Medoura Privacy Policy

Version 1

Medoura Privacy Policy

Effective Date: July 26, 2026
Last Updated: July 26, 2026

CoFabri LLC owns and operates Medoura (“Medoura,” “Company,” “we,” “us,” or “our”).

This Privacy Policy explains how Medoura collects, uses, discloses, retains, and protects information when you:

  • visit medoura.co or another Medoura-operated public website;
  • communicate or do business with Medoura;
  • create or use a Medoura account;
  • access a healthcare practice’s Medoura-powered workflow; or
  • otherwise interact with Medoura services.

“Personal Information” or “Personal Data” means information that identifies, relates to, describes, or can reasonably be linked to an individual or household. “PHI” means protected health information governed by HIPAA. “Consumer Health Data” means health-related information governed by an applicable state consumer health data law.

This Privacy Policy describes Medoura’s practices. It is not a healthcare practice’s Notice of Privacy Practices and does not expand Medoura’s obligations beyond applicable law or contract.

1. Medoura’s Different Privacy Roles

Medoura’s privacy role depends on the context.

A. Medoura-Controlled Business Information

Medoura generally determines how and why information is processed for:

  • its public Website;
  • sales, demonstrations, and business inquiries;
  • customer contracting and onboarding;
  • Medoura account, subscription, and billing administration;
  • technical support;
  • security, compliance, and legal operations; and
  • Medoura’s internal business activities.

For applicable privacy laws, Medoura may be described as a business, controller, or regulated entity for this information.

B. Information Processed for a Healthcare Practice

When Medoura processes patient or customer-controlled information for a healthcare practice, Medoura generally acts as the practice’s service provider or processor and, where HIPAA applies, its Business Associate.

The healthcare practice determines the purposes of patient care and is responsible for:

  • providing healthcare services;
  • maintaining the official medical record;
  • issuing its Notice of Privacy Practices;
  • determining required patient notices, consents, and authorizations;
  • deciding how patient information is used for treatment, payment, and healthcare operations; and
  • responding to medical-record and HIPAA-rights requests.

Patients should direct medical-record, treatment, clinical privacy, billing, and HIPAA requests to the healthcare practice identified in the applicable workflow or patient portal.

If Medoura receives a request involving practice-controlled information, Medoura may route it to the practice and assist as required by law and contract.

C. Non-Clinical Brands

A Medoura customer may use a separate patient-facing Brand or administrative company.

The healthcare practice identified in the patient workflow—not Medoura or a non-clinical Brand—is responsible for clinical care.

2. Information We Collect

The information collected depends on how you interact with Medoura and how the applicable customer configures the Platform.

A. Website, Device, and Usage Information

We may collect:

  • IP address;
  • browser, device type, operating system, and language;
  • referring and exit pages;
  • pages viewed and actions taken;
  • approximate location derived from IP address;
  • dates, times, and duration of activity;
  • cookie, local-storage, advertising, and similar identifiers;
  • session and account identifiers; and
  • diagnostic, performance, fraud-prevention, security, and error information.

See the Medoura Cookie and Tracking Notice for additional information.

B. Contact and Business Information

We may collect:

  • name;
  • business email address and telephone number;
  • company, Practice, or organization name;
  • job title and professional information;
  • mailing or business address;
  • information submitted through contact, demonstration, waitlist, sales, support, or onboarding forms;
  • communications with Medoura; and
  • contracting, insurance, compliance, and business-verification information.

C. Customer and Authorized-User Information

For customers, providers, workforce users, and platform administrators, we may collect:

  • account, user, tenant, Practice, Brand, and organization identifiers;
  • role and permission assignments;
  • authentication factors and security events;
  • login, session, device, browser, network, and account activity;
  • support requests and administrative communications;
  • configurations, workflows, forms, and integration information;
  • provider, insurance, training, and compliance records supplied during onboarding;
  • agreement, attestation, acknowledgment, and electronic-acceptance evidence; and
  • audit, access, administrative, and security records.

D. Billing and Transaction Information

We may collect:

  • billing name, contact information, and address;
  • selected plan, seats, add-ons, and subscription details;
  • invoices and payment status;
  • transaction, application-fee, refund, dispute, and chargeback metadata;
  • responsible merchant and customer identifiers; and
  • limited payment-method information provided by the payment processor.

Full payment-card numbers and sensitive authentication data are generally collected and processed by a designated third-party payment provider. Medoura does not intentionally store them in its application systems.

