Dion Health — Privacy Policy
Version: 1.1 Effective Date: July 24, 2026 Last Updated: July 24, 2026
Dion Health Management Company LLC ("Dion," "we," "us," or "our"), a California limited liability company with offices at 450 Sutter Street, Suite 1519, San Francisco, CA 94108, provides the Dion Suite — a family of software products used by dental and healthcare practices, dental service organizations, and their staff.
This Privacy Policy explains what information the Dion Suite collects, how we use it, who we share it with, how long we keep it, and what rights you have. It applies to every product in the Dion Suite, not to any single application.
This Policy is incorporated into the Master Subscription Agreement (the "Agreement") under Section 2.3 of that Agreement. Capitalized terms not defined here have the meaning given in the Agreement. Where Dion handles Protected Health Information, the Business Associate Agreement ("BAA") controls over this Policy to the extent of any conflict.
1. Scope and Our Role
1.1 Who this Policy covers
- Customers — the practices, groups, dental service organizations, and other organizations that subscribe to Dion products.
- Authorized Users — the administrators, providers, and staff who sign in to a Dion product on a Customer's behalf.
- Individuals whose information a Customer puts into the Services — patients, prospective patients, employees, members, and contacts. Dion generally has no direct relationship with these individuals; their information reaches us because a Customer sent it or authorized us to read it.
- Website visitors — people who visit our public websites and marketing pages, or who submit an inquiry form.
1.2 What this Policy covers
All Dion products, whether generally available, in limited availability, or not yet released — including the Dion Console and suite platform, Dion Insights, MedicalDentalRCM (MDRCM), Lead Intelligence, Smile Design Lab, Oralogix, Dion Growth Studio, Dion Workforce, Patient Engagement, Dion Desk, Dion Clinical (including Dion Scribe), Dion Pay, Dion Membership, and the Dion PMS Bridge. What each product is designed to process is set out in the Product Schedules; availability designations are stated there and summarized in Section 2 below.
1.3 Our role
Dion's role — and therefore your rights and our obligations — depends on the data:
- Protected Health Information (PHI). Where Dion creates, receives, maintains, or transmits PHI for a Customer, Dion acts as a Business Associate under HIPAA and the Customer acts as a Covered Entity (or, for a DSO acting for affiliated practices, as a business associate for which Dion is a subcontractor). Patient-facing privacy rights are governed by the BAA and by the Customer's own Notice of Privacy Practices, not by this Policy. A patient who wants to exercise a HIPAA right should contact the practice, not Dion. See Sections 5 and 9.
- Employee, payroll, marketing, lead, and member data. Dion generally acts as a service provider (California) or processor (other state privacy laws) on the Customer's behalf. The Customer decides what is collected and why; Dion processes it to deliver the Services and under the Customer's instructions.
- Our own business data. For Authorized User account records, billing records, Service Data, and information collected on our public websites, Dion acts as a business (California) or controller in its own right.
1.4 What this Policy does not cover
- A Customer's own privacy practices, consent collection, or Notice of Privacy Practices. Customers are solely responsible for those under Section 5.3 of the Agreement.
- Third-party systems the Customer connects — practice management systems, clearinghouses, payment processors, lenders, carriers, and advertising platforms — which handle data under their own terms.
- Websites we link to but do not operate.
2. Information We Collect
The Dion Suite covers materially different workflows, and the data categories differ by product. The presence of a category below does not mean every Customer's data includes it — it depends on which products the Customer has subscribed to and how they are configured.
