Hero EMR Logo Hero EMR
  • Front Office
  • Back Office
  • Superpowers
  • Free Tools
    Free Tool Library
    Now liveEZ-FMLAMedical form prep for patients and physicians.
    Coming soonDo I Qualify For a GLP-1Future eligibility screener and intake workflow.
  • Mobile
  • Pricing
  • $200k
Schedule Demo

Privacy Policy

Effective date: September 7, 2026 (previous version effective June 16, 2026)

1. Introduction

Hero EMR LLC, a Delaware limited liability company doing business as Hero EMR ("Hero EMR," "we," "us," or "our"), is committed to protecting the privacy of our users. This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you visit our website at heroemr.com (the "Site") and use our electronic medical records platform (the "Service").

Hero EMR LLC was formerly named Soaper LLC. The name changed on May 14, 2026. It is the same legal entity, with the same Delaware file number and the same taxpayer identification number.

An important distinction about health information. Our customers are healthcare practices acting as HIPAA covered entities. When we handle patient health information, we do so as their business associate, on their documented instructions, under an executed Business Associate Agreement. If you are a patient of a practice that uses Hero EMR, that practice's own Notice of Privacy Practices governs your health information, not this policy. This policy governs the information we collect in our own right — from visitors to our Site, from practice staff who use the Service, and from people who contact us.

By accessing or using our Site or Service, you agree to the terms of this Privacy Policy. If you do not agree, please do not use the Site or Service.

2. Information We Collect

Information You Provide

  • Account & Contact Information: Name, email address, phone number, practice name, and professional credentials when you register, request a demo, or contact us.
  • Billing Information: Payment details processed through our third-party payment processor. We do not store full credit card numbers on our servers.
  • Communications: Any messages, feedback, or support requests you send to us.

Information Collected Automatically

  • Usage Data: Pages visited, features used, clickstream data, and interaction patterns within the Service.
  • Device & Browser Information: IP address, browser type and version, operating system, device type, and screen resolution.
  • Cookies & Similar Technologies: We use cookies, web beacons, and similar tracking technologies to enhance your experience and analyze site traffic. See Section 5 for details.
  • Referral Data: If you arrive via a referral link, we may record the referral source for analytics purposes.

3. How We Use Your Information

We use the information we collect for the following purposes:

  • To provide, operate, and maintain the Service
  • To process demo requests and communicate with you about our products
  • To improve, personalize, and optimize the Site and Service
  • To analyze usage trends and measure the effectiveness of our marketing
  • To send you product updates, newsletters, or marketing communications (you may opt out at any time)
  • To detect, prevent, and address technical issues or security threats
  • To comply with legal obligations

4. Protected Health Information (PHI) & HIPAA

Hero EMR is designed to be used by healthcare providers as an electronic medical records system. When our Service is used to store, process, or transmit Protected Health Information (PHI), we do so in compliance with the Health Insurance Portability and Accountability Act (HIPAA) and the Health Information Technology for Economic and Clinical Health (HITECH) Act.

  • We enter into Business Associate Agreements (BAAs) with our covered entity customers as required by HIPAA.
  • PHI is encrypted in transit and at rest using industry-standard encryption protocols.
  • Access to PHI is restricted to authorized personnel and governed by role-based access controls.
  • We maintain administrative, physical, and technical safeguards as required by the HIPAA Security Rule.

This Privacy Policy governs the information collected through our marketing Site. The handling of PHI within the Service is governed by our BAA and applicable HIPAA regulations.

5. Cookies & Tracking Technologies

We use the following types of cookies:

  • Essential Cookies: Required for the Site to function properly (e.g., session management, cookie consent preferences).
  • Analytics Cookies: Help us understand how visitors interact with the Site by collecting usage data in aggregate form.
  • Functional Cookies: Remember your preferences and settings to provide a more personalized experience.

You can control cookies through your browser settings. Disabling certain cookies may affect the functionality of the Site.

