CLINICAL MEDIA HUB
  • Plans
  • Templates
  • Blog
  • FAQ
  • Contact  ·  Data Deletion
  • Sign In
Get Started

Privacy Policy

Effective Date: March 1, 2026  ·  Last Updated: March 18, 2026

Summary: Clinical Media Hub operates a HIPAA-aware marketing platform for medical practices. We collect information to provide our services. We do not sell your personal information. California residents have specific rights under CCPA/CPRA.

1. Who We Are

Clinical Media Hub (“CMH,” “we,” “us,” or “our”) is a subscription-based digital marketing and communication platform designed for medical practices, healthcare providers, and clinical trial sites. Our principal place of business is in California, United States.

This Privacy Policy applies to our marketing website at clinicalmediahub.com, our subscriber dashboard, and all related services (collectively, the “Services”).

2. Information We Collect

2a. Information You Provide

  • Account registration: Name, practice name, email address, phone number, specialty, and billing information.
  • Practice profile: Practice address, provider names, services, hours, photos, and other content you upload.
  • Payment information: Processed by Stripe. We do not store full card numbers.
  • Communications: Messages sent to our support team.
  • Contact form submissions: Name, email, phone, and message content submitted through our website.

2b. Information Collected Automatically

  • IP address, browser type, operating system, referring URLs, and pages visited.
  • Session and usage data through server logs.
  • Essential session cookies (see Section 7).

2c. Information From Third Parties

  • Google Business Profile data when you connect your account.
  • Social media tokens when you authorize Facebook or Instagram integration.
  • IntakeQ data when you connect your IntakeQ account (subscriber-controlled).
  • Square payment data when you connect your Square account (subscriber-controlled).

3. How We Use Your Information

  • To provision and operate your dedicated practice website and subscriber dashboard.
  • To generate AI-powered marketing content for your review and approval.
  • To process billing and manage your subscription.
  • To send transactional communications (receipts, service alerts, security notices).
  • To respond to support inquiries.
  • To improve our platform through aggregated, de-identified analytics.
  • To comply with applicable legal obligations.

We do not use your information for behavioral advertising, sell it to data brokers, or share it with third parties for their own marketing purposes.

4. HIPAA and Protected Health Information

CMH operates HIPAA-aware infrastructure. Subscriber practices on Growth and Complete plans execute a Business Associate Agreement (BAA) with CMH, covering the infrastructure CMH controls.

Subscriber practices are independent HIPAA Covered Entities or Business Associates. They are responsible for their own HIPAA compliance, including how they collect, store, and transmit patient Protected Health Information (PHI) through their practice websites and connected third-party tools.

CMH’s AI content generation system operates on marketing and operational data only. Patient PHI should not be entered into the content generation system.

Foundation plan subscribers do not receive a BAA from CMH. Foundation plan infrastructure is HIPAA-aware but not covered by a CMH BAA.

5. Sharing of Information

We share information only as described below:

  • Service providers: AWS (hosting, email, Chime SDK televisit), Stripe (payments), Google APIs, Facebook/Meta API, fal.ai (image generation), Namecheap (domain registration), HelloSign/Dropbox Sign (BAA delivery). Each operates under data processing agreements.
  • Legal compliance: When required by law, court order, or governmental authority.
  • Business transfers: In connection with a merger, acquisition, or sale of assets, with confidentiality protections.

We do not sell personal information to any third party.

6. California Privacy Rights (CCPA/CPRA)

California residents have the following rights:

  • Right to Know: Request disclosure of categories and specific pieces of personal information collected about you.
  • Right to Delete: Request deletion of your personal information, subject to certain exceptions.
  • Right to Correct: Request correction of inaccurate personal information.
  • Right to Opt Out of Sale or Sharing: We do not sell or share personal information for cross-context behavioral advertising.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
  • Right to Limit Sensitive PI Use: We only use sensitive personal information to provide our services.

To exercise your rights, contact us at privacy@clinicalmediahub.com. We respond within 45 days. We may need to verify your identity before processing your request.

7. Cookies

We use only essential session cookies required for platform operation (login state, CSRF protection). We do not use third-party advertising cookies or tracking pixels on our marketing site. You may disable cookies in your browser but this may prevent some platform features from working.

8. Data Retention

  • Active subscribers: Data retained for the duration of your subscription.
  • After cancellation: Account data retained for 90 days for reactivation, then deleted within 30 days of that period ending.
  • Audit logs (BAA subscribers): Retained 7 years as required for HIPAA compliance.
  • Billing records: Retained 7 years as required by law.

To request earlier deletion, see our Data Deletion Policy.

9. Security

We implement industry-standard security including TLS encryption in transit, AES-256 encryption at rest for sensitive fields, AWS KMS key management, isolated per-subscriber infrastructure, role-based access controls, and comprehensive audit logging. No system is completely immune to security risks. Report any suspected unauthorized access to security@clinicalmediahub.com immediately.

10. Children’s Privacy

Our Services are not directed to individuals under 18 years of age. We do not knowingly collect personal information from minors. If you believe we have inadvertently collected such information, contact us immediately.

11. Changes to This Policy

We may update this Privacy Policy periodically. We will notify active subscribers by email and post the updated policy with a revised effective date. Continued use of the Services after the effective date constitutes acceptance of the updated policy.

12. Contact Us

Clinical Media Hub
Privacy: privacy@clinicalmediahub.com
Website: clinicalmediahub.com/contact

CLINICAL MEDIA HUB
Terms of Use Privacy Policy  ·  Content Disclaimer Contact  ·  Data Deletion

© 2026 Clinical Media Hub. All rights reserved.