HealthSpark
Graded against 811 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.
No lens is bandable yet — banding requires fully verified documents with on-criteria findings. The gap is shown honestly, never estimated.
Partially verified: Privacy Policy assessed. Everything below comes only from what was read in full.
Watch: Privacy and data use
Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.
This segment restricts most other uses and disclosures of PHI to those requiring the patient's written authorization, and specifically requires prior written authorization before using PHI for marketing purposes — establishing a consent-based restriction on non-standard disclosures that is protective of the patient.
This segment prohibits HealthSpark from selling patient health information without authorization, imposing a restriction on commercial sale of PHI that is protective of the patient.
This segment enumerates patient rights including the right to obtain electronic or paper copies of medical records, request corrections, request confidential communications, request restrictions on certain disclosures (with a mandatory grant when the patient pays out-of-pocket), receive an accounting of certain disclosures over a six-year period, designate a representative, and other rights — conferring affirmative entitlements on the patient regarding their PHI.
How to read this page: Overall risk rates what HealthSpark's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.
Partially verified — Privacy Policy — Verified (read in full, 7 findings). Findings below are from fully-read, verified documents only; remaining core documents are pending capture.
Terms not yet captured
AIRIN has not yet captured a gate-verified Terms of Service document for this platform.
- Privacy PolicyVerified - read in full - 7 citationsLast captured 2026-07-20
Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.
This segment defines the covered entities collectively referred to as 'HealthSpark' and introduces the scope of the notice, defining what protected health information (PHI) is used for — treatment, payment, healthcare operations, and other lawful purposes — and identifies the subject matter of the document including patient rights to access and control PHI.
" This Notice of Privacy Practices ("Notice") explains how HealthSpark Inc., HealthSpark Medical Group West PC, HealthSpark Medical Group PA (including its assumed name, HealthSpark Medical Group PC), and their licensed clinicians and busine..."
This segment enumerates specific circumstances in which HealthSpark is permitted to disclose PHI without patient authorization, including disclosures to coroners, organ donation facilitation, research, averting health or safety threats, specialized government functions, military authorities, correctional institutions, and workers' compensation — listing lawful disclosure permissions.
" We sometimes rely on third-party service providers—such as secure cloud-hosting platforms, claims-clearinghouses, electronic-prescription networks, telehealth infrastructure vendors, and analytics partners—to support our treatment, payment..."
This segment restricts most other uses and disclosures of PHI to those requiring the patient's written authorization, and specifically requires prior written authorization before using PHI for marketing purposes — establishing a consent-based restriction on non-standard disclosures that is protective of the patient.
" Inform coroners, medical examiners and funeral directors of information necessary for them to fulfill their duties. Facilitate organ and tissue donation or procurement. Conduct research following internal review protocols to ensure the b..."
Evidence appendix
Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.
" Inform coroners, medical examiners and funeral directors of information necessary for them to fulfill their duties. Facilitate organ and tissue donation or procurement. Conduct research following internal review protocols to ensure the balancing of privacy and research needs. Avert a serious threat to health or safety. Assist in specialized government functions such as national security, intelligence and protective services. Inform military and veteran authorities if you are an armed forces member (active or reserve). Inform a correctional institution if you are an inmate. Inform workers' compensation carriers or your employer if you are injured at work. Recommend treatment alternatives. Tell you about health-related products and services. Communicate within our organization for treatment, payment, or healthcare operations. Communicate with other providers, health plans, or their related entities for their treatment or payment activities, or health care operations activities relating to quality assessment and improvement, care coordination and the qualifications and training of healthcare professionals. Provide information to other third parties with whom we do business, such as a record storage provider. However, you should know that in these situations, we require third parties to provide us with assurances that they will safeguard your information. We may also use or disclose your personal or health information for operational purposes. "
This segment restricts most other uses and disclosures of PHI to those requiring the patient's written authorization, and specifically requires prior written authorization before using PHI for marketing purposes — establishing a consent-based restriction on non-standard disclosures that is protective of the patient.
