Related Posts

Privacy Policy

Last Updated: August 31, 2026

EnSoftek, Inc. (EnSoftek) owns and operates this drcloudehr.com website business. All references to “we”, “us”, this “website” or this “site” shall be construed to mean EnSoftek. We understand that visitors to this website are concerned about the privacy of information and we value your privacy. The following describes our privacy policy regarding information, including Personal Information, that we collect through this website. By using this website you are accepting the practices described in this Privacy Policy.

HOW WE MODIFY THIS PRIVACY POLICY

We reserve the right to modify this Privacy Policy at any time, and without prior notice, by posting an amended Privacy Policy that is always accessible by clicking on the “Privacy Policy” link on this site’s home page. Your continued use of this site indicates your acceptance of the amended Privacy Policy.

You should check the Privacy Policy through this link periodically for modifications by clicking on the link provided near the top of the Privacy Policy for a listing of material modifications and their effective dates.

Regarding Personal Information (defined below), if any modifications are materially less restrictive on our use or disclosure of the Personal Information previously disclosed by you, we will obtain your consent before implementing such revisions with respect to such information.

HIPAA PROVISIONS

What We Do.  We provide data processing services to Covered Entities under the Health Insurance Portability and Accountability Act (HIPAA) of 1996, as amended, including without limitation amendments by the Health Information Technology for Economic and Clinical Health (HITECH) Act (collectively referred to herein as “HIPAA”).

The EnSoftek services have been developed for health and human services organizations (“providers”) who have subscribed to the services. In the process of providing our services, we may access, receive, process, maintain, archive, and/or transmit information defined by HIPAA as Protected Heath Information (PHI) and/or Electronic Protected Health Information (ePHI) from our Covered Entity customers (PHI and ePHI are collectively referred to herein as “PHI”).

USE AND DISCLOSURE OF PHI.

We may use or disclose PHI on behalf of, or to provide services to, Covered Entities for purposes of performing our obligations under our services agreements to Covered Entities, provided that such use or disclosure is permitted or required by the applicable Business Associate Agreement and would not violate HIPAA, including its Privacy Rule or Security Rule as applicable to Business Associates.

We may use PHI internally for our own internal management, administration, data aggregation and legal obligations, but only to the extent such use of PHI is permitted or required by the applicable Business Associate Agreement and would not violate HIPAA, including its Privacy Rule or Security Rule as applicable to Business Associates.

We may disclose PHI for law enforcement purposes as required by law or in response to a valid subpoena.

We may disclose PHI to downstream subcontractors or agents that provide supporting services to us; however, we will require such subcontractors and agents to comply with the same terms and conditions that apply to us under the applicable Business Associate Agreement and PHI, including the implementation and maintenance of required safeguards.

Safeguards.  We have established and maintain safeguards that are required by the applicable Business Associate Agreement and HIPAA, including its Privacy Rule and Security Rule as applicable to Business Associates.  These safeguards include administrative, physical, and technical safeguards that are reasonable and appropriate for the protection of the PHI that we access, receive, process, maintain, archive, and/or transmit on behalf of our Covered entity customers.

THE TYPES OF NON-PHI INFORMATION WE COLLECT

Personal Information. In addition to PHI, we collect Personal Information about you when you register to use the services and that may be used to identify you (“Personal Information”). Personal Information that we collect may vary with each separate purpose for which you provide it, and it may include one or more of the following categories: name, physical address, an email address, phone number, and credit card information including credit card number, expiration date, and billing address.

For purposes of this Privacy Policy, the term “Personal Information” does not include any PHI (PHI is governed under the Section titled “HIPAA” Provisions above.

Non-Personal Information. We reserve the right to collect anonymous information such as your browser type, the URL of the previous website you visited, your computer’s operating system and Internet protocol (IP) Address, Internet domain and host name, your Internet Service provider, your clickstream data, and the dates and times that you may access this site and specific pages (Non-Personal Information”). Non-Personal Information is essentially anonymous when collected; however, it’s possible that Non-Personal Information could be used to identify you.

HOW AND WHEN WE COLLECT NON-PHI INFORMATION

Personal Information. We collect Personal Information at the time you provide it to us. We collect Personal Information through sign-up forms and as part of your registration for an account, product, or service from this website. Personal information that we collect may vary with the each sign-up or registration.

Your Communications With Us. We collect Personal Information that we receive from you as you communicate with us.

Passive and Analytical Information. We reserve the right to monitor your use of this site. As you navigate through this site, Non-Personal Information may be passively collected (that is, gathered without your actively providing the information) using various analytics and reporting technologies, such as cookies and web beacons.

HOW WE USE YOUR NON-PHI INFORMATION

We use your Personal Information for the performance of the services or transaction for which it was given, our private, internal reporting for this site, and security assessments for this site.

