Privacy policy
Effective 30 September 2026
Arbor is the trading name of Q It Technologies LLC. We do back-office work for medical practices: sorting the faxes they receive, checking patients' insurance before visits, finding patients who are due for care, and calling patients on the practice's behalf. This page says what information we handle, where it is kept, and who else sees it.
Most of it is patient information that belongs to the practices we work for. The rest is the little we learn from people who visit this website or write to us. We handle the two differently, so each has its own section.
Patient information
Under HIPAA, each practice we work for is a covered entity and Arbor is its business associate. We sign a business associate agreement (BAA) with a practice before any real patient information reaches us, and that agreement sets what we may do with it. Nothing on this page loosens it.
What we receive
It depends on the work a practice asks for. It can include documents faxed to the practice, patient lists and appointment schedules the practice sends us, and records we read from the practice's electronic health record (EHR).
We read from an EHR only after the practice authorizes our application in that EHR, and the practice can withdraw that authorization at any time. That connection is read-only. Separately, and only when a practice asks, our software can carry out specific tasks inside the practice's EHR, such as filing a faxed document to the staff member it belongs to.
How we use it
We use it only for the work the practice has asked us to do, and only as much of it as that work needs. We do not sell patient information, we do not use it for advertising or marketing, and we never combine one practice's information with another's.
Our software uses AI models, for example to read a faxed referral and decide which staff member it belongs to. When our own software calls a model, it does so through Amazon Bedrock inside our Amazon Web Services (AWS) account, under our BAA with AWS. Amazon does not use those requests to train its models. Arbor does not use patient information to train AI models.
Who else receives it
Three companies handle patient information for us, each under a BAA with Arbor:
- Amazon Web Services stores everything we hold and runs our software.
- Stedi receives a patient's name, date of birth and insurance member ID when a practice asks us to check that patient's coverage, and passes the request to the insurer.
- Retell AI runs the voice platform for the calls we make on a practice's behalf, and receives what each call needs, such as the patient's first name and their clinician's name. Retell's standard terms allow it to process call data outside the United States and to use de-identified call data for its own purposes.
We may also disclose patient information when the law requires it.
Where it is kept and who can see it
Everything is stored in our AWS account. The database and the document store are encrypted with keys that rotate automatically. The database has no public address and refuses unencrypted connections. Each practice is a separate tenant, and the database itself refuses to return one practice's records to a query made for another.
Arbor staff and the practice's own staff sign in to our console with individual accounts and a second factor. A practice's staff see only that practice's information.
How long we keep it
We keep it for as long as our agreement with the practice runs. When the agreement ends, we return or destroy the practice's information, including any copies our vendors hold, and confirm that in writing. Database backups are deleted after 30 days. A practice can ask for a full copy of its information at any time.
If something goes wrong
If patient information is exposed, we tell the practice without unreasonable delay and within the time HIPAA and our agreement with the practice allow. The practice decides how its patients are notified.
If you are a patient
Your practice decides how your information is used, and its Notice of Privacy Practices describes your rights. To see or correct your information, or to ask who it has been shared with, contact your practice. We help it answer.
People who visit this website or write to us
joinarbor.ai has no forms, sets no cookies and runs no analytics. It loads its fonts from Google Fonts, so Google receives your IP address when the page loads, and Cloudflare, which serves the site, sees the same. If you book a call, you do it on Calendly under Calendly's privacy policy, and the name and email address you enter reach us through Calendly. If you email us, we use your message to reply to you.
Changes and contact
If we change this page, we change the date at the top. Questions go to developers@joinarbor.ai.