1. OVERVIEW
mbSolutioneers (“we”, “our”, or “us”) is committed to protecting your privacy. This Privacy Policy explains how information is collected, used, disclosed, and safeguarded in connection with the EMRFinX software application (“EMRFinX”) or the “App”), which integrates with Intuit services such as QuickBooks Online.
EMRFinX is a server-side data mapping and automation tool published by mbSolutioneers. It is not a consumer-facing application.
EMRFinX is installed and operated by the Licensee, the business deploying it, on the Licensee’s own infrastructure. All data the software reads, maps, and transmits belongs to and is controlled by the Licensee.
The software is offered for use in the United States and this policy is governed by United States federal and applicable state law.
2. HOW THE SOFTWARE HANDLES DATA
EMRFinX moves data in one direction, from a data source the Licensee configures into the Licensee’s QuickBooks Online company.
a) It connects to data sources the Licensee configures and credentials. Supported source types are Snowflake, Microsoft SQL Server, ODBC data sources, CSV files, and Excel files.
b) It executes queries the Licensee authors against those sources and reads the result rows.
c) It applies the field mappings the Licensee has created, pairing source columns with fields on a QuickBooks Online document, and posts the resulting Invoices, Credit Memos, Sales Receipts, or Journal Entries into the Licensee’s QuickBooks Online company through the Intuit QuickBooks Online API.
d) It records the outcome of each run locally. Where the Licensee has configured it, the software also writes a log entry to a Microsoft SharePoint list and sends failure alerts through the Licensee’s own mail server.
When the Licensee authorizes the App to connect with an Intuit account, the categories of information the App handles are account details (company name and QuickBooks Online company identifier), financial data (invoices, credit memos, sales receipts, journal entries, and the transaction rows behind them), and local run and performance records. The App does not handle personal information unless the Licensee’s own queries and field mappings make it necessary for the Licensee’s core functionality; Section 5 describes the control that applies in that case.
3. DATA TRANSMITTED TO QUICKBOOKS ONLINE
The specific fields sent to QuickBooks Online are determined by the Licensee’s queries and field mappings and are not fixed by the software.
In the intended configuration, the data sent is aggregate financial data:
– Amounts, quantities, unit prices, service and transaction dates, document numbers, line descriptions, and, where the Licensee has enabled class tracking, class names;
– QuickBooks Online configuration references the Licensee supplies once during setup: customer reference, income account reference, department reference, and sales term reference.
The software does not require, and its intended configuration does not send, patient names, dates of birth, medical record numbers, government identification numbers, street addresses, telephone numbers, or email addresses.
Because the Licensee controls the queries and mappings, a mapping could select an individual identifier. Section 5 describes the control that applies in that case.
4. CREDENTIALS AND SECURITY
All credentials and configuration are stored on the Licensee’s own server. The software applies the following measures:
a) ENCRYPTION AT REST
QuickBooks Online refresh tokens and company identifiers, and data source secrets such as database passwords and private keys, are encrypted at rest using the platform’s data protection facilities. The encryption key material is stored locally and protected by the host operating system.
b) ENCRYPTION IN TRANSIT
The application redirects HTTP to HTTPS and sets HTTP Strict Transport Security outside development. Calls to the QuickBooks Online API and to Microsoft Graph are made over HTTPS. Data source connections use each provider’s transport security.
c) AUTHORIZATION AND REVOCATION
QuickBooks Online access is granted through Intuit’s OAuth 2.0 flow. Each authorization request carries a single-use, cryptographically random state value that is validated on return. Access tokens are refreshed automatically and the rotated refresh token replaces the stored one. Disconnecting a client within the application revokes the token at Intuit and clears the locally stored token and company identifier.
d) LOG HYGIENE
Credential values are redacted before any string is written to logs or console output.
e) APPLICATION ACCESS CONTROL
EMRFinX uses a single shared API key for access to its interface and endpoints. It has no per-user account system and therefore no authenticated per-operator identity. Controlling who can reach the server, and who holds the API key, is the Licensee’s responsibility.
Data is handled using industry-standard practices, and access to any deployment should be restricted to authorized personnel. However, no method of transmission over the Internet and no method of electronic storage is one hundred percent secure, and neither the software nor mbSolutioneers can guarantee absolute security.
The security of the deployment environment is the Licensee’s responsibility.
5. HEALTH-RELATED DATA
Some Licensees connect EMRFinX to practice management or medical billing systems. Data in those systems may constitute Protected Health Information under the Health Insurance Portability and Accountability Act (HIPAA).
QuickBooks Online is not a business-associate-covered destination for Protected Health Information. EMRFinX should not be used to place patient identifiers into QuickBooks Online.
When a Licensee maps a source column onto a QuickBooks Online field, the software checks the column’s name against a fixed list of identifier terms, including patient, name, date of birth, Social Security number, medical record number, address, telephone, email, guarantor, subscriber, and insured. A match blocks the report from being saved or run until an operator acknowledges the mapping by typing a name. The acknowledgement is recorded on the mapping and in a separate append-only log. Editing the underlying query invalidates a previous acknowledgement. The same check runs before every scheduled or manual run, before any data is read or transmitted.
