Privacy Policy

Last updated: April 2, 2026  |  Effective: April 2, 2026

Table of Contents

  1. Overview
  2. Information We Collect
  3. How We Use Your Information
  4. Data Sharing
  5. Data Storage & Security
  6. Your Rights
  7. Mobile App Permissions
  8. Push Notifications
  9. Cookies
  10. Children's Privacy
  11. Changes to This Policy
  12. Contact Us

1. Overview

HMSPoint ("we", "our", or "us") operates a cloud-based Hospital Management System accessible via web at app.hmspoint.com and via the HMSPoint Patient mobile application ("App").

This Privacy Policy explains how we collect, use, store, and protect your personal and health information when you use our services. By using HMSPoint, you agree to the practices described in this policy.

HMSPoint processes Protected Health Information (PHI) on behalf of healthcare facilities. Each facility (tenant) is responsible for obtaining appropriate patient consent under their jurisdiction's health data laws.

2. Information We Collect

Patient Information

Medical & Health Data

Billing Information

Account & Authentication Data

Technical Data

3. How We Use Your Information

We use your information solely to provide and improve healthcare management services:

We do not use your health data for advertising, sell it to third parties, or use it for any purpose unrelated to your healthcare.

4. Data Sharing

Your data is shared only in the following circumstances:

Healthcare Staff at Your Facility

Doctors, nurses, lab technicians and administrative staff at the hospital you registered with have role-based access to your records — only to the extent required for your care.

Service Providers

We use the following infrastructure providers who process data on our behalf under strict data processing agreements:

Legal Requirements

We may disclose your information if required by law, court order, or regulatory authority.

We Never Sell Your Data

We do not sell, rent, or trade your personal or health information to any third party for any purpose.

5. Data Storage & Security

We take the security of health data seriously and implement the following measures:

Your data is stored on servers hosted in the cloud. We retain patient records as long as required by applicable healthcare regulations or as directed by your healthcare facility.

6. Your Rights

As a patient, you have the following rights regarding your data:

To exercise these rights, contact us at pijushsukanta@email.com or reach out to your healthcare facility directly.

7. Mobile App Permissions

The HMSPoint Patient Android and iOS app requests the following device permissions:

All permissions are requested at the time of use. You can revoke any permission from your device settings at any time.

The app stores your authentication token in encrypted secure storage on your device — never in plain shared preferences or local storage.

8. Push Notifications

We use Google Firebase Cloud Messaging (FCM) to deliver push notifications to your device. Notifications are sent for:

Your FCM device token is transmitted to our servers to enable notification delivery. We do not share this token with any third party other than Google Firebase for the sole purpose of message delivery.

You can disable push notifications at any time in your device settings or within the app.

9. Cookies

The HMSPoint web application (app.hmspoint.com) uses minimal cookies:

We do not use advertising cookies, tracking pixels, or third-party analytics cookies. The marketing website (hmspoint.com) uses no cookies.

10. Children's Privacy

HMSPoint may process health records for patients of all ages, including minors, as part of legitimate healthcare services. Records for patients under 18 are managed by their guardian or the healthcare facility under applicable laws.

The patient mobile app is not directed at children under 13 for self-registration purposes.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable laws. When we make significant changes, we will:

Continued use of HMSPoint after changes are posted constitutes acceptance of the updated policy.

12. Contact Us

For privacy-related questions, data requests, or concerns about how your health information is handled, contact us:

HMSPoint Privacy Team

Email: pijushsukanta@email.com

Website: hmspoint.com

We aim to respond to all privacy inquiries within 5 business days.