Skip to main content
Platform Review
PricingSign in
← All platforms
Workflow & Automation · beaconhealth.ai

Beacon Health

Graded against 811 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.

Overall riskLOWReviewed 2026-07-19
Creator: low · GRC: low · Counsel: low
Benchmark

No lens is bandable yet — banding requires fully verified documents with on-criteria findings. The gap is shown honestly, never estimated.

14 verified findings6 policy surfaces2/2 core docs verified
Risk triage

Watch: Data retention

Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.

0
high
1
medium
2
low
2/2
docs
Trains on your data?
Not yet assessed
no verified finding covers this surface yet
Who owns outputs?
Not yet assessed
no verified finding covers this surface yet
Commercial use?
Not yet assessed
no verified finding covers this surface yet
Every rating:verbatim-citedsnapshot-datedchange-loggedHow we keep ratings honest →

How to read this page: Overall risk rates what Beacon Health's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.

Fully verifiedWorkflow & Automation

Fully verified — complete core corpus captured and read in full.

Document status
  • Terms of Service
    Verified - read in full - 3 citationsLast captured 2026-07-19
  • Privacy Policy
    Verified - read in full - 11 citationsLast captured 2026-07-19
Tier conditions

Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.

plan language
Privacy & data use

This segment defines the categories of information collected — account information, protected health information, usage data, and communication data — establishing the scope of personal and clinical data subject to the policy's obligations.

" We may collect the following categories of information: Account Information: Name, email address, organization affiliation, role, and login credentials. Protected Health Information (PHI): Patient demographics, clinical data, care gap re..."
📍 § 2 (Information We Collect)Jump to exact text →
plan language
Privacy & data use

This segment obligates the company to act as a Business Associate when processing PHI on behalf of healthcare organizations, to maintain administrative, physical, and technical safeguards in accordance with a named regulatory framework, and to detail PHI obligations in a Business Associate Agreement executed with each covered entity — establishing compliance and contractual obligations around sensitive health data.

" When we process PHI on behalf of healthcare organizations, we do so as a Business Associate under the Health Insurance Portability and Accountability Act (HIPAA). We maintain administrative, physical, and technical safeguards to protect PH..."
📍 § 4 (HIPAA Compliance)Jump to exact text →
plan language
Subprocessors & data sharing

This segment restricts the company from selling personal information (user-favorable prohibition), and specifies the limited circumstances under which information may be shared: with the subscribing organization for service delivery, with third-party service providers subject to confidentiality obligations and BAAs where PHI is involved, when required by law or legal process, and for safety and security purposes — establishing both protective restrictions and conditional sharing permissions.

" We do not sell your personal information. We may share information in the following circumstances: With your organization: We share platform usage and operational data with the subscribing healthcare organization as needed to deliver the ..."
📍 § 5 (Information Sharing)Jump to exact text →

Evidence appendix

Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.

High - 0
Medium - 1
Tier-specific - 0
Total citations - 14
Severity
Surface
Document
Tier
Data retention
High
" We retain information for as long as necessary to provide the Services and fulfill the purposes described in this Privacy Policy, unless a longer retention period is required by law or by the terms of a BAA. When data is no longer needed, we securely delete or de-identify it."
§ 7 (Data Retention)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

This segment obligates the company to retain information only as long as necessary to provide the Services and fulfill stated purposes, unless a longer period is required by law or BAA, and to securely delete or de-identify data when it is no longer needed — establishing both a retention standard and a deletion obligation.

AI-generated interpretation, not legal advice.

Subprocessors & data sharing
High
" We do not sell your personal information. We may share information in the following circumstances: With your organization: We share platform usage and operational data with the subscribing healthcare organization as needed to deliver the Services. Service providers: We engage trusted third-party vendors who assist in operating our Services, subject to confidentiality obligations and, where PHI is involved, Business Associate Agreements. Legal requirements: We may disclose information when required by law, regulation, or legal process. Safety and security: We may share information to protect the rights, property, or safety of Beacon Health, our users, or the public."
§ 5 (Information Sharing)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

This segment restricts the company from selling personal information (user-favorable prohibition), and specifies the limited circumstances under which information may be shared: with the subscribing organization for service delivery, with third-party service providers subject to confidentiality obligations and BAAs where PHI is involved, when required by law or legal process, and for safety and security purposes — establishing both protective restrictions and conditional sharing permissions.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" We use essential cookies to operate the Services and may use analytics tools to understand how the platform is used. We do not use advertising cookies or trackers. You can manage cookie preferences through your browser settings."
§ 9 (Cookies and Tracking)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

