Effective date: September 7, 2026 (previous version effective June 16, 2026)
Hero EMR LLC, a Delaware limited liability company doing business as Hero EMR ("Hero EMR," "we," "us," or "our"), is committed to protecting the privacy of our users. This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you visit our website at heroemr.com (the "Site") and use our electronic medical records platform (the "Service").
Hero EMR LLC was formerly named Soaper LLC. The name changed on May 14, 2026. It is the same legal entity, with the same Delaware file number and the same taxpayer identification number.
An important distinction about health information. Our customers are healthcare practices acting as HIPAA covered entities. When we handle patient health information, we do so as their business associate, on their documented instructions, under an executed Business Associate Agreement. If you are a patient of a practice that uses Hero EMR, that practice's own Notice of Privacy Practices governs your health information, not this policy. This policy governs the information we collect in our own right — from visitors to our Site, from practice staff who use the Service, and from people who contact us.
By accessing or using our Site or Service, you agree to the terms of this Privacy Policy. If you do not agree, please do not use the Site or Service.
We use the information we collect for the following purposes:
Hero EMR is designed to be used by healthcare providers as an electronic medical records system. When our Service is used to store, process, or transmit Protected Health Information (PHI), we do so in compliance with the Health Insurance Portability and Accountability Act (HIPAA) and the Health Information Technology for Economic and Clinical Health (HITECH) Act.
This Privacy Policy governs the information collected through our marketing Site. The handling of PHI within the Service is governed by our BAA and applicable HIPAA regulations.
We use the following types of cookies:
You can control cookies through your browser settings. Disabling certain cookies may affect the functionality of the Site.
We may share information with third-party service providers who assist us in operating the Site and Service, including:
These providers are contractually obligated to protect your information and may only use it for the purposes we specify.
If you connect a Google Calendar account to Hero EMR, we request access only so the Service can provide calendar synchronization features that you enable. This may include reading calendar metadata and events, creating or updating events that correspond to appointments, detecting conflicts, and maintaining synchronization state between Hero EMR and your connected calendar.
We do not sell Google user data. We do not use Google Calendar data for advertising, marketing, or generalized AI model training. We do not share Google Calendar data with third parties except as necessary to provide the calendar synchronization feature, comply with law, protect security, or as otherwise directed by you or your organization.
Google OAuth tokens are stored securely and used only to operate the connected calendar integration. You can disconnect your Google Calendar account in the Service, which revokes future synchronization and removes the stored connection credentials from Hero EMR. Calendar-derived records may also be retained where required for security, auditability, HIPAA, contractual obligations, or legal compliance.
Hero EMR's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We retain information for the periods set out below. Where information falls into more than one category, the longer period applies. These periods reflect our contractual commitments to customer practices and the requirements of medical-records and health-privacy law.
| Category | Retention period |
|---|---|
| Patient records and other practice data ("Client Data") held on behalf of a customer practice | Retained for the life of the practice's agreement with us, then 90 days after termination to allow migration, after which it is securely deleted from our active production systems. We provide written certification of deletion on request. A complete export is available on request during the agreement and for 10 business days after it ends. |
| Chart and record access logs; staff login and authentication logs; encounter, prescription, laboratory and referral event logs — the six audit-log families we are contractually required to keep | At least 7 years (2,555 days) from the event. These logs are the record of who accessed which patient record and when. They are retained even after a practice's data is deleted, because both the practice and we may need them. |
| Login and authentication audit records | 2,555 days, moved to archival storage after 30 days. |
| Provider webhook event logs | 180 days. |
| Application and server logs | 14 days. |
| Backups, snapshots and disaster-recovery copies | Database backups with point-in-time recovery are retained for 7 days; scheduled snapshots on a 7 daily and 1 monthly cycle. Deleted information may persist in these copies until they expire on their ordinary schedule. |
| Risk, policy, security and compliance records | 6 years, as required by the HIPAA Security Rule at 45 CFR § 164.316(b)(2). |
| Site visitor, prospect and marketing contact information | Retained while the relationship is active and for 24 months after your last interaction with us, unless you ask us to delete it sooner. |
| Payment information | We store payment method tokens and transaction references only. We never store full card numbers anywhere in our systems; card details are handled directly by our payment processors. |
Copies in backups and archives. Where information has been deleted from our active systems, copies may remain in backups, archives, audit records, records subject to a legal hold, and disaster-recovery copies. Those copies stay protected by the same security and confidentiality obligations, are not returned to active use, and are deleted or overwritten as the applicable retention cycle runs.
Legal holds. A legal hold suspends deletion of the identified information until the hold is released.
We implement industry-standard security measures to protect your information, including:
While we strive to protect your information, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.
Depending on your jurisdiction, you may have the following rights regarding your personal information:
To exercise any of these rights, please contact us using the information in Section 13.
Most of the information we handle is exempt from the CCPA. Medical information governed by HIPAA, and protected health information held by a HIPAA business associate, are exempt from the California Consumer Privacy Act under California Civil Code § 1798.145(c). The overwhelming majority of the personal information Hero EMR processes is protected health information that we hold on behalf of covered-entity practices, and it falls within that exemption.
Where the exemption does not apply, these rights do. Information we collect in our own right — from Site visitors, from people who request a demo or contact us, and from practice staff who use the Service — is not protected health information. If you are a California resident, in relation to that information you may:
We do not sell or share your personal information. Hero EMR does not sell personal information, and does not share it for cross-context behavioral advertising, as those terms are defined by the CCPA. We have not done so in the preceding twelve months.
Our role. Where we process personal information on behalf of a customer practice, we act as that practice's service provider and business associate. We use that information only to perform the services, only on the practice's documented instructions, and never for our own purposes. If you are a patient of a practice that uses Hero EMR, direct your request to that practice; if you send it to us, we will forward it to them.
Making a request. Use the contact details in Section 13. We will verify your identity before acting on a request, and we will respond within the timeframes the law requires. You may use an authorized agent, and we will ask for proof of their authority.
Other US states. Where another state's privacy law gives you comparable rights over information that is not exempt health information, we will honor those rights on the same basis.
Our Site and our marketing are not directed to children, and we do not knowingly collect personal information from children through them.
The Service is different. Customer practices provide care to patients of all ages, including minors, and their records — including minors' records — are processed through the Service on the practice's behalf. Access to a minor's record is controlled by the practice and, where the practice configures one, by a parent or guardian relationship in the patient portal. Consent, guardianship and access decisions for a minor's health information are made by the practice as the covered entity, in accordance with applicable law, not by Hero EMR.
We may update this Privacy Policy from time to time. When we make changes, we will revise the "Effective date" at the top of this page. We encourage you to review this policy periodically. Your continued use of the Site or Service after changes are posted constitutes your acceptance of the updated policy.
If you have questions or concerns about this Privacy Policy or our data practices, or if you wish to exercise a privacy right, please contact us:
Hero EMR LLC
Attention: Privacy Officer
8 The Green, Suite D
Dover, DE 19901
United States
Email: privacy@heroemr.com
Website: heroemr.com
Our Privacy Officer is Ling Zhou, MD, who also serves as our Security Officer.
If you are a patient of a practice that uses Hero EMR, please contact that practice first. They are the covered entity responsible for your health information, and they hold the Notice of Privacy Practices that applies to you. If you contact us directly, we will forward your request to them and will not respond substantively without their direction.