Skip to main content
Platform Review
PricingSign in
← All platforms
Workflow & Automation · dimehealth.ai

Dime

Graded against 809 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.

Overall riskLOWReviewed 2026-07-20
Creator: low · GRC: low · Counsel: low
Benchmark

No lens is bandable yet — banding requires fully verified documents with on-criteria findings. The gap is shown honestly, never estimated.

10 verified findings4 policy surfaces1/1 core docs verified

Partially verified: Privacy Policy assessed. Everything below comes only from what was read in full.

Risk triage

Watch: Data retention

Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.

0
high
1
medium
2
low
1/1
docs
Trains on your data?
Not yet assessed
no verified finding covers this surface yet
Who owns outputs?
Not yet assessed
no verified finding covers this surface yet
Commercial use?
Not yet assessed
no verified finding covers this surface yet
Every rating:verbatim-citedsnapshot-datedchange-loggedHow we keep ratings honest →

How to read this page: Overall risk rates what Dime's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.

Partially verifiedWorkflow & Automation

Partially verified — Privacy Policy — Verified (read in full, 10 findings). Findings below are from fully-read, verified documents only; remaining core documents are pending capture.

Why partial?

Terms not yet captured

AIRIN has not yet captured a gate-verified Terms of Service document for this platform.

Document status
  • Privacy Policy
    Verified - read in full - 10 citationsstaticLast captured 2026-07-20
Tier conditions

Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.

plan language
Privacy & data use

Defines the scope of the Privacy Policy by specifying what information it covers, to whom it applies, and that it includes PHI processed under a Business Associate Agreement, establishing the operative boundaries of the document.

"This Privacy Policy explains how we collect, use, disclose, and protect information when healthcare providers and their patients use our platform and related services. It applies to all data handled by us as part of our services, including ..."
📍 § 2 (Scope)Jump to exact text →
plan language
Subprocessors & data sharing

Establishes obligations as a Business Associate, requiring PHI to be used only as permitted to perform contracted services, implementing safeguards against unauthorized use or disclosure, reporting breaches, and ensuring subcontractors agree to similar restrictions — all user-favorable protective obligations.

"As a Business Associate under HIPAA, we enter into Business Associate Agreements with our healthcare clients ("Covered Entities") to ensure all handling of PHI is fully compliant.Under the BAA, we:Use PHI only as permitted or required to pe..."
📍 § 3 (Compliance and Business Associate Agreements (BAA))Jump to exact text →

Evidence appendix

Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.

High - 0
Medium - 1
Tier-specific - 0
Total citations - 10
Severity
Surface
Document
Tier
Data retention
High
"We retain PHI only for as long as necessary to fulfill our service obligations or as required by law or contract. Upon termination of a client agreement or upon request, PHI is securely deleted or returned in accordance with the BAA."
§ 8 (Data Retention and Deletion)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Establishes that PHI is retained only as long as necessary to fulfill service obligations or as required by law or contract, and that upon termination or request PHI is securely deleted or returned in accordance with the BAA — user-favorable retention and deletion obligation.

AI-generated interpretation, not legal advice.

Privacy & data use
High
"We use PHI and related data solely for operational and service delivery purposes, including:Automating document delivery and matching with EMR systems.Conducting authorized patient communications (e.g., appointment reminders, phone calls).Providing technical support and ensuring platform performance.Maintaining security, auditing, and compliance records.We do not use or disclose PHI for marketing, profiling, or unrelated purposes."
§ 5 (How We Use Information)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Restricts use of PHI and related data solely to operational and service delivery purposes enumerated in the clause, and expressly prohibits use or disclosure of PHI for marketing, profiling, or unrelated purposes — user-favorable restriction.

AI-generated interpretation, not legal advice.

Subprocessors & data sharing
High
"We may share information only as follows: With Covered Entities: To perform contracted services under the BAA. With Subcontractors (if any): Only under written agreements requiring HIPAA compliance. As Required by Law: When responding to lawful requests from authorities or regulatory agencies. We never sell, rent, or trade PHI or personal data to third parties."
§ 6 (Information Sharing and Disclosure)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Limits permissible information sharing to three enumerated circumstances (covered entities under BAA, subcontractors under written HIPAA-compliant agreements, and lawful legal requests), and expressly prohibits selling, renting, or trading PHI or personal data to third parties — user-favorable restriction.

AI-generated interpretation, not legal advice.

Privacy & data use
High
"‍ Dime Health AI ("we," "us," or "our") provides healthcare automation solutions that enable providers, clinics, and healthcare organizations to streamline workflows, integrate with Electronic Medical Record (EMR) systems, and communicate securely with patients.We are committed to protecting the privacy and security of Protected Health Information ("PHI") and other personal data in accordance with the Health Insurance Portability and Accountability Act of 1996 ("HIPAA") and other applicable laws."
§ 1 (Introduction)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Defines the entity, describes its healthcare automation services, and states a commitment to protecting the privacy and security of Protected Health Information and other personal data in accordance with applicable law, establishing a foundational compliance obligation.

AI-generated interpretation, not legal advice.

Privacy & data use
High
"This Privacy Policy explains how we collect, use, disclose, and protect information when healthcare providers and their patients use our platform and related services. It applies to all data handled by us as part of our services, including PHI processed under a Business Associate Agreement (BAA)."
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Defines the scope of the Privacy Policy by specifying what information it covers, to whom it applies, and that it includes PHI processed under a Business Associate Agreement, establishing the operative boundaries of the document.

AI-generated interpretation, not legal advice.

