Privacy Policy & HIPAA Notice
Effective Date: September 2026 • Compliant with US HIPAA & HITECH
AES-256 Encryption
Encrypted electronic health records at rest and in transit.
Zero Data Selling
We never monetize, rent, or sell your health records.
Role-Based Access
Only treating doctors assigned to your care have access.
1. Information We Collect
To deliver healthcare services, we collect information you provide directly:
- Account Data: Name, email address, phone number, and encrypted password.
- Protected Health Information (PHI): Medical intake questionnaires, consultation notes, diagnoses, allergies, and prescription histories.
- Transaction Details: Payment card tokens, receipts, and insurance billing codes.
2. How We Use Protected Health Information
Under the Health Insurance Portability and Accountability Act (HIPAA), your PHI is strictly used for treatment, payment, and healthcare operations (TPO). Specifically:
- Enabling licensed physicians to review medical records and conduct clinical evaluations.
- Issuing prescriptions to verified pharmacies chosen by you.
- Providing automated appointment reminders via SMS and email.
3. Data Security & Storage Architecture
MedCare utilizes microservices architecture hosted in SOC-2 Type II certified cloud environments. Database-per-service isolation ensures that medical records, financial billing data, and authentication tokens reside in segregated, encrypted partitions.
4. Patient Rights Under HIPAA
You possess clear legal rights regarding your health data:
- Right to Inspect & Export: You can download complete clinical summaries of all visits in PDF format from your patient dashboard.
- Right to Amend: You may request corrections to demographic or medical history items.
- Right to Accounting of Disclosures: You may request an audit log of all healthcare providers who accessed your chart.