ASTAST
Get in Touch
EMR / EHR Development
Full-cycle clinical platform builds, from architecture to go-live.
EHR Integration
HL7 v2, FHIR R4, and API integrations with Epic, Cerner, PointClickCare, and athenahealth.
Clinical Mobile Applications
iOS and mobile-first tools purpose-built for clinical workflows.
AI Clinical Documentation
Ambient listening, NLP pipelines, and automated clinical note generation.
Revenue Cycle Technology
Clearinghouse integrations, claims processing, and denial management tooling.
Post-Acute Care Platforms
Purpose-built software for therapy networks, SNFs, and long-term care operators.
HIPAA Compliance Architecture
PHI handling, BAA-ready infrastructure, and audit trail design built in from day one.
SOC 2 Readiness
Gap assessments, control implementation, and evidence preparation for Type I and Type II audits.
HITRUST Certification Support
Control mapping, scoping, and remediation support for HITRUST CSF.
FedRAMP Readiness
Cloud security controls and authorization support for government-adjacent healthcare clients.
Regulatory Intelligence
Automated tracking and surfacing of regulatory changes across your clinical and compliance operations.
DHA / NABIDH Compliance
UAE Digital Health Authority compliance architecture for platforms operating in the MENA market.
HIPAA Security Rule Assessment
Risk analysis and remediation aligned to the HIPAA Security Rule technical and administrative safeguards.
Cloud Security Architecture
Zero-trust design, IAM hardening, and HIPAA-compliant AWS and Azure environments.
Penetration Testing
Application and infrastructure testing scoped for healthcare systems handling PHI.
Vendor Risk Management
Third-party assessment frameworks and BAA governance for healthcare supply chains.
Security Incident Response
Breach response planning, tabletop exercises, and post-incident remediation.
Integrated Engineering Pods
Cross-functional teams (dev, QA, DevOps, PM) that embed into your product org and own delivery end-to-end.
Technical Architecture Review
Independent assessment of your current stack, integration approach, and scalability posture.
Legacy System Modernization
Structured migration from outdated clinical systems to modern, maintainable architecture.
DevOps & Cloud Infrastructure
CI/CD pipelines, infrastructure-as-code, and HIPAA-compliant cloud environments.
Technical Due Diligence
Engineering assessment for investors, acquirers, and boards evaluating healthcare technology assets.
From the blog
An empty concrete corridor with hard sunlight, deep shadows, and strong geometric lines in a quiet medical building interior.
Automated Referral Management That Actually Moves
Read the guide
A candid over-the-shoulder scene of two healthcare workers reviewing care tasks in a modest office with cool daylight through blinds.
Architecting a Clinical Workflow Engine for Value-Based Care
Read the guide
An empty concrete corridor beside a server hall entrance, lit by hard sunlight with deep shadow and strong geometric lines.
Compliance for Multi-State Telehealth Data Governance
Read the guide
Two compliance staff review an access checklist at a desk in cool daylight, seen candidly from over the shoulder.
Designing Audit-Ready EHR Access Control
Read the guide
Ransomware: How It Works and Prevention Tips
Ransomware: How It Works and Prevention Tips
Read the guide
ICS/OT Compliance: How to Meet Regulatory and Legal Requirements
ICS/OT Compliance: How to Meet Regulatory and Legal Requirements
Read the guide
The Best Practices for Software Quality Assurance and Testing in 2024
The Best Practices for Software Quality Assurance and Testing in 2024
Read the guide
The Benefits of Responsive Web Design for SEO and User Experience
The Benefits of Responsive Web Design for SEO and User Experience
Read the guide
Health Systems & IDNs
Large provider organizations evaluating clinical software or integration partners.
Post-Acute & Therapy Networks
SNFs, rehab groups, and therapy operators running or building clinical platforms.
Digital Health Startups
Series A–C teams that need an engineering pod without building an internal team from scratch.
Healthcare IT Vendors
Software companies that need FHIR integrations, compliance architecture, or delivery capacity.
UAE / MENA Healthcare Operators
Organizations building or scaling digital health platforms under DHA and NABIDH frameworks.
From the blog
An empty concrete corridor with hard sunlight, deep shadows, and strong geometric lines in a quiet medical building interior.
Automated Referral Management That Actually Moves
How I build automated referral management workflows that reduce manual chasing, surface missing data early, and keep referrals moving across EMR and payer systems.
Read the guide
About AST
Seventeen years in healthcare IT. Who we are and how we work.
Meet the Team
The engineers, architects and clinicians who build and run the platform.
AST LabsNew
Our internal innovation unit. Where we build products we own.
Careers
We hire engineers who want to go deep in healthcare, not generalists.
Latest
An empty geometric hospital corridor with hard sunlight, deep shadow, and strong concrete lines.
Best Partner for Automated Appointment Reminders
How I choose the best partner for automated appointment reminders, from scheduling and SMS to EHR integration, consent, retries and reporting.
Read the story
MedexaFlagship
AI clinical documentation & claims automation — from ambient visit to payer-ready approval.
AST AI Answer Engine Live
The AI layer running on this site — ask it anything about our work, right now.
In the Lab4 experiments
59-modifier engine, 8-minute rule, ambient notes, claims — being built in the open at AST Labs.
The Build Log
What we're testing, what worked, what didn't — published as we go.
Spotlight
● In developmentMedexa.Trusted AI for payer-ready approvals.See the product