E. Patient and Health-Related Information

When a healthcare practice uses Medoura, Medoura may process information submitted by or about a patient, including:

  • name, contact information, date of birth, and age;
  • identity and current physical-location information when required;
  • health questionnaires, intake answers, and treatment interests;
  • symptoms, conditions, medical history, allergies, medications, photographs, and related records;
  • patient notices, consents, acknowledgments, signatures, and authorization evidence;
  • messages and communications;
  • provider and workforce workflow records;
  • provider attestations and clinical-administration records;
  • payment, subscription, refund, pharmacy-coordination, shipping, and fulfillment metadata; and
  • authentication, device, security, access, and audit records.

The healthcare practice determines the specific patient information collected through its configuration and services.

F. Sensitive Information

Depending on the context, we may process information considered sensitive under applicable law, including:

  • PHI and Consumer Health Data;
  • account credentials and authentication information;
  • precise or current physical location when required for healthcare eligibility, licensure, or safety;
  • government or professional identifiers;
  • payment information;
  • information concerning minors through an approved workflow; and
  • other information treated as sensitive by law.

We use sensitive information only for the requested or authorized service, security, fraud prevention, legal compliance, or another purpose permitted by law.

G. Information From Other Sources

We may receive information from:

  • healthcare practices and their authorized workforce;
  • non-clinical Brands authorized by a healthcare practice;
  • patients, representatives, and other account users;
  • payment, form, intake, communications, fulfillment, shipping, and identity-verification providers;
  • customer-authorized integrations;
  • hosting, database, authentication, security, monitoring, analytics, and support providers;
  • professional, licensing, regulatory, sanctions, or public sources used for legitimate verification; and
  • parties involved in a transaction, investigation, dispute, or legal request.

3. How We Use Information

We may use information to:

  • operate, host, secure, maintain, and improve Medoura;
  • create and administer accounts, tenants, roles, permissions, and authentication;
  • provide customer-configured workflows, features, communications, and integrations;
  • support healthcare-practice administrative workflows;
  • process transactions, subscriptions, invoices, and authorized payment activity;
  • provide implementation, technical support, and customer service;
  • send service, account, security, billing, legal, and administrative communications;
  • document acceptance, consent, attestation, access, and other actions;
  • detect, investigate, prevent, and respond to fraud, misuse, unauthorized access, security incidents, and unlawful activity;
  • maintain audit, compliance, support, and business records;
  • respond to legal requests and enforce agreements;
  • protect patients, users, customers, Medoura, and third parties;
  • measure and improve performance, reliability, accessibility, and usability;
  • develop and improve features using aggregated, synthetic, or appropriately De-Identified Data;
  • conduct accounting, insurance, contracting, and other internal business operations; and
  • comply with legal, regulatory, and contractual obligations.

When Medoura processes patient information for a healthcare practice, Medoura uses it only as permitted by the applicable agreement, Business Associate Agreement, documented customer instructions, and law.

A technically available feature does not authorize a customer or user to collect or use information unlawfully.

4. Artificial Intelligence and Automated Systems

Medoura may use approved artificial intelligence or automated systems for limited security, support, analytics, software-development, workflow, or operational functions.

Medoura does not use PHI or Consumer Health Data to train a general-purpose external AI model.

Where approved AI or automation processes Personal Information, Medoura applies access, minimization, vendor, contractual, and security controls appropriate to the use.

Automated routing, qualification logic, flags, scores, summaries, and workflow outputs are administrative tools. They do not independently diagnose, treat, prescribe, establish clinical eligibility, or replace a provider’s professional judgment.

Medoura customers and users may not submit PHI, identifiable patient information, credentials, or confidential information to an unapproved AI or external tool.

5. How We Disclose Information

We may disclose information for the purposes described below.

A. Healthcare Practices and Authorized Users

We disclose patient and tenant information to the applicable healthcare practice and its authorized workforce according to configured roles, permissions, workflows, and instructions.

B. Service Providers and Subprocessors

We use service providers and subprocessors for functions such as:

  • cloud hosting, databases, storage, and content delivery;
  • authentication, security, monitoring, and fraud prevention;
  • forms and intake;
  • email, SMS, telephone, and customer support;
  • payment processing;
  • analytics and error diagnosis;
  • electronic signatures;
  • pharmacy coordination, fulfillment, and shipping; and
  • other Platform and business operations.

Authorized users may review Medoura’s current subprocessor list within their tenant app.

