Privacy Policy

M2 Physician-Facing Platform

Effective Date: May 18, 2026

1. Overview

This Privacy Policy explains how M2 handles information in connection with a physician-facing clinical decision support platform that is not intended to receive or process PHI.

2. No Collection of PHI

M2 is designed not to collect, store, or process Protected Health Information (PHI).

Users must not submit identifiable patient data. The Platform does not require PHI to function.

3. Information That May Be Collected

M2 may collect limited non-clinical information such as:

  • User account credentials
  • Professional role and specialty
  • Platform usage metrics
  • Technical and security logs

This information is used solely to:

  • Operate and secure the Platform
  • Improve performance and reliability
  • Support authorized access

4. De-Identified and Abstracted Inputs

Any clinical information entered into M2 must be:

  • Fully de-identified
  • Hypothetical or abstracted
  • Non-traceable to an individual patient

5. No Sale or Sharing of Data

M2 does not sell user data.

Information is not shared except as necessary to:

  • Operate the Platform
  • Comply with legal obligations
  • Protect security and integrity

6. Security Measures

Reasonable administrative, technical, and organizational safeguards are used to protect Platform data.

However, no system can be guaranteed 100% secure.

7. HIPAA Status

Because PHI must not be entered:

  • M2 is not a HIPAA Business Associate
  • HIPAA does not apply to the Platform as used
  • Users remain responsible for HIPAA compliance

8. User Responsibilities

Users are responsible for:

  • Ensuring no PHI is entered
  • Following institutional privacy policies
  • Using the Platform in compliance with applicable law

9. Changes to This Policy

This Privacy Policy may be updated periodically. Continued use of M2 constitutes acceptance of any changes.

10. Text Messages

With your consent, we use the mobile number you provide to send you one-time sign-in codes and account notifications, such as invitations to view a visit. We do not send marketing or promotional text messages.

  • Consent: We only send text messages after you explicitly opt in, for example on our public SMS page or by texting START. SMS consent is optional and is not a condition of purchase or of using the service.
  • Message frequency: Varies with your account activity (for example, each time you request a sign-in code or receive a visit invitation).
  • Rates: Message and data rates may apply, depending on your mobile carrier and plan.
  • Opt out: Reply STOP to any message to unsubscribe, or HELP for assistance.
  • No sharing of opt-in or consent: We never sell or share your mobile number or your SMS opt-in/consent with third parties or affiliates for marketing or promotional purposes. Text-messaging originator opt-in data and consent are not shared with any third parties.

You can review the consent form at /sms-opt-in.

11. Contact

For questions regarding privacy or compliance:

[email protected]