| Category | Products | Is it PHI? |
|---|---|---|
| Patient health and treatment data | MDRCM, Dion Insights, Smile Design Lab, Oralogix, Patient Engagement, Dion Console, Dion PMS Bridge | Yes |
| Clinical records and encounter audio | Dion Clinical (incl. Dion Scribe) — limited availability | Yes |
| Patient financial and payment data | Dion Pay — limited availability; patient balances also in MDRCM | Yes |
| Communications data | Dion Desk, Patient Engagement, Lead Intelligence | Sometimes — see 2.4 |
| Employee and payroll data | Dion Workforce | No — employee PII, different law |
| Marketing and lead data | Lead Intelligence, Dion Growth Studio | No — and must not be commingled with PHI |
| Member and coverage data | Dion Membership — limited availability | Sometimes — see 2.7 |
| Operator account and contact data | All products | No |
| Website and product telemetry (Service Data) | All products and our websites | No |
2.1 Patient health information (PHI)
Most of the suite is designed to process PHI. Depending on the product, this includes patient demographics and contact details; insurance and subscriber information; procedure and diagnosis codes; appointment and scheduling records; claim, remittance, denial, and adjustment data; production, collections, and receivable balances; case photographs, intraoral scans, and diagnostic imaging; prescriptions and appliance parameters; and provider identifiers.
Two integration patterns bring this data to us, both described in the Product Schedules:
- Read Integration — Dion's hub reads a connected product's database using a service-role credential and applies tenant scoping in code on every read. Dion does not write to, modify, or delete records read this way.
- Event Integration — a product emits structured events into Dion's event bus. Events carry identifiers, references, codes, and amounts only — never clinical narrative content. Events that fail contract validation are rejected and dead-lettered.
The Dion PMS Bridge (not generally available) is an on-premises agent that reads a locally installed practice management system through a sanctioned developer interface or a read-only database connection and transmits only PHI-safe event data to the hub.
2.2 Clinical records and encounter audio
Dion Clinical, including the Dion Scribe ambient documentation assistant, is offered in limited availability to designated Customers. It processes complete clinical records — charting and periodontal data, examination findings, clinical narrative notes, treatment plans, images and scans — and, where Dion Scribe is enabled, audio recordings of clinical encounters and the transcripts derived from them. Recording a clinical encounter requires patient consent that the Customer must obtain before enabling the feature.
2.3 Patient financial and payment data
Dion Pay is offered in limited availability to designated Customers. It processes patient balances, charges, adjustments, plan terms, payment records, statement history, and collection status, together with the patient identifying information needed to associate a balance with a person. That combination constitutes PHI, and Dion processes it as a Business Associate under the BAA. Patient balances and payment records are also processed by MDRCM.
Full payment card numbers, magnetic-stripe data, card verification values, and bank account credentials are collected and processed by the third-party payment processor, not by Dion. Dion Pay retains processor references and tokens only. Customers must not transmit those values into any Dion field not documented to receive them.
2.4 Communications data
Dion Desk processes contact and interaction data (names, telephone numbers, email addresses, ticket content, message bodies), call recordings and transcripts where recording is enabled, and telephony and messaging metadata. Patient Engagement processes patient message content across SMS, email, and in-app chat, plus intake responses and appointment records. Lead Intelligence processes conversation content including message bodies, call records, transcripts, and sentiment and intent classifications.
Two things follow from this:
- Because patients and prospects routinely volunteer health information in a support call or an inquiry, these products may receive PHI. A BAA must be executed before a Customer uses them for interactions that may include PHI.
- Call recording and monitoring consent law varies by state, and several states require the consent of all parties to a call. The Customer — not Dion — determines which consent regime applies to each interaction, delivers the required disclosure, and configures recording, transcription, and retention settings accordingly. Transcription is machine-generated and may be inaccurate; a transcript is not a verbatim record.
2.5 Employee and payroll data
Dion Workforce processes information about a Customer's own workforce: employment records (names, contact details, work authorization and identification data, job and location assignment), compensation and payroll data (pay rates, hours, earnings, deductions, withholding elections, net pay, and payroll run records), tax-related identifiers submitted by the Customer, and credential, license, and compliance records including expiration tracking.