We do NOT tie or link your Personal Information to Non-Personal Information with persistent identifiers. For example, we would not tie or link your email address (Personal Information) with information collected by a cookie regarding the length of time you visit our site (Non-Personal Information).

We reserve the right to make full use of Non-Personal Information. For example, we may use Non-Personal Information to provide better service to site visitors, customize the site based on your preferences, compile and analyze statistics and trends about the use of this site, and otherwise administer and improve this site for your use.

HOW WE DISCLOSE YOUR NON-PHI INFORMATION

General Disclosure Policy. Our general policy is that we will not share, sell, or rent your Personal Information to others. The only exceptions to this general policy: (i) are described in the subsections below, and (ii) if you explicitly approve through our site. We reserve the right to disclose Non-Personal Information without restriction.
Mobile Information Exception. Notwithstanding any other provision of this Privacy Policy, no mobile information – including mobile telephone numbers, SMS or text messaging consent, and opt-in data – will be shared, sold, rented, leased, or otherwise transferred to any third parties, affiliates, subsidiaries, or lead generators for marketing or promotional purposes at any time. This restriction takes precedence over every other disclosure provision in this Privacy Policy, including the subsections below. All other categories of Personal Information may be shared only as described in this Privacy Policy.

Disclosure to Affiliated Entities. We reserve the right to provide your Personal Information to any affiliated entities we may have, including our subsidiaries. This does not apply to mobile information. Mobile telephone numbers, SMS consent, and opt-in data are never shared with affiliated entities, subsidiaries, or any other party for marketing or promotional purposes.

Disclosure to Service Providers and Online Partners for Website Operations. We reserve the right to disclose your Personal Information to our trusted service providers that assist us with the operation and maintenance of this site. For example, we may use third parties to process payments, host our servers, provide security, and provide production, fulfillment, optimization, analytics, and reporting services. We will take commercially reasonable efforts to cause these third parties to agree to hold your information in confidence or to disclose information only to third parties that we believe in good faith are trustworthy regarding the confidentiality of your information. With respect to our text messaging program, mobile telephone numbers and SMS opt-in data are disclosed only to the licensed telecommunications carriers and messaging service providers strictly necessary to transmit the messages you have requested. These providers are contractually prohibited from using mobile information for their own marketing or promotional purposes, and from selling, renting, or further disclosing it. No mobile information is shared with advertisers, data brokers, lead generators, or analytics partners.

Disclosure to Successors. If we are acquired by or merged with a third party entity, or if we sell this website business or a line of business from this website, we reserve the right to transfer such information as part of such merger, acquisition, sale, or other change of control. In the unlikely event of our bankruptcy, insolvency, reorganization, receivership, or assignment for the benefit of creditors, or the application of laws or equitable principles affecting creditors’ rights generally, we reserve the right to transfer such information to protect our rights or as required by law. Any successor entity will remain bound by the mobile information restrictions in this Privacy Policy. Mobile telephone numbers and SMS consent data will not be used for marketing or promotional purposes by any successor without obtaining new, separate consent from you.

Disclosure Incident to Legal Process and Enforcement. We reserve the right to disclose your Personal Information if we have a good faith belief that access, use, preservation or disclosure of such information is reasonably necessary (i) to satisfy any applicable law, regulation, legal process or enforceable governmental request (such as for example, to comply with a subpoena or court order), or (ii) to investigate or enforce violations of our rights or the security of this site.

SMS AND TEXT MESSAGING PROGRAM

Consent to Receive Text Messages. EnSoftek, Inc. and its DrCloudEHR platform offer text messaging (SMS/MMS) services. You will only receive text messages from us if you have expressly opted in to receive them. We obtain your consent through one or more of the following methods: completing a web form on our website that includes a text messaging consent checkbox; completing a paper or electronic intake, registration, or communication-preferences form provided by your care provider; providing verbal consent that is documented in your record; or replying to a text message with a designated opt-in keyword. Consent to receive text messages is not a condition of purchasing any goods or services, and is not a condition of receiving care or services from any provider.

Information We Collect for Text Messaging. In connection with our text messaging program, we collect your mobile telephone number, records documenting how and when you provided consent, your messaging preferences, and records of messages sent to and received from you, including your responses to keywords such as STOP and HELP.

How We Use Text Messaging Information. We use this information solely to deliver the messages you have requested, to honor your opt-out and support requests, to maintain records of consent as required by applicable law and carrier requirements, and to troubleshoot delivery issues.

No Sharing or Sale of Mobile Information. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes at any time. We do not sell, rent, lease, or trade mobile telephone numbers, SMS consent, or text messaging opt-in data to any third party under any circumstances. Text messaging originator opt-in data and consent are not shared with any third parties or affiliates, excluding aggregators and licensed telecommunications providers who deliver the messages on our behalf and who are contractually prohibited from using that information for any other purpose.

