Skip to main content
Switchyard
ProductHow it worksSecurity
Legal · Privacy

Privacy Policy

Switchyard HCC Assistant (Chrome Extension)

Effective date: July 20, 2026

This policy describes how the "Switchyard HCC Assistant" Chrome extension (the "Extension") handles information. The Extension is operated bySwitchyardAI.com ("Switchyard," "we," "us"), the operator of the Switchyard platform and the data controller. The current Chrome Web Store dev/test listing may be published by Agilus, an authorized partner, on Switchyard's behalf; the production listing will be published by Switchyard. The listing publisher is a distribution detail — the data controller is Switchyard.

1. Overview

The Extension is a provider-facing tool for healthcare risk-adjustment (HCC/RAF) workflows. It is not a consumer product and is available only to authenticated users of an organization that has a Switchyard account. The Extension acts as anoverlay on the clinical systems a provider already uses — it surfaces administrative, claims-derived coding suggestions for the patient the provider currently has in view. It does not replace, store, or duplicate the clinical record maintained by the provider's EHR.

This policy explains what information the Extension accesses, how it is used, and how it is protected.

2. Information the Extension accesses

  • Patient identifiers (in context only). On a supported EHR page (athenahealth) or within the Switchyard web application, the Extension reads the identifier of the patient currently displayed — for example a medical record number (MRN), and where necessary the patient name and date of birth — in order to look up that patient in Switchyard.
  • Health-related / claims information. The Extension requests and displays risk-adjustment information (e.g., suggested HCC/RAF codes and the claims evidence supporting them) for the in-context patient. This information is retrieved from Switchyard's backend; the Extension does not derive it from, or write it to, the EHR.
  • Provider authentication identity. When you sign in, the Extension authenticates you through our identity provider (Amazon Cognito) and receives a short-lived access token. The Extension uses Chrome's identity API only to complete this sign-in redirect; it does not access your Google account, profile, or contacts.
  • Local preferences. Your selected organization (tenant) and interface filter preferences.

The Extension does not track your browsing history, doesnot read pages other than the supported EHR and Switchyard pages it is designed for, and does not collect data for advertising.

3. How information is used

Information is used solely to deliver the Extension's single purpose: identifying the in-context patient and displaying that patient's risk-adjustment suggestions and supporting evidence to authorized users within your organization. Patient identifiers are transmitted to Switchyard's API only to perform this lookup.

4. Information storage

  • Patient identifiers and health/claims information are processed in memory to render the current view and are not persisted by the Extension to local browser storage.
  • The Extension stores only the following in your browser's local extension storage: your selected organization (tenant), UI filter preferences, and your short-lived authentication token. This information stays on your device and is used to maintain your session and settings.

5. How information is shared

  • We do not sell or rent your data, and we do not share it with third parties for their own purposes.
  • We do not use or transfer the data for any purpose unrelated to the Extension's single purpose, and never to assess creditworthiness or for lending.
  • Patient and health information transmitted by the Extension goes only to Switchyard's own backend systems, which process it on your organization's behalf. Such data is Protected Health Information (PHI) handled under our agreements with your organization, including any applicable Business Associate Agreement (BAA) and HIPAA obligations.

6. Security

All network communication between the Extension and Switchyard's API occurs over encrypted connections (modern TLS). Access requires authentication through Amazon Cognito, and all data access is scoped to your organization. Data is isolated per organization (tenant), enforced with row-level security and role-based access controls, with encryption at rest — consistent with Switchyard's HIPAA security program.

7. Data retention

The Extension itself retains only your local preferences and session token on your device until you sign out, clear browser data, or uninstall the Extension. Retention of data within Switchyard's backend is governed by Switchyard's master privacy policy and your organization's agreement with us.

8. Limited Use disclosure (Chrome Web Store)

Switchyard's use of information received from the Extension adheres to theChrome Web Store User Data Policy, including the Limited Use requirements. Data is used only to provide and improve the Extension's single purpose, is not transferred or sold for unrelated purposes, and is not used for advertising or creditworthiness determination.

9. Children's privacy

The Extension is a professional tool intended for use by healthcare provider organizations and is not directed to consumers or children.

10. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the effective date above and, where appropriate, notifying customer organizations.

11. Contact

Questions about this policy: privacy@switchyardai.com
SwitchyardAI.com

Switchyard

Secure healthcare technology for clinical operations, data quality, and compliance.

ProductHow it worksSecurityPrivacy
© Switchyard
All rights reserved