← Back to Home

Privacy Policy

Effective Date: June 22, 2026 (last reviewed)

Previous version: March 15, 2026. Updates added Sections 7A (Subprocessors) and 9A (California Privacy Rights).

1. Introduction

Omniasis, Inc. ("Omniasis," "we," "our," or "us") is committed to protecting the privacy and security of your personal information, including Protected Health Information (PHI) as defined under the Health Insurance Portability and Accountability Act (HIPAA). This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you use the Omniasis Cardiac Rehab Coach mobile application and the Omniasis Cardiac Rehabilitation Platform (collectively, the "Platform").

By using the Platform, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with these practices, please do not use the Platform.

2. Information We Collect

We collect the following categories of information:

a. Personal Information

Name, email address, date of birth, phone number, and other contact information provided during account registration.

b. Health Information (Protected Health Information)

  • Vital Signs: Heart rate, blood pressure, SpO2 (blood oxygen saturation), heart rate variability (HRV), and resting heart rate trends.
  • Exercise Data: Exercise session duration, exercise type, repetition counts, Rate of Perceived Exertion (RPE) scores, calories burned, and active energy.
  • Clinical Data: Medications, symptoms, medical history relevant to cardiac rehabilitation, and clinical notes from your care team.
  • AI Coaching Data: Exercise form assessments generated by on-device computer vision analysis.

c. Device and Wearable Information

  • Data from Apple Watch (heart rate, workout sessions, active energy via HealthKit)
  • Data from Bluetooth-connected blood pressure monitors, pulse oximeters, and smart scales
  • Device model, operating system version, and app version

d. Technical Data

IP address, browser type (for admin portal), app crash reports, and usage analytics. We do not collect precise location data.

3. How We Use Your Information

We use the information we collect for the following purposes:

  • Treatment and Care Delivery: To provide cardiac rehabilitation monitoring, deliver guided exercise sessions, and transmit health data to your authorized healthcare providers.
  • Clinical Safety Monitoring: To generate real-time alerts when vital signs exceed clinician-defined safety thresholds during exercise sessions.
  • Progress Tracking: To create progress reports, trend analyses, and recovery dashboards for you and your care team.
  • AI-Powered Coaching: To analyze exercise form using on-device computer vision and provide real-time coaching feedback.
  • Quality Improvement: To improve the safety, effectiveness, and quality of our cardiac rehabilitation services.
  • Communication: To send you appointment reminders, exercise session notifications, and important safety information.
  • Legal Compliance: To comply with applicable healthcare regulations, including HIPAA.

4. Apple HealthKit Data

Our app integrates with Apple HealthKit to read and write health data, including heart rate, blood oxygen saturation (SpO2), active energy burned, and workout sessions. Your use of HealthKit data is subject to the following commitments:

  • HealthKit data is used solely to provide cardiac rehabilitation monitoring and to share relevant health information with your authorized healthcare providers.
  • HealthKit data is never sold to third parties, including advertising platforms, data brokers, or information resellers.
  • HealthKit data is never used for advertising or marketing purposes of any kind.
  • HealthKit data is never disclosed to third parties without your explicit consent, except as required to provide core app functionality to your authorized care team or as required by law.
  • HealthKit data is stored securely and encrypted both at rest and in transit.

You can revoke HealthKit access at any time through your iPhone's Settings > Health > Data Access & Devices.

5. HIPAA Compliance

Omniasis operates as a Business Associate under the Health Insurance Portability and Accountability Act (HIPAA) and fully complies with the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule. Our safeguards include:

Administrative Safeguards

  • Designated Privacy and Security Officers
  • Workforce training on HIPAA compliance and data handling
  • Documented policies and procedures for PHI management
  • Regular risk assessments and compliance audits

Technical Safeguards

  • Encryption at Rest: All health data is encrypted using AES-256 via AWS Key Management Service (KMS) with automatic key rotation.
  • Encryption in Transit: All data transmitted between your device and our servers uses TLS 1.3 encryption.
  • Access Controls: Multi-factor authentication (MFA) and time-based one-time passwords (TOTP) are required for all clinical and administrative users. Role-based access controls (RBAC) limit data access to authorized personnel only.
  • Audit Logging: All access to patient data is logged via AWS CloudTrail. Audit logs are retained for a minimum of 7 years.

