Patient data is the reason clinics distrust marketing software.
So here is exactly what we do with it, what we will never do with it, and what we are not yet entitled to claim. If your procurement team needs something not on this page, email security@shmel.ai and we will answer it directly.
What Shmel does, and what it will never do
- Reads last-visit dates and treatment history to know who is due back
- Drafts messages and campaigns for a named human to approve
- Writes approved appointments back to your calendar
- Sends aggregate performance figures to your ad accounts
- Upload a patient record, list or identifier to Meta or Google
- Build custom or lookalike audiences from your patients
- Send anything to a patient without a human approving it
- Make, suggest or influence a clinical decision
- Order a prescription product on its own
Where we actually stand
Vendors overstate this constantly. We would rather lose a deal than claim a certification we do not hold.
There is no such thing as HIPAA certification. What exists is a Business Associate Agreement and the controls behind it, which is what we offer and what you should ask every vendor for.
Sub-processors
Every third party that could touch your data, what it sees, and whether it is covered by a BAA. We give notice before adding one that can handle protected health information.
Named vendors are provided on request under NDA, and always before you sign. Email security@shmel.ai.
Questions procurement always asks
Do you train models on our data?
No. Nothing from your practice is used to train general-purpose models, and our contracts with model providers carry no-training terms. This is the single most common vendor lie in this category, so ask every one of them for it in writing.
Where is data hosted?
United States. If you have a residency requirement beyond that, tell us before you sign rather than after.
How long do you keep our data?
Patient data for the life of the account plus thirty days, then deleted. Compliance records for six years, because their entire value is that they can be produced later. You can export everything at any time and request earlier deletion.
What happens if you are breached?
Under the BAA we notify you without unreasonable delay so you can meet your own HIPAA breach-notification obligations. We would rather tell you early and be wrong than late and be right.
How do we report a vulnerability?
Email security@shmel.ai. We acknowledge within one business day. We will not pursue anyone acting in good faith.
Can we get a security questionnaire completed?
Yes. Send it over. A founder will fill it in — we are small enough that it will not sit in a queue.
SHMEL