ClearPathGISecurity

Security that stands up to review.

Encryption, consent controls, and BAA terms — for patients who enroll and organizations doing diligence.

Patients control sharing. Organizations start with a BAA.

If you're enrolling, see what we collect and when anything is shared. If you're reviewing us as a vendor, see the partnership requirements next.

Contact details are shared with healthcare organizations only after an explicit, timestamped opt-in.

Only what reminders need

We collect name, phone, email, date of birth, ZIP, city, state, and next due month.

Not clinical charts

We do not collect diagnoses, clinical notes, insurance, SSN, or financial data.

BAA required

Before any organization access to patient contact information.

Business Associate

ClearPath GI LLC is a Business Associate when a covered entity partners for those features.

Encrypted PHI

In transit and at rest for name, phone, email, and date of birth.
Get in touch for vendor review →

Your privacy rights

How patients update information, delete accounts, and manage consent.

Read the Notice of Privacy Practices for the full rights framework.

Access and update your information

View and update name, contact details, location, and next due date from your dashboard anytime. For a full copy of what we hold, or a correction you cannot make in the dashboard, contact privacy@clearpathgi.com — we acknowledge requests within 5 business days.

Delete your account

Remove your account from settings. You disappear from organization-facing views immediately. We retain a limited regulatory archive for up to 10 years after deletion (as described in our Notice of Privacy Practices), then permanently delete or de-identify your data.

Revoke organization consent

If you opted in to share contact details with a practice, revoke that consent from your dashboard anytime. Revocation is immediate and logged.

We will never sell your information. We only share it with healthcare organizations if you explicitly consent, and with service providers needed to operate the platform.

Security controls

Technical and administrative safeguards designed for production use.

Business Associate Agreement (BAA)

Required with every healthcare organization before features that access patient-related data (for example, Care Outreach).

Encryption in transit and at rest

Encryption in transit (TLS 1.2 or higher; TLS 1.3 where supported). Selected sensitive fields (name, date of birth, phone, email) are encrypted at rest; keys are managed separately from application credentials.

Minimum necessary access

Invoices may show enrollment counts by ZIP or service area. Dashboards list only patients who opted in; contact details appear only for those patients and only to your organization.
Before any contact details are shared with an organization, the patient must take an explicit, documented opt-in from their dashboard. Consent is timestamped, logged, and reversible — no passive opt-in, no pre-checked box.

Append-only audit logging

Significant access, disclosure, and modification events are append-only logged with user, timestamp, IP, and action. Records supporting your account are kept for up to 10 years after account deletion (longer if a legal hold applies), then securely destroyed with the regulatory archive.

Automatic session timeout

Patient, organization, and admin sessions warn 60 seconds before logout after 15 minutes idle (HIPAA Security Rule §164.312(a)(2)(iii)).

Organization access model

Each provisioned staff member gets a unique login with owner-level access to dashboard, billing, and care outreach. Access is granted during onboarding and recorded in the audit log. Additional role tiers are not offered in the current release.

Sign-in: passwordless for patients, MFA for staff

Patients sign in with one-time SMS or email codes on clearpathgi.com. Organization and admin portals use email, password, and MFA on every login. Credentials are verified by our identity provider; ClearPath GI does not operate its own password database.

Reliability and reminder delivery

Built for reliable reminder delivery. Reminder dispatch is designed to continue even if the patient dashboard is temporarily unavailable.

HIPAA rules we design around

How our safeguards map to Privacy, Security, and Breach Notification Rules.

  • PHI collected with patient enrollment and channel consents
  • Minimum necessary standard on organization disclosures
  • Patient rights to access, update, and delete via dashboard; other corrections via Privacy Officer
  • No PHI disclosed to organizations without documented consent
  • Notice of Privacy Practices presented at enrollment
  • Access controls: unique user identifiers, automatic session logoff
  • Audit controls: activity logs for significant PHI access and disclosures
  • Integrity controls: data modification requires authenticated action
  • Transmission security: TLS for all data in transit
  • Encryption: selected PHI fields encrypted at rest
  • Breach notification procedures per 45 CFR §164.400
  • BAA includes breach notification obligations and timelines
  • Covered entity notified within required timeframes upon discovery of any breach involving their patients

For patients

Stay ahead of your next colonoscopy.

Free text or email reminders before you're due. Optionally connect with a clinic when you're ready to schedule.

Enroll free

For organizations

Connect with patients due for colonoscopy.

After a BAA, reach patients in your area who choose to share when their next colonoscopy is approaching.

Get in touch