Last updated: August 2026
This Privacy Policy explains how PLYXIO ("we," "us," "our") collects, uses, and protects information when hospitals and other healthcare facilities ("Hospitals," "Customers") and their staff and patients ("Users") use Vitals, our hospital management software ("Service").
This policy covers three types of people: (a) staff members of a Hospital using Vitals (administrators, doctors, nurses, and other employees), (b) patients of a Hospital who use the patient portal, and (c) visitors to our public website.
Important distinction for patient data: when it comes to patient health records, appointments, prescriptions, and other clinical information, the Hospital is the data controller and PLYXIO acts as a data processor on the Hospital's behalf. This means the Hospital decides what patient data is collected and how it is used clinically; PLYXIO's role is to store, secure, and make that data available to the Hospital and its authorized staff and patients through the Service. Questions about how a specific Hospital uses its patients' data should be directed to that Hospital.
We use a small number of trusted service providers to operate Vitals, each of whom processes data only as needed to provide their specific service to us:
We do not sell personal data or patient data to third parties, and we do not share patient clinical data across Hospitals — each Hospital's data is isolated from every other Hospital on the platform.
We use industry-standard security practices, including encrypted connections, row-level database access controls that isolate each Hospital's data, optional two-factor authentication for accounts, and bot/abuse protection on public forms. No system is perfectly secure, and we encourage Hospitals and Users to use strong, unique passwords and enable two-factor authentication where available.
We retain account and clinical data for as long as a Hospital's account remains active, and for a reasonable period afterward in case of reactivation, unless the Hospital requests earlier deletion or applicable law requires a different retention period. A Hospital administrator may request deletion of their Hospital's account and associated data at any time by contacting us.
Depending on your role and location, you may have rights to access, correct, or request deletion of your personal information. Staff and patients should generally contact their Hospital administrator first, since the Hospital controls its own patient and staff records. You can also reach us directly using the contact details below for questions about data we hold in our role as service provider.
Vitals may be used by Hospitals to store medical records for patients of any age, including minors, as part of standard healthcare recordkeeping. In such cases, the Hospital — not PLYXIO — is responsible for ensuring appropriate parental or guardian consent is obtained in line with its own clinical and legal obligations.
We may update this Privacy Policy from time to time. We will post the updated version here with a revised "last updated" date. Continued use of the Service after an update constitutes acceptance of the revised policy.
Questions about this Privacy Policy can be sent through our Contact page.
This document is a general-purpose privacy policy template and has not been reviewed by a lawyer. Given that Vitals handles patient health information, we'd strongly recommend having this reviewed by legal counsel familiar with healthcare data and applicable regulations in the jurisdictions where you operate before relying on it as your final policy.