One flagship shipping · four experiments in the lab

Guides & White Papers
Long-form technical guides written by engineers who have shipped this work.
EMR / EHR
Building, integrating and modernizing clinical record systems.
FHIR & Interoperability
HL7, FHIR R4, and real-world multi-EMR data exchange.
AI Clinical Documentation
Ambient capture, NLP pipelines, and automated clinical notes.
Healthcare Compliance
HIPAA, SOC 2, and the regulatory architecture behind safe systems.
Editor's picks
An empty geometric hospital corridor with hard sunlight, deep shadow, and strong concrete lines.
Best Partner for Automated Appointment Reminders
Read the guide
Two clinic staff members work over a desk near a window with cool daylight, captured in an unposed documentary style.
Patient engagement apps that actually cut no-shows
Read the guide
Browse every guide
Home/Privacy Policy

Privacy Policy

Last updated: 23 September 2026

This Privacy Policy explains how All Star Technology (“AST”, “we”, “us”, “our”) collects, uses, shares and protects personal information when you visit allstartech.net(the “Site”), use the AI assistant on the Site, subscribe to our newsletter, register for an event, apply for a job, or otherwise contact us. AST is the controller of the personal information described in this policy.

This policy does not cover information we process on behalf of our clients while delivering services, including any protected health information (“PHI”). That processing is governed by our client agreements, business associate agreements and data processing agreements, and by our clients’ own privacy notices.

1. Information we collect

Information you give us.

  • Enquiries and consultations: name, work email, phone number, company, job title, the service you are interested in, and the content of your message.
  • Newsletter and events: email address and, for events, name, company and role.
  • Job applications: name, contact details, LinkedIn profile, CV, cover note, and any other information you choose to include.
  • AI assistant: the questions you type and the answers generated. If you leave your details through the assistant, we receive those details as an enquiry.
  • Communication preferences: whether you have agreed to receive marketing emails or SMS messages.

Information collected automatically.

  • Usage data: pages viewed, links clicked, referring page, approximate location derived from IP address, device, browser and operating system. Analytics data is collected only after you accept analytics cookies.
  • Technical and security data: IP address, request logs and a random session identifier, used to deliver the Site, prevent abuse (including rate-limiting the AI assistant) and keep our systems secure.

Information from others. We may receive business contact information from referral partners, event organisers and publicly available professional sources such as company websites and LinkedIn.

Please do not submit PHI, payment card data or other sensitive personal information through the Site’s forms or the AI assistant. They are not designed to receive it.

2. How we use information, and our legal bases

  • To respond to enquiries and provide services you request. This is necessary to take steps at your request before entering into a contract, or it is in our legitimate interest in running our business.
  • To send newsletters, event information and marketing. We do this with your consent where the law requires it, otherwise on the basis of our legitimate interest. You can opt out at any time.
  • To assess job applications. This is needed to take steps toward an employment contract, and it is in our legitimate interest in recruiting.
  • To operate, measure and improve the Site, including analytics. We do this with your consent for non-essential cookies, and in our legitimate interest for essential operations.
  • To secure the Site and prevent fraud, spam and abuse. This is in our legitimate interest.
  • To comply with legal obligations and to establish, exercise or defend legal claims.

We do not use personal information from the Site for automated decision-making that produces legal or similarly significant effects.

3. Cookies and similar technologies

We use a small number of cookies and browser storage entries:

  • Strictly necessary: storage that remembers your cookie choice, and a cookie that keeps the version of a page you are shown consistent between visits. These cannot be switched off.
  • Analytics (only with consent): Google Analytics and Google Tag Manager cookies, such as _ga, measure how the Site is used. HubSpot’s hubspotutk cookie, where present, links your form submissions to your earlier visits.
  • Security: Google reCAPTCHA or Cloudflare Turnstile may set cookies or collect device signals to tell people from bots when you submit a form or use the AI assistant.

Analytics stays off until you choose “Accept” on our cookie banner. You can change your choice at any time using “Cookie Settings” in the footer, or by clearing cookies in your browser.

4. How we share information

We share personal information only with:

  • Service providers who process it on our behalf and under contract:
    • Amazon Web Services (hosting, content delivery and the AI assistant’s infrastructure)
    • HubSpot (CRM, forms and email)
    • Google (Analytics, Tag Manager and reCAPTCHA)
    • Cloudflare (bot protection)
    • Anthropic (the language model that generates AI-assistant answers)
    • Cusdis (blog comments, where enabled)
  • AST affiliates and offices in the United States, Saudi Arabia, the United Arab Emirates and Pakistan, so the right team can respond to you.
  • Authorities and advisers, where the law requires it or where it is needed to protect our rights, users or the public.
  • A successor business in connection with a merger, acquisition or sale of assets, subject to this policy.