This is employee personal information, not patient PHI, and it is governed by different law — wage and hour, tax, employment, and state employee-privacy statutes rather than HIPAA. We treat it as a separate category with its own access controls, and we do not merge it into the patient-facing data of other products. Dion Workforce is not designed to process patient PHI. Where a Customer chooses to store employee health-related records (for example immunization or occupational-health items) in compliance tracking, the Customer is responsible for the additional legal requirements that attach to that data.
Dion is not the employer, joint employer, or employer of record of a Customer's personnel, and is not a payroll agent or tax filing agent. We process employee data on the Customer's instructions.
2.6 Marketing and lead data
Lead Intelligence and Dion Growth Studio process prospect and lead records (names, email addresses, telephone numbers, inquiry content), lead-source and campaign configuration data, campaign engagement and performance metrics, brand mentions, and advertising-platform data.
Dion Growth Studio is not designed to receive PHI, clinical records, or payment card data. Under the Product Schedules, Customers must not commingle marketing or lead data with PHI except within a Service and configuration expressly covered by an executed BAA. Customers are responsible for their lead sources and for the consents required to contact each individual by the channel used, including under the TCPA, CAN-SPAM, and state telemarketing and consent statutes.
2.7 Member and coverage data
Dion Membership is offered in limited availability to designated Customers. It processes member enrollment and identifying information, plan, premium, and payment records, risk-tier and score-band classifications derived from member data, and participating-provider business and payout data. Member data used to produce a risk classification may constitute PHI, and where it does, Dion processes it as a Business Associate under the BAA. Consistent with the platform's PHI rule, membership events carry coarse risk bands and tiers only — never a raw score and never a clinical condition.
2.8 Operator account and contact data
When a Customer sets up an account or an Authorized User signs in, we collect names, work email addresses, professional role, entitlements, practice name and address, National Provider Identifier where provided, and authentication records. Billing and payment information for the Customer's own subscription is processed by a third-party payment processor; we do not store full card numbers.
2.9 Website and product telemetry (Service Data)
We generate and collect Service Data — defined in the Agreement as data generated by Dion in operating the Services that contains no PHI and no Customer Confidential Information. This includes configuration data, telemetry, log data, usage statistics, performance metrics, error reports, audit records, and aggregate operational measurements. On our public websites we also collect IP address, browser and device type, pages viewed, referring URL, and any information you volunteer in an inquiry form.
3. How We Use Information
We use information to:
- Provide the Services — compute analytics and KPIs, process claims and remittances, route cases, run payroll, deliver messages and calls, maintain ledgers, and surface cross-product views in the Console.
- Authenticate and authorize — verify sessions, enforce role-based access and tenant isolation, and apply entitlements.
- Secure and monitor — detect and investigate unauthorized access, abuse, and fraud; maintain audit logs of access to and disclosure of PHI.
- Support and troubleshoot — respond to Customer requests, diagnose defects, and restore service.
- Send operational messages — sync status, alerts, service notices, and billing communications.
- Bill and administer — invoicing, collections on our own subscriptions, and usage verification.
- Improve and develop the Services — using Service Data and De-Identified Data, as described in Section 4.
- Comply with law — including HIPAA, and to respond to lawful requests.
We use PHI only as permitted by the BAA: to provide the Services, for our own proper management and administration, to provide data aggregation services relating to the Customer's health care operations, to de-identify it under Section 4, and to report violations of law. We apply the minimum necessary standard.
4. De-Identification and AI Training
This section describes how Dion uses data to build and improve machine-learning models. It restates, and must be read consistently with, Section 8 of the Agreement and Section 3 of the BAA.
4.1 Express authorization
Customers expressly authorize Dion to de-identify Customer Data, including PHI, in accordance with 45 C.F.R. § 164.514(a)–(c). That authorization is granted under 45 C.F.R. § 164.504(e)(2)(i), which permits a business associate agreement to specify additional permitted uses of PHI, and it is restated in the BAA as a material term.
