DocumentAssist — Privacy Policy
Last updated: August 19, 2026
DocumentAssist is an internal Chrome extension built for the clinical staff of Mariam Maniya Internal Medicine PC d/b/a Maniya Health Medical Group. It is distributed by administrator policy and is not intended for public use. This policy describes what the extension handles, where it goes, and what is retained.
What the extension does
On a patient document page in the Practice Fusion EHR, a clinician right-clicks and chooses "Analyze medical document" and a document type. The extension then reads the document PDF already displayed in that page and sends it, with a summarization prompt, to our organization's own Google Cloud Vertex AI project. The summary is displayed in a panel next to the document. Nothing happens unless the user explicitly invokes the menu item.
Data the extension handles
- Health information and website content. The patient document (PDF) displayed on the page, and the model-generated summary of it.
- Personally identifiable information. The patient name and date of birth shown in the EHR's patient ribbon, used to label the summary panel so a clinician cannot mistake which patient a summary belongs to. The identifier of the signed-in EHR user, recorded in a local audit entry.
- Authentication information. The document stream URL provided by Practice Fusion includes a short-lived access parameter, which the extension reuses to retrieve the document from Practice Fusion's own servers. Where an administrator configures the extension locally rather than by policy, a shared secret for our token endpoint is stored in extension storage on that device. Neither is transmitted to any party other than the service it authenticates to.
Where data goes
- The document PDF and the resulting summary travel from the clinician's browser to Google Cloud Vertex AI only — specifically, to our organization's own Google Cloud project, which is covered by our Business Associate Agreement with Google. They are processed for the sole purpose of generating the requested summary.
- Our token endpoint receives only a request for a short-lived access token. It has no request body. It never receives document content, patient identifiers, or model output.
- The prompt configuration is retrieved read-only from a Google Sheet. No patient data, user data, or document content is sent to it.
- No data is sold, rented, or transferred to any third party other than Google Cloud acting as our service provider under the Business Associate Agreement described above. No data is used for advertising, profiling, credit assessment, lending decisions, or any purpose unrelated to producing the requested document summary.
Retention
- The document PDF and the summary are not stored by the extension. They exist in the page while the panel is open and are discarded when the tab is closed or navigated away.
- The extension stores, in local browser storage on the clinician's own device: the feature on/off setting, administrator configuration values, cached menu labels and prompt text, and a capped list (most recent 200) of audit entries containing the EHR user identifier, the document identifier, and a timestamp. Audit entries record that an analysis occurred; they never contain document content, patient names, or model output. They exist to support our practice's own access-audit obligations under HIPAA, and are retained on the device until the extension is removed or its data cleared.
- No analytics, telemetry, crash reporting, or usage tracking of any kind is collected.
Browsing activity
The extension runs only on practicefusion.com. It does not read, record, or transmit browsing history, visited URLs on other sites, clicks, keystrokes, scrolling, mouse position, or network activity.
Clinical use
Summaries produced by this extension are informational only. A qualified person must verify every summary against the source document before it is relied on for any clinical, billing, or operational purpose. The extension is not a medical device and is not a basis for autonomous clinical decisions. This disclaimer is displayed persistently in the summary panel.
Contact
Questions about this policy: help@maniyahealth.com — Mariam Maniya Internal Medicine PC d/b/a Maniya Health Medical Group.