Legal
Privacy Policy
Last updated August 17, 2026
Who we are
MediOS is software operated by Nav Collective LLC. Clinics use MediOS to run the workflow around immigration medical exams: scheduling, intake, callbacks, lab and vaccine tracking, and preparation of the Form I-693 packet.
We provide MediOS to clinics. If you are a patient, your relationship is with your clinic, not with us. The clinic decides what information goes into MediOS and what happens to it. We handle that information on the clinic’s behalf and under its instructions. Where a Business Associate Agreement is in place, Nav Collective LLC acts as a business associate of the clinic under HIPAA.
Information in MediOS
Clinics use MediOS to store the information they need to complete an exam and its packet. That can include:
- Identity and contact details: name, date of birth, gender, phone numbers, mailing address, country and city of birth.
- Immigration identifiers: A-Number, USCIS online account number, and the form of ID presented at the visit.
- Health information for the exam: vaccination history and self-reported vaccine records, lab status and dates, and the civil surgeon’s findings recorded on the I-693.
- Insurance details: provider, member and group identifiers, and the insurer’s phone number.
- Communications: records of inbound calls including the calling number, time and duration, and callback notes. Where a clinic’s phone system records calls and has confirmed to us that it announces this to callers, we also store a link to that recording; where it has not confirmed it, we discard the recording. Where a clinic has enabled the automated phone assistant, we store its call records including whether consent to record was given.
- Text message consent: whether a patient agreed to receive texts, when, how it was recorded, and whether they have since opted out.
- Clinic staff accounts: name, work email, role, and a hashed password. We never store staff passwords in readable form.
- Activity logs: a record of which staff account viewed or changed what and when, including the network address the request came from, so a clinic can audit its own records. Sign-in attempts are recorded the same way and kept for 90 days.
MediOS is not advertising software. We do not sell information, we do not share it with advertisers or data brokers, and we do not use patient information to train machine learning models.
Text messages
Clinics can send a patient a secure link by text before a visit so vaccination history and appointment details can be confirmed in advance. Those messages are sent at the clinic’s direction and identify the clinic. Message and data rates may apply, and message frequency varies.
We only send a text to someone the clinic has recorded as having agreed to receive one. You can reply STOP at any time to stop them, or HELP for help; we also recognize the equivalent words in Spanish, Haitian Creole, French and Portuguese. An opt-out is recorded against your number and clinic staff cannot reverse it. If you want texts again, reply START. Our SMS consent notice describes this in full.
Service providers
We rely on a small number of providers to run MediOS. They process information only to provide their service to us, and only to the extent needed to do so:
- Vercel, application hosting.
- Neon, the database where clinic records are stored.
- Twilio, delivery of the pre-visit text messages described above.
- Calendly, where a clinic connects it, so that bookings become cases.
- The clinic’s telephone provider, such as VitalPBX or Telnyx, which sends call records into the callback queue.
- An automated voice provider, only where a clinic has explicitly enabled the phone assistant and recorded a signed agreement with that vendor.
How information is protected
Traffic between your browser and MediOS is encrypted in transit. Access requires an account created by a clinic administrator; MediOS has no public sign-up. Every record is scoped to the clinic that owns it, and staff of one clinic cannot read another clinic’s records. Staff accounts can be protected with a second factor from an authenticator app, sessions end after a period of inactivity, and repeated failed sign-in attempts are throttled. Links sent to patients before a visit use a single-purpose token that grants access only to that patient’s own intake form, nothing else in the system, and it stops working 30 days after it is sent.
No system is perfectly secure, and we do not claim otherwise. If we become aware of a breach affecting a clinic’s information, we will notify that clinic without undue delay.
How long information is kept
Records stay in MediOS for as long as the clinic keeps them there. The clinic controls its own data and can ask us to correct or delete it. When a clinic closes its account, we delete or return its records at its direction, except where we are required to keep something by law.
Patient requests
If you are a patient and you want to see, correct, or delete information about you, please contact the clinic that examined you. They hold the relationship with you and the authority over those records, and we act on their instructions. If you contact us directly, we will refer you to your clinic.
Changes to this policy
If we change this policy we will update the date at the top of this page. If a change materially affects how clinic or patient information is handled, we will tell the affected clinics directly rather than relying on this page alone.
Contact
Nav Collective LLC
privacy@mymedios.co