Types of Messages. Depending on the program you have opted into, messages may include appointment reminders and confirmations, notifications that a secure message or document is available in your patient portal, account and service notifications, service updates, and customer support responses.

Message Frequency. Message frequency varies based on your interactions with us and the program you have enrolled in. You may receive up to messages per month.

Message and Data Rates. Message and data rates may apply. Your mobile carrier’s standard messaging and data charges will apply to all messages sent to and received from us. We are not responsible for these charges. Carriers are not liable for delayed or undelivered messages.

How to Opt Out. You may cancel text messages at any time by replying STOP to any message you receive from us. After you send STOP, we will send you a single confirmation message and will send no further text messages unless you opt in again. You may also opt out by contacting us using the information in the “Contacting EnSoftek” section below.

How to Get Help. For assistance, reply HELP to any message from us, email legal@ensoftek.com, or call (503) 643-1226.

Supported Carriers. Our text messaging program is supported by major U.S. wireless carriers.

Protected Health Information and Text Messaging. Standard text messaging is not a secure or encrypted channel. We limit the content of text messages so that they do not disclose diagnoses, treatment details, medications, or other sensitive Protected Health Information. Messages may include limited identifying information such as your name, the name of your provider organization, and appointment date and time. Your consent to receive text messages is separate from, and does not substitute for, any HIPAA authorization or provider consent you may give. Where a health care provider uses the DrCloudEHR platform to communicate with you, that provider is the covered entity responsible for the content of those communications, and EnSoftek acts as its business associate.

Terms and Conditions. 

DrCloudEHR may use SMS/text messaging to provide security-related and transactional communications, including one-time passcodes (OTPs) and two-factor authentication (2FA) verification codes used to verify your identity and help protect access to your DrCloudEHR account.

Consent to Receive Text Messages: By providing your mobile phone number and opting in to receive text messages from DrCloudEHR, you consent to receive transactional SMS/text messages at the mobile number you provide. These messages may include one-time security codes, authentication codes, account verification messages, and other security-related notifications.

Consent to receive text messages is not a condition of purchasing any product or service.

Message Frequency: Message frequency varies based on your use of DrCloudEHR and the number of authentication or security verification requests associated with your account.

Message and Data Rates: Standard message and data rates may apply. Your mobile carrier’s messaging and data rates and other applicable charges are your responsibility.

Opt-Out / STOP: You may stop receiving SMS/text messages by replying STOP to the number from which you received the message. After submitting a STOP request, you may receive a confirmation message indicating that you have been unsubscribed.

Please note that opting out of SMS messages may prevent you from using SMS as a method of two-factor authentication. Where available, you may need to select another supported authentication method to access your account.

Help / Customer Support: For assistance with SMS/text messaging, reply HELP to the number from which you received the message or contact DrCloudEHR Customer Support at [support@drcloudehr.com].

 Mobile Carrier Disclaimer: Carriers are not liable for delayed or undelivered messages. Message delivery is subject to effective transmission by your mobile carrier and is not guaranteed by DrCloudEHR.

Supported Carriers and Mobile Numbers: SMS/text messaging functionality depends on your mobile device, mobile carrier, network availability, and the accuracy of the mobile number associated with your account. You are responsible for providing and maintaining a current and valid mobile phone number.

Privacy: DrCloudEHR uses your mobile phone number and SMS/text messaging information in accordance with the DrCloudEHR Privacy Policy. Information collected in connection with the SMS/text messaging program will be used to provide authentication, security, and related transactional communications.

DrCloudEHR does not use enrollment in its 2FA SMS program to send marketing or promotional text messages unless separate consent for such communications has been obtained.

Security of Authentication Codes: One-time passcodes and authentication codes are intended only for the individual requesting access to the applicable account. You should never share a security or authentication code with another person. DrCloudEHR personnel will not ask you to provide your one-time authentication code by telephone, email, or text message.

Changes to SMS Terms: DrCloudEHR may modify these SMS/Text Messaging Terms and Conditions from time to time to reflect changes to our services, technology, legal requirements, or messaging practices. Updated terms will be posted on the DrCloudEHR website.

SPECIFIC INFORMATION ABOUT COOKIES AND WEB BEACONS

3rd Party Cookies for Web Analytics and Reporting. We reserve the right to use web analytics services provided by 3rd parties. These services use 3rd party cookies (cookies passed by others, not by us) to collect Non-Personal about your use of this site. These web analytics services may also transfer this information to third parties where required to do so by law, or where such third parties process the information on the service’s behalf.