Where required, Medoura contractually limits service providers’ use of information and enters into Business Associate Agreements with downstream providers that handle PHI.

C. Customer-Authorized Integrations and Recipients

We disclose information through integrations, accounts, vendors, and recipients selected, configured, or authorized by a customer.

The customer is responsible for ensuring that its choices, instructions, permissions, recipients, and third-party accounts are lawful and appropriately secured.

D. Payment, Pharmacy, Laboratory, Communications, and Fulfillment Parties

Information may be disclosed to the responsible merchant, payment processor, pharmacy, laboratory, communications provider, fulfillment provider, shipping provider, or other party needed to complete a customer-configured or patient-requested function.

Those independent parties may have their own privacy notices and legal responsibilities.

E. Legal, Security, and Protection Purposes

We may disclose information when we reasonably believe it is necessary to:

  • comply with law, regulation, legal process, or a governmental request;
  • respond to a subpoena, court order, audit, investigation, or legal claim;
  • enforce agreements or protect legal rights;
  • detect, prevent, investigate, or respond to fraud, abuse, security incidents, or unlawful activity;
  • protect the safety, rights, property, or security of patients, users, customers, Medoura, or others; or
  • establish, exercise, or defend legal claims.

Where legally permitted and appropriate, Medoura may notify the affected customer before responding to a request involving customer-controlled information.

F. Business Transfers

Information may be disclosed or transferred in connection with a merger, financing, acquisition, reorganization, due-diligence process, sale of assets, bankruptcy, or transfer to an affiliate or successor that owns or operates CoFabri LLC or Medoura.

The recipient remains subject to applicable law and assumed contractual obligations.

G. De-Identified, Aggregated, and Synthetic Information

We may use and disclose aggregated, synthetic, or De-Identified Data that is not reasonably identifiable to an individual, subject to applicable law and contractual restrictions.

Where required, Medoura will maintain De-Identified Data in de-identified form and will not attempt to reidentify it except as legally permitted to test or validate de-identification.

6. Sale, Sharing, and Targeted Advertising

A. Health Information

Medoura does not:

  • sell PHI;
  • sell Consumer Health Data;
  • use PHI or Consumer Health Data for targeted advertising;
  • share PHI or Consumer Health Data with data brokers; or
  • use advertising or retargeting technologies on patient intake, authenticated patient, clinical, messaging, or payment pages.

Medoura does not use geofences around healthcare facilities to identify or track individuals, collect Consumer Health Data, or send health-related advertisements or messages.

B. Public Website Advertising and Analytics

Medoura does not exchange Personal Information for money.

Medoura may use analytics, advertising, conversion-measurement, or retargeting technologies on public business-to-business marketing pages. Those providers may receive device identifiers, IP address, browser information, and public-Website interaction data.

Some state laws may call that activity a “sale,” “sharing,” or processing for targeted advertising even when no money is exchanged.

Where applicable, you may opt out through:

  • the Cookie Settings link;
  • a legally recognized browser-based opt-out preference signal, such as Global Privacy Control; or
  • a request to legal@cofabri.com.

See the Medoura Cookie and Tracking Notice for the current technologies and choices.

7. Consumer Health Data Notice

This section provides additional disclosures where a state consumer health data law applies to information that is not governed by HIPAA or another exemption.

A. Categories of Consumer Health Data Collected

Depending on the customer configuration and interaction, Medoura may collect:

  • identifiers and contact information associated with a health-related service;
  • health conditions, symptoms, treatment interests, medical history, medications, allergies, photographs, and intake responses;
  • information indicating that a person is seeking or receiving a health-related service;
  • current physical location when required for eligibility, licensure, safety, or workflow purposes;
  • health-related communications, consents, and authorizations;
  • payment, subscription, pharmacy-coordination, shipping, and fulfillment information that reveals a health-related service;
  • device, authentication, security, and audit information associated with a health-related interaction; and
  • inferences derived from the information above for permitted operational or workflow purposes.

B. Sources

Medoura may receive Consumer Health Data:

  • directly from the individual or authorized representative;
  • from the healthcare practice and its authorized workforce;
  • from an authorized non-clinical Brand;
  • through forms, communications, payment, identity-verification, pharmacy, laboratory, fulfillment, and shipping providers;
  • through customer-authorized integrations; and
  • automatically from Platform use where technical information reveals a health-related interaction.

