Legal
Last updated — June 2026
Privacy Policy
Automate Clinic, PBC, doing business as Closer Clinic (“Closer Clinic,” “we,” “us,” or “our”) cares about your privacy. This Privacy Policy explains what information we collect through the website at closer.clinic and our related services (the “Services”), how and why we collect it, how we use and share it, and the choices you have. By using the Services, you agree to this Privacy Policy. If you have questions, contact us using the details at the end.
Closer Clinic is a management services organization. It is not a medical practice and does not provide health care. Clinical care offered through the Services is delivered by Automate Clinic, PC and its affiliated professional entities (collectively, “Provider Group”), each independently owned by one or more licensed physicians.
Key Terms
“Personal Information” means information that identifies, relates to, or could reasonably be linked with you, as further described below.
“PHI” means protected health information as defined by the Health Insurance Portability and Accountability Act (“HIPAA”).
“Services” means the website, applications, messaging, and related tools we provide.
“Terms of Service” means our Terms of Service, available on our website.
How This Policy Relates to Your Health Information (Important)
This Privacy Policy covers information we collect through the public parts of our website and our general business operations. It does not govern the protected health information created or maintained in the course of your care.
When you log in to the secure, patient-facing portions of the Services to receive care, the information you and your clinician add — your medical history, the details of your visits, clinical messages, orders, and results — is PHI. That PHI is held by Provider Group and is governed by its HIPAA Notice of Privacy Practices and by the Business Associate Agreements between Closer Clinic and Provider Group, not by this Privacy Policy. Where Closer Clinic handles PHI as a service provider (business associate) to Provider Group, it does so under HIPAA. We do not use or disclose PHI for marketing or advertising except as HIPAA permits, and we do not sell PHI. If anything in this Privacy Policy conflicts with the HIPAA Notice of Privacy Practices as applied to PHI, the HIPAA Notice of Privacy Practices controls. Provider Group is responsible for giving you that Notice; please review it for your rights regarding your PHI.
Relationship to the Terms of Service
This Privacy Policy is incorporated into our Terms of Service, which also apply when you use the Services.
Information We Collect
Depending on how you interact with us, we may collect:
Contact and identification details — such as your name, email address, mailing address, and phone number.
Identity verification information — such as date of birth or a government identifier where needed to confirm who you are or to provide care lawfully.
Account information — such as your username and password.
Payment, billing, and insurance information — such as your transactions, billing address, and insurance details. Full payment card numbers are handled by our payment processor, not stored by us.
Communications — the contents of messages you send us and any attachments.
Limited health-related information collected outside of care — for example, the condition you indicate interest in when you fill out an intake or contact form before you become a patient. Once you are receiving care through the secure Services, health information is handled as PHI as described above.
Device and online-activity information — such as IP address, device and browser type, operating system, general location derived from IP address, the pages you view, the links you click, and how you use the Services over time.
How We Collect Information
From you. We collect most information directly from you — when you fill out forms, create an account, make a payment, or communicate with us by phone, text, or email.
Automatically. We and our service providers collect device and online-activity information automatically through cookies, pixels, and similar technologies (see below).
From third parties. We may receive information from service providers and partners that help us operate, secure, and market the Services, and from payment and verification providers.
Cookies, Analytics, and Similar Technologies
We and our service providers use cookies and similar technologies to operate the website, remember your preferences, measure performance, and understand how the Services are used. Session cookies expire when you close your browser; persistent cookies remain until they expire or you delete them. We use analytics services, such as Google Analytics, to understand site usage. You can usually refuse or delete cookies through your browser settings, though some features may not work properly if you do. See the “Your Privacy Choices” section for ways to limit tracking. We use analytics and advertising technologies, including tracking scripts and audience-building tools provided by third-party vendors to understand how the Services are used and to support our marketing. We do not configure these tools to collect or transmit PHI, or information that identifies you as seeking or receiving a particular type of care, to any advertising destination, and we do not use such information to build advertising audiences or target advertising to you. Information used for these purposes is limited to the device and online-activity information described above under “Information We Collect.”
Artificial Intelligence and Automated Tools
The Services use artificial intelligence and other automated tools to support care and operations — for example, to help gather your information before a visit, organize and summarize it for your clinician, assist with documentation, and support scheduling and billing. A licensed clinician of Provider Group, not an automated tool, makes clinical decisions. By using the Services, you agree that we and Provider Group may process the information you provide, including health information, using these tools to deliver, secure, and improve the Services, consistent with this Privacy Policy and the applicable HIPAA Notice of Privacy Practices. We may use information in de-identified or aggregated form to develop and improve our tools and the Services; once information is de-identified so that it no longer identifies you, it is no longer Personal Information or PHI and may be used and disclosed as permitted by law.
