MCP Server Privacy Policy
orphan
Overview
Emtelligent (“we,” “our,” or “us”) provides medical entity linking services through our Model Context Protocol (MCP) server integration with Anthropic’s Claude. Our service performs entity linking on medical text to medical ontologies such as SNOMED-CT and ICD-10 (medical coding). This privacy policy explains how we receive, use, protect, and retain data when you use our MCP server services.
MCP Server Integration Details
Anthropic Claude Integration & Processing Flow
- Text submission: Medical text received through MCP protocol
- Medical text processing: Text processed through Claude’s APIs
- Specialized medical ontology linking to the SNOMED and ICD-10 ontologies: Medical entities mapped to SNOMED-CT/ICD-10 codes using our technology
- Results delivery: Coded entities with metadata returned to you
- Data deletion: All source text and temporary data immediately deleted
Data We Receive
Medical Text Data
- Unstructured medical text that you submit for entity linking and coding
- Clinical documents containing medical terminology for ontology mapping
- Medical narratives requiring SNOMED-CT or ICD-10 code assignment
Technical Data
- API usage logs including request timestamps and identifiers
- Processing metadata: number of bytes processed, number of documents processed, processing features used
- Authentication tokens and session identifiers
- Error logs associated with any processing failures or server issues
Data Retention and Storage
Inputs sent to the MCP server are processed in memory and are not stored on disk. After a response is returned, inputs and outputs are discarded and not retained by Emtelligent. Emtelligent does not retain or store any data outside of temporary data processing. Emtelligent does not use MCP inputs or outputs to train Emtelligent or third‑party models. Emtelligent does not sell or share MCP inputs or outputs with third parties, except as necessary to provide the service or comply with law.
Use of the MCP server occurs via an LLM provider (e.g., Anthropic’s Claude) as configured by you. Your inputs to the LLM, tool‑call requests, and tool‑call results may be retained by your LLM provider depending on your account settings and agreement. You are responsible for enabling zero data retention (or equivalent) with Anthropic for both inputs and outputs and for maintaining any required enterprise/BAA agreements. Your use of the MCP server does not bypass your obligations or your LLM provider’s policies. Emtelligent cannot control or guarantee how an LLM provider handles your data.
Active Processing Data
- Medical text: Retained in memory only during active entity linking processing
- Linking results: Available for download immediately, and deleted after download. The data is not permanently stored by us for any purpose
Metadata and Logs
- Technical performance logs: Retained for 90 days for service monitoring
- Audit logs: Retained for 7 years to meet healthcare compliance requirements
Automatic Data Deletion
- Source medical text: Automatically deleted upon processing completion
- Processing metadata: Character offsets, document metadata, and all other section information data sent as the input to the MCP server are deleted
- Temporary entity cache: Purged every 4 hours or upon session end
- Results delivery: Linked entities and metadata delivered once, then deleted from our systems
Data Security
Medical Text Protection
- End-to-end encryption: All medical text encrypted using TLS during transmission
- Memory-only processing: Source text never written to persistent storage during entity linking
- Secure deletion: Medical text and linking data wiped within 4 hours of processing
Entity Linking Security
- Isolated processing: Each entity linking session operates in isolation
- No cross-contamination: Medical text from different users never processed simultaneously in a combined batch
Healthcare Compliance
Medical Coding Standards
- SNOMED-CT licensing: Full compliance with SNOMED International licensing terms
- ICD-10 standards: Adherence to WHO ICD-10 classification standards
Privacy Regulations
- HIPAA compliance: Business Associate Agreement available for covered entities
- Medical text handling: Strict protocols for protected health information
You are responsible for lawful submission of PHI and other sensitive data and for configuring zero data retention with your LLM provider.
Your Rights and Controls
Entity Linking Control
- Ontology selection: Specify preferred medical code systems (SNOMED-CT, ICD-10, etc.)
- Metadata options: Control which metadata types are generated and returned
Data Access and Portability
- Results format: Linked entities available in text format for easy inclusion into LLM prompts.
- Our tools may also return JSON or other structured formats.
Third-Party Medical Ontologies
SNOMED-CT
- Licensed access: We maintain proper licensing for SNOMED-CT terminology
- Version control: Regular updates to latest SNOMED-CT releases
ICD-10
- WHO ICD-10: Current version maintained with regular updates
Contact Information
For all privacy-related inquiries, please contact:
