Arrowhealth Bridge

Effective date: September 7, 2026
Last updated: September 7, 2026

Scope. This policy covers the Bridge browser extension for Chrome and Edge, the Arrowhealth services the extension connects to, and the Arrowhealth website at arrowhealth.io. Bridge is a professional tool used by clinical and administrative staff inside their organization’s electronic health record (EHR). Because Bridge runs inside a patient chart, this policy separates two very different things: the small amount of information Arrowhealth actually receives and stores, and the patient information Bridge displays in the browser and never receives.

1. Who we are

Arrowhealth Bridge Inc. (“Arrowhealth,” “we,” “us”) builds and operates Bridge. Bridge is a browser extension that runs alongside a clinician’s EHR and shows applications that are relevant to the patient chart currently on screen. Those applications are built by Arrowhealth or by partner companies that a healthcare organization has separately contracted with.

Bridge is distributed to healthcare organizations. It is not a consumer product, and it is not directed to the general public.

2. Who this policy describes

  • Bridge users — clinicians, front-office staff, and other authorized workforce members of a healthcare organization or partner company who sign in to Bridge.
  • Patients — individuals whose records appear in the EHR that the user is working in. Bridge displays information about these individuals but does not receive or store it. See Section 4.
  • Website visitors — anyone who visits arrowhealth.io.

3. What Arrowhealth collects and stores

3.1 Account and authentication information

To create and maintain a Bridge user account, we collect and store:

  • Work email address.
  • Which applications and settings are assigned to the account.
  • Authentication records — sign-in events, session identifiers, and the identity provider used where the organization signs in through single sign-on.

Bridge supports sign-in with a username and password, with an organization’s own single sign-on (OIDC or SAML), and with a one-time code emailed to a new user during account setup. Passwords, where used, are stored only in hashed form.

We store this information on Arrowhealth systems for as long as the account exists.

3.2 Operational and diagnostic information

The extension reports information we use to keep the product working:

  • Extension version and browser type.
  • Which EHR the extension detected.
  • Error and status information — failure codes, error types, and whether the extension was able to read the page it was on.
  • Timestamps and the account the event belongs to.
  • The IP address a request came from, recorded in server logs. An IP address indicates approximate region.

This information is used to diagnose failures, monitor availability, and decide what to fix. It is not an audit log of who opened which patient chart, and it is not used to build a record of patients. See Section 4.3 for the limit on this claim.

3.3 Website information

On arrowhealth.io we collect standard web analytics — IP address, browser and device type, pages viewed, and referring page — through cookies and similar technologies, and any information a visitor submits through a contact or demo request form. Browser settings can be used to block or clear cookies; the website works without them.

4. Patient information

This section is the part of Bridge’s behavior most likely to be relevant to a healthcare organization evaluating the extension.

4.1 What Bridge reads

When a user opens a patient chart, Bridge assembles a description of the patient and the open encounter from what the EHR is already showing that user. Depending on the EHR and the user’s own permissions, that can include:

  • Identifiers such as the medical record number.
  • Name, date of birth, and recorded sex.
  • Contact details — address, phone numbers, email.
  • Insurance coverage information.
  • Clinical context — the department, treating and referring provider, date of last service, active problems, and diagnoses associated with the open encounter.

Bridge reads this using the user’s own signed-in EHR session and permissions. It obtains nothing the user could not already see by looking at the chart, it reads only the chart that is currently open, and it has no ability to search, list, or download records in bulk.

4.2 Where it goes

Patient information stays in the browser tab. It is assembled when a chart is opened, held in the tab’s memory while the user is looking at that chart, and discarded when the user navigates away. It is not written to the browser’s storage, and it is not sent to Arrowhealth.

Arrowhealth does not receive, store, sell, or otherwise transfer patient information through Bridge. Where patient information leaves the browser, it does so because an application running inside Bridge sent it to that application’s own systems as part of a workflow the user performed — submitting a referral, for example. Section 6 covers that case.

4.3 The limit on this claim

Diagnostic information (Section 3.2) is generated while people are working in live clinical systems. The reporting is built to carry operational values only, and we do not represent that a patient detail can never appear in an error message. Any such information is treated as protected health information under Arrowhealth’s Business Associate Agreement, is subject to the safeguards in Section 7, and is deleted on the schedule in Section 8.

5. How we use information

We use the information in Section 3 to:

  • Authenticate users and maintain their sessions.
  • Determine which applications and settings to present to a user.
  • Operate, monitor, troubleshoot, and improve the extension and the services behind it.
  • Provide support to healthcare organizations and partner companies.
  • Detect and investigate security incidents and misuse.
  • Meet legal, regulatory, and contractual obligations.

We do not use any of it for advertising or to determine creditworthiness or lending eligibility, and we do not sell it or share it for cross-context behavioral advertising. We do not use it to train generalized artificial intelligence or machine learning models. Arrowhealth personnel access user or diagnostic data only where it is necessary to operate or support the service, to investigate a security issue, or where required by law.

6. Applications running inside Bridge

A healthcare organization decides which applications appear in its users’ Bridge panels. Bridge hands each application the patient and encounter context described in Section 4.1, in the browser, for the chart the user is currently viewing. Applications are isolated from one another and cannot observe each other’s data.

Where an organization uses Bridge to sign users in to an application, Bridge provides that application with the user’s verified email address and an internal Bridge identifier for the user. It provides no other user information.