How We Use Information
We use Personal Information to: provide, operate, secure, and maintain the Services; communicate with you, including service, administrative, and support messages; respond to your requests and feedback; improve and personalize the Services; conduct research and development, including creating de-identified and aggregated data; send marketing communications where permitted by law (which you can opt out of); comply with law and respond to lawful requests and legal process; protect the rights, safety, and property of you, us, and others; detect and prevent fraud and security incidents; enforce our Terms of Service; and for any other purpose with your consent.
How We Disclose Information
We may disclose Personal Information:
To service providers and partners that perform functions on our behalf — such as hosting, data storage, analytics, communications, identity verification, security, and professional advisors (auditors, lawyers, accountants).
To Provider Group and other health care providers, and to insurers, as needed to arrange and support your care and its billing.
For legal and safety purposes — to comply with law and lawful requests, to enforce our Terms of Service, and to protect rights, safety, and property.
In a business transaction — if we are involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction, as permitted by law.
De-identified or aggregated information — which we may disclose for any lawful purpose.
With your consent or at your direction.
We do not sell PHI. We do not sell other Personal Information in exchange for money; for any “sale” or “sharing” as those terms are defined under U.S. state privacy laws (for example, certain uses of advertising cookies), see “Your Privacy Choices” and “Your U.S. State Privacy Rights.”
Your Privacy Choices
Marketing. You can opt out of marketing emails using the unsubscribe link in those messages. You will still receive non-marketing messages about your account and the Services. You can reply STOP to opt out of marketing texts.
Cookies and online tracking. You can manage cookies through your browser, use privacy-focused browsers or plug-ins, and opt out of certain advertising through the Network Advertising Initiative and Digital Advertising Alliance opt-out pages. You can opt out of Google Analytics using Google’s opt-out browser add-on.
Do Not Track. Browsers are not uniform in how they send “Do Not Track” signals, and we do not currently respond to them. We do honor recognized opt-out preference signals where required by applicable state law.
Your U.S. State Privacy Rights
Depending on your state of residence, you may have rights to: confirm whether we process your Personal Information and access it; correct inaccuracies; request deletion; obtain a portable copy; and opt out of targeted advertising or any “sale” or “sharing” of your Personal Information. We will not discriminate against you for exercising these rights. Note that information governed by HIPAA is generally exempt from these state laws and is handled under the HIPAA Notice of Privacy Practices instead. To exercise a right, contact us using the details below; we will verify your request as required by law, and you may use an authorized agent where permitted. If we deny a request, you may appeal by contacting us. These rights include those under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”), and comparable laws in other states. Under the CCPA, California residents specifically have the right to know the categories and specific pieces of Personal Information we have collected about them, to request deletion, to correct inaccurate Personal Information, to opt out of the sale or sharing of Personal Information (including for cross-context behavioral advertising), and to limit the use of sensitive Personal Information. We do not sell Personal Information for money.
Certain states, including Washington and Nevada, regulate “consumer health data” under laws such as Washington’s My Health My Data Act and Nevada’s Consumer Health Data Privacy Law. This may include information that is not otherwise Protected Health Information under HIPAA — for example, information you provide before you become a patient, such as through an intake or contact form, or information about your interactions with our public website that reveals or could reveal your health status or interest in a particular health condition.
Where these laws apply to you, we:
collect and use your consumer health data only as strictly necessary to provide the Services you request, or for another purpose to which you have separately and affirmatively consented;
do not sell your consumer health data without your valid authorization;
do not use geofencing technology to establish a virtual boundary around a health care facility for the purpose of identifying, tracking, collecting data from, or sending notifications to consumers regarding their consumer health data; and
limit access to your consumer health data to employees and contractors who need it to perform their duties.
You have the right to confirm whether we process your consumer health data, to access it, to withdraw consent for its collection or sharing, and to request its deletion. To exercise these rights, contact us using the details at the end of this Privacy Policy.
California “Shine the Light.” California residents may ask whether we disclose Personal Information to third parties for those third parties’ own direct marketing. We do not, but you may contact us to inquire.
Accessing and Correcting Your Information
You can review and update your account information by logging in to the Services, or by contacting us. We will accommodate reasonable requests to correct or delete information unless we are required or permitted by law to keep it.