4.2 Method
De-identification is performed by Dion or a qualified expert engaged by Dion using one or both of the methods HIPAA recognizes:
- Expert Determination under 45 C.F.R. § 164.514(b)(1) — a qualified person determines and documents that the risk is very small that the information could be used, alone or in combination with other reasonably available information, to identify an individual. Dion re-certifies its expert determination at least every three (3) years, or upon a material change to the process or the data.
- Safe Harbor under 45 C.F.R. § 164.514(b)(2) — removal of the eighteen enumerated identifiers, with no actual knowledge that what remains could identify an individual.
We maintain documentation of our de-identification methodology, and of any expert analysis and certification, and make it available to a Customer on request.
4.3 Status of de-identified data
Once de-identified in accordance with Section 4.2, the information is not Protected Health Information and HIPAA does not apply to it (45 C.F.R. § 164.502(d)(2)).
4.4 What we do with it
As between Dion and the Customer, Dion owns De-Identified Data and may use it for any lawful purpose, including to:
- develop, train, fine-tune, evaluate, and improve machine-learning models and artificial-intelligence features;
- produce industry benchmarks, comparative analytics, indices, and research;
- develop, improve, and market new and existing products and services; and
- publish aggregate findings — provided no publication identifies any Customer, practice, provider, or individual.
Dion owns the resulting models, model weights, embeddings, features, heuristics, statistical parameters, and derived insights. They are Dion Technology and are not Customer Data, notwithstanding that De-Identified Data derived from a Customer's data contributed to their development.
4.5 No training on identified PHI
Dion does not train, fine-tune, or improve machine-learning models on identified Protected Health Information. Model development uses De-Identified Data and Service Data only. Where an AI feature processes identified data to do its job for a Customer — for example drafting a reply or summarizing a record — that processing serves that Customer under the BAA and is not used to train models for anyone else.
4.6 More-stringent state law
Where applicable state law — including the California Confidentiality of Medical Information Act, Texas Health and Safety Code Chapter 181 (HB 300), or another state medical-information, genetic-privacy, or artificial-intelligence statute — imposes requirements on de-identification or secondary use that are more stringent than HIPAA, Dion complies with the more stringent requirement, and the rights described in Section 4.4 apply only to the extent that standard permits.
4.7 Negotiated limits
A Customer may negotiate limitations on Section 4.4 in an Order Form under Section 8.8 of the Agreement. Absent such a negotiated limitation, Section 4.4 applies in full.
5. HIPAA
5.1 Business Associate role
Where Dion creates, receives, maintains, or transmits PHI on a Customer's behalf, Dion is a Business Associate and is directly liable under HIPAA for the provisions applicable to business associates — the Security Rule, the Breach Notification Rule, and the applicable provisions of the Privacy Rule.
5.2 A BAA is required first
A signed BAA must be executed before a Customer transmits any PHI to the Services. The BAA is a signed two-party instrument; it is not accepted by click-through. Contact privacy@dionhealth.com to execute one.
Customers must not transmit PHI to any Service, module, field, or channel that the Documentation does not designate as intended to receive PHI.
5.3 Subcontractors
Any subcontractor that creates, receives, maintains, or transmits PHI on our behalf must agree in writing to restrictions at least as restrictive as those in the BAA. Dion remains responsible for its subcontractors' performance. A current list of subcontractors that process PHI is available on request.
5.4 Breach and incident notification
Under the BAA, Dion will report to the affected Customer:
- any impermissible use or disclosure of PHI — without unreasonable delay and no later than ten (10) business days after discovery; and
- any Breach of Unsecured PHI — without unreasonable delay and no later than thirty (30) calendar days after discovery, with the information required by 45 C.F.R. § 164.410(c) to the extent known, supplemented as more becomes available.
Successful security incidents are reported on the same basis. Routine unsuccessful attempts — port scans, blocked malware, failed log-ons, and similar — occur constantly and are not individually reported; the BAA constitutes notice of their ongoing occurrence. Notification is not an admission of fault or liability.
