Effective date: July 1, 2026 · OnePath Health, Inc.
OnePath Health, Inc. ("OnePath," "we," "our," or "us") operates OnePath Connect, a business-to-business REST API that enables healthcare organizations to integrate AI-powered clinical intelligence into their own platforms. OnePath Connect is not a consumer product; it is accessed exclusively by credentialed Partner organizations that have executed a Business Associate Agreement with us.
Questions about this Privacy Policy may be directed to privacy@onepath.health.
This Privacy Policy describes how OnePath collects, uses, stores, and shares information in connection with (a) our website and marketing properties, and (b) the OnePath Connect API services. It does not describe the privacy practices of our Partners with respect to their own end users or patients.
Protected Health Information ("PHI") submitted to the OnePath Connect API by Partners is governed by the Business Associate Agreement between OnePath and each Partner, and by applicable provisions of HIPAA and its implementing regulations. Our handling of PHI is described separately in Section 7.
When a healthcare organization applies to become an OnePath Connect Partner, we collect:
When Partners use the OnePath Connect API, we automatically collect:
If you visit our website, we may collect standard web server log data (IP address, browser type, referring URL, pages visited, timestamps). We do not use persistent third-party advertising trackers.
We use the information described above to:
We do not sell Partner information or API usage data to third parties. We do not use PHI for any purpose other than providing the services described in each Partner's BAA.
We do not share Partner organization information with third parties except:
OnePath employs administrative, physical, and technical safeguards including:
OnePath operates as a HIPAA Business Associate (45 CFR §160.103) with respect to PHI submitted to the OnePath Connect API by Covered Entities and their Business Associates. Our use and disclosure of PHI is limited to the purposes permitted by each Partner's executed BAA and by applicable HIPAA regulations. For more information, see our HIPAA Compliance page.
We retain Partner organization information and API usage logs for as long as the Partner relationship is active and for a reasonable period thereafter as required by law. PHI submitted through the OnePath Connect API is retained as specified in the applicable BAA and consistent with HIPAA requirements.
OnePath Connect infrastructure is hosted in the United States on Microsoft Azure. If you access our services from outside the United States, your information will be transferred to and processed in the United States.
We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date and notify active Partners by email. Continued use of OnePath Connect after such notification constitutes acceptance of the updated Policy.
Questions about this Privacy Policy should be directed to:
OnePath Health, Inc. — Privacy Office
privacy@onepath.health
Questions about how we handle data?
Talk to Our Team