Version 1
Effective Date: July 26, 2026
Last Updated: July 26, 2026
CoFabri LLC owns and operates Medoura (“Medoura,” “Company,” “we,” “us,” or “our”).
This Privacy Policy explains how Medoura collects, uses, discloses, retains, and protects information when you:
“Personal Information” or “Personal Data” means information that identifies, relates to, describes, or can reasonably be linked to an individual or household. “PHI” means protected health information governed by HIPAA. “Consumer Health Data” means health-related information governed by an applicable state consumer health data law.
This Privacy Policy describes Medoura’s practices. It is not a healthcare practice’s Notice of Privacy Practices and does not expand Medoura’s obligations beyond applicable law or contract.
Medoura’s privacy role depends on the context.
Medoura generally determines how and why information is processed for:
For applicable privacy laws, Medoura may be described as a business, controller, or regulated entity for this information.
When Medoura processes patient or customer-controlled information for a healthcare practice, Medoura generally acts as the practice’s service provider or processor and, where HIPAA applies, its Business Associate.
The healthcare practice determines the purposes of patient care and is responsible for:
Patients should direct medical-record, treatment, clinical privacy, billing, and HIPAA requests to the healthcare practice identified in the applicable workflow or patient portal.
If Medoura receives a request involving practice-controlled information, Medoura may route it to the practice and assist as required by law and contract.
A Medoura customer may use a separate patient-facing Brand or administrative company.
The healthcare practice identified in the patient workflow—not Medoura or a non-clinical Brand—is responsible for clinical care.
The information collected depends on how you interact with Medoura and how the applicable customer configures the Platform.
We may collect:
See the Medoura Cookie and Tracking Notice for additional information.
We may collect:
For customers, providers, workforce users, and platform administrators, we may collect:
We may collect:
Full payment-card numbers and sensitive authentication data are generally collected and processed by a designated third-party payment provider. Medoura does not intentionally store them in its application systems.
When a healthcare practice uses Medoura, Medoura may process information submitted by or about a patient, including:
The healthcare practice determines the specific patient information collected through its configuration and services.
Depending on the context, we may process information considered sensitive under applicable law, including:
We use sensitive information only for the requested or authorized service, security, fraud prevention, legal compliance, or another purpose permitted by law.
We may receive information from:
We may use information to:
When Medoura processes patient information for a healthcare practice, Medoura uses it only as permitted by the applicable agreement, Business Associate Agreement, documented customer instructions, and law.
A technically available feature does not authorize a customer or user to collect or use information unlawfully.
Medoura may use approved artificial intelligence or automated systems for limited security, support, analytics, software-development, workflow, or operational functions.
Medoura does not use PHI or Consumer Health Data to train a general-purpose external AI model.
Where approved AI or automation processes Personal Information, Medoura applies access, minimization, vendor, contractual, and security controls appropriate to the use.
Automated routing, qualification logic, flags, scores, summaries, and workflow outputs are administrative tools. They do not independently diagnose, treat, prescribe, establish clinical eligibility, or replace a provider’s professional judgment.
Medoura customers and users may not submit PHI, identifiable patient information, credentials, or confidential information to an unapproved AI or external tool.
We may disclose information for the purposes described below.
We disclose patient and tenant information to the applicable healthcare practice and its authorized workforce according to configured roles, permissions, workflows, and instructions.
We use service providers and subprocessors for functions such as:
Authorized users may review Medoura’s current subprocessor list within their tenant app.
Where required, Medoura contractually limits service providers’ use of information and enters into Business Associate Agreements with downstream providers that handle PHI.
We disclose information through integrations, accounts, vendors, and recipients selected, configured, or authorized by a customer.
The customer is responsible for ensuring that its choices, instructions, permissions, recipients, and third-party accounts are lawful and appropriately secured.
Information may be disclosed to the responsible merchant, payment processor, pharmacy, laboratory, communications provider, fulfillment provider, shipping provider, or other party needed to complete a customer-configured or patient-requested function.
Those independent parties may have their own privacy notices and legal responsibilities.
We may disclose information when we reasonably believe it is necessary to:
Where legally permitted and appropriate, Medoura may notify the affected customer before responding to a request involving customer-controlled information.
Information may be disclosed or transferred in connection with a merger, financing, acquisition, reorganization, due-diligence process, sale of assets, bankruptcy, or transfer to an affiliate or successor that owns or operates CoFabri LLC or Medoura.
The recipient remains subject to applicable law and assumed contractual obligations.
We may use and disclose aggregated, synthetic, or De-Identified Data that is not reasonably identifiable to an individual, subject to applicable law and contractual restrictions.
Where required, Medoura will maintain De-Identified Data in de-identified form and will not attempt to reidentify it except as legally permitted to test or validate de-identification.
Medoura does not:
Medoura does not use geofences around healthcare facilities to identify or track individuals, collect Consumer Health Data, or send health-related advertisements or messages.
Medoura does not exchange Personal Information for money.
Medoura may use analytics, advertising, conversion-measurement, or retargeting technologies on public business-to-business marketing pages. Those providers may receive device identifiers, IP address, browser information, and public-Website interaction data.
Some state laws may call that activity a “sale,” “sharing,” or processing for targeted advertising even when no money is exchanged.
Where applicable, you may opt out through:
See the Medoura Cookie and Tracking Notice for the current technologies and choices.
This section provides additional disclosures where a state consumer health data law applies to information that is not governed by HIPAA or another exemption.