This segment restricts the company's cookie use to essential and analytics purposes, explicitly prohibiting the use of advertising cookies or trackers (user-favorable restriction), and grants users the right to manage cookie preferences through browser settings.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" The Services are not intended for use by individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected information from a child, we will take steps to delete it promptly."
§ 10 (Children's Privacy)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

This segment restricts the Services from being used by individuals under 18, prohibits knowing collection of personal information from children (user-favorable restriction), and obligates the company to delete any such information if discovered — protecting minors' data.

AI-generated interpretation, not legal advice.

Moderation & enforcement
High
" You may use the Services only for lawful purposes and in accordance with these Terms. You agree not to: Use the Services in violation of any applicable law or regulation, including HIPAA Attempt to gain unauthorized access to any part of the Services or related systems Interfere with or disrupt the integrity or performance of the Services"
§ 4 (Permitted Use)Jump to exact text →
Source: Terms of Service- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Prohibits reverse-engineering, decompiling, or disassembling any aspect of the Services, extending the permitted-use restrictions from the preceding segment.

AI-generated interpretation, not legal advice.

Confidentiality
High
" To use our Services, you must be at least 18 years old and authorized by a subscribing healthcare organization. You are responsible for maintaining the confidentiality of your account credentials and for all activities that occur under your account. You agree to notify Beacon Health immediately of any unauthorized use."
§ 3 (Eligibility and Accounts)Jump to exact text →
Source: Terms of Service- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Imposes obligations on the user: they must be at least 18 years old and authorized by a subscribing organization, must maintain confidentiality of account credentials, are responsible for all activities under their account, and must notify Beacon Health immediately of any unauthorized use.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Beacon Health ("we," "our," or "us") is committed to protecting the privacy and security of the information we collect and process. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our platform and services ("Services")."
§ 1 (Introduction)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

This segment introduces the company's commitment to protecting privacy and security and defines the scope of the Privacy Policy as governing how information is collected, used, disclosed, and safeguarded when using the Services — establishing the foundational obligation and framing for downstream data-use provisions.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" We may collect the following categories of information: Account Information: Name, email address, organization affiliation, role, and login credentials. Protected Health Information (PHI): Patient demographics, clinical data, care gap records, and other healthcare information processed on behalf of your organization under a Business Associate Agreement. Usage Data: Log data, device information, browser type, pages visited, feature usage patterns, and interaction timestamps. Communication Data: Information you provide when contacting us for support or inquiries."
§ 2 (Information We Collect)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

This segment defines the categories of information collected — account information, protected health information, usage data, and communication data — establishing the scope of personal and clinical data subject to the policy's obligations.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" When we process PHI on behalf of healthcare organizations, we do so as a Business Associate under the Health Insurance Portability and Accountability Act (HIPAA). We maintain administrative, physical, and technical safeguards to protect PHI in accordance with the HIPAA Security Rule. Our obligations regarding PHI are detailed in the Business Associate Agreement (BAA) executed with each covered entity."
§ 4 (HIPAA Compliance)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

This segment obligates the company to act as a Business Associate when processing PHI on behalf of healthcare organizations, to maintain administrative, physical, and technical safeguards in accordance with a named regulatory framework, and to detail PHI obligations in a Business Associate Agreement executed with each covered entity — establishing compliance and contractual obligations around sensitive health data.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Depending on your jurisdiction, you may have the right to:"
§ 8 (Your Rights)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

This segment introduces jurisdiction-dependent individual rights regarding personal information, framing the conditional availability of those rights to users depending on their location.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" For PHI-related requests, please contact your healthcare organization directly, as they are the covered entity responsible for responding to individual rights requests under HIPAA."
Privacy Policy › “Receive a copy of your data in a portable format”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

This segment establishes a procedural routing rule directing users with PHI-related rights requests to contact their healthcare organization directly, because the covered entity — not the company — is responsible for responding to individual rights requests concerning PHI.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" We may update this Privacy Policy periodically. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. We encourage you to review this policy regularly."
§ 11 (Changes to This Policy)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

This segment establishes the procedure by which the company may update the Privacy Policy — by posting the updated policy and updating the date — and notifying users of material changes, while encouraging regular review.

