Skip to main content

Policy

Privacy practices for health information

Our position on HIPAA, and the safeguards we apply to medical records either way.

Effective

1. Our position on HIPAA, stated plainly

HIPAA applies to covered entities — health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically in connection with certain standard transactions, principally billing insurance — and to their business associates.

We provide independent medical opinions for use as evidence in benefits claims. We do not bill insurance, Medicare, or the VA for these services, and the consultation does not establish a treating relationship. Across most of what we do, we are therefore not acting as a HIPAA covered entity.

We are telling you this rather than implying a compliance status we do not hold, because claiming HIPAA coverage as a marketing badge is common in this market and is frequently untrue.

2. What we do regardless

The information you send us is your complete medical and service history. It deserves protection whatever the statutory label, so we apply safeguards equivalent to the HIPAA Security Rule as a matter of policy:

  • Administrative safeguards: role-based access, a minimum-necessary standard for staff, background-checked personnel, confidentiality obligations, and access reviews.
  • Technical safeguards: TLS in transit, encryption at rest, application-level AES-256-GCM encryption of clinical free text, unique per-user credentials, automatic session expiry, account lockout, and comprehensive audit logging.
  • Physical safeguards: all data held in the facilities of a major cloud provider with certified physical security. No medical records are stored on staff devices.

3. Your physician's own obligations

The licensed physicians who review your records carry professional and ethical duties of confidentiality independent of anything in this document, arising from their licensure and from state medical practice law. Those duties apply to your consultation and to everything they read in your file.

4. We ask for what is needed, and no more

Your intake requests only information relevant to the medical question at hand. We do not collect a full Social Security number. Where a VA file number helps match records, we ask for the last four digits only, and we store even that encrypted.

If you upload a document containing more than we need, we do not extract or index the surplus.

5. Disclosure

We disclose your health information only in these circumstances:

  • To the physician assigned to your case, so they can form an opinion.
  • To administrators supporting your case, under a minimum-necessary standard.
  • To you, or to someone you explicitly authorise in writing.
  • Where compelled by valid legal process, or where disclosure is required to prevent serious and imminent harm.

6. If something goes wrong

If we discover unauthorised access to your health information, we will notify you without undue delay, describe what was affected, explain what we are doing about it, and tell you what steps you may wish to take. We will do this whether or not a breach notification statute compels it.

7. Your control

  • Request a copy of everything we hold about you.
  • Ask for a correction where something is inaccurate.
  • Withdraw a document you uploaded, unless it has already been relied on in a completed opinion.
  • Ask for an account of who has accessed your records — we maintain the audit log precisely so this is answerable.
  • Ask us to delete your records, subject to retention obligations.