Skip to content

Legal

Privacy Notice

How information is collected, used, disclosed, stored and safeguarded across our products, services and website.

Privacy at a Glance

Mirewa builds software for licensed healthcare organizations. This Privacy Notice explains how Mirewa handles information in connection with our website and our services.

Most of the health information in our systems does not belong to us. It belongs to the healthcare organizations that use our software, and we process it only on their instructions under a Business Associate Agreement.

Key Privacy Commitments

  • The clinic controls its data. Mirewa processes Protected Health Information only as a HIPAA Business Associate, under an executed Business Associate Agreement, and only on the clinic's documented instructions.
  • We do not sell personal information or Protected Health Information.
  • We do not train AI models on customer clinical content without the clinic's express written authorization.
  • AI assists; it does not decide. A licensed professional reviews and approves clinical documentation.
  • Our website sets no cookies and runs no advertising or analytics trackers.

Questions: compliance@mirewa.com. See Section 20.

Table of Contents

  1. 01We’re Here to Help
  2. 02About Mirewa
  3. 03Who This Policy Applies To
  4. 04Definitions
  5. 05Our Role Under HIPAA
  6. 06Information We Collect
  7. 07How We Collect Information
  8. 08How We Use Information
  9. 09Artificial Intelligence
  10. 10Clinical Imaging & Biometric Privacy
  11. 11Data Sharing & Service Providers
  12. 12Data Retention
  13. 13Security
  14. 14Your Privacy Rights
  15. 15Cookies and Website Technology
  16. 16Children
  17. 17State Privacy Rights
  18. 18International Users
  19. 19Changes to This Privacy Notice
  20. 20Contact Us
01

We’re Here to Help

For privacy questions, security reports, or legal requests, contact compliance@mirewa.com.

We aim to respond within ten (10) business days.

Patients: if you are a patient and want to see, correct, or ask about your medical records, please contact your healthcare provider directly. Your provider holds your records; Mirewa cannot act on them without your provider's instruction. See Section 14.

02

About Mirewa

Mirewa Inc. is an Illinois corporation that develops software for licensed healthcare organizations.

Depending on what a clinic has purchased, Mirewa may provide:

VeinCare: clinical photography for medical documentation and comparison across visits.

Live Translation Suite: real-time translation to help providers and patients communicate during a visit, and documentation drafted from that conversation.

Admin Suite: tools that reduce administrative work, including summarizing prior records, combining documents, and clinical calculators.

We may add or change services over time. If a change materially affects this Notice, we will update it.

03

Who This Policy Applies To

This Notice applies to:

  • Clinics: the healthcare organizations that subscribe to our services.
  • Clinical Users: the people a clinic authorizes to use Mirewa.
  • Website Visitors: anyone who visits our website or contacts us.

It does not govern patient health information. Mirewa handles that only on behalf of a clinic, under that clinic's instructions and its Business Associate Agreement. How a clinic uses, discloses, and protects patient information is described in that clinic's own Notice of Privacy Practices, not here. Patients do not have Mirewa accounts.

04

Definitions

Clinic: a licensed healthcare provider or healthcare organization using Mirewa.

Clinical User: a person a Clinic authorizes to use Mirewa.

Business Associate, Covered Entity, and Protected Health Information (PHI) have the meanings given to them under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA").

Personal Information: information that identifies or can reasonably be linked to an individual, as defined by applicable privacy law.

Services: Mirewa's website, applications, and any products we make available to customers.

05

Our Role Under HIPAA

Where a Clinic is a HIPAA Covered Entity, Mirewa acts as its Business Associate. Our handling of PHI is governed by the executed Business Associate Agreement between Mirewa and that Clinic.

As a Business Associate, Mirewa uses and discloses PHI only:

  • To provide the services the Clinic has requested;
  • As permitted by the Business Associate Agreement;
  • As required by law; and
  • On the Clinic's documented instructions.

The Clinic remains responsible for:

  • Deciding how Mirewa is used in its practice;
  • Obtaining any patient consent or authorization required by law;
  • Meeting its own obligations to patients, including its Notice of Privacy Practices and responding to patient requests about their records;
  • Complying with the laws that govern its practice, including advertising and professional conduct rules; and
  • Reviewing and approving clinical documentation before it enters the medical record.

Mirewa does not practice medicine. We do not diagnose, treat, decide on care, or establish a relationship with any patient.

Information we handle outside HIPAA, such as website inquiries, business contacts and recruiting, is covered by this Notice and applicable privacy law.

06

Information We Collect

We collect only what we need to provide and secure the Services. There are two categories, and they are treated differently.