This control has the following limits:
– Detection is based on the column’s name and does not inspect the values in the data. A column with an uninformative name that contains a patient identifier is not flagged.
– The prompt is a gate, not a prohibition. An operator can acknowledge a flagged column and map it. The control makes such a decision deliberate and recorded, not impossible.
– The acknowledgement name is not a verified identity. As stated in Section 4(e), the software has no per-user authentication.
The Licensee is responsible for ensuring the server environment meets applicable administrative, physical, and technical safeguard requirements, for executing any required Business Associate Agreements with its own service providers, for maintaining access controls over configuration files, and for determining that any data element its queries and mappings transmit may lawfully be transmitted to the destination.
6. THIRD-PARTY SERVICES
EMRFinX exchanges data with the following third parties, in each case at the Licensee’s direction and using the Licensee’s own accounts:
a) INTUIT QUICKBOOKS ONLINE
The destination for the accounting documents described in Section 3. Intuit’s privacy statement governs data handling on their platform. See: https://www.intuit.com/privacy/statement/
b) THE LICENSEE’S DATA SOURCE
Snowflake, Microsoft SQL Server, an ODBC data source, or a CSV or Excel file, under the Licensee’s own infrastructure and credentials. EMRFinX reads from these sources and does not write to them.
c) MICROSOFT SHAREPOINT, VIA MICROSOFT GRAPH (optional)
If the Licensee configures it, run results are written to a SharePoint list the Licensee owns. Microsoft’s privacy statement governs their handling of that data. See: https://privacy.microsoft.com/
d) THE LICENSEE’S MAIL SERVER (optional)
If the Licensee configures alerting, failure notifications are sent through a mail server the Licensee specifies.
The App may link to Intuit or to other third-party services. Those services are governed by their own privacy policies, and mbSolutioneers is not responsible for their privacy practices or content.
mbSolutioneers is not a recipient of Licensee data. There are no other subprocessors.
7. INFORMATION mbSolutioneers RECEIVES, AND HOW IT IS USED
As stated in Section 1, mbSolutioneers does not receive data from a Licensee’s deployment in the ordinary course of the software’s operation.
mbSolutioneers receives information only where a Licensee sends it to us directly, for example the business contact details of the person who licenses or administers the App, and any log excerpt, screenshot, configuration file, or description a Licensee chooses to send when requesting support. We use that information only to:
– Provide, maintain, and improve the App’s functionality;
– Troubleshoot problems and respond to Licensee support requests;
– Comply with legal obligations.
Where we hold such information, we share it only with:
– Intuit, to the extent necessary for QuickBooks Online API functionality;
– Our trusted service providers, under confidentiality obligations; and
– Regulatory or law enforcement authorities where required by law.
We do not sell or rent Licensee data or personal information, and we do not use it for advertising or for any purpose unrelated to providing and supporting the App.
Licensees are asked to redact credentials and any individual identifiers before sending logs or configuration files for support.
8. DATA RETENTION AND DELETION
All retained data resides on the Licensee’s own server.
– Run history and mapping change history are retained for 90 days by
default. This period is configurable by the Licensee.
– The acknowledgement log described in Section 5 is append-only and is not pruned.
– Records written to a Licensee’s SharePoint list are retained according to that Licensee’s SharePoint configuration.
– Deleting a client within the application removes that client’s stored credentials, connection settings, and mapping definitions.
– Records the software has created in QuickBooks Online remain in QuickBooks Online and are removed there.
Because mbSolutioneers does not receive or store Licensee data, requests to access, correct, or delete data held by a deployment should be directed to the Licensee operating it.
9. YOUR RIGHTS AND CHOICES
Within a deployment of the App, you may:
– Access or update the configuration, queries, and mapping definitions the App holds;
– Disconnect the App from a QuickBooks Online account at any time, either from within the application or from within QuickBooks Online. Disconnecting within the application revokes the authorization at Intuit and clears the locally stored token and company identifier;
– Request deletion of data, subject to applicable legal and record-retention obligations. Deleting a client within the application removes that client’s stored credentials, connection settings, and mapping definitions, as described in Section 8.
Because the data resides on the Licensee’s own server, these rights are exercised against the deployment. Where an individual wishes to exercise a right in respect of data held in a deployment, the request should be directed to the Licensee operating it. Requests concerning information mbSolutioneers itself holds, as described in Section 7, may be sent to the contact address in Section 12.
10. CHILDREN’S PRIVACY
EMRFinX is a business tool and is not directed at or intended for use by individuals under the age of 18. mbSolutioneers does not knowingly collect personal information from minors.
11. CHANGES TO THIS POLICY
mbSolutioneers may update this Privacy Policy from time to time. The Effective Date above reflects the current version. Licensees will be notified of material changes by email or by an alert within the App. Continued use of the software after a material change takes effect constitutes acceptance of the revised policy.

