Skip to main content
Platform Review
PricingSign in
← All platforms
Workflow & Automation · framewisehealth.com

Framewise Health

Graded against 811 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.

Overall riskLOWReviewed 2026-09-01
Creator: low · GRC: low · Counsel: low
Benchmark

No lens is bandable yet — banding requires fully verified documents with on-criteria findings. The gap is shown honestly, never estimated.

19 verified findings2 policy surfaces2/2 core docs verified
Risk triage

Lower concern: subprocessors data sharing

Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.

0
high
0
medium
1
low
2/2
docs
Trains on your data?
Not yet assessed
no verified finding covers this surface yet
Who owns outputs?
Not yet assessed
no verified finding covers this surface yet
Commercial use?
Not yet assessed
no verified finding covers this surface yet
Every rating:verbatim-citedsnapshot-datedchange-loggedHow we keep ratings honest →

How to read this page: Overall risk rates what Framewise Health's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.

Fully verifiedWorkflow & Automation

Fully verified — complete core corpus captured and read in full.

Document status
  • Privacy Policy
    Verified - read in full - 19 citationsstaticLast captured 2026-07-20
  • Terms of Service
    Verified - read in full - 0 citationsstaticLast captured 2026-09-01
Tier conditions

Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.

plan language
Privacy & data use

Declares that the company operates as a Business Associate when processing Protected Health Information on behalf of Covered Entity customers and commits to maintaining administrative, physical, and technical safeguards to protect PHI, establishing a compliance obligation and framing the protective scope of PHI handling.

" Framewise Health operates as a Business Associate under HIPAA when processing Protected Health Information (PHI) on behalf of our Covered Entity customers. We maintain appropriate administrative, physical, and technical safeguards to prote..."
📍 Privacy Policy › “HIPAA Compliance”Jump to exact text →
plan language
Privacy & data use

Describes implementation of security measures including encryption and secure hosting under a Business Associate Agreement, but then disclaims absolute security by stating no method of electronic transmission or storage is 100% secure — limits liability for security failures.

" We implement industry-standard security measures to protect your information, including encryption, secure hosting on AWS with a signed Business Associate Agreement, and regular security reviews. However, no method of electronic transmissi..."
📍 Privacy Policy › “Data Security”Jump to exact text →
plan language
Subprocessors & data sharing

Requires Business Associate Agreements with all applicable service providers, imposing a contractual obligation that restricts how subprocessors may handle protected data — user-favorable requirement.

" Business Associate Agreements (BAAs) with all applicable service providers"
📍 Privacy Policy › “End-to-end encryption for all data in transit and at rest”Jump to exact text →

Evidence appendix

Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.

High - 0
Medium - 0
Tier-specific - 0
Total citations - 19
Severity
Surface
Document
Tier
Subprocessors & data sharing
High
" We do not sell your personal information. We may share information with:"
Privacy Policy › “Data Sharing”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

States that personal information is not sold, then introduces categories of permitted sharing — establishes a baseline prohibition on sale as user-favorable.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" This website does not collect or process PHI. PHI is handled exclusively within our clinical platform under separate agreements with healthcare provider customers."
Privacy Policy › “Regular security assessments and employee training”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Restricts the website from collecting or processing PHI, and specifies that PHI is handled exclusively within the clinical platform under separate agreements — a user-favorable limitation that prohibits PHI collection through the public website.

AI-generated interpretation, not legal advice.

Subprocessors & data sharing
High
" Mobile opt-in data, consent records, and patient phone numbers will not be shared with any third parties or affiliates for any purpose, including marketing or promotional purposes."
Privacy Policy › “No sale of mobile data”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Prohibits sharing of mobile opt-in data, consent records, and patient phone numbers with any third parties or affiliates for any purpose, expressly including marketing or promotional purposes — user-favorable restriction on data sharing.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Framewise Health, Inc. ("Framewise," "we," "us," or "our") is committed to protecting the privacy and security of your information. This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you visit our website at framewisehealth.com or use our services."
Privacy Policy › “Introduction”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Declares the company's commitment to protecting privacy and security and describes the scope of the policy — collection, use, disclosure, and safeguarding of information — establishing an overarching obligation to handle information in accordance with the described practices.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Contact information (name, email address, phone number) when you book a demo or contact us"
Privacy Policy › “Information you provide to us”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Defines the specific contact data items collected when a user books a demo or contacts the company, establishing the scope of voluntarily provided personal data subject to policy obligations.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Send you information about our products and services (with your consent)"
Privacy Policy › “Provide, maintain, and improve our services”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