AI-generated interpretation, not legal advice.

Moderation & enforcement
High
" We implement industry-standard security measures to protect your information, including encryption in transit and at rest, access controls, audit logging, and regular security assessments. While we strive to protect your information, no electronic transmission or storage method is completely secure. We encourage you to use strong passwords and report any suspected security issues promptly."
§ 6 (Data Security)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

This segment obligates the company to implement industry-standard security measures including encryption, access controls, audit logging, and regular assessments, while also issuing a disclaimer that no transmission or storage method is completely secure, and placing an obligation on users to use strong passwords and report security issues.

AI-generated interpretation, not legal advice.

Indemnity & liability
High
" By accessing or using the Beacon Health platform and services ("Services"), you agree to be bound by these Terms of Service ("Terms"). If you do not agree to these Terms, do not use our Services. These Terms apply to all users, including healthcare organizations, administrators, and authorized personnel."
§ 1 (Acceptance of Terms)Jump to exact text →
Source: Terms of Service- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Establishes the condition of acceptance: by accessing or using the Services the user agrees to be bound by these Terms, imposes an obligation on all users including healthcare organizations and personnel to comply, and conditions access on agreement.

AI-generated interpretation, not legal advice.

Clause detail — protections, your obligations, and coverage

Every clause below is a verbatim quote from Beacon Health's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.

✅ Protections found

0 verified clauses

Clauses in Beacon Health's policies that work in your favour — commitments the platform made to you.

No protective clause has been verified in Beacon Health's published policies yet. That means we did not find one in the documents we read — not that the platform offers nothing.

📋 Rules you must follow

0 verified clauses

What Beacon Health requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.

No user-conduct rule has been verified in Beacon Health's published policies yet.

What the policies actually cover

0 topics

None of Beacon Health's verified clauses has been assigned a topic yet. The clause-trust review has not reached this platform's findings.

Clause intelligence

Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.

14
clauses
2
patterns
2
stances
data retention · 1privacy sharing · 1
data retentionMEDIUM§ 7 (Data Retention)

The clause allows indefinite, perpetual, or necessity-based retention.

We retain information for as long as necessary to provide the Services and fulfill the purposes described in this Privacy Policy, unless a longer retention period is required by law or by the terms of a BAA. When data is no longer needed, we securely delete or de-identify it.
Open source citation
privacy sharingHIGH§ 5 (Information Sharing)

The clause permits sale of personal data or information.

We do not sell your personal information. We may share information in the following circumstances: With your organization: We share platform usage and operational data with the subscribing healthcare organization as needed to deliver the Services. Service providers: We engage trusted third-party vendors who assist in operating our Services, subject to confidentiality obligations and, where PHI is involved, Busines...
Open source citation

Tier matrix

Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.

TierSurfaceVerdictRiskCitations
All applicable tiersdata retentionconditionalMEDIUM1
Team / Businesssubprocessors data sharingworsensHIGH1

Policy evolution

Open full timeline

Before/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.

Jul 19, 2026data sharingHIGH

Latest stance: sale or sell on subprocessors data sharing

We do not sell your personal information. We may share information in the following circumstances: With your organization: We share platform usage and operational data with the subscribing healthcare organization as needed to deliver the Services. Service providers: We engage trusted third-party vendors who assist in operating our Services, subject to confidentiality obligations and, where PHI is involved, Business Associate Agreements. Legal requirements: We may disclose information when required by law, regulation, or legal process. Safety and security: We may share information to protect the rights, property, or safety of Beacon Health, our users, or the public.
Open timeline citation
Jul 19, 2026retentionMEDIUM

Latest stance: indefinite or necessity based on data retention

We retain information for as long as necessary to provide the Services and fulfill the purposes described in this Privacy Policy, unless a longer retention period is required by law or by the terms of a BAA. When data is no longer needed, we securely delete or de-identify it.
Open timeline citation

Capture recency

  • Terms of Service:Last captured 2026-07-19· verified 2026-07-19verified once — not yet re-verified
  • Privacy Policy:Last captured 2026-07-19· verified 2026-07-19verified once — not yet re-verified

Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.

14 findings first captured First scan: July 2026.

Claim this profile

Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Beacon Health's policies — no human edits the data.

Need this for procurement or legal diligence?

Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.

Every finding above is a verbatim quote from Beacon Health's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.