Physical Safeguards

  • Infrastructure hosted on HIPAA-eligible AWS services in SOC 2 Type II certified data centers
  • Data isolation ensures patient data is logically separated by healthcare organization

We maintain Business Associate Agreements (BAAs) with all third-party service providers who may access PHI, including Amazon Web Services.

6. Data Storage and Security

Your data is stored on secure servers provided by Amazon Web Services (AWS) in HIPAA-eligible regions within the United States. We implement industry-leading security measures including:

  • AES-256 encryption for all data at rest
  • TLS 1.3 for all data in transit
  • Automatic database backups with encrypted snapshots
  • Network segmentation and firewall protections
  • Regular penetration testing and vulnerability assessments
  • Real-time intrusion detection and monitoring

7. Data Sharing and Disclosure

We may share your information in the following limited circumstances:

  • Authorized Healthcare Providers: Your health data is shared with the healthcare providers and hospitals authorized to manage your cardiac rehabilitation program.
  • Emergency Situations: If our system detects a critical health event during an exercise session, we may notify your emergency contacts and healthcare providers.
  • Legal Requirements: We may disclose information when required by law, court order, or regulatory authority.
  • Business Associates: Service providers who assist us in operating our Platform, subject to Business Associate Agreements and HIPAA requirements.

We do NOT sell, rent, lease, or trade your personal information or health data to any third parties for marketing, advertising, or any other commercial purposes. This commitment applies to all data, including data obtained from Apple HealthKit.

7A. Subprocessors

We rely on the following subprocessors to operate the Platform. Each subprocessor is bound by a written agreement requiring confidentiality, appropriate security controls, and (where they handle PHI) a Business Associate Agreement.

SubprocessorPurposeData categoryLocation
Amazon Web Services (AWS)Cloud hosting, database storage (DynamoDB), serverless compute (Lambda), object storage (S3), encryption (KMS), email delivery (SES), authentication (Cognito), monitoring (CloudWatch).PHI, account, audit logs, encrypted backups.United States (us-east-1)
Apple HealthKitOn-device collection of vital signs (heart rate, SpO2, HRV, workouts) from Apple Watch and iPhone sensors.PHI (transient, on device). HealthKit data is read by the app and forwarded to our backend only with the user's active session consent.User's device (no Apple cloud sync of HealthKit data initiated by Omniasis)
Apple App Store / TestFlightDistribution of the iOS application to authorized devices.No PHI. Account email may be visible to Apple for App Store account management.Apple infrastructure
GitHub (source code)Source code repository and CI/CD triggers. No PHI is stored in source.No PHI.United States

We will notify hospital customers of any material changes to this subprocessor list before the change takes effect, in accordance with Business Associate Agreement obligations. The current list is maintained on this page; customers may also request the current list at any time from the Privacy Officer contact in Section 13.

8. Data Retention

We retain your health data in accordance with applicable federal and state laws and clinical record-keeping standards:

  • Health Records: Retained for a minimum of 6 years from the date of last treatment, or longer as required by state law.
  • Audit Logs: Retained for a minimum of 7 years in compliance with HIPAA requirements.
  • Account Information: Retained for the duration of your account and for 30 days after account closure, unless longer retention is required by law.
  • De-identified Data: Aggregated, de-identified data may be retained indefinitely for quality improvement and research purposes.

You may request deletion of your data at any time, subject to legal retention requirements. See Section 9 for details.