C. Purposes

Medoura may collect and use Consumer Health Data to:

  • provide a product or service requested by the individual or healthcare practice;
  • operate customer-configured healthcare workflows;
  • authenticate users and secure accounts;
  • process authorized transactions and requested services;
  • communicate about requested services;
  • prevent fraud, misuse, and security incidents;
  • maintain acceptance, audit, support, and compliance records;
  • comply with law and contract; and
  • perform another purpose disclosed at collection or authorized by the individual or healthcare practice.

Where applicable law requires consent for collection, use, or sharing beyond what is necessary to provide a requested service, Medoura or the responsible healthcare practice will obtain the required consent before that processing.

D. Categories of Consumer Health Data Shared

Medoura may share the following categories when necessary for an authorized purpose:

  • identifiers and contact information;
  • health, intake, treatment-interest, and medication information;
  • physical-location information used for healthcare workflows;
  • health-related communications and consent evidence;
  • transaction, pharmacy, laboratory, shipping, and fulfillment information; and
  • authentication, security, device, and audit information.

E. Categories of Recipients

Consumer Health Data may be shared with:

  • the applicable healthcare practice and authorized workforce;
  • service providers and subprocessors supporting Platform operations;
  • customer-authorized integrations and recipients;
  • payment, communications, identity-verification, pharmacy, laboratory, fulfillment, and shipping providers;
  • legal, regulatory, law-enforcement, security, and safety recipients where permitted or required; and
  • a successor or acquirer in a business transfer, subject to applicable law.

Specific affiliates receiving Consumer Health Data: None as of the Effective Date. Medoura will update this section if a specific affiliate begins receiving Consumer Health Data.

Medoura does not sell Consumer Health Data.

F. Consumer Health Data Rights

Where applicable, you may have the right to:

  • confirm whether Medoura collects, shares, or sells Consumer Health Data;
  • access Consumer Health Data;
  • obtain a list of third parties and affiliates that received Consumer Health Data;
  • withdraw consent;
  • request correction where provided by law;
  • request deletion; and
  • appeal a denied request.

Submit a request through:

  • Privacy request form: Log into your account and use the Privacy/Data Requests option, or contact your telehealth provider directly; or
  • Email: legal@cofabri.com.

You are not required to create a new account to submit a request.

Medoura may authenticate your identity and authority using commercially reasonable methods. We will respond within the time required by applicable law. Where required, requests are provided without charge, subject to legally permitted exceptions for manifestly unfounded, excessive, or repetitive requests.

Deletion may require notification to processors and other recipients. Deletion from archived or backup systems may be delayed where law permits.

If an appeal is denied, Medoura will provide information about further complaint options where required.

These rights may not apply to PHI, information processed solely on behalf of a healthcare practice, or information subject to another legal exemption.

8. Cookies and Similar Technologies

Medoura may use cookies, local storage, pixels, tags, software development kits, server logs, and similar technologies for:

  • essential Website and Platform operation;
  • authentication and security;
  • fraud prevention;
  • preferences;
  • performance and error monitoring;
  • public-Website analytics;
  • public-Website advertising and conversion measurement; and
  • other purposes described in the Cookie and Tracking Notice.

You may manage nonessential technologies through Cookie Settings, browser controls, or recognized opt-out preference signals where applicable.

Customers and users may not place advertising pixels, retargeting tags, session-replay tools, or unapproved analytics on sensitive Platform pages.

9. Your Privacy Rights

Depending on your location, Medoura’s role, and the information involved, you may have rights to:

  • know or confirm whether Personal Information is processed;
  • access Personal Information;
  • request correction;
  • request deletion;
  • obtain a portable copy;
  • opt out of sale, sharing, targeted advertising, or certain profiling;
  • withdraw consent;
  • limit certain uses or disclosures of sensitive information;
  • obtain information about categories of recipients; and
  • appeal a denied request.

Medoura will not unlawfully discriminate against a person for exercising an applicable privacy right.

A. Submitting a Request

Submit a request through:

  • Privacy request form: Log into your account and use the Privacy/Data Requests option, or contact your telehealth provider directly; or
  • Email: legal@cofabri.com.

We may verify your identity, account, residency, and authority before acting.

An authorized agent may submit a request where permitted by law. We may require evidence of the agent’s authority and verification of the individual.

A request may be denied or limited where Medoura cannot reasonably authenticate it, an exemption applies, information must be retained, or law otherwise permits.

