Legal

Privacy Policy.

How Sage Health collects, uses, and protects information — including the protected health information our agents handle under HIPAA on behalf of the independent practices we serve.

Effective May 1, 2026 Last updated May 2026 Houston · Dallas

This Privacy Policy explains how Sage Health Partners LLC ("Sage Health," "we," "us," or "our"), a Texas limited liability company, collects, uses, and protects information when you visit sagehealth.partners, contact us, or use the services we provide to medical practices. It also describes how we handle protected health information ("PHI") in our role as a Business Associate under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA").

For the technical safeguards, BAA practices, and infrastructure controls that govern our handling of PHI, see our HIPAA & Compliance page. This Privacy Policy and that page are intended to be read together.

1. Who we are

Sage Health is a healthcare technology and advisory firm headquartered in Houston, Texas, with a second office in Dallas. We build operational methodology and intelligent technology — including AI agents for voice, eligibility, and patient communication — for independently-owned medical practices. We act as a Business Associate of the practices we serve.

The data controller for this site is Sage Health Partners LLC. For privacy questions, contact privacy@sagehealth.partners.

2. Information we collect

2.1 Information you give us directly

When you contact us through this website, request a discovery call, request a BAA, or correspond with us by email, we collect the information you choose to share. That typically includes your name, role, practice name, email address, phone number, and the content of your message. If you schedule a meeting, we may also collect calendar availability and a brief note on what you'd like to discuss.

2.2 Information we collect automatically

When you visit sagehealth.partners, our hosting provider (Vercel) and standard server processes record limited technical information for security, abuse prevention, and basic site analytics. This includes IP address, browser type and version, referring URL, pages requested, and timestamps. We do not use this information to identify individual visitors.

2.3 Protected health information (PHI)

In our role as a Business Associate, we receive, create, transmit, and store PHI on behalf of the practices we serve. PHI is governed exclusively by the Business Associate Agreement ("BAA") in effect between Sage Health and the practice, by HIPAA, and by the technical and administrative safeguards described on our HIPAA & Compliance page.

PHI handled by our agents is never used for marketing, never sold, and never disclosed for any purpose not permitted by the BAA and HIPAA. Each agent collects only the minimum necessary information — for example, a voice scheduling agent records caller phone number, conversation transcript, and the appointment context it is negotiating; it does not collect clinical notes, lab results, or other information outside its operational scope.

3. Cookies and similar technologies

Our website uses a minimal set of strictly necessary technologies. We do not deploy third-party advertising cookies, cross-site tracking pixels, or behavioral retargeting tags. Specifically, we use:

  • Strictly necessary technologies required for the site to function — for example, the standard mechanisms our hosting provider uses to route requests and protect against abuse.
  • Privacy-respecting analytics that record aggregate page-view counts without persistent identifiers, without behavioral profiling, and without sharing data with advertising networks.

We do not currently use cookies that require consent under the ePrivacy Directive. If that changes, we will update this policy and present an appropriate notice on the site before any non-essential cookie is set.

4. How we use information

We use the information described in Section 2 for a specific, limited set of purposes:

  • To respond to you. When you contact us, we use the information you provide to answer your question, schedule a meeting, send you a BAA, or follow up on a discovery call.
  • To deliver the services we have agreed to provide. Information you share during an active engagement is used to perform the assessment, deploy the technology, or produce the deliverable we have contracted to produce.
  • To operate and improve our website. Server logs and aggregate analytics help us understand which pages are useful, diagnose errors, and protect the site from abuse.
  • To meet legal and contractual obligations. We retain certain records — including BAAs, executed engagement letters, and audit logs — for the periods required by HIPAA, our agreements with practices, and applicable Texas and federal law.

We do not use information collected through this website to train any general-purpose machine learning model.

5. How we share information

We share information only in the specific circumstances listed below.