Depending on the customer configuration and interaction, Medoura may collect:
Medoura may receive Consumer Health Data:
Medoura may collect and use Consumer Health Data to:
Where applicable law requires consent for collection, use, or sharing beyond what is necessary to provide a requested service, Medoura or the responsible healthcare practice will obtain the required consent before that processing.
Medoura may share the following categories when necessary for an authorized purpose:
Consumer Health Data may be shared with:
Specific affiliates receiving Consumer Health Data: None as of the Effective Date. Medoura will update this section if a specific affiliate begins receiving Consumer Health Data.
Medoura does not sell Consumer Health Data.
Where applicable, you may have the right to:
Submit a request through:
You are not required to create a new account to submit a request.
Medoura may authenticate your identity and authority using commercially reasonable methods. We will respond within the time required by applicable law. Where required, requests are provided without charge, subject to legally permitted exceptions for manifestly unfounded, excessive, or repetitive requests.
Deletion may require notification to processors and other recipients. Deletion from archived or backup systems may be delayed where law permits.
If an appeal is denied, Medoura will provide information about further complaint options where required.
These rights may not apply to PHI, information processed solely on behalf of a healthcare practice, or information subject to another legal exemption.
Medoura may use cookies, local storage, pixels, tags, software development kits, server logs, and similar technologies for:
You may manage nonessential technologies through Cookie Settings, browser controls, or recognized opt-out preference signals where applicable.
Customers and users may not place advertising pixels, retargeting tags, session-replay tools, or unapproved analytics on sensitive Platform pages.
Depending on your location, Medoura’s role, and the information involved, you may have rights to:
Medoura will not unlawfully discriminate against a person for exercising an applicable privacy right.
Submit a request through:
We may verify your identity, account, residency, and authority before acting.
An authorized agent may submit a request where permitted by law. We may require evidence of the agent’s authority and verification of the individual.
A request may be denied or limited where Medoura cannot reasonably authenticate it, an exemption applies, information must be retained, or law otherwise permits.
For medical records, treatment information, HIPAA access, amendment, restriction, accounting, or a healthcare practice’s privacy practices, contact the healthcare practice identified in the patient workflow.
Medoura may route a request involving practice-controlled information to that practice and assist as required.
Where applicable, appeal a denied request by replying to the decision or emailing legal@cofabri.com with the subject line “Privacy Appeal.”
You may unsubscribe from nonessential Medoura marketing email through the unsubscribe link in the message.
Healthcare-practice communications, patient communications, SMS, telephone calls, recurring notifications, and marketing may be governed by separate Practice or merchant consents and policies.
Opting out of marketing does not prevent service, security, account, legal, billing, transactional, or other nonmarketing communications.
Medoura retains information for as long as reasonably necessary to:
Retention periods vary by information type, customer instructions, configuration, legal requirements, and business need.
Patient information processed for a healthcare practice is retained and deleted according to the practice’s instructions, Medoura’s agreements, applicable law, legal holds, and backup cycles.
Deletion from active systems may not immediately remove information from encrypted backups, immutable security or audit records, transaction records, legal holds, or information Medoura must retain.
When backup deletion is delayed, information remains protected and is removed according to applicable cycles or legal requirements.
Medoura uses administrative, technical, and organizational safeguards designed for the nature and sensitivity of the information and the risks involved.
Safeguards may include:
No system, storage method, transmission, or security program can guarantee complete security or prevent every incident.
Medoura will investigate and provide notifications as required by applicable law and contract. When Medoura processes information for a healthcare practice, the practice and Medoura may have different notification responsibilities.
Report a suspected privacy or security issue to legal@cofabri.com.
Medoura’s public Website is not directed to children under thirteen (13), and Medoura does not knowingly collect Personal Information directly from a child through the public Website without appropriate authorization.
A healthcare practice may collect and process information about a minor through Medoura only through an approved workflow and under the practice’s responsibility.
The healthcare practice is responsible for determining and implementing legally sufficient parent, guardian, minor, consent, privacy, clinical, and recordkeeping procedures.
If you believe information was collected from a child through the public Website without appropriate authorization, contact legal@cofabri.com.
Medoura is intended for customers and users in the United States.
Information may be stored or processed in the United States and in other locations where approved service providers operate, subject to applicable law and contractual safeguards.
Do not use Medoura where its processing would violate applicable law or an applicable customer agreement.
The Website and Platform may link to or interoperate with independent third-party websites and services.
This Privacy Policy does not govern an independent third party’s privacy practices except when that party processes information on Medoura’s behalf as a service provider.
Review the applicable third party’s privacy notice before providing information directly to it.
A customer’s selection of an integration does not mean Medoura controls that third party’s independent practices.
Medoura may update this Privacy Policy to reflect changes in law, technology, security, vendors, services, or business practices.
The “Last Updated” date identifies the current version.
Medoura will provide additional notice, obtain consent, or require renewed acknowledgment when required by law.
A materially different use of Consumer Health Data will not apply where prior consent is legally required unless the required disclosure and consent are provided.
CoFabri LLC / Medoura
Privacy and legal email: legal@cofabri.com Privacy request form: Visit your practice's website, Patient Portal, or email them directly if you are an existing account holder Technical support: https://cofabri.com/support
For medical care, prescriptions, treatment, medical records, refunds, pharmacy coordination, or a healthcare practice’s Notice of Privacy Practices, contact the healthcare practice identified in the patient workflow.