Who May Use the Services
You must be at least 18 years old and located in a U.S. state where the Services are available. The Services are offered only in the United States and only where the relevant Provider Group entity is authorized to provide care. They are not available outside the United States or where prohibited.
Security
We use administrative, technical, and physical safeguards designed to protect Personal Information. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security. You are responsible for keeping your password confidential. Any transmission of information is at your own risk.
Children’s Information
The Services are not directed to anyone under 18, and we do not knowingly collect Personal Information from children under 18. If we learn that we have collected information from someone under 18, we will delete it, unless we are legally required to keep it. If you believe a child under 18 has provided us information, contact us so we can address it.
Social Media
We may maintain pages on social media platforms. When you interact with those pages, the platform’s own privacy policy governs that interaction and its collection and use of your information.
Data Retention
We keep Personal Information for as long as needed to provide the Services, comply with our legal obligations, resolve disputes, and enforce our agreements, after which we delete or de-identify it. Retention of PHI is governed by the HIPAA Notice of Privacy Practices and applicable law.
Changes to This Policy
We may update this Privacy Policy from time to time. We will post changes on this page and update the Last Updated date, and we will provide additional notice for material changes where required. Please review this page periodically.
Contact Us
For questions about this Privacy Policy or to exercise your rights, contact:
Attention: Privacy Officer, Automate Clinic, PBC d/b/a Closer Clinic 4845 Pearl East Cir, Ste 118, PMB 619246, Boulder, Colorado 80301-6112
Email: support@automate.clinic
Phone: (970) 239-1441
Notice of Privacy Practices
This notice describes how medical information about you (or the patient for whom you are a parent or authorized guardian) may be used and disclosed, and how you can get access to this information. Please review it carefully.
Who Will Follow This Notice
This notice describes BRDG, Inc.’s privacy practices and those of its affiliates, including Cloud Health Medical Group, P.A., Cloud Health Medical Group of Kansas, P.A., Cloud Health Medical Group of California, P.C., and Cloud Health Medical Group of New Jersey, their physicians, other healthcare practitioners, and other personnel (collectively, “Bridge,” “we,” or “us”).
Our Pledge Regarding Medical Information
We understand that medical information about you and your health is personal and we are committed to protecting it. We create a record of the care and services you receive at Bridge. We need this record to provide you with quality care and to comply with certain legal requirements. This notice is required by law and applies to all records of your care generated by us.
This notice will tell you about the ways in which we may use and disclose medical information about you. We also describe your rights and certain obligations we have regarding the use and disclosure of medical information.
We are required by law to:
Ensure that medical information that identifies you is kept private (with certain exceptions);
Give you this notice of our legal duties and privacy practices with respect to medical information about you;
Follow the terms of the notice that is currently in effect; and
Promptly notify you if a breach occurs that may have compromised the privacy or security of your information.
Note for Parents and Authorized Guardians: Where a parent or authorized guardian has signed consent on behalf of a patient, references to “you” throughout this notice apply to the patient. The parent or authorized guardian has the right to exercise the rights described herein on the patient’s behalf to the extent permitted by applicable law.
How We May Use and Disclose Medical Information About You
The following categories describe different ways that we use and disclose medical information. For each category, we will explain what we mean. Not every use or disclosure in a category will be listed; however, all ways we are permitted to use and disclose information will fall within one of these categories.
For Treatment
We may use medical information about you to provide you with medical treatment or services. We may disclose medical information to doctors, nurses, technicians, or other Bridge personnel involved in providing Bridge’s services. For example, Bridge personnel may discuss your prescription with your doctor to ensure we dispense the appropriate drug.
For Payment
We may use and disclose medical information to obtain payment for the services we provided to you. For example, we may need to give your health plan information about your appointment so your health plan will pay us.
For Healthcare Operations
We may use and disclose medical information about you for healthcare operations. These uses and disclosures are necessary to run Bridge and ensure that all patients receive quality care. For example, we may use medical information to review our treatment and services and to evaluate the performance of our staff in caring for you. We may also combine medical information with information from other providers to identify where we can make improvements in the care and services we offer. We may remove information that identifies you from this set of medical information so others may use it to study health care and delivery without learning who the specific patients are.
We may also use and disclose your medical information to other providers when necessary for them to treat you or receive payment for services they have rendered to you. Additionally, we may disclose your medical information in order to resolve any complaints you may have.
To You
We may use and disclose medical information to contact you as a reminder that you have an upcoming refill.
