Physicians' AI
PRACTICE OS

Privacy Policy

Version 1.2 · Effective 12 August 2026 · Physicians' AI Mid-Atlantic, PLLC

This policy explains what information Practice OS collects, how it is used and protected, and the choices available to you. It applies to the Practice OS web application, to the connections it makes to QuickBooks Online and Google Sign-In, and to the clinical, billing and payroll data a practice provides to it.

What changed in version 1.2. Practice OS now uses Claude, an AI assistant operated by Anthropic, to answer questions about the practice's operations, review how ledger entries are categorised, and draft reports and recommendations. Section 4 sets out exactly what is sent to it and, just as importantly, what is not. Patient records are not sent. The practice was notified and approved this before the feature was switched on.
What changed in version 1.1. Practice OS now works with two further categories of practice data: patient billing and encounter records exported from the practice's electronic medical record, and employee payroll records exported from its payroll system. Sections 2, 3, 5, 7 and 8 describe both, and section 8 replaces the earlier description of retention. The practice was notified and approved these categories before the data was loaded.

Practice OS is a private, invitation-only application. It is provided to a medical practice and to the specific individuals that practice authorizes. There is no public sign-up.

1. Who we are

Physicians' AI Mid-Atlantic, PLLC ("Physicians' AI", "we", "us") operates Practice OS. For any privacy question, request, or complaint, contact dmitri@physiciansai.com.

2. What we collect

Account identity

When you sign in, Google confirms your identity to us and we receive your email address and the fact that Google verified it. We never see, receive, or store your Google password. Only email addresses on an explicit allowlist can sign in; everyone else is refused.

Practice accounting data from QuickBooks Online

When a QuickBooks administrator for the practice authorizes the connection, we retrieve accounting reports for that company:

This is business accounting information. The connection is read-only: Practice OS never creates, edits, or deletes anything in your QuickBooks company, and never initiates a payment, transfer, or any other financial transaction.

Patient billing and encounter data from the practice's medical record

The practice exports billing and encounter data from its electronic medical record and supplies it to Practice OS. Each record describes a single billed service line and contains:

This is protected health information, and we process it as a business associate of the practice. It does not include patient names, addresses, telephone numbers, email addresses, Social Security numbers, or any clinical note, image or laboratory result.

Employee payroll data from the practice's payroll system

The practice exports payroll records for its own employees and supplies them to Practice OS:

Practice OS holds only the fields it needs on an explicit permitted list; anything outside that list is discarded before the data is stored, and storage is refused outright if a prohibited field is present. The practice informs its employees of this use through its employee handbook.

Access logs

For security and access review we record, for each request: timestamp, the signed-in email address, the action, the resource requested, whether it was allowed or denied, a request identifier, and the source IP address. These logs deliberately contain no credentials, session cookies, or record contents.

3. What we do not collect

Protected health information. Practice OS processes the patient billing and encounter data described in section 2 on behalf of the practice, under an executed Business Associate Agreement. It does not receive patient identities, contact details, appointment schedules, clinical notes, images, or laboratory results, and it is never used to make or influence a clinical decision about any patient.

We do not collect payment card numbers, bank account numbers, Social Security numbers, or any password. Authentication is delegated to Google, and QuickBooks authorization is delegated to Intuit; neither credential is ever visible to Practice OS. For employees, Social Security numbers, dates of birth, home addresses, telephone numbers and email addresses are removed before payroll data is stored, and the reasons an employee gives when requesting time off are never collected at all.

4. How we use information

We do not sell, rent, or trade your information. We do not use it for advertising, and we do not use it to train machine-learning models.

Artificial intelligence

Practice OS uses Claude, an AI assistant operated by Anthropic PBC, for four features: answering questions in the ask bar, reviewing how ledger entries are categorised, drafting operational recommendations, and generating custom reports. When one of those features runs, the following is sent to Anthropic:

What is never sent: patient records. No patient names, medical record numbers, dates of birth, individual dates of service, or per-patient rows of any kind are available to the AI assistant. The system does not merely decline to send them — the AI features are not given access to that data at all. Where a statistic would describe fewer than eleven patients, it is combined with others before being sent, so that no figure can be traced back to an individual; on a quiet day the calendar shows a range rather than an exact count for the same reason.

Anthropic does not use this data to train its models. Every AI request is recorded in the same access log as any other use of practice data, showing who asked and when. AI-generated text is labelled as such on screen, and every figure shown in the dashboard comes from the practice's own stored records rather than from the model.

If we ever change what is sent — in particular, if patient-level information were ever to be included — this policy will be updated first and the practice will be notified, and that change would additionally require a signed agreement with Anthropic covering protected health information.

5. Where the data comes from

Your QuickBooks connection

Scope requestedcom.intuit.quickbooks.accounting — used only to read the reports listed in section 2
Who can authorizeA QuickBooks administrator for the practice's company file
Where tokens liveGoogle Secret Manager, encrypted at rest, readable only by this application's dedicated service account
How to disconnectIn QuickBooks Online: Settings → Apps → Practice OS → Disconnect. You may also email us and we will disconnect it for you.
Effect of disconnectingWe immediately stop retrieving data and delete the stored authorization tokens.

Practice-supplied exports

The patient and payroll data described in section 2 do not arrive through a connection we hold. The practice extracts them from its own electronic medical record and payroll system and supplies the resulting files to Practice OS, and the practice decides what to send and when. Practice OS has no access to either system, cannot write to them, and cannot retrieve anything the practice has not provided. A direct read-only connection to the practice's payroll system is planned; this policy will be updated, and the provider added to section 6, before any such connection is used.

6. Who else is involved

We use a small number of service providers to run Practice OS. We do not disclose your information to anyone else except where required by law.

ProviderRoleLocation
Google Cloud PlatformApplication hosting, secret storage, log storageUnited States (us-east4)
Google LLCSign-in and identity verificationUnited States
Intuit Inc.Source of the QuickBooks accounting data you authorizeUnited States
Anthropic PBCAI assistant (Claude) for the features described in section 4 — accounting, payroll and de-identified practice statistics only; no patient recordsUnited States

7. How we protect information

Who can see this information

Access is limited to a small number of individuals the practice has authorized — at the effective date of this policy, three. There is no tiered view: an authorized user can see all of the data described in section 2, including employee compensation and patient-level billing detail. Each of them is bound by a written agreement with Physicians' AI Mid-Atlantic, PLLC governing the confidentiality and permitted use of that information. Anyone not on the allowlist is refused.

No system is perfectly secure, and we do not claim otherwise. If we become aware of a breach affecting your information, we will notify the practice promptly.

8. How long we keep information

9. Your choices

You may at any time disconnect QuickBooks, ask us what information we hold about you, ask us to delete it, or ask that your access be removed. Email dmitri@physiciansai.com and we will respond promptly. Because Practice OS is invitation-only, the practice that authorized your access may also request its removal.

Patients and employees of the practice. Practice OS holds your information on the practice's behalf and acts on the practice's instructions. If you are a patient of the practice, or one of its employees, please direct any request about your information — to see it, correct it, or have it deleted — to the practice itself. It remains responsible for that information, and we will carry out what it asks of us.

10. Children

Practice OS is a business tool for medical-practice staff. It is not directed to children and we do not knowingly collect information from anyone under 18.

11. Changes to this policy

If we change this policy we will post the revised version at this address with a new effective date. Material changes — in particular any change to the categories of data we collect — will be communicated to the practice before they take effect.

12. Contact

Physicians' AI Mid-Atlantic, PLLC
dmitri@physiciansai.com

See also the End-User License Agreement.