What an application does with the context it receives — what it displays, what it sends to its own systems, what it retains, and how it logs access — is governed by that application’s own agreement and Business Associate Agreement with the healthcare organization. Questions about a specific application’s data handling should go to that application’s provider.

7. How we protect information

Arrowhealth operates a documented information security program covering the systems that run Bridge. Its main elements:

  • Encryption of data in transit (TLS 1.2 or higher) and at rest (AES-256).
  • Role-based, least-privilege access to production systems, requiring multi-factor authentication and reviewed at least annually.
  • Independent third-party penetration testing at least annually, and internal and external vulnerability scanning at least quarterly, with remediation timelines set by severity.
  • Background checks and confidentiality agreements for personnel, and security training at hire and annually thereafter.
  • A documented incident response program, tested annually, including notification of affected organizations and authorities where warranted.
  • Risk assessment and ongoing review of vendors and subprocessors that handle confidential data.

Independent audit reports and further security documentation are available to customers and partners under non-disclosure agreement.

No system is completely secure, and we do not claim otherwise. Bridge runs in a browser on a device the healthcare organization owns and manages. Securing that device, its browser, and the user’s own EHR credentials is the organization’s responsibility.

8. Retention and deletion

  • Account information is retained while the account is active. When an organization or partner ends its relationship with Arrowhealth, or an administrator removes a user, we delete or de-identify the associated account information within a defined period unless we are required to retain it by law or contract.
  • Diagnostic information is retained on a limited rolling schedule sized to troubleshooting and security investigation, then deleted.
  • Patient information is not retained, because it is never received (Section 4.2).
  • Website analytics are retained according to the retention settings of our analytics provider.

Retention practices are reviewed at least annually. Data is disposed of using secure deletion methods.

9. How we share information

We do not sell personal information. We share it only as follows:

  • Service providers. Vendors that host our infrastructure, deliver email, provide error monitoring, or support our operations. They are bound by contract to use the information only to provide their service to us, are risk-assessed before onboarding, and are reviewed at least annually. Where they may handle protected health information, they sign a Business Associate Agreement.
  • The organization that provisioned the account. A healthcare organization or partner company can see the accounts and usage associated with its own Bridge deployment.
  • Applications the organization has enabled, as described in Section 6.
  • Legal and regulatory disclosure. Where required by law, subpoena, or other legal process, or where necessary to protect our rights, our users, or the security of our systems.
  • Business transfer. If Arrowhealth is involved in a merger, acquisition, or sale of assets, information may transfer as part of that transaction, subject to this policy.

10. HIPAA and our role

Bridge is used with protected health information, so Arrowhealth acts as a business associate. Arrowhealth signs a Business Associate Agreement with the partner whose application a healthcare organization has contracted for, and operates as a subprocessor beneath that relationship. The application partner holds the direct agreement with the healthcare organization. A healthcare organization that needs Arrowhealth disclosed as a subprocessor can obtain that from its application partner.

The EHR remains the system of record for patient charts and for any accounting of who accessed them.

11. Permissions the extension requests

Permission What it is used for
cookies Work within the user’s existing signed-in EHR session, and manage Bridge’s own session cookie.
scripting Load the Bridge panel into recognized EHR pages.
storage Hold short-lived session state, cleared when the browser restarts.
webRequest Observe requests to recognized EHR addresses in order to detect navigation and sign-in. Observation only — the extension cannot modify or block traffic.
Host access (<all_urls>) Reach the EHR pages Bridge supports, including clinics that run their EHR on their own domains.

Bridge requests host access to all sites so that adding support for a new EHR does not change the permissions the extension asks for. When an extension update adds a host permission, the browser disables the extension until every user approves the change — so listing EHRs individually would interrupt every Bridge user each time a new EHR was added, including users at clinics that will never visit it. Which pages Bridge actually runs on is decided by the extension’s own recognition of supported EHRs: it loads its runtime on pages matching a supported EHR and takes no action on other sites. A clinic that centrally manages browser extensions can narrow this further through browser policy.

Bridge runs under Manifest V3, executes only code shipped in the signed extension package, and is distributed through a private Chrome Web Store listing.

12. Your choices and rights

Bridge users can request access to, correction of, or deletion of their Bridge account information by contacting us or their organization’s Bridge administrator. Depending on where a person lives, additional rights may apply, including the right to know what personal information is held, to request deletion, to correct it, and to appeal a refusal. We do not discriminate against anyone for exercising these rights.

Requests about a patient’s medical record go to the healthcare organization that holds the record, not to Arrowhealth. We do not hold patient records, and we cannot identify, retrieve, amend, or delete a patient’s information.

Marketing email from Arrowhealth carries an unsubscribe link.

13. Children

Bridge is a workplace tool for authorized staff and is not directed to children, and we do not knowingly collect personal information from children through the extension or the website. Patient records displayed in the EHR may relate to minors; that information is held by the healthcare organization and handled under Section 4.

14. Where information is processed

Arrowhealth operates its services in the United States, and information described in Section 3 is processed and stored there.

15. Changes to this policy

We update this policy when our practices change. The current version is always posted at https://arrowhealth.io/privacy-policy/ with a revised effective date. Material changes are communicated to the healthcare organizations and partners we work with.

16. Contact

Questions about this policy, or a request under Section 12:

Arrowhealth Bridge Inc.
1873 W Traverse Pkwy, Ste E208
Lehi, UT 84048
info@arrowhealth.io