Privacy

Privacy Policy

ClearPath Care is remote therapeutic monitoring software that medical practices use to run their own monitoring programs. The health information inside it belongs to the practice. We handle it only to run the software for them, under a written HIPAA business associate agreement. We do not sell it, we do not advertise against it, and we do not use it for anything the practice has not asked us to do.

Effective
August 4, 2026
Version
1.0
Operator
Tensor Solutions
Role under HIPAA
Business associate

1. Who we are

ClearPath Care is remote therapeutic monitoring software, operated by Tensor Solutions (referred to here as Tensor, we, or us). It runs on the Verabill reimbursement engine.

Medical practices license ClearPath Care to run their own Medicare remote therapeutic monitoring programs: enrolling a patient on a practitioner order, collecting the monitoring data the patient sends in, recording the staff time spent managing that data, and assembling the evidence a claim has to have behind it.

The practice is the covered entity under HIPAA. The health information in ClearPath Care is the practice's, and the practice decides how it is used. Tensor is a business associate. We handle that information only to provide the service to the practice, and only within the limits of the written business associate agreement we sign before any of it reaches us.

eClinicalWorks stays the practice's clinical system of record. ClearPath Care reads from it. It does not write back to it.

2. What this policy covers

Two different things carry the ClearPath Care name, and they are governed differently. This page covers both.

  • This website, clearpathcare.ai. A marketing site we operate ourselves. It collects almost nothing. Section 11 is the whole story.
  • The ClearPath Care product, used by practice staff and their patients at a separate address. Health information there is processed for the practice under a business associate agreement. Sections 3 through 10 cover it.

Where this page and a signed business associate agreement differ, the agreement governs.

3. What the product processes for practices

For a practice running a monitoring program, ClearPath Care holds these categories of protected health information:

  • Patient identity and contact details, taken from the practice's own records.
  • Insurance and Medicare coverage details, as they appear in the practice's own records.
  • The practitioner order, the treatment plan, and the patient's consent to the monitoring program.
  • The patient's monitoring submissions: the assessments and readings sent in from the patient app.
  • Staff time entries recording the minutes spent managing that monitoring data.
  • Claim candidates and the stored evidence bundle behind each one.
  • Coinsurance statements and their delivery status.

It arrives from three places: the practice's eClinicalWorks export, the practice's own staff working in the console, and the patient's own submissions in the patient app. Verifying a patient's Medicare eligibility is the practice's own billing function and happens outside ClearPath Care.

We collect what the monitoring program needs and no more. Fields we do not need for a condition of payment, for patient safety, or for supporting the practice are not imported.

4. What we do with it, and what we never do

We use protected health information only to:

  • Run the monitoring program the practice has configured.
  • Produce claim candidates and the evidence that supports them.
  • Support the practice, investigate faults, and keep the service secure and available.
  • Meet our own legal obligations.

We never:

  • Sell it, rent it, or share it for anyone else's marketing.
  • Use it for advertising, or make it available to advertisers.
  • Use it to train machine learning models, ours or anyone else's.
  • Disclose it to a third party, except to a subcontractor under a business associate agreement, at the practice's instruction, or where the law requires it.
  • Use it for any purpose the practice has not agreed to.

Disclosures are bounded by the minimum necessary standard at 45 CFR 164.502(b): a request gets the least information that answers it, and access inside the product is scoped to the sites a staff member actually works at.

5. The AI layer

ClearPath Care uses AI to assist staff. The boundary is drawn tightly and enforced in the software itself, not by policy alone.

  • AI never writes to a patient. Everything a patient reads is fixed text from a reviewed catalog, not generated at the time it is sent.
  • AI never records billable time, and never counts as the live conversation Medicare requires. AI activity is written to a separate ledger that cannot produce a claim.
  • No AI output enters a record until a staff member has read it and either edited or confirmed it.
  • Decisions that touch safety or payment, including eligibility and Qualified Medicare Beneficiary status, do not go to AI at all. They follow deterministic rules.
  • Inference runs on infrastructure we operate. Prompts are processed in memory, request and output logging is off, and no prompt data is cached to disk.
  • No practice data and no patient data is used to train any model.

6. How we protect it

We maintain a written HIPAA security risk analysis and the supporting administrative, physical, and technical safeguards required by 45 CFR 164.302 through 164.318. They are reviewed annually and after any material change. In practice:

  • Encrypted in transit. Every connection uses TLS 1.2 or higher.
  • Encrypted at rest. The database and every stored object are encrypted with managed keys. Each claim evidence bundle gets its own key.
  • Least privilege and site scoping. A staff member sees only patients at the sites their role allows, enforced in the database itself rather than only in the application.
  • Multi-factor authentication for staff, with a fresh second factor required again before sensitive actions such as exporting patient data.
  • An access log. Every read of patient data through the product is recorded, and the practice can review it.
  • Append-only billing and audit records. Corrections are new entries that reference the old one. Nothing is edited or deleted in place.
  • Write-once storage for claim evidence, which cannot be deleted before its retention period ends, including by us.

