AuthPay

Privacy Policy

Effective date: July 11, 2026

AuthPay (“AuthPay,” “we,” “us,” or “our”) is a business tool for healthcare practices and their authorized staff. This Privacy Policy explains how we collect, use, and share information when staff use the AuthPay portal to manage payment links and related workflows. It should be read with our Terms of Service.

AuthPay is not a public patient website. Patient payment pages and patient-facing SMS or email for payment collection are provided by AuthPay’s payment partners (and any notices those partners or the practice provide). Practices remain responsible for their own HIPAA programs, patient notices, and consents. AuthPay does not replace a practice’s HIPAA compliance program, and this policy is not a Business Associate Agreement.

1. Roles

  • Practice / covered entity (or business associate of a covered entity): controls patient relationships and determines when payment links or reminders are sent.
  • AuthPay: provides staff accounts, portal tools, and integrations so practice staff can initiate payment workflows.
  • Payment partners: host patient payment pages and deliver patient payment communications.
  • Practice systems: practice management / EHR sources for appointment, patient, and charge metadata the practice connects.

2. Information we collect

  • Staff account data: name, email, role, tenant/practice association, authentication credentials (hashed), invite and reset tokens, and session activity.
  • Practice configuration: tenant settings, branding/theme, integration credentials or tokens needed for connected systems, and operational preferences.
  • Practice-system metadata: appointment, patient, and charge identifiers and related fields the practice authorizes AuthPay to retrieve so staff can select balances and send payment links.
  • Payment workflow metadata: link send status, amounts, references, and limited transaction status information returned by payment partners. AuthPay does not intentionally store full primary account numbers (PAN) or CVV.
  • Technical logs: IP address, browser/user agent, timestamps, and error or security logs needed to operate and protect the portal.

3. How we use information

We use this information to authenticate staff, operate the portal, connect authorized integrations, help staff create or send payment links, deliver staff invites and password resets, prevent abuse, troubleshoot issues, and comply with law.

4. Subprocessors and sharing

  • Connected practice systems — appointment/patient/charge metadata at the practice’s direction.
  • Payment partners — patient payment pages and payment communications; patient payment data is processed under those partners’ systems and terms.
  • Email delivery providers — staff invite, activation, and password-reset email.
  • Hosting / infrastructure providers — application hosting, databases, and related infrastructure.

We do not sell staff or patient personal information. We may disclose information when required by law or to protect security, rights, or safety.

5. Patient communications

When staff trigger a patient payment message, delivery typically occurs through AuthPay’s payment partners. Content, retention, and delivery of those patient-facing communications are governed by the payment partners and the practice’s instructions. Practices must ensure they have a lawful basis and any required patient notices or consents.

6. Security and retention

We use administrative and technical safeguards appropriate to a staff business tool, including access controls, encrypted transport, and hashed passwords. No system is perfectly secure. We retain account, integration, and workflow records as needed to provide the service, meet legal obligations, and resolve disputes.

7. Your choices

Staff may update profile details through the portal or by asking a practice administrator. Practices may request deactivation of staff accounts. Privacy requests relating to patient records should generally be directed to the practice; AuthPay will assist the practice where appropriate for portal-held metadata.

8. Children

AuthPay is a business staff tool and is not directed to children under 13.

9. Changes and contact

We may update this policy by posting a revised version with a new effective date. Questions: contact your AuthPay administrator or Authorized Credit Card Systems through the practice’s ACCS relationship.

Confirm

Privacy Terms