5.5 Assisting with individual rights
Dion will make PHI in a Designated Record Set available to the Customer, or as the Customer directs, and will support access, amendment, and accounting-of-disclosures requests within the timeframes set in the BAA. Where an individual contacts Dion directly, we forward the request to the Customer rather than responding, unless the Customer directs otherwise. We maintain an audit log of access to and disclosure of PHI through the Services for this purpose.
6. Sharing and Disclosure
6.1 What we never do
Dion does not sell personal information, and Dion does not share personal information for cross-context behavioral advertising. We have not sold or shared personal information for these purposes, and we do not do so for the personal information of anyone we know to be under 16.
We do not share Customer data or PHI with dental insurance companies for their own purposes, pharmaceutical companies, data brokers, or advertising platforms.
6.2 Subprocessors
We engage subprocessors to operate the Services — cloud infrastructure, database and authentication providers, and application hosting. Each is evaluated for security posture before engagement, is bound by data protection obligations no less protective than those in the Agreement and the BAA, and — where it will access PHI — must execute a BAA before access. Our current material infrastructure subprocessors are Supabase (database and authentication), AWS (cloud infrastructure), and Vercel (application hosting). A current subprocessor list is available on request.
6.3 Third-party processors, carriers, and platforms
Several products depend on third parties that a Customer contracts with directly and that handle data under their own terms:
- Payment processors and lenders (Dion Pay, and billing for Dion's own subscriptions) — they collect and process card and bank credentials; Dion holds tokens and references only.
- Clearinghouses and payers (MDRCM) — eligibility, adjudication, and remittance data originates with them.
- Telephony, messaging, and email providers (Dion Desk, Patient Engagement, Lead Intelligence) — they carry calls and messages.
- Advertising and analytics platforms (Dion Growth Studio, Lead Intelligence) — campaign and performance data comes from them.
- Laboratories and manufacturers (Smile Design Lab, Oralogix) — cases are routed to the participating counterparties a Customer selects.
- Practice management system vendors (Dion Insights, Dion PMS Bridge) — the Customer's own source systems.
Dion is not responsible for the privacy practices of these third parties.
6.4 At the Customer's direction
We share data as a Customer explicitly directs — including cross-product linking within that Customer's own subscribed products, and export or transmission the Customer configures.
6.5 Legal compulsion
We may disclose information where required by law, subpoena, court order, or governmental authority, or to establish or defend legal claims. Where legally permitted, we give the affected Customer prompt notice and reasonable cooperation to seek protective treatment. We will make our internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services as HIPAA requires, and will notify the Customer unless prohibited.
6.6 Business transfers
In a merger, acquisition, financing, reorganization, or sale of assets, Customer Data may transfer subject to equivalent privacy protections and to the BAA. Customers will be notified.
7. Retention and Deletion
7.1 During the subscription
We retain Customer Data for as long as the Customer's subscription is active and as necessary to provide the Services.
7.2 Export window
For ninety (90) days following termination, Dion will make Customer Data available for export in a commercially reasonable format on the Customer's written request (Agreement Section 14.5). PHI is made available for export for the same ninety (90) days before we proceed to return or destroy it under the BAA.
7.3 Deletion
After the export window, Dion will delete or de-identify Customer Data in accordance with its retention practices, the BAA, and applicable law. Under the BAA, we will, if feasible, return or destroy all PHI, including PHI held by subcontractors, and retain no copies.
7.4 Where deletion is not feasible
Where return or destruction is not feasible — for example PHI retained in immutable backups or archival systems, or retained because law requires it — we extend the protections of the BAA to that PHI and limit further uses and disclosures to the purposes that make return or destruction infeasible, for as long as we retain it. The same applies to archival copies of Confidential Information retained in routine backups.
7.5 De-Identified Data and Service Data
De-Identified Data and Service Data already created are not subject to deletion (Agreement Section 14.5; BAA Section 5.5). De-identified information is not PHI and is not returnable or destructible under the BAA, and this survives termination. It also cannot be re-linked to an individual — see Section 10.
