Ellery Health
Privacy Policy
Effective 27 September 2026 · Last updated 9 October 2026
Ellery Health (“we”, “us”) provides medical and dental practices with insurance eligibility checks, scheduling, appointment reminders, payments at the front desk and a voice agent that books visits by phone. This policy explains what information we handle, why, and what choices people have. It covers the Ellery Health application and this website.
Two kinds of people, two different roles
Practices and their staff are our customers. We hold their account information directly and this policy governs it.
Patients are their patients, not ours. We handle patient information only on a practice's instructions, as part of running that practice's eligibility checks, schedule, appointment reminders and front-desk payments. The practice decides what is collected and why; we act on its behalf under a written agreement, including a business associate agreement where HIPAA applies. If you are a patient and want your information corrected or removed, ask your practice — they hold your record, control it, and can reach us on your behalf.
How to stop appointment reminders
Email. Every email reminder carries an unsubscribe link at the bottom. Using it stops reminders to that address immediately, with no account or password needed, and the choice is recorded so it cannot be silently reversed.
Text. Reply STOP to any text reminder. That stops text reminders from that practice to your number, and the choice is recorded so it cannot be silently reversed. Reply HELP for help: every practice's number answers. Text reminders are not being sent yet: see Text message reminders below.
You can also tell your practice, or write to support@elleryhealth.net and we will pass it to them. We do not send marketing email or marketing texts to patients at all, so there is nothing else to opt out of.
What we handle
- Practice and staff information: practice name, address, NPI, staff names, work email addresses, roles, and sign-in records.
- Patient information, on the practice's behalf: name and date of birth; insurance member and group identifiers and, for a patient covered on someone else's plan, the policyholder's name and date of birth; the payer's response about coverage and benefits; appointment details; contact details: a phone number and an email address (an email reminder goes to the email address and, for text reminders, a mobile phone number is used); a record of whether the patient has agreed to reminders, by email and by text; and a record of the payments the practice takes at its front desk: the amount, the method and the date, a check number where there is one, any note the practice adds, and who took the payment.
- Billing information for practices: plan, usage counts and invoices. Card details are handled by our payment processor and are never stored by us.
- Technical records: application logs, access logs that include the network address a request came from, and audit records of who did what and when. Patient names, dates of birth, member identifiers and contact details are stripped from application logs before they are written.
Patient information reaches us from the practice; from the payer, in its answer to an eligibility check; and from the patient, when they use a link in a reminder, speak to the practice's voice agent, reply to a text reminder or contact us. We do not get it from anywhere else: we do not buy, rent, scrape or import contact lists, and we never sell or rent anyone's information.
Why we handle it
- To check insurance coverage with the payer, at the practice's request.
- To run the practice's calendar and send the appointment reminders it has configured.
- To let a patient confirm, move or cancel a visit from the link in a reminder, and to book, move or cancel a visit when a patient calls the practice's voice agent.
- To record the payments a practice takes at its front desk.
- To bill the practice for its use of the service.
- To keep the service secure, diagnose faults, and maintain the audit record a practice needs to answer who did what.
We do not use patient information to advertise anything, to train models, or for any purpose other than delivering the service to the practice that provided it.
Who else sees it
We use a small number of service providers, each under contract and each limited to what its job requires:
- A clearinghouse, to exchange eligibility requests and responses with payers.
- Amazon Web Services, which hosts the application and its database in the United States, which sends reminder email, and which will pass text reminders to the mobile carriers once they start.
- A payment processor, for practice subscriptions and invoices, and for the card payments a practice takes at its front desk. For subscriptions it receives usage counts and billing details. For a card payment at the desk, the card details go straight to the processor and we send it the amount, with nothing that identifies the patient.
- A telephone and voice service, for practices that use the voice agent. It answers the call and carries what the caller says.
- An email provider, for our support mailbox. A message you send us is held there.
This website sets no cookies and runs no analytics. Its typefaces load from Google Fonts, which sees your browser's network address when a page loads.
We disclose information otherwise only where the law requires it, and we will tell the affected practice unless we are prohibited from doing so.
Text message reminders
Text reminders are not being sent yet. A practice can send them only once a phone number has been registered to it with the mobile carriers. Until then its reminders go by email. This section applies from the first text.
- What they are. Reminders about an appointment you already have with your practice. Each one names the practice and comes from a phone number registered to that practice alone. They never carry marketing.
- Who gets them. Only patients whose practice has recorded their agreement to text reminders. Our terms require the practice to hold that agreement in writing. Agreeing to email reminders is not agreeing to texts, and a phone number on file is not agreement. Agreeing is optional, and it is not a condition of being seen by your practice.
- How often. Message frequency varies with your appointments. You get no more than about two text reminders for each appointment.
- Cost. Message and data rates may apply.
- To stop. Reply STOP to any text reminder. That stops text reminders from that practice to your number, and the choice is recorded so it cannot be silently reversed. You may get one last message confirming it.
- For help. Reply HELP to any text reminder: every practice's number answers. You can also write to support@elleryhealth.net or call (732) 444-7364.
We do not share mobile information for marketing. No mobile information is shared with third parties or affiliates for marketing or promotional purposes. Text-message opt-in data and consent are not shared with any third party. To deliver a text reminder, the mobile number and the message pass through our messaging provider (Amazon Web Services) and the mobile carriers.
The text message terms are on our Terms of Service page.
Where it is held, and for how long
Information is stored in the United States. Each practice's data is separated from every other practice's at the database level, and that separation is tested on every release.
We keep information for as long as the practice's account is active. After an account closes, we delete the practice's data — including patient records and the payer responses held against them — within 30 days. That window gives the practice time to export anything it still needs. Audit and billing records are kept longer than other data because we are required to retain them. Billing records here means the record of what we billed the practice: the record of payments a practice took from its patients is deleted with the rest of its data.
Security
Access is limited by role, and every action is written to an append-only audit record that cannot be altered or deleted. Data is encrypted in transit and at rest. Sign-in to the application requires a second factor.
The separation between practices is enforced by the database itself rather than by application code, so a mistake in the application cannot expose one practice's data to another. That separation is covered by automated tests, and it is verified against the running system as part of each release.
The link in a reminder opens that one visit without a sign-in, so that a patient needs no account. Anyone who has the link can confirm, move or cancel that visit until it starts. The page shows the practice, the provider, the place and the time, and nothing else about the patient.
No service can promise that nothing will ever go wrong. If information is breached, we will notify the affected practice without undue delay and cooperate with the notifications it is required to make.
Choices for practices
A practice can see, correct and export its data from within the application, switch reminders off at any time, and ask us to delete its data when it leaves. Requests go to support@elleryhealth.net.
Children
This service is sold to practices, not to individuals, and it is not directed at children. Where a practice treats children, we handle their information the same way we handle any other patient information: only on that practice's instructions.
Changes to this policy
If we change this policy in a way that materially affects how we handle information, we will update the date at the top and tell practices before the change takes effect.
Contact
Ellery Health
support@elleryhealth.net · (732) 444-7364