B. Patient and Medical-Record Requests

For medical records, treatment information, HIPAA access, amendment, restriction, accounting, or a healthcare practice’s privacy practices, contact the healthcare practice identified in the patient workflow.

Medoura may route a request involving practice-controlled information to that practice and assist as required.

C. Appeals

Where applicable, appeal a denied request by replying to the decision or emailing legal@cofabri.com with the subject line “Privacy Appeal.”

10. Communications Choices

You may unsubscribe from nonessential Medoura marketing email through the unsubscribe link in the message.

Healthcare-practice communications, patient communications, SMS, telephone calls, recurring notifications, and marketing may be governed by separate Practice or merchant consents and policies.

Opting out of marketing does not prevent service, security, account, legal, billing, transactional, or other nonmarketing communications.

11. Data Retention

Medoura retains information for as long as reasonably necessary to:

  • provide the Website and Platform;
  • follow authorized customer instructions;
  • support customer export, transition, and medical-record responsibilities;
  • complete transactions;
  • provide support;
  • maintain authentication, security, audit, and acceptance records;
  • satisfy legal, tax, accounting, insurance, contractual, and regulatory obligations;
  • preserve evidence and legal holds;
  • resolve disputes; and
  • enforce agreements.

Retention periods vary by information type, customer instructions, configuration, legal requirements, and business need.

Patient information processed for a healthcare practice is retained and deleted according to the practice’s instructions, Medoura’s agreements, applicable law, legal holds, and backup cycles.

Deletion from active systems may not immediately remove information from encrypted backups, immutable security or audit records, transaction records, legal holds, or information Medoura must retain.

When backup deletion is delayed, information remains protected and is removed according to applicable cycles or legal requirements.

12. Security and Privacy Incidents

Medoura uses administrative, technical, and organizational safeguards designed for the nature and sensitivity of the information and the risks involved.

Safeguards may include:

  • encryption in transit;
  • infrastructure-level encryption at rest;
  • tenant separation and role-based access;
  • multi-factor authentication for Medoura personnel with privileged access;
  • managed credential and secret storage;
  • protected audit and security records;
  • monitoring and incident-response procedures;
  • workforce confidentiality and training; and
  • vendor review and contractual controls.

No system, storage method, transmission, or security program can guarantee complete security or prevent every incident.

Medoura will investigate and provide notifications as required by applicable law and contract. When Medoura processes information for a healthcare practice, the practice and Medoura may have different notification responsibilities.

Report a suspected privacy or security issue to legal@cofabri.com.

13. Children and Minors

Medoura’s public Website is not directed to children under thirteen (13), and Medoura does not knowingly collect Personal Information directly from a child through the public Website without appropriate authorization.

A healthcare practice may collect and process information about a minor through Medoura only through an approved workflow and under the practice’s responsibility.

The healthcare practice is responsible for determining and implementing legally sufficient parent, guardian, minor, consent, privacy, clinical, and recordkeeping procedures.

If you believe information was collected from a child through the public Website without appropriate authorization, contact legal@cofabri.com.

14. United States Use and Processing

Medoura is intended for customers and users in the United States.

Information may be stored or processed in the United States and in other locations where approved service providers operate, subject to applicable law and contractual safeguards.

Do not use Medoura where its processing would violate applicable law or an applicable customer agreement.

15. Third-Party Websites and Independent Services

The Website and Platform may link to or interoperate with independent third-party websites and services.

This Privacy Policy does not govern an independent third party’s privacy practices except when that party processes information on Medoura’s behalf as a service provider.

Review the applicable third party’s privacy notice before providing information directly to it.

A customer’s selection of an integration does not mean Medoura controls that third party’s independent practices.

16. Changes to This Privacy Policy

Medoura may update this Privacy Policy to reflect changes in law, technology, security, vendors, services, or business practices.

The “Last Updated” date identifies the current version.

Medoura will provide additional notice, obtain consent, or require renewed acknowledgment when required by law.

A materially different use of Consumer Health Data will not apply where prior consent is legally required unless the required disclosure and consent are provided.

17. Contact Us

CoFabri LLC / Medoura

Privacy and legal email: legal@cofabri.com Privacy request form: Visit your practice's website, Patient Portal, or email them directly if you are an existing account holder Technical support: https://cofabri.com/support

For medical care, prescriptions, treatment, medical records, refunds, pharmacy coordination, or a healthcare practice’s Notice of Privacy Practices, contact the healthcare practice identified in the patient workflow.