7.6 Other retention
- Audit and access logs are retained for a minimum of twelve (12) months and protected from unauthorized modification.
- Account, billing, and accounting records are retained as long as necessary for the purposes described in this Policy and as required by law, including tax and accounting recordkeeping requirements.
We have not established a fixed retention period for every category of data. Where no specific period is stated above, we retain information only as long as necessary for the purposes described in this Policy and as required by law. Customers may request earlier deletion by writing to privacy@dionhealth.com; we will honor the request except where retention is required by law or is necessary to provide the Services to that Customer.
8. Security
Dion maintains a written information security program with administrative, physical, and technical safeguards designed to protect Customer Data against unauthorized access, use, disclosure, alteration, and destruction, consistent with the HIPAA Security Rule and our published Information Security Policy and Access Control Policy. Its principal controls:
- Encryption in transit — TLS 1.2 or higher for all data transmitted between Customer systems and Dion infrastructure; unencrypted HTTP is rejected.
- Encryption at rest — AES-256 for Customer data and PHI stored in Dion databases, enforced at the infrastructure level.
- Credential protection — integration credentials and API keys are stored with application-layer encryption in addition to database encryption, and are never written to logs, error messages, or application output.
- Authentication — single sign-on through WorkOS AuthKit with session tokens cryptographically verified on every request; MFA required for all production systems, cloud consoles, and administrative interfaces; shared credentials prohibited.
- Authorization and tenant isolation — role-based access control, least privilege, and deny-by-default. Each Customer tenant is isolated from every other in code: per-tenant operations require a tenant scope and fail closed without one, with database row-level security as defense in depth.
- Access reviews and deprovisioning — access is reviewed quarterly and revoked immediately on termination or role change, with automated deprovisioning driven by signature-verified identity-provider events.
- Audit logging — all access to PHI, authentication events, and administrative actions are logged with timestamp and actor identity, retained at least twelve months, and reviewed for anomalies.
- Network segmentation — production, staging, and development are segmented; direct database access from the public internet is disabled.
- Vulnerability management — automated dependency and static analysis scanning on every commit and pull request; critical vulnerabilities remediated within 7 days, high within 30.
- Incident response — a written incident response plan with defined detection, containment, assessment, notification, remediation, and post-incident review steps.
- Personnel — HIPAA security awareness training on hire and annually; background checks for roles with access to PHI or production systems; encrypted device requirements for a remote-first workforce.
On certifications, we state the position plainly: Dion has not completed a SOC 2 Type II audit and does not hold HITRUST or ISO 27001 certification. Our cloud infrastructure providers maintain their own SOC 2 Type II attestations, and we require SOC 2 Type II certification or equivalent of subprocessors that access PHI, but that is their certification, not ours, and we do not represent otherwise. A full description of our security practices is available in our Information Security Policy on request.
No system is perfectly secure. Section 11.4 of the Agreement disclaims any warranty that the Services will be uninterrupted, error-free, or secure.
9. Individual Rights
9.1 If the information is PHI
HIPAA rights — access, amendment, an accounting of disclosures, restriction requests, and confidential communications — are exercised through the Covered Entity, which is the practice, not Dion. Contact the practice that treated you and consult its Notice of Privacy Practices. As a Business Associate, Dion supports the Customer in fulfilling those requests within the BAA's timeframes, and forwards to the Customer any request an individual sends us directly.
9.2 California (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act as amended by the CPRA gives you the right to:
- Know what personal information we have collected about you, the categories of sources, the purposes, and the categories of third parties to whom it was disclosed.
- Delete personal information we collected from you, subject to legal exceptions.
- Correct inaccurate personal information.
- Opt out of sale or sharing for cross-context behavioral advertising. Dion does not sell or share personal information for these purposes, so there is nothing to opt out of — but the right stands and we will honor a request confirming it.
- Limit the use and disclosure of sensitive personal information to what is necessary to provide the Services. We already limit sensitive personal information — including health information, financial account information, and government identifiers — to providing the Services, securing them, and the other purposes permitted by law.
