Form693 Get started

Privacy

This policy describes how FORM693 LLC (“Form693,” “we”) collects and uses information about visitors to this website and practices with a Form693 account. It does not govern patient records: Form693 holds those on behalf of your practice as its business associate, under HIPAA and the Business Associate Agreement with that practice, and nothing in this policy limits those protections.

Last updated 19 August 2026.

Information we collect

Account information: When you sign up at start.form693.com, we collect the email address you verify, your practice’s details, the plan you select, and a record of the agreements you accepted, including their version and date. Verification codes and service notices are delivered through an email delivery provider, which processes the address and the message.

Correspondence: If you contact us through the questions panel or the get-started form, we retain your name, your practice, your contact details and your message in order to respond and to maintain the conversation. We do not share this information, and contacting us does not add you to any marketing list.

Billing: Payments are processed by Stripe. Form693 does not store your card number, and Stripe receives only the subscription itself — never a patient name, a date of birth, or any identifier that resolves to a person.

Server logs: This site keeps standard server logs — IP address, timestamp, pages requested and browser type — for security and operations. They are not combined with other data and are not used to build profiles.

Cookies and analytics

This website uses Google Analytics to understand how its pages are used. Google Analytics sets cookies in your browser, and Google receives your IP address, the page you are viewing and the page you came from. We do not use advertising networks or retargeting, and nothing on this site is personalized to you. The questions panel on this site uses Cloudflare Turnstile to prevent automated abuse; it is a security control, not analytics, and it runs only inside the panel. The patient portal is different. The pages your applicants use to upload their records contain no analytics, no tag manager and no third-party scripts. The page where a patient begins uses Google reCAPTCHA to prevent automated abuse; it is a security control, not analytics, and it receives no patient information.

Patient information and email

Do not send patient information by email. The product is designed to carry it; ordinary email is not. Protected health information that reaches us by email is handled under the same safeguards as everything else, and we will notify you that it arrived.

Protected health information

Patient records do not pass through this website and are not governed by this policy. The following terms apply to them.

The clinic is the covered entity; Form693 is its business associate

The use and disclosure of patient records is governed by HIPAA and by the Business Associate Agreement with your practice, not by this policy. In the event of any inconsistency between this policy and the Business Associate Agreement, the Business Associate Agreement governs.

A Business Associate Agreement precedes any patient data

On the self-serve plans, the Business Associate Agreement is accepted at signup, before the account can hold any patient information. See Security for how records are encrypted and logged, how long they are retained, and how they are exported and deleted.

Patient records are never shared

Patient records are not shared with anyone, for any purpose, at any time.

When this policy changes, the date at the top of this page is updated, and a change that materially affects a clinic under a Business Associate Agreement is communicated to that clinic directly. Questions, security concerns and suspected breaches can be reported through the questions panel.