Privacy & data use
High
"We collect and process the following categories of information:a. Patient Data (PHI)Patient names, contact details, and demographic data.Medical record identifiers and visit information.Health-related documents and data transmitted from EMR or EHR systems.Communication records related to scheduling, reminders, or follow-ups.b. Client and User DataAccount registration information (name, email, organization).Platform usage logs, device information, and system activity for security and support.c. Automatically Collected InformationWe may collect limited metadata (e.g., access times, IP addresses, browser type) for security, analytics, and service improvement — never for advertising or resale."
§ 4 (Information)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Enumerates the categories of information collected and processed, including patient PHI, client and user account data, and automatically collected metadata, defining the scope of data collection practices.

AI-generated interpretation, not legal advice.

Privacy & data use
High
"We use administrative, physical, and technical safeguards consistent with HIPAA Security Rule standards, including:Encryption of PHI in transit and at rest.Access controls and audit logging.Regular security assessments and vulnerability management.Role-based access and employee training on data protection."
§ 6 (Information Sharing and Disclosure)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Imposes an obligation to implement administrative, physical, and technical safeguards for PHI, specifying encryption, access controls, audit logging, security assessments, role-based access, and employee training as protective measures.

AI-generated interpretation, not legal advice.

Privacy & data use
High
"We may update this Privacy Policy periodically. Any changes will be posted on our website with an updated effective date. Continued use of our platform after changes indicates acceptance of the revised policy."
§ 10 (Changes to This Privacy Policy)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Establishes the procedure for updating the Privacy Policy, requiring changes to be posted on the website with an updated effective date, and deems continued use of the platform after changes as acceptance of the revised policy.

AI-generated interpretation, not legal advice.

Subprocessors & data sharing
High
"As a Business Associate under HIPAA, we enter into Business Associate Agreements with our healthcare clients ("Covered Entities") to ensure all handling of PHI is fully compliant.Under the BAA, we:Use PHI only as permitted or required to perform our contracted services.Implement safeguards to protect PHI against unauthorized use or disclosure.Report any breaches of unsecured PHI as required by law.Ensure our subcontractors agree to similar restrictions and protections."
§ 3 (Compliance and Business Associate Agreements (BAA))Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Establishes obligations as a Business Associate, requiring PHI to be used only as permitted to perform contracted services, implementing safeguards against unauthorized use or disclosure, reporting breaches, and ensuring subcontractors agree to similar restrictions — all user-favorable protective obligations.

AI-generated interpretation, not legal advice.

Audit rights / DPA / residency
High
"All patient rights regarding access, correction, or restriction of their PHI are governed by their healthcare provider (the Covered Entity). Patients seeking to exercise such rights should contact their provider directly."
§ 9 (Patient Rights)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Specifies that patient rights regarding access, correction, or restriction of PHI are governed by the healthcare provider as Covered Entity, and directs patients to contact their provider to exercise such rights, establishing a procedural channel for rights exercise.

AI-generated interpretation, not legal advice.

Clause detail — protections, your obligations, and coverage

Every clause below is a verbatim quote from Dime's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.

✅ Protections found

0 verified clauses

Clauses in Dime's policies that work in your favour — commitments the platform made to you.

No protective clause has been verified in Dime's published policies yet. That means we did not find one in the documents we read — not that the platform offers nothing.

📋 Rules you must follow

0 verified clauses

What Dime requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.

No user-conduct rule has been verified in Dime's published policies yet.

What the policies actually cover

0 topics

None of Dime's verified clauses has been assigned a topic yet. The clause-trust review has not reached this platform's findings.

Clause intelligence

Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.

10
clauses
2
patterns
2
stances
data retention · 1privacy sharing · 1
data retentionMEDIUM§ 8 (Data Retention and Deletion)

The clause allows indefinite, perpetual, or necessity-based retention.

We retain PHI only for as long as necessary to fulfill our service obligations or as required by law or contract. Upon termination of a client agreement or upon request, PHI is securely deleted or returned in accordance with the BAA.
Open source citation
privacy sharingHIGH§ 6 (Information Sharing and Disclosure)

The clause permits sale of personal data or information.

We may share information only as follows: With Covered Entities: To perform contracted services under the BAA. With Subcontractors (if any): Only under written agreements requiring HIPAA compliance. As Required by Law: When responding to lawful requests from authorities or regulatory agencies. We never sell, rent, or trade PHI or personal data to third parties.
Open source citation

Tier matrix

Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.

TierSurfaceVerdictRiskCitations
All applicable tiersdata retentionconditionalMEDIUM1
All applicable tierssubprocessors data sharingworsensHIGH1

Policy evolution

Open full timeline

Before/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.

Jul 20, 2026data sharingHIGH

Latest stance: sale or sell on subprocessors data sharing

We may share information only as follows: With Covered Entities: To perform contracted services under the BAA. With Subcontractors (if any): Only under written agreements requiring HIPAA compliance. As Required by Law: When responding to lawful requests from authorities or regulatory agencies. We never sell, rent, or trade PHI or personal data to third parties.
Open timeline citation
Jul 20, 2026retentionMEDIUM

Latest stance: indefinite or necessity based on data retention

We retain PHI only for as long as necessary to fulfill our service obligations or as required by law or contract. Upon termination of a client agreement or upon request, PHI is securely deleted or returned in accordance with the BAA.
Open timeline citation

Capture recency

  • Privacy Policy:Last captured 2026-07-20· verified 2026-07-20verified once — not yet re-verified

Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.

10 findings first captured First scan: July 2026.

Claim this profile

Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Dime's policies — no human edits the data.

Need this for procurement or legal diligence?

Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.

Know where the missing document lives?

We haven't yet verified Dime's Terms of Service. Point us at the official page and our pipeline will attempt to capture and read it in full. Submissions are candidates only — nothing is published until it passes the same verification gates as every other document on this site.

Every finding above is a verbatim quote from Dime's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.