- Non-discrimination — we will not deny service, charge a different price, or provide a different quality of service because you exercised a privacy right.
Important exemptions. PHI handled by a Business Associate under HIPAA, and medical information governed by the California Confidentiality of Medical Information Act, are exempt from the CCPA. For that information, the routes in Section 9.1 apply instead.
9.3 Other state privacy laws
Residents of other states with comprehensive privacy laws — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others as they take effect — have broadly similar rights to access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale, and certain profiling. These laws also generally exempt PHI and other information regulated by HIPAA. We honor verified requests to the extent the applicable law grants them, and we do not engage in targeted advertising or the sale of personal information.
9.4 Where Dion is a service provider
For personal information Dion processes on a Customer's behalf — patient, employee, member, lead, and contact data — the Customer decides what happens to it. Send your request to the Customer. If you send it to us, we will forward it to the Customer and assist them in responding rather than acting on it ourselves. This includes employee and payroll data in Dion Workforce: the employer, not Dion, is the business or controller for its own personnel records.
9.5 Authorized Users
An Authorized User may access and correct their own account profile in the product, and may ask us to delete their account by writing to privacy@dionhealth.com. Account provisioning and de-provisioning is the Customer's responsibility under Section 5.1 of the Agreement.
9.6 How to exercise a right
Write to privacy@dionhealth.com with the right you are exercising and enough information for us to locate your records. We will verify your identity before acting — the level of verification will match the sensitivity of the data — and we will respond within the timeframe the applicable law requires. You may use an authorized agent where the law permits; we may ask for proof of authorization. We will not charge a fee for a first request in a twelve-month period.
10. No Re-Identification
Dion will not attempt to re-identify De-Identified Data, and will not attempt to contact any individual whose information contributed to it. We contractually require the same of every recipient of De-Identified Data, maintain De-Identified Data in de-identified form, implement reasonable safeguards against re-identification, and do not combine De-Identified Data with PHI or other data in a way that would render it individually identifiable.
This is a public commitment, made as the California Consumer Privacy Act as amended requires of a business that handles deidentified information, and it is restated as a contractual covenant in Section 8.5 of the Agreement and Section 3.4 of the BAA.
11. Children's Privacy
The Dion Suite is business software sold to and operated by healthcare organizations. We do not knowingly collect personal information directly from children, and our products are not directed to children.
Dental and healthcare practices treat minors, so a Customer's records may include information about children — including pediatric patients and their guardians. That information reaches us as Customer Data, is handled under HIPAA and the BAA like any other PHI, and remains under the Customer's control as the Covered Entity. Rights concerning a minor's health record are exercised through the practice by the minor's parent or guardian, as Section 9.1 describes.
If you believe a child has provided personal information directly to Dion outside this structure, contact privacy@dionhealth.com and we will delete it.
12. Changes to This Policy
Dion may update this Policy. For material changes, we will give at least thirty (30) days' notice by email to the Customer's designated contact or by in-product notice, and will post the updated Policy at /legal/privacy-policy with a new version number and effective date.
Because this Policy is click-accepted, a material change re-opens the acceptance gate: Authorized Users are asked to accept the updated version at their next sign-in. Every version is recorded with the cryptographic hash of its exact text, so what was accepted, and when, is provable.
13. Contact
Questions, requests, BAA execution, or complaints:
Dion Health Management Company LLC 450 Sutter Street, Suite 1519 San Francisco, CA 94108
- Privacy: privacy@dionhealth.com
- Security: security@dionhealth.com
- Legal: legal@dionhealth.com
Dion designates its CEO as Security Officer responsible for HIPAA Security Rule compliance until a dedicated CISO role is filled. Privacy inquiries reach the same office.
If you are a patient, member, employee, or contact of a Dion Customer, please contact that organization first — under Sections 1.3 and 9.4, it controls your information and we act on its instructions.