Discover Specialists
By City and Category
Privacy Policy
1. Introduction and Scope
| Clause | Description |
| Our Commitment | We are committed to protecting the privacy and security of your personal information, especially your Protected Health Information (PHI). We comply with all applicable privacy laws, including [Insert Relevant Laws, e.g., HIPAA, GDPR, DPDPA, etc.]. |
| Policy Scope | This Policy applies to all information collected, used, and stored by [Portal Name] through the website and mobile applications. It does not govern the privacy practices of the independent doctors you interact with; those practices are governed by their own Notice of Privacy Practices. |
| Contact Details | Provide the name and contact information for the Data Protection Officer (DPO) or Privacy Officer responsible for handling privacy inquiries and complaints. |
2. Information We Collect
We collect information to facilitate the secure connection between patients and doctors and to operate our platform.
Personally Identifiable Information (PII) / Identifiers: Name, address, phone number, email, date of birth, unique portal ID, and payment information.
Protected Health Information (PHI) / Sensitive Personal Data: Health history, lab results, prescriptions, medical images, consultation notes, and communications with the doctor uploaded or transmitted through the portal.
Technical / Usage Data (Non-PHI): IP address, device type, browser information, pages visited, time spent on the portal, and referral sources.
3. How We Use Your Information (Purpose Limitation)
Your information is primarily used for Treatment, Payment, and Healthcare Operations (TPO) as defined by law.
| Purpose Category | Specific Use of Data |
| Treatment | To securely transmit your health information and messages to the doctor you select to enable them to provide a diagnosis, treatment plan, and prescription. |
| Payment | To process billing, verify eligibility with your insurance provider, and manage payment transactions for the medical services rendered by the doctor. |
| Healthcare Operations | For internal management purposes, such as quality assessment, system administration, auditing, legal compliance, and training our support staff. |
| Platform Improvement | To analyze aggregated, de-identified data to improve the platform's functionality, security, and user experience. |
| Marketing | We will never use your PHI for marketing without your explicit, written authorization. We may use your email for service updates and non-medical communication unless you opt out. |
4. How and With Whom We Share Data
We are legally and ethically bound to limit data sharing.
Sharing for Treatment: Your PHI is securely shared only with the licensed doctor and their authorized staff with whom you are consulting through the portal.
Business Associates: We share limited information with trusted third-party vendors (e.g., cloud storage providers, payment processors) who perform services on our behalf. These vendors are legally required to comply with our privacy standards via a Business Associate Agreement (BAA) or equivalent contract.
Legal/Regulatory Requirements: We will disclose information when required by law, court order, search warrant, or to protect the safety of the patient or the public (e.g., mandatory reporting of communicable diseases).
Aggregated Data: We may share de-identified and aggregated data (data that cannot be traced back to you) for research, public health, or business analytics.
5. Security Measures and Data Storage
Technical Safeguards: We use industry-standard security measures, including end-to-end encryption for all data transmitted between your device and the portal, as well as encryption at rest for stored data. We use firewalls, strong access controls, and regular system audits.
Physical Safeguards: Our data servers are hosted in secure, access-controlled facilities.
Data Retention: We retain your PHI for as long as necessary to comply with legal and regulatory requirements for medical record keeping (e.g., [Insert specific retention period based on jurisdiction]) and for as long as your account is active.
6. Your Privacy Rights
Patients have rights concerning their PHI, which the portal facilitates:
Right to Access: The right to inspect and obtain a copy of your PHI stored by the portal (and maintained by your doctor).
Right to Amendment/Correction: The right to request an amendment to your health information if you believe it is incomplete or incorrect.
Right to Restriction: The right to request that we restrict how we use or disclose your PHI for TPO purposes.
Right to Portability: The right to request an electronic copy of your health information to be sent to you or another third party.
Right to Withdraw Consent: The right to revoke or withdraw your consent for certain future uses of your data, provided the withdrawal is not retroactive.
7. Changes to This Privacy Policy
We reserve the right to modify this Privacy Policy at any time. If we make a material change, we will notify you via email or a prominent notice on the portal homepage before the change takes effect, giving you the opportunity to review and accept the new terms.
Disclaimer: I am an AI and this is a general guide. Medical privacy policies are complex legal documents. You must consult with a qualified legal professional specializing in healthcare or data privacy law (like HIPAA, GDPR, etc.) in your operating jurisdiction to ensure your policy is fully compliant and legally enforceable.