1. Information Mirewa holds in its own right

CategoryExamples
Account informationName, professional title, work email, organization, role, account preferences
Operational and security informationSign-in events, IP address, device and browser information, audit logs, security events
CommunicationsSupport requests, correspondence, product inquiries
Website informationPages visited and basic technical information needed to serve and secure the site

2. Patient information processed for a Clinic

Depending on the services a Clinic enables, this may include patient identifiers entered by Clinical Users, clinical photographs, translated conversation transcripts, and clinical documentation drafted for provider review.

Mirewa holds this information on the Clinic's behalf, not its own. It is governed by the Business Associate Agreement and the Clinic's instructions.

What we do not collect

  • Biometric identifiers or biometric information.
  • Facial recognition data or facial geometry.
  • Protected Health Information through our public website.
07

How We Collect Information

We receive information:

  • From a Clinic, when it sets up and administers its account;
  • From Clinical Users, when they use the Services or contact support;
  • Automatically, as a by-product of operating the Services securely: sign-in events, audit logs, and basic technical information about the device and browser used.

We do not buy personal information, and we do not collect it from third-party data brokers.

08

How We Use Information

We use information to:

  • Provide the Services a Clinic has requested;
  • Authenticate users and control access;
  • Protect the Services against fraud, abuse, and security threats;
  • Meet legal, regulatory, and contractual obligations, including audit logging;
  • Provide customer support; and
  • Maintain and improve the reliability, security, and performance of the Services.

We do not:

  • Sell or rent personal information or Protected Health Information;
  • Share clinical information with advertisers or data brokers;
  • Use customer Protected Health Information to train or improve AI models without the Clinic's express written authorization; or
  • Allow third parties to use customer information for their own purposes.
09

Artificial Intelligence

Some Mirewa features use artificial intelligence to assist Clinical Users. For example, drafting documentation from a translated conversation, or summarizing prior records.

AI output is a draft. It may be incomplete or wrong. An authorized healthcare professional must review, correct, and approve any AI-generated content before relying on it or placing it in a patient's record. Mirewa does not diagnose, make clinical decisions, or sign documentation.

Where a feature sends information to a third-party AI provider, that provider processes it only to deliver the requested functionality, under contractual confidentiality obligations and, where applicable, a Business Associate Agreement.

We do not use customer clinical content to train or improve AI models unless the Clinic authorizes it in writing.

10

Clinical Imaging & Biometric Privacy

Some Mirewa services let a Clinic capture clinical photographs for medical documentation.

Consent is the Clinic's responsibility. The Clinic decides whether patient consent or authorization is required and obtains it. Mirewa provides features that help a Clinic record that it did so; Mirewa does not determine what the law requires for a given patient or encounter.

Faces are refused, not stored. Mirewa checks each image for recognizable facial features and rejects images in which a face is detected: they are not uploaded, saved, or attached to any record. This check exists only to enforce that rule. It is not facial recognition, identity verification, or biometric matching.

Mirewa does not collect biometric information. We do not perform facial recognition, create or store facial templates or facial geometry, identify anyone by biometric characteristics, or profit from biometric information. This includes the Illinois Biometric Information Privacy Act (BIPA) and comparable laws.

11

Data Sharing & Service Providers

We share information only as needed to run the Services, meet a legal obligation, or protect our systems. We do not sell personal information or Protected Health Information.

Service providers. We use vetted vendors for cloud hosting and storage, AI processing, email delivery, and system monitoring. They receive only what they need, are bound by confidentiality and security obligations, and, where they handle PHI, by a Business Associate Agreement. If we add a category of service provider that handles personal information, we will update this Notice.

Clinics. Information processed through Mirewa is available to the applicable Clinic and its authorized users.

Legal. We may disclose information where required or permitted by law, including to comply with legal process or to investigate fraud, abuse, or a security incident.

Business transactions. If Mirewa is involved in a merger, acquisition, or sale of assets, information may transfer as part of that transaction, subject to confidentiality obligations and applicable law.

Never for advertising. We do not disclose customer or clinical information to advertising networks, and we do not permit behavioral advertising on it.

12

Data Retention

Clinical information is retained as agreed with the Clinic. Retention periods and deletion are set out in the applicable Business Associate Agreement and the Clinic's instructions, consistent with the Clinic's own retention obligations and applicable law.

On termination, Mirewa returns or destroys Protected Health Information as required by the applicable Business Associate Agreement.

Other information, meaning account records, audit logs and business correspondence, is kept for as long as needed to provide the Services and to meet our legal, contractual, tax, and audit obligations, and then deleted or de-identified.

