Xchart Privacy Policy

Effective date: July 23, 2026

Last updated: July 23, 2026

Short version. Xchart provides cloud-based software for anesthesia charting to clinical practices. As a Business Associate under HIPAA, Xchart processes Protected Health Information (PHI) which is owned by the practices (Covered Entities). A signed Business Associate Agreement (BAA) is required before PHI may be uploaded. This page explains the details.

1. Who this policy covers

This Privacy Policy describes how Xchart, Inc. ("Xchart," "we," "us") collects, uses, discloses, and protects information when you:

If you are a patient whose provider uses Xchart, this policy is not the Notice of Privacy Practices that governs your medical records. That notice comes from your treating provider. Direct questions about your records to them. Xchart only handles your PHI as a vendor on their behalf.

2. Our role under HIPAA

For purposes of HIPAA and 45 CFR Parts 160 and 164:

3. Information we collect

This policy covers both Protected Health Information (PHI) and other personal information we collect about users and website visitors.

(a) Protected Health Information (PHI), controlled by our customers. Examples: patient identifiers, case data, vitals, medications administered, intraoperative events, provider identifiers, and clinical notes entered into the application. PHI is processed only under the BAA and only to provide the service or as otherwise permitted by the BAA.

(b) Account and usage information, controlled by Xchart. Examples: user name and work email, role, practice affiliation (org), login timestamps, IP address, device and browser metadata, audit logs of in-app actions, product usage events, and billing contacts. We use this to operate the service, understand product usage, and bill our customer practices.

(c) Website and marketing information. Examples: pages viewed on our websites, referring URL, marketing form submissions, advertising attribution parameters, and cookies. See Section 9.

4. How we use information

We use the information described above to:

  1. Provide, operate, and maintain the Xchart application for the customer practice that subscribes to it.
  2. Authenticate users and enforce access controls.
  3. Generate audit logs.
  4. Provide customer support.
  5. Bill our customer practices and manage our business relationship with them.
  6. Understand product usage and improve the product. We may also use information that has been de-identified in accordance with HIPAA (45 CFR § 164.514) or aggregated, if permitted by the BAA.
  7. Comply with legal obligations and respond to lawful requests.
  8. Communicate product updates, security notices, and (with consent where required) marketing messages to business contacts. This includes onboarding, product education, and related offer communications to business users, which may be informed by account and usage information.

We do not use customer data to train artificial intelligence (AI) or machine learning (ML) models. We do not use AI or ML to make decisions within the product.

5. How we share information

We share information only as described here.

We do not sell personal information or PHI. We do not share PHI for behavioral advertising. We do not use product analytics for third-party or behavioral advertising, and we do not share account information with advertising networks. We may use account and usage information to send onboarding, product, and related offer communications to business contacts, who can opt out at any time.

6. Security

Protecting the information entrusted to us is a priority we invest in continuously. For PHI we maintain reasonable and appropriate administrative, physical, and technical safeguards designed to meet or exceed the requirements of the HIPAA Security Rule (45 CFR Part 164, Subpart C). These safeguards include access controls, encryption of PHI in transit and at rest, audit logging, and workforce training on privacy and security.

No method of transmission or storage is 100% secure. We cannot guarantee absolute security, but we work to protect information consistent with our HIPAA obligations and the terms of the BAA.

7. Breach notification

If we discover a breach of unsecured PHI, we will notify the affected Covered Entity in accordance with our BAA and 45 CFR § 164.410. The Covered Entity is responsible for notifying affected individuals and, where required, HHS and the media. For non-PHI security incidents that affect account or website information, we will notify affected users as required by applicable law.

8. Your rights

If you are a patient, exercise your HIPAA rights, including access, amendment, accounting of disclosures, restrictions, and confidential communications, through your treating practice. Xchart will support the practice's response to your request.

If you are a user, customer contact, or website visitor, you may:

State privacy rights. Depending on where you live, you may have additional rights under state privacy laws (for example, the California Consumer Privacy Act, as amended) with respect to the account, usage, and website information we control as a business. These may include the rights to know, access, correct, or delete that information and to opt out of its sale or sharing. As stated above, we do not sell personal information or share it for cross-context behavioral advertising. Information we process as a Business Associate (PHI) is generally exempt from these state privacy laws and is instead governed by HIPAA and the BAA. To exercise a state privacy right, contact us at privacy@xchart.com; we will not discriminate against you for doing so.

HIPAA complaints

To file a HIPAA complaint, contact your provider, contact us, or contact the U.S. Department of Health and Human Services, Office for Civil Rights, at hhs.gov/hipaa/filing-a-complaint or 1-877-696-6775. We will not retaliate against anyone who exercises a privacy right or files a complaint.

9. Cookies and tracking technologies

On our marketing and information websites we use a limited set of cookies and analytics to understand traffic, remember your preferences, and measure the effectiveness of our marketing.

Inside the Xchart application, we use cookies and browser storage to:

You can manage cookies through your browser settings.

10. Data retention

Xchart retains PHI for as long as the BAA with the relevant customer practice requires, and for any period otherwise required by law. On termination of a customer relationship, we return or destroy PHI in accordance with the BAA. Account, usage, and marketing data are retained only as long as needed for the purposes described above or as required by law.

11. Changes to this policy

We reserve the right to make updates and revisions to this policy at our discretion and at any time, and will post any updates to this policy on this page and update the "Last updated" date above. Material changes that affect how we use PHI will be communicated to affected Covered Entities through the BAA process.

12. Contact us

If you have any questions or comments about this policy or if you have a disability and would like to access this policy in an alternative format, please contact us by writing to: privacy@xchart.com.

Prior versions of this policy are available on request.