Privacy Policy

Effective date: July 1, 2026

1. Who we are

Molarone (“Molarone,” “we,” “us,” or “our”) is a dental insurance billing automation platform operated by Molarone Inc. This Privacy Policy explains how we collect, use, disclose, and safeguard information when a dental practice (“Practice,” “you”) and its authorized users use molarone.com and our related services (the “Service”).

2. What data we collect

We collect the following categories of information:

  • Account information — practice name, NPI, tax ID, address, phone, billing email, and staff user credentials (name, email, role).
  • Protected Health Information (PHI) — patient demographic data, insurance eligibility and coverage details, claims, remittance (ERA) data, and related billing records that your Practice submits to or generates through the Service in the course of dental insurance billing.
  • Usage data — log data, device and browser information, and product usage events (e.g., pages viewed, features used) collected to operate, secure, and improve the Service.

3. How we use data

We use the information described above to:

  • Provide the Service, including eligibility checks, claims submission, and denial management;
  • Operate, maintain, secure, and improve the Service and troubleshoot issues;
  • Communicate with you about your account, support requests, and Service updates; and
  • Comply with our legal, regulatory, and contractual obligations.

We do not use PHI for advertising, and we do not sell PHI or any other personal information, under any circumstance.

4. HIPAA compliance

Molarone acts as a Business Associate, as defined under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), to Practices that qualify as Covered Entities. We enter into a Business Associate Agreement (“BAA”) with every Practice prior to processing PHI through the Service.

Our HIPAA safeguards include:

  • Encryption — PHI at rest is encrypted using AES-256-GCM; all data in transit is encrypted via TLS.
  • Access controls — row-level security (RLS) enforced at the database layer so that each Practice can only access its own data, combined with role-based permissions within a Practice’s account.
  • Minimum necessary — access to PHI is limited to what is reasonably necessary to provide and support the Service.
  • Audit logging — access to and modification of PHI is logged to support security monitoring and HIPAA-mandated audit controls.
  • Breach notification — in the event of a breach of unsecured PHI, we will notify affected Practices without unreasonable delay and in no event later than 60 days after discovery, consistent with the HIPAA Breach Notification Rule.

5. How we share data

We share data only as necessary to provide the Service, including with:

  • Payers and clearinghouses — to perform eligibility checks and submit claims and appeals on your Practice’s behalf;
  • Subprocessors and vendors — infrastructure and service providers who support our platform (e.g., hosting and database providers), each of whom has signed a BAA where they may handle PHI; and
  • Legal and safety — where required by law, subpoena, or to protect the rights, property, or safety of Molarone, our users, or others.

We do not sell personal information or PHI to third parties.

6. Data retention

We retain PHI and account data for as long as your Practice maintains an active account, and thereafter for the period required to meet our legal, regulatory, and contractual obligations (including HIPAA recordkeeping requirements). Upon termination of your account, you may request export or deletion of your data, subject to these retention obligations.

7. Security

We maintain administrative, physical, and technical safeguards designed to protect data against unauthorized access, alteration, disclosure, or destruction, including the encryption, access-control, and audit-logging measures described in Section 4. No method of transmission or storage is completely secure; we cannot guarantee absolute security, but we work to continuously improve our safeguards.

8. Your rights

Depending on your role and applicable law, you may have the right to:

  • Access, correct, or request deletion of personal information we hold about you;
  • Request a copy of the PHI processed on your Practice’s behalf; and
  • Object to or restrict certain processing of your information.

To exercise any of these rights, contact us at support@molarone.com. Individual patients should direct requests regarding their own health information to their dental Practice directly, as Molarone acts as the Practice’s service provider, not the Covered Entity.

9. Cookies

We use only essential cookies required to operate the Service — for example, to keep you signed in and to protect against cross-site request forgery. We do not use advertising or third-party tracking cookies.

10. Children’s privacy

The Service is intended for use by dental practices and their staff, not by individual children. We do not knowingly collect personal information directly from children. Patient records that include minors’ information are processed solely on behalf of, and at the direction of, the dental Practice as part of routine dental billing.

11. Contact us

Questions about this Privacy Policy or our data practices can be directed to support@molarone.com, Molarone Inc., or via molarone.com.