6. Third-Party Services

We may share information with third-party service providers who assist us in operating the Site and Service, including:

  • Hosting & Infrastructure: Cloud hosting providers that store and process data on our behalf.
  • Analytics: Services that help us analyze site usage and performance.
  • Payment Processing: Third-party processors that handle billing transactions securely.
  • Communication Tools: Email and messaging platforms used to communicate with users.

These providers are contractually obligated to protect your information and may only use it for the purposes we specify.

7. Third-Party Calendar Integrations and Google User Data

If you connect a Google Calendar account to Hero EMR, we request access only so the Service can provide calendar synchronization features that you enable. This may include reading calendar metadata and events, creating or updating events that correspond to appointments, detecting conflicts, and maintaining synchronization state between Hero EMR and your connected calendar.

We do not sell Google user data. We do not use Google Calendar data for advertising, marketing, or generalized AI model training. We do not share Google Calendar data with third parties except as necessary to provide the calendar synchronization feature, comply with law, protect security, or as otherwise directed by you or your organization.

Google OAuth tokens are stored securely and used only to operate the connected calendar integration. You can disconnect your Google Calendar account in the Service, which revokes future synchronization and removes the stored connection credentials from Hero EMR. Calendar-derived records may also be retained where required for security, auditability, HIPAA, contractual obligations, or legal compliance.

Hero EMR's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

8. Data Retention

We retain information for the periods set out below. Where information falls into more than one category, the longer period applies. These periods reflect our contractual commitments to customer practices and the requirements of medical-records and health-privacy law.

CategoryRetention period
Patient records and other practice data ("Client Data") held on behalf of a customer practiceRetained for the life of the practice's agreement with us, then 90 days after termination to allow migration, after which it is securely deleted from our active production systems. We provide written certification of deletion on request. A complete export is available on request during the agreement and for 10 business days after it ends.
Chart and record access logs; staff login and authentication logs; encounter, prescription, laboratory and referral event logs — the six audit-log families we are contractually required to keepAt least 7 years (2,555 days) from the event. These logs are the record of who accessed which patient record and when. They are retained even after a practice's data is deleted, because both the practice and we may need them.
Login and authentication audit records2,555 days, moved to archival storage after 30 days.
Provider webhook event logs180 days.
Application and server logs14 days.
Backups, snapshots and disaster-recovery copiesDatabase backups with point-in-time recovery are retained for 7 days; scheduled snapshots on a 7 daily and 1 monthly cycle. Deleted information may persist in these copies until they expire on their ordinary schedule.
Risk, policy, security and compliance records6 years, as required by the HIPAA Security Rule at 45 CFR § 164.316(b)(2).
Site visitor, prospect and marketing contact informationRetained while the relationship is active and for 24 months after your last interaction with us, unless you ask us to delete it sooner.
Payment informationWe store payment method tokens and transaction references only. We never store full card numbers anywhere in our systems; card details are handled directly by our payment processors.

Copies in backups and archives. Where information has been deleted from our active systems, copies may remain in backups, archives, audit records, records subject to a legal hold, and disaster-recovery copies. Those copies stay protected by the same security and confidentiality obligations, are not returned to active use, and are deleted or overwritten as the applicable retention cycle runs.

Legal holds. A legal hold suspends deletion of the identified information until the hold is released.

9. Data Security

We implement industry-standard security measures to protect your information, including:

  • TLS/SSL encryption for all data in transit
  • AES-256 encryption for data at rest
  • Regular security audits and vulnerability assessments
  • Access controls and authentication requirements for all personnel

While we strive to protect your information, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.

10. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal information:

  • Access, correct, or delete your personal information
  • Object to or restrict processing of your information
  • Request portability of your data
  • Withdraw consent for marketing communications

To exercise any of these rights, please contact us using the information in Section 13.

10A. California Privacy Rights (CCPA/CPRA)

Most of the information we handle is exempt from the CCPA. Medical information governed by HIPAA, and protected health information held by a HIPAA business associate, are exempt from the California Consumer Privacy Act under California Civil Code § 1798.145(c). The overwhelming majority of the personal information Hero EMR processes is protected health information that we hold on behalf of covered-entity practices, and it falls within that exemption.