AI-generated interpretation, not legal advice.
"For example, we may communicate with individuals involved in your care or payment for that care, such as family or guardians and send appointment reminders. All other uses and disclosures, not previously described, may only be done with your written authorization. We will also obtain your authorization before we: Use or disclose your health information for marketing purposes;"
This segment prohibits HealthSpark from selling patient health information without authorization, imposing a restriction on commercial sale of PHI that is protective of the patient.
AI-generated interpretation, not legal advice.
" This Notice of Privacy Practices ("Notice") explains how HealthSpark Inc., HealthSpark Medical Group West PC, HealthSpark Medical Group PA (including its assumed name, HealthSpark Medical Group PC), and their licensed clinicians and business partners (collectively, "HealthSpark," "we," "our," or "us") may use and disclose your protected health information (PHI) to provide treatment, obtain payment, and conduct health‑care operations, as well as other uses permitted or required by law. It also describes your rights to access and control your PHI. HealthSpark operates as an organized health‑care arrangement. All covered entities and workforce members within HealthSpark agree to follow the terms of this Notice and may share PHI with one another for treatment, payment, and health‑care‑operations purposes. This Notice applies to the technology-enabled and in-person physical therapy services provided by HealthSpark."
This segment defines the covered entities collectively referred to as 'HealthSpark' and introduces the scope of the notice, defining what protected health information (PHI) is used for — treatment, payment, healthcare operations, and other lawful purposes — and identifies the subject matter of the document including patient rights to access and control PHI.
AI-generated interpretation, not legal advice.
" Privacy & Security. We are required by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) to maintain the privacy and security of your PHI. Notice. We must give you this Notice and follow the terms currently in effect. Breach Notification. We will notify you promptly if a breach occurs that may have compromised the privacy or security of your PHI. Changes to This Notice. We may change this Notice at any time. Revised Notices apply to all PHI we maintain and will be posted on our website and made available upon request. Where any other state law provides greater privacy protection than HIPAA, we will follow that state law."
This segment imposes obligations on HealthSpark to maintain privacy and security of PHI, provide and follow the notice, notify patients of breaches, reserve the right to update the notice (with revised notices applying to all maintained PHI), and comply with any state law providing greater privacy protections — all framed as affirmative duties owed to the patient.
AI-generated interpretation, not legal advice.
" We sometimes rely on third-party service providers—such as secure cloud-hosting platforms, claims-clearinghouses, electronic-prescription networks, telehealth infrastructure vendors, and analytics partners—to support our treatment, payment, and health-care-operations activities. These companies, known under HIPAA as Business Associates, may receive, create, or maintain your protected health information on our behalf only after signing a Business Associate Agreement (BAA) that contractually requires them to: (a) use or disclose PHI solely as permitted by us or as required by law; (b) implement appropriate administrative, physical, and technical safeguards to protect the information; (c) report any suspected or confirmed privacy or security breach to HealthSpark without unreasonable delay; and (d) ensure that any of their subcontractors who handle PHI are bound by the same protections. We share the minimum necessary information for them to perform their duties, and we monitor their compliance as part of our ongoing privacy-and-security program. We may also use and disclose your health information to: Comply with federal, state or local laws that require disclosure. Assist in public health activities such as tracking diseases or medical devices. Inform authorities to protect victims of abuse or neglect. Comply with federal and state health oversight activities such as fraud investigations. Respond to law enforcement officials or to judicial orders, subpoenas or other processes. "
This segment enumerates specific circumstances in which HealthSpark is permitted to disclose PHI without patient authorization, including disclosures to coroners, organ donation facilitation, research, averting health or safety threats, specialized government functions, military authorities, correctional institutions, and workers' compensation — listing lawful disclosure permissions.
AI-generated interpretation, not legal advice.
" You may also file a complaint with the U.S. Department of Health & Human Services, Office for Civil Rights:"
This segment imposes an obligation on HealthSpark not to retaliate against patients for filing a privacy complaint, creating a non-retaliation protection that is favorable to the patient.
