Privacy Policy

Last Updated: June 15, 2026

At MedMagic, we are committed to protecting the privacy of healthcare providers, practices, and the patients they serve. This Privacy Policy describes how MedMagic (“we,” “us,” or “our”) collects, uses, protects, and discloses information in connection with our patient acquisition, marketing, CRM, and practice-growth services.

1. Healthcare Compliance & HIPAA

MedMagic operates in strict compliance with the Health Insurance Portability and Accountability Act (HIPAA) and the Health Information Technology for Economic and Clinical Health (HITECH) Act.

In providing our services, we act as a Business Associate to our healthcare provider clients, who are Covered Entities. We execute standard Business Associate Agreements (BAAs) with all of our clients to govern the processing of Protected Health Information (PHI). All data transmissions and storage are fully encrypted in accordance with HIPAA Security Rules.

2. Information We Collect

We collect information in two main categories:

  • Practice Information: Information about your healthcare practice, including clinic names, employee credentials, EHR systems, and contact details.
  • Lead and appointment information: Names, contact details, practice details, appointment selections, and campaign attribution submitted through our forms, booking tools, or connected systems. This information is handled in accordance with applicable agreements and is used to coordinate strategy sessions, support practice-growth services, and measure performance.

3. How We Use Information

We use the information we collect to:

  • Deliver, manage, and optimize patient acquisition, CRM, and practice-growth services.
  • Coordinate strategy sessions and connect approved booking or practice systems when requested.
  • Measure campaign performance and improve follow-up and conversion workflows.
  • Maintain clinical safety records and perform service improvements, as permitted by HIPAA rules and the BAA.

4. Data Security

We employ enterprise-grade, HIPAA-aligned security protocols to protect your practice and patient data. This includes:

  • Encryption: All data is encrypted at rest and in transit using AES-256 and TLS 1.3 encryption protocols.
  • Access Control: Strict role-based access controls and multi-factor authentication (MFA) for administrative access.
  • Hosting: Data is hosted in secure, HIPAA-compliant cloud facilities located in the United States.

5. Data Sharing & Third-Party Disclosure

We do not sell, rent, or trade practice data, patient contact lists, or Protected Health Information to third parties. We only share information with authorized subcontractors (e.g., compliant cloud databases, analytics platforms, and messaging gateways) who are contractually bound to protect it and only as necessary to deliver the MedMagic service.

6. Contact Information

If you have any questions or concerns regarding this Privacy Policy or our security compliance practices, please contact us at:

MedMagic Compliance TeamEmail: privacy@medmagicagency.comAddress: 3816 San Jacinto St, Unit 302, Dallas, TX 75204