Privacy Policy

Beloved Minds LLC · Effective September 27, 2026 · Version 1.1

Who we are

Beloved Minds LLC ("Beloved Minds," "we," "us") provides daily AI phone calls to residents of memory care and assisted living communities, in partnership with those facilities and residents' families.

Under HIPAA, Beloved Minds operates as a Business Associate to the memory care facilities we serve, which are the Covered Entities. We access Protected Health Information (PHI) only as permitted by our Business Associate Agreement with each facility and as required or permitted by HIPAA.

This page describes our privacy practices. Where it differs from an executed Business Associate Agreement or from applicable law, applicable law controls first and the Business Associate Agreement controls second; where more than one applies, the stricter requirement governs. This page is not incorporated into the Facility Services Agreement or any Order Form, and it creates no contractual rights.

Information we access

Resident information

Call data

Beloved Minds does not collect, store, or process resident billing or insurance information, clinical records, medication data, or diagnostic information. Our access is limited strictly to what is necessary to deliver personalized calls.

How we use it

We do not use PHI to train artificial intelligence models. We do not use or disclose PHI for marketing purposes, and we do not sell PHI.

Minimum necessary

Access to PHI is limited to personnel who require it for their specific job functions. System access is role-based and restricted by technical controls. Information shared with subcontractors or technology vendors is limited to what is essential to their function. Information disclosed to a resident's authorized family contact is limited to that resident's own information.

Security

All subcontractors and technology vendors who access PHI on our behalf must execute a Business Associate Agreement and maintain safeguards equivalent to those required by HIPAA. Executed agreements are maintained on file and available to facility clients on request.

How long we keep it

Where information cannot be destroyed because of a genuine technical limitation, we document the limitation and the safeguards in place, and we destroy the information as soon as the limitation is resolved. Anything retained in that situation stays protected under HIPAA for as long as we hold it.

Where we retain or use de-identified data, de-identification is performed in accordance with the HIPAA Safe Harbor method (45 CFR 164.514(b)(2)), removing all eighteen categories of identifiers. Data that has not been de-identified to that standard is treated as PHI.

Mitigation

If we become aware of a use or disclosure of PHI that violates this policy, an applicable Business Associate Agreement, or HIPAA, we take reasonable steps to mitigate any harmful effect of that use or disclosure to the extent practicable, and we document the steps taken.

Breach notification

We notify the affected facility of any Security Incident, meaning any attempted or successful unauthorized access, use, disclosure, modification, or destruction of PHI, or interference with system operations involving PHI, whether or not it rises to the level of a reportable breach. Notice of an unsuccessful Security Incident, one that does not result in unauthorized access to or disclosure of PHI, may be provided in aggregate form on a periodic basis rather than individually.

In the event of a breach of unsecured PHI, we will notify the affected facility without unreasonable delay and no later than fifteen (15) calendar days after discovery, or sooner where the applicable Business Associate Agreement requires; describe the nature of the information involved and what occurred; cooperate fully with any notifications the facility must make; and document the breach and our response as HIPAA requires. We maintain a separate Breach Response Plan covering internal procedures for identifying, containing, investigating, and reporting incidents.

Facility personnel who observe or suspect a privacy or security incident involving Beloved Minds systems or data should report it immediately to our HIPAA Compliance Officer, using the contact details below.

Resident and family rights

Requests from residents or their authorized representatives to access, amend, or receive an accounting of PHI are directed to and handled by the facility, not by Beloved Minds. Where a facility needs information we hold in order to respond, we provide it within the timeframe specified in the applicable Business Associate Agreement, or promptly if no timeframe is specified.

Where a resident or their representative believes information we hold is inaccurate — including an observation, Priority Alert, summary, or synopsis generated by the service — a request for amendment is directed to the facility. Where the facility determines an amendment is warranted, we correct the record and, where practicable, notify any party to whom the inaccurate information was previously disclosed.

Beloved Minds does not independently evaluate individual rights requests and does not determine whether a requesting party holds legal authority; that determination rests with the facility. This does not apply to a resident's profile, including Family-Seeded Memories, which is maintained through the family dashboard.

Website visitors

If you contact us through this website, the information you submit — your name, facility, email address, and message — is sent to us by email so that we can respond to your enquiry. We use it for that purpose only. We do not sell it, and we do not add you to marketing lists without your consent. This website does not use advertising or tracking cookies.

State law

In addition to HIPAA, Beloved Minds complies with applicable state privacy and breach-notification laws in the states where it operates and where affected individuals reside. Where state law imposes stricter requirements than HIPAA, the stricter requirement applies.

Changes to this policy

This policy is reviewed at least annually and updated as needed to reflect changes in our services, applicable law, or regulatory guidance. Material changes are communicated to facility clients. Where a change affects the terms of an existing Business Associate Agreement, that agreement is updated accordingly.

Complaints and contact

Facilities, residents (through their facilities), or any individual with concerns about our privacy practices may contact our HIPAA Compliance Officer:

Rebecca McCallum, Co-Founder & CEO · HIPAA Compliance Officer
Beloved Minds LLC · Boise, Idaho
support@belovedminds.care

Individuals also have the right to file a complaint with the U.S. Department of Health and Human Services, Office for Civil Rights: HHS Office for Civil Rights, 200 Independence Avenue S.W., Washington, D.C. 20201 · 1-800-368-1019 · hhs.gov/ocr. Beloved Minds will not retaliate against any individual for filing a complaint in good faith.

Our full HIPAA Privacy Policy, including internal safeguards and workforce procedures, is available to facility clients on request.