AI-generated interpretation, not legal advice.
" You have the right to: Get an electronic or paper copy of your medical record. Ask us to correct your record if you believe it is incomplete or inaccurate. Request confidential communications (e.g., alternative address or phone). Ask us to limit what we use or share—we may deny most requests, but we must grant a restriction on disclosures to a health plan if you pay in full out‑of‑pocket, unless disclosure is required by law. Receive a list of certain disclosures we made in the six years prior to your request. Choose a representative to act on your behalf (e.g., medical power of attorney). Receive a paper copy of this Notice at any time, even if you agreed to receive it electronically. File a complaint without retaliation if you feel we have violated your rights (see "Complaints" below). To exercise any right listed above, email contact@joinhealthspark.com or mail a signed request to the Privacy Officer at the address below."
This segment enumerates patient rights including the right to obtain electronic or paper copies of medical records, request corrections, request confidential communications, request restrictions on certain disclosures (with a mandatory grant when the patient pays out-of-pocket), receive an accounting of certain disclosures over a six-year period, designate a representative, and other rights — conferring affirmative entitlements on the patient regarding their PHI.
AI-generated interpretation, not legal advice.
Clause detail — protections, your obligations, and coverage
Every clause below is a verbatim quote from HealthSpark's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.
✅ Protections found
0 verified clausesClauses in HealthSpark's policies that work in your favour — commitments the platform made to you.
No protective clause has been verified in HealthSpark's published policies yet. That means we did not find one in the documents we read — not that the platform offers nothing.
📋 Rules you must follow
0 verified clausesWhat HealthSpark requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.
No user-conduct rule has been verified in HealthSpark's published policies yet.
What the policies actually cover
0 topicsNone of HealthSpark's verified clauses has been assigned a topic yet. The clause-trust review has not reached this platform's findings.
Clause intelligence
Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.
The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.
“Inform coroners, medical examiners and funeral directors of information necessary for them to fulfill their duties. Facilitate organ and tissue donation or procurement. Conduct research following internal review protocols to ensure the balancing of privacy and research needs. Avert a serious threat to health or safety. Assist in specialized government functions such as national security, intelligence and protectiv...”Open source citation
Tier matrix
Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.
| Tier | Surface | Verdict | Risk | Citations |
|---|---|---|---|---|
| Government | privacy data use | conditional | MEDIUM | 1 |
Policy evolution
Open full timelineBefore/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.
Latest stance: third party or vendor sharing on privacy data use
“Inform coroners, medical examiners and funeral directors of information necessary for them to fulfill their duties. Facilitate organ and tissue donation or procurement. Conduct research following internal review protocols to ensure the balancing of privacy and research needs. Avert a serious threat to health or safety. Assist in specialized government functions such as national security, intelligence and protective services. Inform military and veteran authorities if you are an armed forces member (active or reserve). Inform a correctional institution if you are an inmate. Inform workers' compensation carriers or your employer if you are injured at work. Recommend treatment alternatives. Tell you about health-related products and services. Communicate within our organization for treatment, payment, or healthcare operations. Communicate with other providers, health plans, or their related entities for their treatment or payment activities, or health care operations activities relating to quality assessment and improvement, care coordination and the qualifications and training of healthcare professionals. Provide information to other third parties with whom we do business, such as a record storage provider. However, you should know that in these situations, we require third parties to provide us with assurances that they will safeguard your information. We may also use or disclose your personal or health information for operational purposes.”Open timeline citation
Capture recency
- Privacy Policy:Last captured 2026-07-20· verified 2026-07-20verified once — not yet re-verified
Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.
7 findings first captured First scan: July 2026.
Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of HealthSpark's policies — no human edits the data.
Need this for procurement or legal diligence?
Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.
Know where the missing document lives?
We haven't yet verified HealthSpark's Terms of Service. Point us at the official page and our pipeline will attempt to capture and read it in full. Submissions are candidates only — nothing is published until it passes the same verification gates as every other document on this site.
Every finding above is a verbatim quote from HealthSpark's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.