ChiroCode
  • Features
  • How It Works
  • Pricing
  • Compare
  • The Rules
  • Find a Chiropractor
Sign In Start Free Trial

Privacy Policy

Last updated: 11 August 2026

The short version. ChiroCode is software sold to chiropractic practices. Two very different kinds of information pass through it: information about the practice staff who use the software, and health information about their patients. We treat those differently. Patient health information belongs to the practice, not to us — we only handle it to provide the service, under a written agreement with that practice, and we never sell it or use it to train AI models.

1. Who we are

ChiroCode is operated by Joticle, Inc., a Nevada corporation ("Joticle", "we", "us"). This policy covers the ChiroCode web application at chiroverify.com and the marketing site that surrounds it.

Questions about this policy: privacy@chiroverify.com

2. The distinction that matters

Almost everything else in this policy depends on this section, so it comes first.

TypeWhose it isGoverned by
Practice & account data
names, work emails, logins, billing details of the clinicians and staff who use ChiroCode
Ours to control, as the service provider This policy
Patient health information (PHI)
patient records, appointments, clinical notes, diagnoses, claims
The practice's. We are a service provider handling it on their behalf Our Business Associate Agreement with that practice, and HIPAA

If you are a patient of a practice that uses ChiroCode, we are not the right people to ask about your records. Your provider controls them and decides who sees them. Contact your practice directly to see, correct, or ask questions about your information. We will help your practice answer you, but we cannot act on your record without their instruction.

3. What we collect

From practices and their staff

  • Name, work email address, telephone number, and job role
  • Practice name, address, tax identification number, and provider identifiers such as NPI
  • Login credentials — passwords are stored only as salted hashes, never in readable form
  • Billing and subscription details. Card numbers are handled by our payment processor and never touch our servers
  • Support correspondence you send us

Automatically, when the application is used

  • IP address, browser and device type, and pages visited
  • Timestamps and audit records of actions taken in the application — who viewed or changed which record, and when. This is a HIPAA requirement, not an analytics choice, and it cannot be switched off

On behalf of practices

Whatever the practice enters or imports: patient demographics, contact details, appointments, clinical notes, diagnosis and procedure codes, insurance and claims data, and documents they upload. We do not decide what this contains — the practice does.

4. Why we use it

  • To provide, maintain, and secure the service
  • To authenticate users and enforce who may see which records
  • To send service messages — password resets, billing notices, and system notifications
  • To send appointment reminders to patients, on the practice's behalf and only where the practice has recorded that patient's consent (see section 7)
  • To provide support, and to investigate problems and security incidents
  • To meet legal, tax, and regulatory obligations

5. What we do not do

These are commitments, not aspirations.

  • We do not sell personal information or patient health information. Not to anyone, for any price
  • We do not use patient health information to train, fine-tune, or improve artificial intelligence models — ours or anyone else's — including in de-identified or aggregated form, except where a practice has given specific written permission
  • We do not use patient health information for advertising or marketing
  • We do not combine one practice's data with another's. Every record is scoped to the practice that owns it
  • We do not disclose patient health information to third parties except as needed to run the service, and only under agreements that impose these same obligations

6. Who else touches the data

We use third-party providers to run ChiroCode. Those that handle patient health information do so under a Business Associate Agreement or equivalent contractual protections.

PurposeWhat they see
Application and database hostingAll data stored in the service
File storage for uploaded documentsDocuments a practice uploads
Transactional email deliveryRecipient name, email address, message content
Text message deliveryRecipient phone number, practice name, appointment date and time
Payment processingBilling contact and payment details. Never patient data
Insurance claim clearinghouseClaim data submitted by the practice
AI-assisted code suggestionClinical note text a provider submits for coding assistance

We may also disclose information where the law requires it — a subpoena, a court order, or a regulator's lawful demand — and to protect the rights or safety of our users. Where a legal demand concerns patient health information, we notify the affected practice before responding unless we are legally barred from doing so.

If ChiroCode is acquired or merged, data may transfer as part of that transaction. Notice would be given, and any acquirer would be bound by commitments no weaker than these.

7. Text messages and email reminders

ChiroCode can send appointment reminders to patients by text message and by email, on behalf of the practice.

  • Every patient starts opted out. Consent is never assumed from the fact that a phone number is on file
  • Consent is collected by the practice's own staff from their own patients, and recorded against the patient's record with a timestamp
  • The number used for reminders is stored separately from the general contact number, so a landline is never texted
  • Reminders contain the practice name, the appointment date and time, and opt-out instructions. They contain no clinical information
  • Replying STOP opts a patient out permanently, and that opt-out overrides any later consent entry
  • Message and data rates may apply. Message frequency varies by appointment schedule
  • We do not send marketing text messages, and mobile numbers collected for reminders are never shared or sold for marketing

8. Security

What we actually do:

  • Data encrypted in transit using TLS
  • Passwords stored only as salted hashes
  • Role-based access control, with records scoped to the owning practice and provider
  • Audit logging of access to and changes of patient records, retained for at least six years
  • Regular backups

Plainly: no system is perfectly secure, and we do not claim otherwise. We hold no third-party security certification at this time and will say so rather than imply one. If a breach affects patient health information, we notify the affected practice promptly under our agreement with them, and the practice notifies affected individuals as HIPAA requires.

9. How long we keep it

  • Patient health information — for as long as the practice's account is active. On termination it is returned or destroyed at the practice's election, as their agreement with us provides
  • Audit records — at least six years, as HIPAA requires
  • Account and billing records — as long as needed for tax, accounting, and legal obligations
  • Deleted records — deactivated rather than erased where a medical or audit record must be preserved. A deleted clinical record is a deleted medical record, and that is rarely the right outcome

10. Your rights

Practice staff and account holders may ask us to access, correct, export, or delete their own account information, and may object to certain processing. Write to privacy@chiroverify.com.

Patients should contact their practice, which controls the record. See section 2.

Depending on where you live, you may have additional rights — for example under the California Consumer Privacy Act, or the Washington My Health My Data Act. We honour those rights where they apply. We do not sell or share personal information for cross-context behavioural advertising, so there is nothing to opt out of on that front.

11. Cookies

We use cookies that are necessary for the service to function — keeping you signed in, remembering your preferences, and protecting forms against cross-site request forgery. Blocking these will break sign-in. We do not use advertising or cross-site tracking cookies.

12. Where data is held

Data is stored and processed in the United States. We do not intend the service for use outside the United States.

13. Children

ChiroCode is a professional tool, and accounts are for practice staff only — not for anyone under 18. Practices do treat minor patients, and records about them are patient health information under section 2, controlled by the practice.

14. Changes

We will update this policy as the service changes. The date at the top always reflects the current version. Where a change materially affects how we handle information, we will notify account holders by email rather than relying on you to notice.

15. Contact

Joticle, Inc.
privacy@chiroverify.com
Support: support@chiroverify.com

ChiroCode

Chiropractic EHR with a claim compiler built in.

Product

  • Features
  • How It Works
  • Pricing

Patients

  • Find a chiropractor

Legal

  • Privacy Policy
  • Terms of Use
© 2026 Joticle, Inc. All rights reserved.
ChiroCode provides coding assistance tools for informational purposes only.