This policy explains what information Practice OS collects, how it is used and protected, and the choices available to you. It applies to the Practice OS web application, to the connections it makes to QuickBooks Online and Google Sign-In, and to the clinical, billing and payroll data a practice provides to it.
Practice OS is a private, invitation-only application. It is provided to a medical practice and to the specific individuals that practice authorizes. There is no public sign-up.
Physicians' AI Mid-Atlantic, PLLC ("Physicians' AI", "we", "us") operates Practice OS. For any privacy question, request, or complaint, contact dmitri@physiciansai.com.
When you sign in, Google confirms your identity to us and we receive your email address and the fact that Google verified it. We never see, receive, or store your Google password. Only email addresses on an explicit allowlist can sign in; everyone else is refused.
When a QuickBooks administrator for the practice authorizes the connection, we retrieve accounting reports for that company:
This is business accounting information. The connection is read-only: Practice OS never creates, edits, or deletes anything in your QuickBooks company, and never initiates a payment, transfer, or any other financial transaction.
The practice exports billing and encounter data from its electronic medical record and supplies it to Practice OS. Each record describes a single billed service line and contains:
This is protected health information, and we process it as a business associate of the practice. It does not include patient names, addresses, telephone numbers, email addresses, Social Security numbers, or any clinical note, image or laboratory result.
The practice exports payroll records for its own employees and supplies them to Practice OS:
Practice OS holds only the fields it needs on an explicit permitted list; anything outside that list is discarded before the data is stored, and storage is refused outright if a prohibited field is present. The practice informs its employees of this use through its employee handbook.
For security and access review we record, for each request: timestamp, the signed-in email address, the action, the resource requested, whether it was allowed or denied, a request identifier, and the source IP address. These logs deliberately contain no credentials, session cookies, or record contents.
We do not collect payment card numbers, bank account numbers, Social Security numbers, or any password. Authentication is delegated to Google, and QuickBooks authorization is delegated to Intuit; neither credential is ever visible to Practice OS. For employees, Social Security numbers, dates of birth, home addresses, telephone numbers and email addresses are removed before payroll data is stored, and the reasons an employee gives when requesting time off are never collected at all.
We do not sell, rent, or trade your information. We do not use it for advertising, and we do not use it to train machine-learning models.
Practice OS uses Claude, an AI assistant operated by Anthropic PBC, for four features: answering questions in the ask bar, reviewing how ledger entries are categorised, drafting operational recommendations, and generating custom reports. When one of those features runs, the following is sent to Anthropic:
What is never sent: patient records. No patient names, medical record numbers, dates of birth, individual dates of service, or per-patient rows of any kind are available to the AI assistant. The system does not merely decline to send them — the AI features are not given access to that data at all. Where a statistic would describe fewer than eleven patients, it is combined with others before being sent, so that no figure can be traced back to an individual; on a quiet day the calendar shows a range rather than an exact count for the same reason.
Anthropic does not use this data to train its models. Every AI request is recorded in the same access log as any other use of practice data, showing who asked and when. AI-generated text is labelled as such on screen, and every figure shown in the dashboard comes from the practice's own stored records rather than from the model.
If we ever change what is sent — in particular, if patient-level information were ever to be included — this policy will be updated first and the practice will be notified, and that change would additionally require a signed agreement with Anthropic covering protected health information.
| Scope requested | com.intuit.quickbooks.accounting — used only to read the reports listed in section 2 |
|---|---|
| Who can authorize | A QuickBooks administrator for the practice's company file |
| Where tokens live | Google Secret Manager, encrypted at rest, readable only by this application's dedicated service account |
| How to disconnect | In QuickBooks Online: Settings → Apps → Practice OS → Disconnect. You may also email us and we will disconnect it for you. |
| Effect of disconnecting | We immediately stop retrieving data and delete the stored authorization tokens. |
The patient and payroll data described in section 2 do not arrive through a connection we hold. The practice extracts them from its own electronic medical record and payroll system and supplies the resulting files to Practice OS, and the practice decides what to send and when. Practice OS has no access to either system, cannot write to them, and cannot retrieve anything the practice has not provided. A direct read-only connection to the practice's payroll system is planned; this policy will be updated, and the provider added to section 6, before any such connection is used.
We use a small number of service providers to run Practice OS. We do not disclose your information to anyone else except where required by law.
| Provider | Role | Location |
|---|---|---|
| Google Cloud Platform | Application hosting, secret storage, log storage | United States (us-east4) |
| Google LLC | Sign-in and identity verification | United States |
| Intuit Inc. | Source of the QuickBooks accounting data you authorize | United States |
| Anthropic PBC | AI assistant (Claude) for the features described in section 4 — accounting, payroll and de-identified practice statistics only; no patient records | United States |
Access is limited to a small number of individuals the practice has authorized — at the effective date of this policy, three. There is no tiered view: an authorized user can see all of the data described in section 2, including employee compensation and patient-level billing detail. Each of them is bound by a written agreement with Physicians' AI Mid-Atlantic, PLLC governing the confidentiality and permitted use of that information. Anyone not on the allowlist is refused.
No system is perfectly secure, and we do not claim otherwise. If we become aware of a breach affecting your information, we will notify the practice promptly.
You may at any time disconnect QuickBooks, ask us what information we hold about you, ask us to delete it, or ask that your access be removed. Email dmitri@physiciansai.com and we will respond promptly. Because Practice OS is invitation-only, the practice that authorized your access may also request its removal.
Patients and employees of the practice. Practice OS holds your information on the practice's behalf and acts on the practice's instructions. If you are a patient of the practice, or one of its employees, please direct any request about your information — to see it, correct it, or have it deleted — to the practice itself. It remains responsible for that information, and we will carry out what it asks of us.
Practice OS is a business tool for medical-practice staff. It is not directed to children and we do not knowingly collect information from anyone under 18.
If we change this policy we will post the revised version at this address with a new effective date. Material changes — in particular any change to the categories of data we collect — will be communicated to the practice before they take effect.
Physicians' AI Mid-Atlantic, PLLC
dmitri@physiciansai.com