Wellis Privacy Policy
Effective date: July 14, 2026
Artha Technologies LLC ("Artha," "we," "us") provides Wellis, a HIPAA-ready clinical operations assistant for primary care practices. This policy describes how Wellis accesses and handles information when a practice authorizes an EHR integration and a communication channel.
Scope
This policy applies to Wellis when deployed for a healthcare practice that has authorized an EHR connection and entered into appropriate agreements with Artha (including a Business Associate Agreement where required by HIPAA).
Information we access
Wellis accesses health information from your connected EHR only after your administrator authorizes the integration and selects permitted data categories. Depending on the EHR and configuration, this may include:
- Patient demographics and identifiers
- Insurance coverage information
- Encounter records
- Explanation of benefit data
Wellis only accesses data within the categories you select.
How we use information
Information accessed through Wellis is used solely to:
- Respond to authorized staff requests for clinical and billing operations support
- Summarize relevant chart, coverage, and encounter context for the requesting user's task
We do not sell patient data. We do not use PHI for advertising or unrelated product development.
Where processing happens
Wellis is designed to operate on HIPAA-eligible infrastructure configured for your practice. Typical components include:
- Staff communication channel — the HIPAA-eligible channel you select
- BAA-covered LLM — natural language understanding and response generation (for example Azure OpenAI), when enabled
- Artha-operated services — secure token management and EHR API integration (for example Practice Fusion FHIR or other authorized connectors)
Subprocessors are bound by agreements consistent with your compliance requirements, including a BAA where HIPAA requires it.
Data retention
Query responses are transient by default — generated to answer a staff request in your authorized channel. Operational logs may retain metadata (timestamps, resource types accessed) for security and troubleshooting, not full chart exports. Retention specifics are documented in your BAA and deployment configuration.
Your practice’s data
Your EHR credentials, endpoints, and staff access controls stay under your practice’s configuration. Wellis uses them only to answer requests from your allowlisted staff.
Security
We use industry-standard controls including encrypted transport (TLS), least-privilege API scopes, short-lived access tokens, and staff allowlists on your communication channel. Private signing keys used for EHR authentication are stored securely and never committed to source control.
Your rights and practice responsibilities
You (the practice) are the covered entity or business associate responsible for workforce authorization, minimum necessary use, and staff training. Staff should only request information needed for their role.
Patients with questions about how you use Wellis should contact your practice directly. You may direct privacy inquiries about Wellis to Artha using the contact below.
Changes
We may update this policy as the product or regulatory landscape changes. Material updates will be reflected on this page with a revised effective date.
Contact
Artha Technologies LLC Privacy inquiries: dtalati@artha-tech.com