9. Your Rights

Under HIPAA and applicable state and federal laws, you have the right to:

  • Access: Request and obtain a copy of your health information maintained by Omniasis.
  • Correction: Request amendments or corrections to your health records if you believe they are inaccurate or incomplete.
  • Deletion: Request deletion of your personal and health data, subject to legal retention obligations.
  • Restriction: Request restrictions on certain uses and disclosures of your health information.
  • Accounting of Disclosures: Receive an accounting of disclosures of your health information made by Omniasis.
  • Data Portability: Receive your health data in a structured, commonly used format.
  • Breach Notification: Be notified in the event of a breach of your unsecured PHI.
  • Complaint: File a complaint with Omniasis or the U.S. Department of Health and Human Services if you believe your privacy rights have been violated.

To exercise any of these rights, please contact our Privacy Officer at the address listed in Section 13.

9A. California Privacy Rights (CCPA / CPRA)

This section supplements Section 9 for California residents whose personal information we collect or process. The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), provides additional rights to California residents.

Notice at collection

We collect the categories of personal information described in Section 2 (Personal Information, Health Information, Device and Wearable Information, Technical Data). We collect these categories for the business purposes described in Section 3 (How We Use Your Information). We retain each category for the periods described in Section 8 (Data Retention).

Do not sell or share my personal information

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We have not sold or shared personal information in the preceding 12 months and have no plans to do so. This commitment is reiterated in Section 7.

Your CCPA/CPRA rights

In addition to the rights in Section 9, California residents have the right to:

  • Know: Request the specific categories and pieces of personal information we have collected about you, the sources of that information, the purposes for collecting it, and the third parties with whom we share it.
  • Delete: Request deletion of personal information we have collected about you, subject to HIPAA and other legal retention obligations.
  • Correct: Request correction of inaccurate personal information.
  • Limit use of sensitive personal information: Request that we limit the use of your sensitive personal information (including PHI) to purposes necessary to provide the requested service.
  • Non-discrimination: Not be discriminated against for exercising any of these rights.

How to exercise California rights

Submit a verifiable consumer request by email to privacy@omniasis.com with subject line "California Privacy Request." We will respond within 45 days as required by law. We may need to verify your identity before fulfilling the request; we will only use the information you provide to verify your identity for this purpose.

Authorized agents

You may designate an authorized agent to submit a request on your behalf. The agent must provide proof of your written authorization, and we will require you to verify your own identity directly.

Interaction with HIPAA

When information is governed by HIPAA (Protected Health Information), HIPAA rules and HIPAA-mandated retention periods take precedence over CCPA/CPRA rights to the extent of any conflict. CCPA/CPRA rights apply to personal information that is not PHI, and to PHI to the extent CCPA/CPRA does not conflict with HIPAA.

10. Children's Privacy

The Platform is intended for adults aged 18 and older who are enrolled in a cardiac rehabilitation program under clinical supervision. We do not knowingly collect information from individuals under the age of 18. If we become aware that we have collected data from a minor, we will take steps to delete that information promptly.

11. Security Incident Response

In the event of a breach of unsecured PHI, Omniasis will comply with the HIPAA Breach Notification Rule (45 CFR Part 164, Subpart D). We will notify affected individuals without unreasonable delay and no later than 60 days following discovery of the breach. We will also notify the U.S. Department of Health and Human Services and, where required (breaches affecting 500 or more individuals), the media.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will notify you of material changes by posting the updated policy on our Platform, updating the effective date above, and where appropriate, notifying you via email or in-app notification. Your continued use of the Platform after the effective date of a revised policy constitutes acceptance of the updated terms.

13. Contact Us

If you have questions about this Privacy Policy, wish to exercise your rights, or need to report a privacy concern, please contact our Privacy Officer:

Omniasis, Inc.

Privacy Officer

Email: privacy@omniasis.com

You may also file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights at www.hhs.gov/ocr.

© 2026 Omniasis, Inc. All rights reserved.