States that information is used to send product and service communications conditional on user consent, imposing a consent requirement as a precondition for this processing purpose — user-favorable restriction.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" To exercise these rights, contact us at contact@framewisehealth.com ."
Privacy Policy › “Opt out of marketing communications”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Provides the procedure for users to exercise their stated rights by contacting the organization at a specified email address.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" SMS delivery and engagement metadata (delivered, failed, opted out, link clicks)"
Privacy Policy › “Patient mobile phone number”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Identifies SMS delivery and engagement metadata as data collected through the program, defining behavioral and operational data within the SMS program's processing scope.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Framewise Health operates as a Business Associate under HIPAA when processing Protected Health Information (PHI) on behalf of our Covered Entity customers. We maintain appropriate administrative, physical, and technical safeguards to protect PHI, including:"
Privacy Policy › “HIPAA Compliance”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Declares that the company operates as a Business Associate when processing Protected Health Information on behalf of Covered Entity customers and commits to maintaining administrative, physical, and technical safeguards to protect PHI, establishing a compliance obligation and framing the protective scope of PHI handling.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Framewise Health, Inc. operates an SMS messaging program for patients enrolled by sponsoring partner hospitals as part of their hospital discharge education. Full program Terms and Conditions are at framewisehealth.com/terms . A standalone description is at framewisehealth.com/sms-program ."
Privacy Policy › “SMS Program”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Describes the SMS messaging program's operational context — patients enrolled by partner hospitals for discharge education — and references external terms and program description documents, incorporating those documents by reference and defining the program scope.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Patients (or their authorized caregivers) opt in by signing a written consent form during hospital intake or discharge planning at the sponsoring partner hospital. Consent is not a condition of treatment or care. "
Privacy Policy › “Consent”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Specifies that patients or authorized caregivers opt in via written consent during hospital intake or discharge planning, and expressly states that consent is not a condition of treatment or care — establishing a consent collection procedure and a user-protective restriction prohibiting coerced consent.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Patients receive recurring messages during the 30 days following hospital discharge. Up to 14 messages per 30-day post-discharge enrollment period. Message frequency varies. Standard message and data rates may apply."
Privacy Policy › “Frequency”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Defines the SMS message frequency parameters — recurring messages for 30 days post-discharge, up to 14 messages per enrollment period — and discloses that standard message and data rates may apply, establishing the scope and cost conditions of SMS processing.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Reply STOP to 1-833-449-2833 at any time. Opt-out is processed by our messaging provider via mobile carrier routing."
Privacy Policy › “Opt-out”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Specifies the opt-out mechanism — replying STOP to a designated number at any time — and describes how opt-outs are processed through the messaging provider via carrier routing, establishing a user right to withdraw from SMS communications and the procedure for exercising it.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" We implement industry-standard security measures to protect your information, including encryption, secure hosting on AWS with a signed Business Associate Agreement, and regular security reviews. However, no method of electronic transmission or storage is 100% secure."
Privacy Policy › “Data Security”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Describes implementation of security measures including encryption and secure hosting under a Business Associate Agreement, but then disclaims absolute security by stating no method of electronic transmission or storage is 100% secure — limits liability for security failures.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Depending on your jurisdiction, you may have the right to:"
Privacy Policy › “Your Rights”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Introduces jurisdiction-dependent user rights over personal information held by the organization, conditioning their availability on the user's jurisdiction.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Our website may use cookies and similar technologies to analyze traffic and improve your experience. You can control cookies through your browser settings."
Privacy Policy › “Cookies”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

States that the website may use cookies and similar technologies to analyze traffic and improve user experience, and informs users they can control cookies through browser settings — grants a limited user control right alongside the permission to use tracking technologies.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on this page with a revised "Last updated" date."
Privacy Policy › “Changes to This Policy”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Establishes the procedure for policy updates, requiring material changes to be communicated by posting the updated policy with a revised date, defining notice obligations to users.

AI-generated interpretation, not legal advice.

Subprocessors & data sharing
High
" Business Associate Agreements (BAAs) with all applicable service providers"
Privacy Policy › “End-to-end encryption for all data in transit and at rest”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Requires Business Associate Agreements with all applicable service providers, imposing a contractual obligation that restricts how subprocessors may handle protected data — user-favorable requirement.

AI-generated interpretation, not legal advice.

Clause detail — protections, your obligations, and coverage

Every clause below is a verbatim quote from Framewise Health's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.

✅ Protections found

0 verified clauses

Clauses in Framewise Health's policies that work in your favour — commitments the platform made to you.

No protective clause has been verified in Framewise Health's published policies yet. That means we did not find one in the documents we read — not that the platform offers nothing.

📋 Rules you must follow

0 verified clauses

What Framewise Health requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.

No user-conduct rule has been verified in Framewise Health's published policies yet.

What the policies actually cover

0 topics

None of Framewise Health's verified clauses has been assigned a topic yet. The clause-trust review has not reached this platform's findings.

Clause intelligence

Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.

20
clauses
1
patterns
1
stances
privacy sharing · 1
privacy sharingHIGHPrivacy Policy › “Data Sharing”

The clause permits sale of personal data or information.

We do not sell your personal information. We may share information with:
Open source citation

Tier matrix

Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.

TierSurfaceVerdictRiskCitations
All applicable tierssubprocessors data sharingworsensHIGH1

Policy evolution

Open full timeline

Before/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.

Jul 20, 2026data sharingHIGH

Latest stance: sale or sell on subprocessors data sharing

We do not sell your personal information. We may share information with:
Open timeline citation

Capture recency

  • Privacy Policy:Last captured 2026-07-20· verified 2026-07-20verified once — not yet re-verified
  • Terms of Service:Last captured 2026-09-01· verified 2026-09-01verified once — not yet re-verified

Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.

20 findings first captured First scan: July 2026.

Claim this profile

Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Framewise Health's policies — no human edits the data.

Need this for procurement or legal diligence?

Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.

Every finding above is a verbatim quote from Framewise Health's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.