
Last updated: [DATE] — Draft pending legal review
Kavera's Privacy Policy explains how Kavera, as a HIPAA business associate to the provider organizations it serves, collects, uses, and safeguards patient assessment data and provider account information across its concussion, mental health, cognitive health, and headache monitoring platform, and where patients and practices can direct privacy questions or requests.
Legal review by [Counsel Name] required before publish.
This Privacy Policy describes how Kavera collects, uses, discloses, and protects information when healthcare providers and their patients use the Kavera platform, including patient-reported outcome data collected through Kavera's concussion, mental health, cognitive health, and headache monitoring instruments, and it explains the rights available to patients and provider organizations under applicable privacy law.
Who This Policy Covers
Kavera is a clinical monitoring platform used by neurologists, neurosurgeons, orthopedists, sports-medicine physicians, nurse practitioners, and their care teams to deliver structured assessments to patients between office visits. This policy applies to:
- Provider organizations ("Covered Entities" or "Customers") that contract with Kavera to use the platform.
- Patients who complete assessments through a link, portal, or device provided by their treating clinician.
- Kavera staff, when acting under the Managed plan to assist with monitoring and documentation on behalf of a provider organization.
Where Kavera processes patient health information on behalf of a covered healthcare provider, Kavera generally acts as a business associate under the HIPAA Privacy Rule (opens in a new tab), and a separate Business Associate Agreement (BAA) between Kavera and the provider organization governs that relationship. Where this policy and a BAA conflict regarding protected health information (PHI), the BAA controls.
Information We Collect
From provider organizations:
- Account and practice information (practice name, NPI, billing contact, staff user accounts).
- Configuration data, such as which assessment modules (Concussion, Mental Health, Cognitive Health, Headache) and plan type (self-serve or Managed) the practice has enabled.
From patients, through assessment delivery:
- Responses to the assessment battery, which may include symptom scales, mood/anxiety/PTSD screening instruments, sleep questionnaires, and cognitive-domain tests assigned by the treating clinician.
- Identifying information needed to route results to the correct patient record (name, date of birth, contact information, and identifiers supplied by the provider's practice management or EHR workflow).
- Technical data such as device type, timestamps, and completion status, used to support monitoring documentation.
Automatically, through platform use:
- Standard web and application usage data (log data, session information, browser/device type) for security, troubleshooting, and platform reliability.
Kavera does not sell patient health information, and does not use patient-reported assessment data for advertising purposes.
How We Use Information
Kavera uses the information described above to:
- Deliver the assessment battery to patients on the schedule configured by their treating clinician.
- Score, organize, and present results to the provider's care team to support clinical decision-making.
- Generate the between-visit monitoring records and documentation that support the provider's own billing determinations, including documentation relevant to Remote Therapeutic Monitoring and neurocognitive testing codes the provider bills under their own clinical judgment.
- Where the Managed plan is in use, support Kavera staff in assisting the provider's monitoring and documentation workflow, under the scope defined in the applicable BAA and services agreement.
- Maintain, secure, and improve the platform, including troubleshooting and quality assurance.
- Meet legal, regulatory, and audit obligations.
Kavera does not make independent billing or diagnostic decisions; the treating clinician retains responsibility for clinical and coding decisions. See Kavera's billing guides for general educational information on how monitoring data can relate to billing documentation.
How We Disclose Information
Kavera discloses information only as necessary to operate the platform, including:
- To the treating provider organization, which is the primary custodian of the patient's health record.
- To subprocessors and service providers (such as hosting and infrastructure vendors) under contracts that include appropriate confidentiality and security obligations, and BAAs where PHI is involved.
- As required by law, such as in response to a valid subpoena, court order, or regulatory request.
- In connection with a business transaction (such as a merger or acquisition), subject to continued protection of the information under materially similar terms.
Kavera does not disclose patient health information for marketing purposes without the applicable authorization required by HIPAA and other applicable law.
Data Security
Kavera applies administrative, technical, and physical safeguards designed to protect the confidentiality, integrity, and availability of health information consistent with the HIPAA Security Rule (opens in a new tab). These safeguards commonly include encryption of data in transit and at rest, access controls limiting data visibility to authorized users, audit logging, and workforce training. No system is completely secure, and Kavera will notify affected provider organizations in the event of a breach affecting PHI, consistent with HIPAA's breach notification requirements and the terms of the applicable BAA.
Further detail on Kavera's security program is available on the Security page.
Patient Rights
Patients whose information is processed through Kavera on behalf of their treating provider generally exercise their privacy rights — including rights to access, amend, or request an accounting of disclosures of their health information — through their treating provider, who remains the HIPAA-covered entity responsible for the patient's medical record. Patients with questions about their data should contact their treating clinician's office first. Kavera supports provider organizations in fulfilling these requests as required under the applicable BAA.
Residents of certain states may have additional rights under state consumer privacy or health data laws (for example, laws addressing consumer health data outside traditional HIPAA coverage). Provider organizations and patients with state-specific privacy questions should contact jma@nybrainspine.com.
Data Retention
Kavera retains assessment data and related records for the period necessary to support the clinical and billing documentation purposes described above, consistent with the retention terms set out in the applicable services agreement and BAA, and applicable medical recordkeeping requirements. Retention periods may vary by data type and by contractual terms with each provider organization.
Children's Information
Kavera's assessment instruments may be used with pediatric patients when assigned by a treating clinician as part of that patient's care. Kavera collects pediatric information only through and at the direction of the treating provider, not directly from minors outside a clinical relationship.
Changes to This Policy
Kavera may update this Privacy Policy from time to time. Material changes will be communicated to provider organizations consistent with the terms of the applicable services agreement. The "Last updated" date at the top of this page reflects the most recent revision.
Contact Us
Questions about this Privacy Policy, or requests related to data handling, can be directed to jma@nybrainspine.com or through the Contact page.
How Kavera Handles This
Privacy and data governance are built into how Kavera structures its assessment delivery, scoring, and documentation workflow: patient-reported data collected through the 14-instrument battery flows to the treating provider's care team, is organized by module (Concussion, Mental Health, Cognitive Health, Headache), and — on the Managed plan — is handled with Kavera staff assistance under the scope defined by each practice's BAA and services agreement. Provider organizations evaluating Kavera can review the Security page and the Platform overview for more detail on how data moves through the system, and can compare Kavera's approach against other monitoring approaches on the Compare pages.
Frequently Asked Questions
Is Kavera a HIPAA business associate?
Yes, in most configurations. Where Kavera processes protected health information on behalf of a covered healthcare provider, Kavera generally enters into a Business Associate Agreement with that provider consistent with HIPAA requirements. Specific terms are set out in each provider's BAA.
Does Kavera sell patient data?
No. Kavera does not sell patient health information, and does not use patient-reported assessment responses for advertising purposes.
Who owns the assessment data collected through Kavera?
The treating provider organization is the primary custodian of the patient's health record. Kavera processes and stores assessment data on the provider's behalf under the terms of the applicable services agreement and BAA.
How do patients request access to their own data?
Patients should contact their treating provider's office directly, since the provider remains the HIPAA-covered entity responsible for the medical record. Kavera supports providers in fulfilling patient access requests as required under the applicable BAA.
Where can I find Kavera's security practices?
General information on Kavera's security safeguards is available on the Security page. Provider-specific security documentation (such as SOC 2 reports, if applicable) is available under NDA on request.
See this on your own patient population
One field. 30 minutes. Live demo with a clinician.