Who we are
Sova Holdings Group Inc. (“we,” “us,” or “our”) offers SovaCare, the Clinical Operating System for Independent Care. SovaCare is a product of Sova Holdings Group Inc. Sova Healthcare Innovation Systems, Inc., a wholly owned subsidiary of Sova Holdings Group Inc., owns SovaCare intellectual property and licenses it within the Sova group. Customer contracts and Business Associate Agreements name the contracting Sova entity on your Order Form.
This Privacy Policy describes how we handle information when you visit sovacare.health, request a demo or pilot, create a staff account, or when a covered entity uses SovaCare under a Business Associate Agreement (BAA).
Important: Business Associate role
SovaCare acts as a Business Associate when it creates, receives, maintains or transmits PHI on behalf of a covered entity pursuant to a Business Associate Agreement.
This is not a covered-entity Notice of Privacy Practices. Your clinic (the Covered Entity) is responsible for notifying patients of their privacy rights. BAA available for covered entities.
When we process Protected Health Information (PHI) for a customer, we do so only for the purposes permitted by the BAA and the customer's written instructions. We do not use PHI for marketing or sell PHI.
1. Information we collect
A. Public website and demo requests
If you book a demo, join a pilot waitlist, or contact us, we collect business contact and practice details you submit—for example name, work email, organization, role, specialty, practice size, current systems, and the challenge you describe. We ask that you do not include patient names or other PHI in these forms.
B. Clinician and staff accounts
When a practice provisions users on SovaCare, we typically process:
- Name, work email, phone, organization, role, and license or NPI where provided
- Authentication data (credentials, session tokens, MFA status)
- Product usage events (features used, login times, support interactions)
- Billing and subscription information for the practice (payment cards are processed by Stripe)
C. Patient information (PHI) for covered entities
When a covered entity uses SovaCare under a BAA, we may create, receive, maintain, or transmit PHI on the covered entity's behalf, such as:
- Patient demographics and contact information
- Clinical records (encounters, diagnoses, medications, allergies, labs, notes)
- Scheduling, intake, consent, and care-coordination records
- Claims and eligibility data needed for revenue-cycle workflows
- Audit and access logs related to that information
Patients should direct HIPAA access, amendment, and accounting requests to their clinic. We assist the covered entity as required by the BAA.
D. Technical and diagnostic data
- IP address, browser and device type, approximate location derived from IP
- Cookies and similar technologies (see Cookies below)
- Application logs and error diagnostics needed to operate and secure the Service
2. How we use information
- Respond to demo, pilot, and sales inquiries and schedule follow-up
- Provide, maintain, secure, and improve SovaCare
- Authenticate users, manage roles, and enforce access controls
- Process subscriptions and invoices
- Send operational notices (security, downtime, product changes)
- Detect fraud, abuse, and security incidents
- Comply with law and enforceable legal process
- For PHI: only as permitted by the applicable BAA and covered-entity instructions
3. How we share information
We do not sell patient data or PHI. We share information only as needed to run the Service:
- Subprocessors that may handle PHI: cloud infrastructure and other vendors that create, receive, maintain, or transmit PHI for us under written agreements that include HIPAA business associate terms where required (for example Microsoft Azure for hosting).
- Payment processing: Stripe processes payment card data under PCI-DSS. Stripe does not receive clinical PHI from marketing-site checkout.
- Marketing analytics: Marketing analytics are restricted to approved public-facing pages and are configured so that PHI is not intentionally transmitted to analytics providers. Analytics tools on the public site are not used inside authenticated clinical areas and are not treated as HIPAA business associates.
- Covered-entity instruction / patient authorization: when the customer directs a permitted disclosure or a patient authorizes one.
- Legal and safety: to comply with law, court orders, or to protect rights, safety, and security.
- Corporate transactions: in a merger, financing, or sale, subject to continued confidentiality and HIPAA obligations for PHI.
4. Retention
- Demo and waitlist leads: retained while we pursue the opportunity and for a reasonable follow-up period, then deleted or minimized unless a customer relationship begins
- Account and operational data: retained while the subscription is active and as needed for billing, security, and legal holds
- PHI and clinical records: retained per the Order Form / BAA and the covered entity's instructions
- Audit logs are retained for seven years pursuant to SovaCare policy and applicable contractual/legal requirements.
- Public-site analytics: typically retained up to 12 months
5. Security
We apply administrative, physical, and technical safeguards appropriate to a healthcare SaaS Business Associate, including:
- Encryption in transit (TLS 1.2+) and encryption at rest for production data stores
- Role-based access control and least-privilege administration
- Audit logging of relevant access and administrative actions
- Workforce training and vendor due diligence
No method of transmission or storage is perfectly secure. Additional detail appears on our Trust Center and HIPAA & PHI Practices pages.
6. Your choices and rights
Patients
Contact your clinic for HIPAA rights (access, amendment, restrictions, accounting of disclosures). We support the covered entity under the BAA; we do not independently fulfill patient NPP requests.
Website visitors and practice contacts
You may request access, correction, or deletion of demo/lead information we hold about you, subject to legal retention needs. Where CCPA/CPRA or similar laws apply to personal information we control as a business, you may also have rights to know, delete, correct, and opt out of certain sharing. We do not sell personal information as that term is commonly defined under those laws.
Privacy requests: admin@sovacare.health · Security: security@sovacare.health
7. Cookies and tracking
We use cookies and similar technologies to:
- Keep you signed in and protect sessions in the product
- Remember preferences
- Measure public-site traffic as described above
You can control cookies in your browser. Blocking cookies may limit some product features that depend on session cookies.
8. Children
The public website and practice-facing Service are not directed at children under 13 (or the age required by local law). We do not knowingly collect personal information from children through marketing forms. Clinical records for pediatric patients are processed only as instructed by the covered entity under a BAA.
9. International transfers
SovaCare is operated primarily from the United States. If you access the Service from outside the U.S., your information may be processed in the United States subject to this Policy and applicable agreements.
10. Changes
We may update this Policy from time to time. We will revise the “Last updated” date and, for material changes affecting customers, provide notice through the Service or email when appropriate. Continued use after the effective date constitutes acceptance of the updated Policy to the extent permitted by law and your agreements with us.
11. Contact
Sova Holdings Group Inc.
Privacy: admin@sovacare.health
Security: security@sovacare.health
Washington, D.C.