We do not claim a certification we do not hold. There is no such thing as HIPAA certification, and we make no SOC 2 or HITRUST claim. What we offer instead is the written risk analysis, the policies behind it, and contractual audit rights into how the platform counts minutes and days.

7. Subcontractors

We keep the list short deliberately. Before any protected health information reaches a subcontractor, that subcontractor has signed a business associate agreement, and the same obligations flow down its own chain. Today the list has one entry:

  • Amazon Web Services: hosting, database, storage, and message delivery for the product, under an executed business associate agreement.

We do not add a subcontractor that touches protected health information without a signed business associate agreement in place first, and we update this page when the list changes.

Text messages we send patients carry no clinical content and no name: only a notice that something is waiting in the app. The message body has no protected health information in it by construction.

8. Retention and deletion

  • We hold a practice's monitoring and billing records for as long as its agreement runs, and afterward for the period the practice's own records retention obligations require. For our North Carolina practices that is 11 years for adults and until age 30 for minors, which is the community standard there. A practice may direct a different period in writing.
  • Claim evidence bundles sit in write-once storage with a 10-year minimum retention. They cannot be deleted before it lapses, by anyone, including us.
  • On written request from the practice, and on termination of the agreement, we return or destroy the protected health information we hold. The exception is anything we are required by law to keep, or that sits under an unexpired retention lock. Where we cannot delete, we say so plainly and keep protecting it under this policy and the business associate agreement for as long as we hold it.
  • Our disposal method is destruction of the encryption key, which makes the stored data permanently unreadable. Physical drives that ever held health information are cryptographically erased and destroyed rather than reformatted. Every disposal is logged.
  • A deletion request from a patient goes to the practice, not to us. See section 9.

9. If you are a patient

Your practice holds your record. Your rights under HIPAA are exercised with the practice, not with us: the right to see your information and get a copy, to ask for a correction, to get an accounting of disclosures, and to ask for restrictions on how it is used. Your practice's Notice of Privacy Practices tells you how, and its privacy officer is the person to ask.

We build the product so the practice can answer you properly. It can export a patient's complete monitoring record, including submissions, time entries, and the claim evidence, in a readable form. That is what the right of access at 45 CFR 164.524 requires, and the practice can produce it without waiting on us. When a practice does want our help answering a request, we help.

If you raised something with your practice and did not get a satisfactory response, you may also file a complaint with the Office for Civil Rights at the U.S. Department of Health and Human Services. Neither the practice nor Tensor may retaliate against you for filing one.

10. Breach notification

If we discover a breach of unsecured protected health information, we notify the affected practice without unreasonable delay and no later than 60 days after discovery, as 45 CFR 164.410 requires, with the detail the practice needs to make its own notifications. The practice, as the covered entity, notifies the affected individuals and the Department of Health and Human Services under 45 CFR 164.404 and 164.408.

Where state law adds an obligation, such as notice to the North Carolina Attorney General when the information involved meets that state's definition of personal information, we support the practice in meeting it. We keep a written incident record of every investigation, including the ones that turn out not to be breaches.

11. This website

clearpathcare.ai is a static marketing site. It is deliberately thin, and the short version is that it collects nothing about you beyond an ordinary server log.

  • No accounts, no forms, no payments. There is nothing here to submit.
  • No cookies. No analytics, no advertising pixels, no third-party trackers, no social embeds.
  • No fonts, scripts, or images loaded from anyone else's servers. Everything is served from ours.
  • Nothing is stored in your browser by us.
  • Our web server and our content delivery network keep ordinary access logs: IP address, time, the page requested, and the browser user agent. They exist to serve the site and defend it from abuse, they are kept for a short operational period, and they are not used to profile you or joined to anything else.
  • Every screen pictured on this site uses synthetic demonstration data. No patient information appears anywhere on this website.

The product itself is at a separate address and is not reachable from this site. This site is not directed at children and we do not knowingly collect information from them. Health information about patients who are minors is handled inside the product, for the practice, under the practice's authority.

12. Changes to this policy

If we change this policy we post the new version here and move the effective date at the top. When a change materially affects how we handle protected health information, we tell the practices under agreement with us directly rather than relying on them to notice. The business associate agreement governs wherever it is stricter than this page.

13. Contact

  • Privacy and security questions, including a suspected vulnerability or an incident: mafuz@tensorsolutions.com. This is the ClearPath Care privacy and security contact at Tensor Solutions, which operates the platform. Our designated Security Officer monitors it, and we acknowledge reports within one business day.
  • Practices under agreement: use the support channel in your agreement for anything urgent.
  • Patients: contact your practice first. See section 9.

ClearPath Care is operated by Tensor Solutions. Written notice may be sent to the address in your agreement.

This policy describes how Tensor Solutions handles information as the operator of ClearPath Care. It is not legal advice and it does not replace the Notice of Privacy Practices your own practice gives you, which is the document that governs your rights as a patient.

Back to ClearPath Care