation vendor is contractually restricted to processing on our behalf and is prohibited from using the data for its own purposes, from selling it, and from combining it with data from other sources — so each is a service provider acting for us, not an independent party listening in.
We do not record telephone calls without telling you. Where a support or sales call is recorded, we announce it at the start of the call.
11. State-specific disclosures
11.1 California
This section supplements the rest of the Policy for California residents.
Notice at collection. Sections 2 and 3 are our notice at collection: the categories of personal information and sensitive personal information we collect, the purposes for which each category is collected and used, whether it is sold or shared (it is not — Section 6), and the length of time we intend to retain each category, or the criteria we use (Section 7). We do not collect additional categories, or use personal information for purposes incompatible with those disclosed, without first giving notice.
Sensitive personal information. See Section 3. We use and disclose sensitive personal information only for the purposes permitted by CCPA § 1798.121, so the “Limit the Use of My Sensitive Personal Information” right does not alter our handling — but we will process and confirm the request.
Do Not Sell or Share My Personal Information. We do not sell or share personal information, so there is nothing to opt out of. You may still submit the request under Section 9.1 and we will confirm our practice in writing.
Global Privacy Control. See Section 9.5. California has required recognition of opt-out preference signals since January 1, 2023, and a signal is treated as a request from an authorized agent.
Limits on retention. We do not retain personal information for longer than reasonably necessary for the disclosed purpose. See Section 7.
Non-discrimination. We will not deny goods or services, charge different prices, impose penalties, or provide a different level or quality of service because you exercised a CCPA right, and we offer no financial incentive programs for personal information.
Automated decision-making. We do not use automated decision-making technology to make decisions producing legal or similarly significant effects about individuals. If that changes, we will publish a pre-use notice and provide access and opt-out rights as California’s regulations require.
PHI exemption. Cal. Civ. Code § 1798.146 exempts protected health information collected by a covered entity or a business associate, and exempts a business associate to the extent it maintains, uses and discloses patient information in the same manner as PHI. The exemption is data-level and conditional: it covers the clinical layer, and it does not cover our marketing-site, prospect, account-contact, billing or support data, which is fully in scope of the CCPA and of this Policy. Requests about PHI are routed to your health care provider, which is the entity that controls that record.
Shine the Light. We do not disclose personal information to third parties for their own direct marketing purposes.
11.2 Multi-state rights
Twenty states have a comprehensive consumer privacy law in effect in 2026. Where one applies to you and to us, you generally have the rights to confirm processing and access your data, to correct it, to delete it, to obtain a portable copy, to opt out of targeted advertising, sale and certain profiling, to give or withhold consent for sensitive data, and to appeal a denial.
| State | Law | In effect since |
|---|---|---|
| California | CCPA / CPRA | January 1, 2020 |
| Virginia | VCDPA | January 1, 2023 |
| Colorado | Colorado Privacy Act | July 1, 2023 |
| Connecticut | CTDPA | July 1, 2023 |
| Utah | UCPA | December 31, 2023 |
| Oregon | OCPA | July 1, 2024 |
| Texas | TDPSA | July 1, 2024 |
| Florida | Florida Digital Bill of Rights | July 1, 2024 |
| Montana | MTCDPA | October 1, 2024 |
| Delaware | DPDPA | January 1, 2025 |
| Iowa | ICDPA | January 1, 2025 |
| Nebraska | NDPA | January 1, 2025 |
| New Hampshire | NHPA | January 1, 2025 |
| New Jersey | NJDPA | January 15, 2025 |
| Tennessee | TIPA | July 1, 2025 |
| Minnesota | MCDPA | July 31, 2025 |
| Maryland | MODPA | October 1, 2025 |
| Indiana | INCDPA | January 1, 2026 |
| Kentucky | KCDPA | January 1, 2026 |
| Rhode Island | RIDTPPA | January 1, 2026 |
Laws in Louisiana and Oklahoma (January 1, 2027), Alabama (May 1, 2027) and Vermont (January 1, 2028) are enacted but not yet in force; we will update this Policy as each takes effect.
How the HIPAA exemption interacts with these laws. Some of these states exempt HIPAA-regulated entities at the entity level; others exempt only PHI at the data level, leaving the rest of our data regulated. We do not ask you to identify your state before we will look at your request: send it under Section 9.1 and we will respond wherever you live. Rights over PHI still run through your health care provider, because that is a matter of HIPAA rather than of state consumer privacy law, and we will route such a request to the provider and assist the provider in responding to it.
Minnesota residents additionally have the right to obtain a list of the specific third parties to which we have disclosed their personal data, and to question the result of profiling; we will provide these on request.
Employment and business-context data. Several state laws exclude individuals acting in a commercial or employment context from the definition of “consumer.” Most users of app.omnipacs.com are clinical and administrative staff acting for their employer, which may place their account data outside those laws. We will not refuse to look at a request on that basis alone.
11.3 Consumer health data and direct-to-consumer accounts
OmniPACS does not offer a standalone, patient-controlled account that exists independently of a health care provider relationship, and a patient cannot obtain platform access without one. Patient access to imaging is available only where a health care provider makes images available through the platform. In that situation the images are PHI, HIPAA governs them through the provider, and the provider’s Notice of Privacy Practices applies. A patient who has been given that access may also upload their own prior imaging into it; that content is received into the provider-linked access and is handled as PHI under our Business Associate Agreement with the provider, as Section 2 describes. There is no patient self-signup and no consumer product offered by OmniPACS directly to individuals.