13

Security

Mirewa maintains administrative, physical, and technical safeguards designed to protect the confidentiality, integrity, and availability of the information we hold, consistent with the HIPAA Security Rule where it applies.

These include encryption of information in transit and at rest, access controls that limit access to authorized users, audit logging that records access to records, including when they are viewed, and monitoring for security events, and HIPAA security and privacy awareness training for our workforce. Mirewa is built for HIPAA obligations on HIPAA-eligible cloud infrastructure.

No method of transmission or storage is completely secure. We review and improve our practices as threats evolve.

Security incidents. If we confirm a security incident affecting customer information, we will investigate, take reasonable steps to contain and remediate it, and notify affected customers as required by law and by contract. Where PHI is involved, notification follows the applicable Business Associate Agreement and HIPAA.

To report a suspected vulnerability or incident, contact compliance@mirewa.com.

14

Your Privacy Rights

Clinical Users may ask us to access or correct their account information, update preferences, or deactivate their account. Some requests need the Clinic's approval, since the Clinic controls how Mirewa is used in its organization.

Patients should contact their healthcare provider. Under HIPAA, the Clinic, not Mirewa, is responsible for responding to requests to access, amend, restrict, or obtain an accounting of disclosures of Protected Health Information. Mirewa assists its Clinics with those requests as required by contract and law, but cannot act on patient records without the Clinic's instruction.

Marketing communications: you may opt out at any time using the unsubscribe link or by contacting us. Operational, security, and service messages continue while an account is active.

15

Cookies and Website Technology

Our website does not set cookies.

We do not use advertising cookies, analytics trackers, pixels, or third-party tracking technologies, and we do not track visitors across websites. Fonts and other assets are served from our own domain rather than third-party networks.

Our web servers keep standard technical logs, for example the IP address and browser type of a request, which we use only to operate and secure the site.

If this ever changes, we will update this Notice before it takes effect.

16

Children

Mirewa is intended for licensed healthcare organizations and their authorized workforce. We do not knowingly provide accounts to anyone under 18.

Where a Clinic uses Mirewa in the care of a minor, Mirewa processes that information solely on the Clinic's behalf. The Clinic is responsible for obtaining any required parental or guardian authorization.

17

State Privacy Rights

Some U.S. states give residents additional privacy rights. Where those laws apply to information we hold in our own right, we honor them.

Protected Health Information is generally exempt. Information Mirewa processes as a HIPAA Business Associate is exempt from the California Consumer Privacy Act (CCPA/CPRA) and most comparable state laws to the extent those laws provide. Requests about patient records go to the healthcare provider that holds them.

For the limited personal information Mirewa holds in its own right, such as a Clinical User's account details or a website inquiry, residents of California and other states with similar laws may ask us to:

  • Know what personal information we hold about them and how we use it;
  • Access a copy of it;
  • Correct it if it is inaccurate;
  • Delete it, subject to our legal and contractual obligations to retain certain records; and
  • Not be discriminated against for exercising any of these rights.

Mirewa does not sell personal information and does not share it for cross-context behavioral advertising. Because we do not sell or share, there is no opt-out to offer.

To make a request, contact compliance@mirewa.com. We will verify your identity before acting, and respond within the time the applicable law allows. You may use an authorized agent where the law permits.

Biometric privacy. Mirewa's clinical imaging refuses images containing faces and does not collect biometric identifiers, consistent with the Illinois Biometric Information Privacy Act (BIPA) and comparable laws.

18

International Users

Mirewa's services are intended for healthcare organizations in the United States, and information is generally stored and processed in the United States.

If Mirewa agrees to serve an organization outside the United States, or to store information outside it, the applicable data location, transfer mechanisms, and safeguards will be set out in the agreement with that organization.

19

Changes to This Privacy Notice

We may update this Notice to reflect changes in our services, our practices, or the law. When we make a material change we will update the "Last Updated" date, publish the revised Notice here, and where appropriate notify customers directly.

Previous versions are listed at the end of this page.

20

Contact Us

Mirewa Inc.

Privacy, security, and legal inquiries: compliance@mirewa.com

Mailing address: 1043 S Roselle Rd PMB 3005, Schaumburg, IL 60193

Website: https://www.mirewa.com

If you believe your privacy rights have been affected, or you want to report a security concern, please contact us so we can investigate and respond.

Patients: for anything concerning your own medical records, please contact your healthcare provider directly.

Previous Versions

Archived versions of this Privacy Notice are listed below. The version currently in force is shown first.

  • v1.0Effective September 18, 2026· current