3rd Party Cookies for Serving Behavioral Ads. We reserve the right to serve our ads and third party ads on our site that are targeted to your interests (“3rd Party Behavioral Ads”). 3rd Party Behavioral Ads are served by 3rd party advertising services that use 3rd party cookies (cookies passed by others, not by us) to collect Non-Personal Information about your use of this site and other websites. This information is your “behavioral data”. 3rd Party Behavioral Ads do not use your Personal Information. Instead, they associate your behavioral data on visited sites with your computer, so that the ads your computer sees on this site are more likely to be relevant to your interests. These advertising services may also transfer this information to third parties where required to do so by law, or where such third parties process the information on the service’s behalf. We will provide notice and the opportunity to opt-out of receiving 3rd Party Behavioral Ads.

Participation in Google’s Adsense Network. We reserve the right to participate in Google’s AdSense network for purposes of serving 3rd Party Behavioral Ads. Google uses DoubleClick’s DART cookie in its AdSense network. You may opt out of the use of the DART cookie. For information regarding how to opt out, go to http://www.google.com/privacy_ads.html .

No Mobile Information in Advertising. Mobile telephone numbers, SMS consent records, and text messaging opt-in data are never used for, shared with, or made available to any advertising service, behavioral advertising network, ad exchange, or audience-matching platform, including Google AdSense. Mobile information collected through our text messaging program is entirely segregated from our website advertising and analytics operations.

DATA SECURITY FOR NON-PHI INFORMATION

We follow reasonable and appropriate industry standards to protect your Personal Information and data. Unfortunately, no data transmission over the Internet or method of data storage can be guaranteed 100% secure. Therefore, while we strive to protect your Personal Information by following generally accepted industry standards, we cannot ensure or warrant the absolute security of any information you transmit to us or archive at this site.

When you transmit Personal Information through our registration process or if you purchase products or services, we encrypt that information in transit using secure socket layer technology (SSL).

After the secure transfer of your Personal Information, the information is maintained and stored with 256-bit encryption.

ONWARD TRANSFER OUTSIDE YOUR COUNTRY OF RESIDENCE

Any Personal Information which we may collect on this site will be stored and processed in our servers located only in the United States. By using this site, if you reside outside the United States, you consent to the transfer of Personal Information outside your country of residence to the United States.

UPDATING PERSONAL INFORMATION

Upon request, we will permit you to request or make changes or updates to your Personal Information for legitimate purposes. We request identification prior to approving such requests. We reserve the right to decline any requests that are unreasonably repetitive or systematic, require unreasonable time or effort of our technical or administrative personnel, or undermine the privacy rights of others. We reserve the right to permit you to access your Personal Information in any account you establish with this site for purposes of making your own changes or updates, and in such case, instructions for making such changes or updates will be provided where necessary.

EMAIL AND TEXT MESSAGE COMMUNICATIONS; OPT-OUT

This site treats email messages and other electronic messages that are sent through this site and not viewable by others as confidential and private, except as required by law, including without limitation, the Electronic Communications Privacy Act of 1986, 18 U.S.C. Sections 2701-2711 (the “ECPA”). The ECPA permits this site’s limited ability to intercept and/or disclose electronic messages, for example (i) as necessary to operate our system or to protect our rights or property, (ii) upon legal demand (court orders, warrants, subpoenas), or (iii) where we receive information inadvertently which appears to pertain to the commission of a crime. This site is not considered a “secure communications medium” under the ECPA.

If you supply us with your e-mail address you may receive periodic messages from us with information specific to the site and required for the normal functioning of the site as well as for new products or services or upcoming events. If you prefer not to receive periodic email messages, you may opt-out by following the instructions on the email.

LINKS TO OTHER SITES; ONLINE ADS

This site may contain links to other websites with whom we have a business relationship. These links may include online advertisements that we deem to be appropriate. Any information that you provide in the process of registration or purchase will be transferred to these sites. We have no responsibility or liability for the policies and practices of these sites; however, we have entered into agreements with these websites which provide that unless you specifically agree otherwise, they will use and share your Personal Information only for the purpose of providing or fulfilling your request for products or services. You should be careful to review any privacy policies posted on any of these sites before providing information to them.

CHILDREN’S ONLINE POLICY

The Services are not permitted for use by individuals under the age of eighteen (18) unless they have provided the written consent of their parents or legal guardians, and we request that these individuals do not provide Personal Information to us.

CONTACTING ENSOFTEK

If you have questions about the privacy aspects of our Services or would like to make a complaint about our compliance with this Privacy Policy, you may contact us at legal@ENSOFTEK.com, by calling 503-643-1226, or at our mailing address:

EnSoftek, Inc.

735 SW 158th Ave,

Beaverton, OR 97006.