Cowboy Systems is committed to protecting the privacy of patients, providers, and all users of our platform. This policy explains what data we collect, how we use it, and your rights regarding that data.
Cowboy Systems ("Cowboy Systems," "we," "our," or "us") is a healthcare software company providing an electronic health record (EHR), scheduling, billing, and practice management platform for physical therapy and wellness practices. Our registered address and contact details are provided at the end of this document.
When you create an account or subscribe to our services, we collect:
As a Business Associate under HIPAA, we process Protected Health Information (PHI) on behalf of covered entities (your practice). This includes:
PHI is processed only as directed by the covered entity (the practice) and governed by our Business Associate Agreement (BAA). We do not use PHI for any purpose other than providing our contracted services.
We automatically collect certain technical data when you use the platform:
We use collected information to:
We do not sell your personal data or PHI to third parties. We do not use PHI for advertising or marketing purposes.
We may share information with:
Cowboy Systems acts as a Business Associate under HIPAA. We maintain appropriate administrative, physical, and technical safeguards to protect PHI as required by the HIPAA Security Rule. A signed BAA is available with all Growth and Enterprise plans. For more detail, see our HIPAA Compliance Statement.
We retain practice and account data for the duration of your subscription plus a minimum of 7 years, or as required by applicable law (including state-specific medical record retention laws). PHI retention periods are governed by the terms of the BAA and applicable state law. You may request deletion of non-PHI personal data by contacting us at the address below.
We implement industry-standard security measures including:
Our website and application use cookies and similar technologies to maintain sessions, remember preferences, and analyze usage. You may disable cookies in your browser settings, though some platform features may not function correctly without them. We do not use third-party advertising cookies on the clinical application.
Depending on your jurisdiction, you may have rights to:
To exercise any of these rights, contact us at privacy@cowboysystems.com. We will respond within 30 days.
Our platform is not directed at children under 13. We do not knowingly collect personal information from children under 13 without parental consent. PHI relating to minor patients is handled in accordance with HIPAA and applicable state law governing minor patient records.
We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notice at least 30 days before taking effect. Continued use of the platform after the effective date constitutes acceptance of the updated policy.
For privacy questions, data requests, or to report a concern:
Email: privacy@cowboysystems.com
Company: Cowboy Systems
Website: cowboysystems.com