
Effective date: April 2026 · Last updated: April 2026
This notice describes how medical information about residents may be used and disclosed and how residents can get access to this information. Please review it carefully.
Care-Call.AI is operated by NIUSIA CO.,LTD. When a Covered Entity — such as an Assisted Living facility, skilled nursing facility, or home-care agency regulated by the Health Insurance Portability and Accountability Act of 1996 ("HIPAA") — enrolls residents on Care-Call.AI, NIUSIA acts as a HIPAA Business Associate as defined in 45 CFR §160.103.
Before ingesting any Protected Health Information ("PHI") we execute a Business Associate Agreement ("BAA") with the facility. That BAA, together with this Notice, the Privacy Policy, and the Terms of Service, governs how we handle PHI.
We use and disclose PHI only for the following purposes:
Any other use of PHI — for example, marketing, research, or sale — requires explicit written authorisation from the resident or their legal representative.
Care-Call.AI relies on large language models and realtime voice models from OpenAI, L.L.C. and Anthropic, PBC to deliver the Service. All PHI is sent to these sub-processors over TLS 1.2+ under zero-retention contractual terms, meaning the providers do not retain or train on PHI. NIUSIA maintains signed BAAs or DPAs equivalent to a BAA with every sub-processor that can touch PHI.
Each resident has the right to:
Rights requests should be submitted through the facility administrator, who will verify identity and forward the request to NIUSIA. We respond within 30 days, with one 30-day extension permitted.
In the event of an unauthorised acquisition, access, use, or disclosure of unsecured PHI, we will notify the affected Covered Entity without unreasonable delay and in no case later than 60 days after discovery, in accordance with 45 CFR §164.410. The notification will include a description of the incident, the types of PHI involved, mitigation steps taken and our recommendations for the Covered Entity's own notification obligations.
PHI is retained according to the schedule in the Privacy Policy §6 and is cryptographically erased at end-of-life. On termination of the BAA we will, at the Covered Entity's direction, either return or destroy all PHI in our possession and provide written certification of destruction.
NIUSIA CO.,LTD. HIPAA Privacy Officer
Contact: use the contact form on our website and select the Privacy category.
Office: NIUSIA CO.,LTD., Tokyo, Japan
You may also file a complaint with the US Department of Health and Human Services, Office for Civil Rights, 200 Independence Avenue SW, Room 509F HHH Bldg., Washington DC 20201, or online at hhs.gov/hipaa/filing-a-complaint.