OnePath logoOnePathConnect
For BusinessFor Developers
PlatformDocsChangelogUse CasesCompanyLive Demo
StatusSign InGet API Access
Legal

Privacy Policy

Effective date: July 1, 2026 · OnePath Health, Inc.

1. Who We Are

OnePath Health, Inc. ("OnePath," "we," "our," or "us") operates OnePath Connect, a business-to-business REST API that enables healthcare organizations to integrate AI-powered clinical intelligence into their own platforms. OnePath Connect is not a consumer product; it is accessed exclusively by credentialed Partner organizations that have executed a Business Associate Agreement with us.

Questions about this Privacy Policy may be directed to privacy@onepath.health.

2. Scope of This Policy

This Privacy Policy describes how OnePath collects, uses, stores, and shares information in connection with (a) our website and marketing properties, and (b) the OnePath Connect API services. It does not describe the privacy practices of our Partners with respect to their own end users or patients.

Protected Health Information ("PHI") submitted to the OnePath Connect API by Partners is governed by the Business Associate Agreement between OnePath and each Partner, and by applicable provisions of HIPAA and its implementing regulations. Our handling of PHI is described separately in Section 7.

3. Information We Collect

3.1 Partner Organization Information

When a healthcare organization applies to become an OnePath Connect Partner, we collect:

  • Organization name, type, and contact information
  • Names and contact details of authorized representatives
  • Technical integration details (RSA public key, partner application identifiers)
  • Business Associate Agreement execution records

3.2 API Usage Data

When Partners use the OnePath Connect API, we automatically collect:

  • API request logs (endpoint, timestamp, response code, latency)
  • Rate limit consumption and AI token usage per partner application
  • Error and exception telemetry
  • API key identifiers (never raw API key values)

3.3 Website Visitors

If you visit our website, we may collect standard web server log data (IP address, browser type, referring URL, pages visited, timestamps). We do not use persistent third-party advertising trackers.

4. How We Use Information

We use the information described above to:

  • Provision, operate, and maintain OnePath Connect API access for Partners
  • Enforce usage limits, detect abuse, and ensure service availability
  • Respond to Partner support inquiries and technical questions
  • Process BAA execution and manage Partner compliance obligations
  • Send operational communications (e.g., service status, security notices)
  • Improve and develop new capabilities in the OnePath platform

We do not sell Partner information or API usage data to third parties. We do not use PHI for any purpose other than providing the services described in each Partner's BAA.

5. How We Share Information

We do not share Partner organization information with third parties except:

  • Service Providers: Cloud infrastructure (Microsoft Azure), email delivery, and similar vendors that process data on our behalf under appropriate data processing agreements.
  • Legal Requirements: If required by law, court order, or valid legal process, or to protect the rights, property, or safety of OnePath, Partners, or the public.
  • Business Transfers: In connection with a merger, acquisition, or sale of assets, subject to the same privacy commitments described in this Policy.

6. Data Security

OnePath employs administrative, physical, and technical safeguards including:

  • Encryption of data in transit (TLS 1.2+) and at rest (AES-256)
  • Per-partner FHIR data namespace isolation
  • Dual-layer authentication for every PHI-returning API call
  • Immutable audit records for all PHI access events
  • Azure-hosted infrastructure with enterprise security controls

7. Protected Health Information (HIPAA)

OnePath operates as a HIPAA Business Associate (45 CFR §160.103) with respect to PHI submitted to the OnePath Connect API by Covered Entities and their Business Associates. Our use and disclosure of PHI is limited to the purposes permitted by each Partner's executed BAA and by applicable HIPAA regulations. For more information, see our HIPAA Compliance page.

8. Data Retention

We retain Partner organization information and API usage logs for as long as the Partner relationship is active and for a reasonable period thereafter as required by law. PHI submitted through the OnePath Connect API is retained as specified in the applicable BAA and consistent with HIPAA requirements.

9. International Data Transfers

OnePath Connect infrastructure is hosted in the United States on Microsoft Azure. If you access our services from outside the United States, your information will be transferred to and processed in the United States.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date and notify active Partners by email. Continued use of OnePath Connect after such notification constitutes acceptance of the updated Policy.

11. Contact Us

Questions about this Privacy Policy should be directed to:
OnePath Health, Inc. — Privacy Office
privacy@onepath.health

Questions about how we handle data?

Talk to Our Team
OnePath logoOnePathConnect

HIPAA-compliant health intelligence API for any organization working with health data.

Status

Product

DocsPlatformChangelogStatusUse Cases

Developers

Getting StartedAPI ReferenceSDKsWebhooksError Reference

Company

AboutSecurityContactLinkedIn

Legal

Privacy PolicyTerms of ServiceHIPAA ComplianceBAA InformationSecurity Disclosure

© 2026 OnePath Health, Inc. All rights reserved.

HIPAA-compliant · FHIR R4 native · SOC 2 in progress