Where the exemption does not apply, these rights do. Information we collect in our own right — from Site visitors, from people who request a demo or contact us, and from practice staff who use the Service — is not protected health information. If you are a California resident, in relation to that information you may:

  • know what categories of personal information we have collected about you, the sources, the purposes, and the categories of third parties we disclose it to;
  • access a copy of the specific pieces of personal information we hold about you;
  • correct inaccurate personal information;
  • delete personal information we have collected from you, subject to the exceptions the law allows — including information we must keep to comply with a legal obligation or that is exempt as described above; and
  • be free from discrimination for exercising any of these rights.

We do not sell or share your personal information. Hero EMR does not sell personal information, and does not share it for cross-context behavioral advertising, as those terms are defined by the CCPA. We have not done so in the preceding twelve months.

Our role. Where we process personal information on behalf of a customer practice, we act as that practice's service provider and business associate. We use that information only to perform the services, only on the practice's documented instructions, and never for our own purposes. If you are a patient of a practice that uses Hero EMR, direct your request to that practice; if you send it to us, we will forward it to them.

Making a request. Use the contact details in Section 13. We will verify your identity before acting on a request, and we will respond within the timeframes the law requires. You may use an authorized agent, and we will ask for proof of their authority.

Other US states. Where another state's privacy law gives you comparable rights over information that is not exempt health information, we will honor those rights on the same basis.

11. Children's Privacy

Our Site and our marketing are not directed to children, and we do not knowingly collect personal information from children through them.

The Service is different. Customer practices provide care to patients of all ages, including minors, and their records — including minors' records — are processed through the Service on the practice's behalf. Access to a minor's record is controlled by the practice and, where the practice configures one, by a parent or guardian relationship in the patient portal. Consent, guardianship and access decisions for a minor's health information are made by the practice as the covered entity, in accordance with applicable law, not by Hero EMR.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we make changes, we will revise the "Effective date" at the top of this page. We encourage you to review this policy periodically. Your continued use of the Site or Service after changes are posted constitutes your acceptance of the updated policy.

13. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, or if you wish to exercise a privacy right, please contact us:

Hero EMR LLC
Attention: Privacy Officer
8 The Green, Suite D
Dover, DE 19901
United States
Email: privacy@heroemr.com
Website: heroemr.com

Our Privacy Officer is Ling Zhou, MD, who also serves as our Security Officer.

If you are a patient of a practice that uses Hero EMR, please contact that practice first. They are the covered entity responsible for your health information, and they hold the Notice of Privacy Practices that applies to you. If you contact us directly, we will forward your request to them and will not respond substantively without their direction.

Hero EMR Hero EMR

Built by healthcare professionals who understand the chaos of modern medicine. Giving every provider superpowers.

Product

  • Front Office
  • Back Office
  • Superpowers
  • Free Tools
  • Pricing
  • Request a Demo

Resources

  • Blog & Guides
  • Payer Directory
  • US Provider Data
  • Payer Network Directory
  • Documentation Center
  • Mobile Apps
  • Recommended Hardware
  • Provider Manual
  • Physician Onboarding Resources
  • APCM Billing Automation
  • Dark Mode for EMR
  • Direct Primary Care
  • Paper & Fax to Digital
  • Remote Patient Monitoring
  • Value in the EMR Tech Stack

Specialties

  • Cardiology
  • Dermatology
  • Endocrinology
  • ENT / Otolaryngology
  • Gastroenterology
  • OB/GYN
  • Ophthalmology
  • Orthopedics
  • Pain Medicine
  • Pediatrics
  • PM&R / Rehab
  • Podiatry
  • Psychiatry
  • Pulm / Sleep / Allergy
  • Rheumatology
  • Urology

Company

  • Reviews
  • Support
  • Privacy Policy
  • Terms of Use
CompliantHIPAA
CompliantHITECH

© 2026 Hero EMR. All rights reserved.