We may use and disclose medical information to tell you about or recommend possible treatment options or alternatives that may be of interest to you.
We may use and disclose medical information to tell you about our health-related products or services that may be of interest to you.
We have the right to use medical information about you to contact you in an effort to encourage you to purchase or use a health care-related product or service from us. If we receive any direct or indirect payment for making such a communication, however, we would need your prior written permission to contact you. The only exceptions are when our communication (i) describes only a drug or medication currently being prescribed for you and our payment for the communication is reasonable in amount, or (ii) is made by one of our business partners consistent with our written agreement with them.
Individuals Involved in Your Care
We may release medical information about you to a friend or family member who is involved in your medical care, provided we (a) obtain your consent, (b) provide you an opportunity to object and you do not object, or (c) can make a reasonable inference that you do not object. We may also give information to someone who helps pay for your care.
Unless there is a specific written request to the contrary, we may also tell your family or friends your condition and that you are a part of Bridge. In addition, we may disclose medical information about you to an entity assisting in a disaster relief effort so that your family can be notified about your condition, status, and location.
Research
Under certain circumstances, we may use and disclose medical information about you for research purposes. All research projects are subject to a special approval process. Before we use or disclose medical information for research, the project will have been approved through this process. We may, however, disclose medical information to people preparing to conduct a research project (for example, to help them look for patients with specific medical needs), so long as the medical information they review does not leave Bridge’s possession. We will always ask for your specific permission if the researcher will have access to your name, address, or other information that reveals who you are.
To Avert a Serious Threat to Health or Safety
We may use and disclose medical information about you when necessary to prevent a serious threat to your health and safety or the health and safety of the public or another person. Any disclosure, however, would only be to someone able to help prevent the threat.
Limitation on the Use of PHI for Paid Marketing
We will, in accordance with federal and state laws, obtain your written authorization to use or disclose your PHI for marketing purposes (e.g., to use your photo in ads), but not for activities that constitute treatment or healthcare operations.
We will obtain your written authorization prior to using your PHI or making any treatment or healthcare recommendations, should financial remuneration from a third party be involved. We must clarify that financial remuneration does not include in-kind payments or payments to implement a disease management program. Any promotional gifts of nominal value are not subject to the authorization requirement.
The only exclusion to this is “refill reminders,” so long as the remuneration for making such a communication is reasonably related to our cost for making it. Permissible reimbursable costs include labor, supplies, and postage. “Generic equivalents,” “adherence to take medication as directed,” and “self-administered drug or delivery system communications” are all considered to be “refill reminders.”
Face-to-face marketing communications, such as sharing a written product brochure or pamphlet, are permissible under current HIPAA law.
Special Situations
Workers’ Compensation
We may release medical information about you for workers’ compensation or similar programs as required by state law. These programs provide benefits for work-related injuries or illness.
Public Health Risks
We may disclose medical information about you for public health activities, including:
To prevent or control disease, injury, or disability;
To report deaths;
To report the abuse or neglect of children, elders, and dependent adults;
To report reactions to medications or problems with products;
To notify people of recalls of products they may be using;
To notify a person who may have been exposed to a disease or may be at risk for contracting or spreading a disease or condition; and
To notify the appropriate government authority if we believe a patient has been the victim of abuse, neglect, or domestic violence. We will only make this disclosure if you agree or when required or authorized by law.
Health Oversight Activities
We may disclose medical information to a health oversight agency for activities authorized by law, including audits, investigations, inspections, and licensure. These activities are necessary for the government to monitor the healthcare system, government programs, and compliance with civil rights laws.
Lawsuits and Disputes
We may disclose medical information about you in response to a court or administrative order, or in response to a subpoena, discovery request, or other lawful process, but only if efforts have been made to notify you about the request or to obtain an order protecting the information requested.
Law Enforcement
We may release medical information to authorized law enforcement officials as required by law or due to a court order, grand jury, or administrative subpoena.
Coroners, Medical Examiners, and Funeral Directors
We may release medical information to a coroner, medical examiner, or funeral director as required by law.
Specialized Government Functions
We may disclose medical information about you to U.S. government entities with special functions, such as the military or Department of State, under certain circumstances when required by law.
Legal Requirement
We may release your medical information when required by law not specifically referenced in the preceding categories.
HIPAA Forms
If you would like us to share your Protected Health Information with anyone besides you, we will need you to complete and sign an Authorization for the Use/Disclosure of Health Information.
