Privacy Policy

M2 Physician-Facing Platform

Effective Date: May 18, 2026

1. Overview

This Privacy Policy explains how M2 handles information in connection with a physician-facing clinical decision support platform that is not intended to receive or process PHI.

2. No Collection of PHI

M2 is designed not to collect, store, or process Protected Health Information (PHI).

Users must not submit identifiable patient data. The Platform does not require PHI to function.

3. Information That May Be Collected

M2 may collect limited non-clinical information such as:

  • User account credentials
  • Professional role and specialty
  • Platform usage metrics
  • Technical and security logs

This information is used solely to:

  • Operate and secure the Platform
  • Improve performance and reliability
  • Support authorized access

4. De-Identified and Abstracted Inputs

Any clinical information entered into M2 must be:

  • Fully de-identified
  • Hypothetical or abstracted
  • Non-traceable to an individual patient

5. No Sale or Sharing of Data

M2 does not sell user data.

Information is not shared except as necessary to:

  • Operate the Platform
  • Comply with legal obligations
  • Protect security and integrity

6. Security Measures

Reasonable administrative, technical, and organizational safeguards are used to protect Platform data.

However, no system can be guaranteed 100% secure.

7. HIPAA Status

Because PHI must not be entered:

  • M2 is not a HIPAA Business Associate
  • HIPAA does not apply to the Platform as used
  • Users remain responsible for HIPAA compliance

8. User Responsibilities

Users are responsible for:

  • Ensuring no PHI is entered
  • Following institutional privacy policies
  • Using the Platform in compliance with applicable law

9. Changes to This Policy

This Privacy Policy may be updated periodically. Continued use of M2 constitutes acceptance of any changes.

10. Contact

For questions regarding privacy or compliance:

[email protected]