If OmniPACS ever offers a direct-to-consumer service, we will publish separate terms and a separate privacy notice for it before launching it, and we will not migrate anyone into such a service under this Policy.
11.4 Geofencing
We do not operate geofences. We do not use geofencing near any medical facility, health care provider, family planning center, mental health facility, or reproductive or sexual health facility to identify or track consumers, to collect consumer health data, or to send notifications, messages or advertisements. Washington, Nevada, Connecticut and California each restrict or prohibit the practice, and we do not engage in it anywhere.
11.5 Texas and other required notice language
For Texas residents: we do not sell sensitive personal data and we do not sell biometric personal data. Texas residents may exercise the rights in Section 9 and appeal under Section 9.3, and may file a complaint with the Texas Attorney General.
12. Children’s privacy
The Services are clinical software sold to health care organizations and are not directed to children. We do not knowingly collect personal information from children under 13 through omnipacs.com or through account registration, and we do not knowingly sell or share the personal information of consumers under 16.
Pediatric imaging is routine in radiology. Any information about a minor patient inside the OmniPACS platform is PHI, and is handled in accordance with HIPAA and our agreements with the health care provider — not under this Policy, and never for advertising.
If we learn that we have collected personal information from a child under 13 through our website, we will delete it. A parent or guardian may email support@omnipacs.com with the subject line “PRIVACY REQUEST” to ask us to review and delete such information.
13. International transfers and where your data lives
The Services are built for U.S. health care organizations and are intended for use in the United States. We are not offering the Services to individuals in the European Economic Area, the United Kingdom or Switzerland, and we do not knowingly target individuals there or monitor their behavior — including through cross-site or behavioral tracking, which we do not deploy for that purpose. Nothing in this Policy is an undertaking to act as a controller or processor under the EU or UK General Data Protection Regulation, and we have not assumed obligations under those regimes.
Where data is stored. The platform runs on third-party cloud infrastructure. OmniPACS does not warrant that customer data, personal information or PHI will be stored or processed in any particular country or region. We will identify the regions then in use on written request, under a non-disclosure agreement. A customer with a data-residency requirement must obtain a written commitment to that effect in an Order Form; absent that written commitment, no residency commitment exists. Certain subprocessors named in Section 5.2 may process limited operational or telemetry data outside the United States.
We do not claim certification under the EU-US Data Privacy Framework, the UK Extension, or the Swiss-US Data Privacy Framework, and we make no representation of adequacy under any transfer framework.
14. Third-party sites and services
Our sites and application link to third-party services, including the CHILI diagnostic viewer, our subscription-billing portal, payment pages hosted by Stripe, and app-store distribution channels. Once you follow a link into a third party’s environment, that party’s own privacy notice governs. We are not responsible for their practices and we encourage you to read their notices.
15. Other notices you may be looking for
| Notice | Where |
|---|---|
| Our commercial and service terms, including our Business Associate Agreement terms and our security commitments to customers | https://omnipacs.com/legal/agreement |
| This Privacy Policy | https://omnipacs.com/legal/privacy |
| Subprocessor list | https://omnipacs.com/legal/subprocessors |
| Cookie preferences | The “Cookie preferences” link on omnipacs.com |
| Your provider’s HIPAA Notice of Privacy Practices | From your imaging center, hospital or physician practice — it is not ours to publish |
16. Changes to this Policy
We may update this Policy as our practices, products or legal obligations change. When we do, we will change the “Last updated” date at the top and post the revised Policy at https://omnipacs.com/legal/privacy.
For material changes — a new category of personal information, a new purpose, a new category of recipient, or any change to whether we sell or share — we will provide at least thirty (30) days’ advance notice before the change takes effect: a notice on the affected site, an in-application notice for account holders, and, where we hold a current email address for you, an email. Where the law requires your consent for a new purpose, category or recipient, we will obtain that consent before beginning the new practice rather than relying on the updated Policy alone.
We keep prior versions of this Policy available on request.
17. Contact us
OmniPACS Healthcare Technologies LLC
17 Griffin Street
Monmouth Beach, New Jersey 07750
United States
Telephone: 813-590-0846
| Purpose | Contact |
|---|---|
| Privacy questions and rights requests | support@omnipacs.com, subject line “PRIVACY REQUEST” · 813-590-0846 |
| Privacy request appeals | support@omnipacs.com, subject line “PRIVACY REQUEST — APPEAL” |
| Security incidents and vulnerability reports | support@omnipacs.com, subject line “SECURITY” |
| HIPAA and Business Associate matters | support@omnipacs.com, subject line “HIPAA” |
| General support | support@omnipacs.com · 813-590-0846 |
| Sales and commercial questions | sales@omnipacs.com |
| Formal legal notice | Written notice to 17 Griffin Street, Monmouth Beach, New Jersey 07750, Attention: Legal, with a copy by email to support@omnipacs.com |
Patients: please contact your health care provider — see the note in Section 1.1.
If you are not satisfied with our response, you may appeal under Section 9.3 and, if still unsatisfied, contact your state Attorney General. California residents may also contact the California Privacy Protection Agency.