LEGAL & PRIVACY

Rura Health Privacy Policy

Effective September 23, 2026

This Privacy Policy explains how Rura Health collects, uses, shares, and safeguards information related to our website, platform, and services.

1. Information We Collect

1.a. Information We Collect from www.rura.health

We collect information in the following categories:

  • Pharmacy Name and State.

  • Usage and device data — log data, IP address, browser type, and analytics collected when you use our website or platform.

  • Communications — information you provide when you contact us, request a demo, or submit a form, including through the Join Us flow.

1.b. Information We Collect After You Sign Up as a Customer

We collect information in the following categories:

  • Account and practice information — pharmacy or organization name, National Provider Identifier (NPI), license numbers, billing Tax Identification Number (TIN), pharmacist names and credentials, business address, and contact details.

  • Credentialing documents — licenses, certifications, malpractice or liability insurance, CAQH data, and other documents required for payer enrollment and credentialing.

  • Patient health information — medical and prescription history, clinical encounter documentation, eligibility and scheduling data, and other Protected Health Information (PHI) that flows through the Rura platform in connection with the clinical services a Client bills through us. See Section 3 for how PHI is specifically handled.

  • Claims and payment data — CPT/HCPCS codes, SNOMED codes, payer remittance information, denial and appeal records, and revenue-cycle reporting data.

  • Usage and device data — log data, IP address, browser type, and analytics collected when you use our website or platform.

  • Communications — information you provide when you contact us, request a demo, or submit a form, including through the Join Us flow.

2. How We Use and Share Information

How we use it. We use the information above to operate and maintain the Rura platform; complete credentialing and payer contracting on a Client’s behalf; verify eligibility, schedule care, and support clinical documentation; submit medical claims and manage denials and the revenue cycle; provide performance and revenue-cycle reporting; communicate with Clients about their account; and improve and secure our services.

Who we share it with. We share information only as needed to deliver the service, including with:

  • Payers and clearinghouses, to submit and collect on claims.

  • Credentialing and technology partners who perform enrollment, EMR, telehealth, or clinical documentation functions on our behalf, under confidentiality and, where PHI is involved, HIPAA business associate obligations.

  • Service providers such as hosting, payment processing, and analytics vendors, bound by contract to protect the information.

  • Regulators or authorities, when required by law, subpoena, or to protect the rights, safety, or property of Rura, our Clients, or others.

  • A successor entity, in the event of a merger, acquisition, or sale of assets, subject to the confidentiality commitments in this Policy.

We do not sell Client or patient information to third parties for their own marketing purposes.

3. Protected Health Information (HIPAA)

Where Rura creates, receives, maintains, or transmits PHI on behalf of a Client in connection with billing, credentialing, scheduling, or clinical documentation, Rura acts as a Business Associate of that Client under the Health Insurance Portability and Accountability Act (HIPAA). Our handling of PHI is governed by a separate Business Associate Agreement (BAA), which every Client must execute before PHI is exchanged. If any term of this Policy conflicts with the BAA, the BAA controls with respect to PHI.

Under the BAA, Rura will, among other obligations:

  • Use and disclose PHI only as permitted to perform the services, as required by law, or as otherwise authorized by the Client.

  • Apply administrative, physical, and technical safeguards consistent with the HIPAA Security Rule.

  • Limit use and disclosure of PHI to the minimum necessary for the intended purpose.

  • Report any breach of unsecured PHI to the affected Client without unreasonable delay.

  • Ensure that any subcontractor that handles PHI on our behalf agrees to the same restrictions.

  • Make PHI available to support a Client’s obligations to patients under HIPAA, including access, amendment, and accounting-of-disclosures requests, and return or destroy PHI at the end of the relationship, subject to legal retention requirements.

This Policy does not itself serve as a Notice of Privacy Practices; each Client remains responsible for its own HIPAA Notice of Privacy Practices provided to patients.

4. Data Security, Retention & Cookies

Security. We maintain administrative, technical, and physical safeguards designed to protect information against unauthorized access, use, or disclosure, including encryption in transit and at rest, role-based access controls, and audit logging. No system is completely secure, and we cannot guarantee absolute security.

Retention. We retain account, credentialing, claims, and PHI records for as long as needed to provide the service and as required by applicable law, payer requirements, and professional record-keeping standards, which for medical and billing records is often 6–10 years or longer depending on the state. We retain website and analytics data only as long as reasonably necessary for the purposes described in this Policy.

Cookies and analytics. Our website uses cookies and similar technologies to operate the site, remember preferences, and understand usage through analytics tools. You can control cookies through your browser settings; disabling cookies may limit some site functionality.

5. Your Rights, Changes to This Policy & Contact

Your choices. You may ask us to access, correct, or delete certain account information by contacting us below. Patients seeking access to, correction of, or an accounting of disclosures for their PHI should contact the pharmacy or pharmacist who treated them, as the HIPAA-covered entity; we will support that Client in responding as required by our BAA.

State privacy laws. Depending on where you live, you may have additional rights under state privacy laws, for example the right to know what personal information is collected or to opt out of certain uses. We follow CCPA/CPRA for California residents.

Changes to this Policy. We may update this Policy from time to time. We will post the revised Policy with an updated effective date and, for material changes, provide additional notice, such as email or an in-platform notice.

Questions about this Policy:

© 2026 Rura Health

2 Bethesda Metro Ctr, Suite 250 Bethesda, MD 20814

Phone: 571-385-2019