We do not sell personal information. We do not share it for cross-context behavioural advertising. We do not share mobile phone numbers or SMS consent with third parties for their own marketing.

5. International transfers

We are a global team, so your information may be processed in the United States, Saudi Arabia, the United Arab Emirates, Pakistan and other countries where our service providers operate. When we transfer personal information out of the European Economic Area, the United Kingdom, the UAE or Saudi Arabia, we use appropriate safeguards, such as the European Commission’s Standard Contractual Clauses and their UK equivalent, as required by applicable law.

6. Data retention

  • Enquiries and business contacts: for as long as we are in active discussion, then up to three years after our last interaction, unless a client relationship begins.
  • Newsletter subscriptions: until you unsubscribe. We keep a suppression record so we do not contact you again.
  • Job applications: up to 24 months after the recruitment process ends, so we can consider you for future roles. If you are hired, your application becomes part of your personnel file.
  • Analytics data: up to 14 months.
  • AI assistant: rate-limit and abuse-prevention records are short-lived. Operational logs are kept for a limited period for security and troubleshooting.

We may keep information for longer where the law requires it or where it is needed to resolve disputes.

7. Security

We apply administrative, technical and physical safeguards appropriate to the sensitivity of the information. These include encryption in transit, access controls based on least privilege, and vetted service providers. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

8. Your rights

Depending on where you live, you may have the right to:

  • access your personal information
  • correct it
  • delete it
  • receive a portable copy
  • restrict or object to its use, including for direct marketing
  • withdraw consent at any time, without affecting processing already carried out

These rights include those under the EU and UK GDPR, the UAE and Saudi Personal Data Protection Laws, and US state privacy laws.

California residents have the right to know what personal information we collect, use and disclose, and to request deletion or correction. You also have the right not to be discriminated against for exercising these rights. We do not sell or share personal information as those terms are defined under the CCPA/CPRA, and we do not use sensitive personal information to infer characteristics about you. You may use an authorised agent to make a request on your behalf.

To exercise any right, email info@allstartech.net with “Privacy request” in the subject line. We will verify your request and respond within the time the law requires. If you are in the EEA or UK, you may also complain to your local data protection authority.

9. Marketing emails and SMS

You can unsubscribe from marketing emails using the link in any email. If you opt in to SMS messages, message frequency varies and message and data rates may apply. Reply STOP to opt out or HELP for help. Consent to SMS is not a condition of any purchase or service.

10. The AI assistant

The AI assistant answers questions about AST using content published on this Site. Your messages are sent to our AI provider to generate a response, and they are not used to train that provider’s models. Answers may be incomplete or inaccurate, and they are not medical, legal or compliance advice. Do not enter PHI or other sensitive information.

11. Children

The Site is intended for business audiences and is not directed to children under 16. We do not knowingly collect their personal information. If you believe a child has given us information, contact us and we will delete it.

12. Changes to this policy

We may update this policy from time to time. We will post the new version on this page and change the “Last updated” date. Where the changes are material, we will give additional notice where appropriate.

13. Contact us

All Star Technology, 121 Pacific Coast Hwy, El Segundo, CA 90245, USA. For privacy questions or requests, email info@allstartech.net with “Privacy request” in the subject line.

Healthcare IT

EMR / EHR DevelopmentEHR IntegrationClinical Mobile ApplicationsAI Clinical DocumentationRevenue Cycle TechnologyPost-Acute Care Platforms

Who We Serve

Health Systems & IDNsPost-Acute & Therapy NetworksDigital Health StartupsHealthcare IT VendorsUAE / MENA Healthcare Operators

Compliance & Regulatory

HIPAA Compliance ArchitectureSOC 2 ReadinessHITRUST Certification SupportFedRAMP ReadinessRegulatory IntelligenceDHA / NABIDH Compliance

Cybersecurity

HIPAA Security Rule AssessmentCloud Security ArchitecturePenetration TestingVendor Risk ManagementSecurity Incident Response

Resources

Guides & White PapersCase StudiesBlog

Engineering & Consultancy

Integrated Engineering PodsTechnical Architecture ReviewLegacy System ModernizationDevOps & Cloud InfrastructureTechnical Due Diligence

Company

About ASTMedexa NewAST LabsCareers
AST
+1 310 683 0412info@allstartech.net

AST is a healthcare engineering partner. For 17 years we've built the EMR/EHR systems, clinical integrations and HIPAA-compliant platforms that run inside real care networks.

SOC 2 Type IIHITRUST CSFISO 27001ISO 9001HIPAACMMI Dev 3

Find us elsewhere

Subscribe to the newsletter

Operator-grade thinking on healthcare engineering. No noise.

United States
121 Pacific Coast Hwy, El Segundo, CA 90245
Saudi Arabia
Level 7, Building 4.07, King Abdullah Financial District, Riyadh
United Arab Emirates
Unit 5, Cluster R, JLT, Dubai
Pakistan
61 Zulfiqar Avenue, DHA Phase 8, Karachi
© 2026 AST. All rights reserved.Privacy PolicyTerms of Use