If you previously provided us with an Authorization and would like to revoke it, please complete and sign a Revocation of Authorization to Disclose Protected Health Information.
If you would like to request a copy of your medical records, please fill out and sign a Patient Request for Health Information.
Your Rights Regarding Medical Information About You
Right to Inspect and Copy
You have the right to inspect and copy medical information that may be used to make decisions about your care. Usually, this includes medical and billing records, but may not include some mental health information. If your medical information is maintained in an electronic health record, you may obtain an electronic copy and, if you choose, instruct us to transmit such copy directly to an entity or person you designate in a clear, conspicuous, and specific manner.
To inspect and copy your medical information, you must submit your request in writing to Bridge’s Privacy Officer at the address listed at the end of this notice. An authorization form must be completed. We may charge a fee for the costs of copying, mailing, or other supplies associated with your request. Our fee for providing an electronic copy will not exceed our labor costs in responding to your request.
We may deny your request to inspect and copy in certain limited circumstances. If you are denied access, you may request that the denial be reviewed by another licensed health care professional chosen by Bridge. We will comply with the outcome of the review.
Right to Amend
If you feel that medical information we have about you is incorrect or incomplete, you may ask us to amend it. To request an amendment, you must submit your request in writing to Bridge’s Privacy Officer, along with a reason supporting your request.
We will act on your request within 60 days (or 90 days if additional time is needed) and will inform you in writing as to whether the amendment will be made or denied. Even if we deny your request for amendment, you have the right to submit a written addendum of not more than 250 words regarding any item or statement in your record you believe is incomplete or incorrect.
Right to an Accounting of Disclosures
You have the right to request an “accounting of disclosures” — a list of disclosures we made of medical information about you other than for treatment, payment, and healthcare operations, and subject to other exceptions permitted by law. To request this list, you must submit a written request to Bridge’s Privacy Officer specifying a time period of no more than six years. We will respond within 60 days (or 90 days if needed). The first list within a 12-month period is free; additional lists may incur a charge.
Right to Request Restrictions
You have the right to request a restriction or limitation on the medical information we use or disclose about you for treatment, payment, or healthcare operations, or to someone involved in your care. We are not required to agree to your request, except where the disclosure is to a health plan for payment or healthcare operation purposes and the medical information relates solely to a healthcare item or service for which you have paid out-of-pocket in full.
To request restrictions, you must submit a written request to Bridge’s Privacy Officer specifying (1) what information you want to limit, (2) whether you want to limit our use, disclosure, or both, and (3) to whom you want the limits to apply.
Right to Request Confidential Communications
You have the right to request that we communicate with you about medical matters in a certain way or at a certain location. To request confidential communications, you must make your request to Bridge’s Privacy Officer. We will accommodate all reasonable requests. Your request must specify how or where you wish to be contacted.
Right to a Paper Copy of This Notice
You have the right to a paper copy of this notice at any time, even if you have agreed to receive it electronically. You may obtain a copy of this notice at our website or by contacting Bridge’s Privacy Officer.
Complaints
If you believe your privacy rights have been violated, you may file a complaint with Bridge or with the Office of Civil Rights, U.S. Department of Health and Human Services. To file a complaint with Bridge, contact Bridge’s Privacy Officer at the address listed below. All complaints must be submitted in writing. We will not retaliate against you if you file a complaint with us or the Director.
Other Uses of Medical Information Requiring Your Authorization
Other uses and disclosures of medical information not covered by this notice or applicable law will be made only with your written permission. If you provide us permission to use or disclose medical information about you, you may revoke that permission in writing at any time. Revoking permission will stop any further use or disclosure for the purposes covered by your written authorization, except where we have already acted in reliance on your permission.
Electronic Consent and Online Access
If you are a parent or authorized guardian who has signed this Notice or related consent forms on behalf of a patient online, your electronic acceptance of this Notice carries the same legal force and effect as a handwritten signature. By accepting this Notice electronically, you confirm that you have read and understood its contents, and that you are authorized to do so on the patient’s behalf.
Changes to This Notice
We reserve the right to change our privacy practices and to make any such change applicable to the protected health information we obtained about you before the change. If a change in our practices is material, we will revise this Notice to reflect the change. We will post a copy of the current notice on www.cloudhealthmedicalgroup.com. You may also obtain any new notice by contacting the Privacy Officer.
Contact Information
Address all correspondence in writing to Bridge’s Privacy Officer at:
Privacy Officer
legal@usebridge.com
Updated: February 2026