  • Service providers (subprocessors) who help us operate. We rely on a small set of vetted vendors — for example, our cloud infrastructure provider, our voice telephony provider, our eligibility clearinghouse, and our email service. Every vendor that may touch PHI is bound by a signed Business Associate Agreement with Sage Health, vetted on a security questionnaire, and reviewed annually.
  • The practice on whose behalf we are operating. If you interact with a Sage Health agent as a patient of one of our practices, the practice is the covered entity and receives the resulting record in the ordinary course of its operations.
  • When required by law. We may disclose information in response to a valid subpoena, court order, or other lawful process, and where required by HIPAA's permitted disclosure rules.
  • In a business transaction. If Sage Health is involved in a merger, acquisition, or sale of assets, information may transfer as part of that transaction, subject to the same privacy commitments described here.

We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not rent, trade, or otherwise commercialize the information described in this policy.

6. Data retention

We retain information only as long as we need it for the purpose we collected it.

  • Website and contact inquiries are retained for up to twenty-four months after our last substantive contact, then deleted or anonymized.
  • Engagement records — contracts, deliverables, invoices — are retained for seven years after the engagement ends, consistent with our records-retention policy and applicable Texas business-records requirements.
  • PHI is retained per the Business Associate Agreement with each practice — typically the duration of the engagement plus the medical-record retention period required by the practice's state. Audit logs covering PHI access are retained for six years as HIPAA requires.
  • Backups are encrypted, retained on a defined cycle, and overwritten according to our backup policy.

On termination of a BAA, PHI is returned or destroyed in accordance with the BAA, and we issue a written certificate of destruction on request.

7. How we protect information

The administrative, physical, and technical safeguards Sage Health applies to PHI — encryption in transit and at rest, multi-factor authentication, role-based access control, audit logging, network isolation, and continuous monitoring — are described in detail on our HIPAA & Compliance page. The same baseline controls protect the personal information described in this Privacy Policy.

8. Your rights

8.1 Rights regarding your personal information

Subject to applicable law and to our obligations under HIPAA and the BAAs we sign, you may:

  • Ask what information we hold about you;
  • Ask us to correct information that is inaccurate;
  • Ask us to delete information when we no longer have a legal or contractual reason to keep it;
  • Withdraw consent to optional uses of your information, where consent is the legal basis;
  • Receive a copy of information you provided to us in a portable format.

Send requests to privacy@sagehealth.partners. We will respond within thirty days. If your request relates to PHI and you are a patient of one of our practices, the practice — not Sage Health — is the appropriate first point of contact under HIPAA; we will help direct you there.

8.2 Patients of practices we serve

If you interacted with a Sage Health agent as a patient of one of our customer practices, your rights to access, amend, and request an accounting of disclosures of your PHI run through that practice under HIPAA. Contact your practice directly to exercise those rights. We will assist the practice promptly in responding.

8.3 Do Not Track

Our website does not respond to "Do Not Track" browser signals, because we do not track visitors across third-party sites in the first place.

9. Children's privacy

Our website is intended for medical practice owners, administrators, and clinicians — not for children. We do not knowingly collect information from anyone under thirteen through this website. PHI for pediatric patients may be handled by our agents in the ordinary course of our services to a pediatric practice; that handling is governed by the BAA and HIPAA, not by this Privacy Policy's child-directed-website rules.

10. International transfers

Sage Health stores all PHI in United States–based infrastructure. PHI does not leave the United States. Limited operational data described in this policy (for example, contact-form submissions) is also processed in the United States. If you are contacting us from outside the United States, you are doing so on the understanding that your information will be processed in the United States.

11. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be reflected in the "Last updated" date at the top of this page, and — where appropriate — communicated directly to active customers. If you want to be sure you are reading the current version, check the date here. Continued use of our website or services after a change indicates acceptance of the updated policy.

12. Contact us

For privacy questions, requests, or concerns:

If you believe we have not addressed a privacy concern adequately, you may also contact the U.S. Department of Health and Human Services, Office for Civil Rights, regarding HIPAA-related matters; or the Texas Attorney General's office regarding state privacy law.


This Privacy Policy is provided for transparency. It does not create a contractual right or obligation between Sage Health and any reader except where required by applicable law. The legal terms governing the services Sage Health provides to a practice are set out in the engagement letter, Master Services Agreement, and Business Associate Agreement signed with that practice.

Let's build together.

Independent practices deserve intelligent practice operations. Get started with a quick conversation.