Wellis Privacy Policy

Effective date: July 14, 2026

Artha Technologies LLC ("Artha," "we," "us") provides Wellis, a HIPAA-ready clinical operations assistant for primary care practices. This policy describes how Wellis accesses and handles information when a practice authorizes an EHR integration and a communication channel.

Scope

This policy applies to Wellis when deployed for a healthcare practice that has authorized an EHR connection and entered into appropriate agreements with Artha (including a Business Associate Agreement where required by HIPAA).

Information we access

Wellis accesses health information from your connected EHR only after your administrator authorizes the integration and selects permitted data categories. Depending on the EHR and configuration, this may include:

  • Patient demographics and identifiers
  • Insurance coverage information
  • Encounter records
  • Explanation of benefit data

Wellis only accesses data within the categories you select.

How we use information

Information accessed through Wellis is used solely to:

  • Respond to authorized staff requests for clinical and billing operations support
  • Summarize relevant chart, coverage, and encounter context for the requesting user's task

We do not sell patient data. We do not use PHI for advertising or unrelated product development.

Where processing happens

Wellis is designed to operate on HIPAA-eligible infrastructure configured for your practice. Typical components include:

  • Staff communication channel — the HIPAA-eligible channel you select
  • BAA-covered LLM — natural language understanding and response generation (for example Azure OpenAI), when enabled
  • Artha-operated services — secure token management and EHR API integration (for example Practice Fusion FHIR or other authorized connectors)

Subprocessors are bound by agreements consistent with your compliance requirements, including a BAA where HIPAA requires it.

Data retention

Query responses are transient by default — generated to answer a staff request in your authorized channel. Operational logs may retain metadata (timestamps, resource types accessed) for security and troubleshooting, not full chart exports. Retention specifics are documented in your BAA and deployment configuration.

Your practice’s data

Your EHR credentials, endpoints, and staff access controls stay under your practice’s configuration. Wellis uses them only to answer requests from your allowlisted staff.

Security

We use industry-standard controls including encrypted transport (TLS), least-privilege API scopes, short-lived access tokens, and staff allowlists on your communication channel. Private signing keys used for EHR authentication are stored securely and never committed to source control.

Your rights and practice responsibilities

You (the practice) are the covered entity or business associate responsible for workforce authorization, minimum necessary use, and staff training. Staff should only request information needed for their role.

Patients with questions about how you use Wellis should contact your practice directly. You may direct privacy inquiries about Wellis to Artha using the contact below.

Changes

We may update this policy as the product or regulatory landscape changes. Material updates will be reflected on this page with a revised effective date.

Contact

Artha Technologies LLC Privacy inquiries: dtalati@artha-tech.com