PropPilot Get Started
🏥 HIPAA

Notice of Privacy Practices

Last updated: April 23, 2026  ·  Effective: April 23, 2026

THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.

Contents

  1. Overview and Legal Basis
  2. How We Use and Disclose Your PHI
  3. Permitted Uses Without Authorization
  4. Uses Requiring Your Authorization
  5. Business Associates and Pharmacy Disclosures
  6. Your Rights Regarding PHI
  7. Our Obligations
  8. Breach Notification
  9. How to File a Complaint
  10. Contact Our Privacy Officer

1. Overview and Legal Basis

PropPilot ("we," "us," "our") is a healthcare marketplace that facilitates connections between patients and independently licensed healthcare providers. In the course of providing our services, we create, receive, maintain, and transmit Protected Health Information ("PHI") about you.

This Notice of Privacy Practices ("Notice") describes how we may use and disclose your PHI and your rights regarding your PHI. We are required by:

  • The Health Insurance Portability and Accountability Act of 1996 (HIPAA), as codified at 45 CFR Parts 160 and 164
  • The Health Information Technology for Economic and Clinical Health (HITECH) Act of 2009, which strengthened HIPAA's privacy and security requirements and significantly expanded breach notification obligations
  • Applicable state telehealth privacy laws, which may impose more stringent protections than federal law

To the extent PropPilot acts as a Business Associate of covered entity healthcare providers on our platform, we are directly subject to HIPAA's Privacy Rule (45 CFR Part 164, Subpart E) and Security Rule (45 CFR Part 164, Subpart C) with respect to PHI we handle on their behalf.

We are required by law to follow the privacy practices described in this Notice. We will not use or share your health information other than as described here unless you provide written authorization.

"Protected Health Information" (PHI) means individually identifiable health information that relates to: (1) your past, present, or future physical or mental health condition; (2) the provision of healthcare to you; or (3) past, present, or future payment for the provision of healthcare, when that information is created or received by a covered entity or business associate.

2. How We Use and Disclose Your PHI

Treatment

We use and disclose your PHI to facilitate healthcare treatment and services. This includes sharing your health assessment data — including current weight, health history, current medications, and relevant contraindications — with the licensed physician on our platform who is evaluating your eligibility for GLP-1 receptor agonist therapy. Providers may also share clinical information back with us (including prescription details and clinical notes) to coordinate your ongoing care and ensure continuity of treatment.

Payment

We may use and disclose your PHI to facilitate payment for healthcare services. This includes verifying your eligibility for services, processing Subscription Fee payments, and sharing minimum necessary prescription and patient information with dispensing pharmacies to enable billing and fulfillment of your prescriptions.

Healthcare Operations

We may use and disclose your PHI for our healthcare operations, including:

  • Quality improvement and care coordination activities
  • Training, credentialing, and oversight of Providers and platform staff who handle PHI
  • Resolving complaints and grievances
  • Conducting audits, internal reviews, and HIPAA compliance activities
  • Business planning and development (using de-identified or aggregate data only)
  • Legal and risk management functions

Telehealth-Specific PHI Handling

Because our services are delivered via telehealth, your PHI may be transmitted electronically across our secure platform infrastructure. All electronic transmission of PHI is encrypted in transit using TLS 1.2 or higher. Providers access your PHI through our HIPAA-compliant platform; no PHI is transmitted via unsecured channels such as standard email or unencrypted messaging.

3. Permitted Uses Without Your Authorization

Under HIPAA, we are permitted or required to use or disclose your PHI without your written authorization in certain circumstances:

  • Required by law: We may disclose PHI when required to do so by federal, state, or local law, including in response to court orders, administrative subpoenas, or other valid legal process. We will seek to limit such disclosures to the minimum necessary PHI.
  • Public health activities: We may disclose PHI to public health authorities authorized to collect such information for disease surveillance, injury reporting, adverse event reporting to the FDA, or other lawful public health activities.
  • Health oversight activities: We may disclose PHI to health oversight agencies — including the U.S. Department of Health and Human Services Office for Civil Rights (OCR) — for audits, investigations, inspections, licensure actions, and other oversight activities authorized by law.
  • Law enforcement: We may disclose PHI to law enforcement officials under the specific, limited circumstances permitted under 45 CFR §164.512(f), including to identify or locate a suspect, fugitive, or missing person, or to report crimes.
  • Serious threats to health or safety: We may use or disclose PHI when, in good faith, we believe such use or disclosure is necessary to prevent or lessen a serious and imminent threat to the health or safety of a person or the public, and the disclosure is to someone reasonably able to prevent or lessen the threat.
  • Decedents: We may disclose PHI to coroners, medical examiners, or funeral directors as permitted or required by law.
  • Workers' compensation: We may disclose PHI to the extent required by applicable workers' compensation laws.
  • Specialized government functions: We may use or disclose PHI for certain specialized government functions as permitted by 45 CFR §164.512(k), including national security and intelligence activities.

4. Uses Requiring Your Written Authorization

All uses and disclosures of your PHI not described in this Notice require your prior written authorization, including:

  • Most uses and disclosures of psychotherapy notes (if any are created in connection with your care)
  • Uses and disclosures of PHI for marketing purposes — we will never use your PHI to market products or services to you without explicit, written authorization
  • Disclosures that would constitute a sale of PHI — we do not sell PHI
  • Uses of PHI for research, unless the use meets the limited exceptions under 45 CFR §164.512(i)
  • Any other use or disclosure of PHI not described in this Notice

You may revoke an authorization at any time by submitting a written revocation to our Privacy Officer (contact information in Section 10). Revocation will not apply to uses or disclosures already made in reliance on your prior authorization before we received your revocation.

5. Business Associates and Pharmacy Disclosures

Business Associate Agreements

We disclose PHI to vendors and contractors who perform services on our behalf that involve access to PHI ("Business Associates"). These include our telehealth infrastructure provider, cloud hosting vendor, and any other subcontractors who access PHI in the course of providing services to us. We require all Business Associates to execute a Business Associate Agreement (BAA) that:

  • Restricts the Business Associate's use and disclosure of PHI to purposes permitted by the BAA and HIPAA
  • Requires the Business Associate to implement appropriate administrative, physical, and technical safeguards to protect PHI consistent with the HIPAA Security Rule
  • Requires the Business Associate to report breaches of unsecured PHI to us no later than 60 days following discovery
  • Requires the Business Associate to ensure that any subcontractors who access PHI are also bound by BAA obligations

Third-Party Pharmacy Disclosures

When a licensed Provider issues a prescription through our platform, we transmit the minimum necessary PHI required to fulfill that prescription to a licensed dispensing pharmacy. This disclosure is made for treatment and payment purposes under HIPAA. Pharmacies receiving PHI through our platform are required to execute a BAA and are independently subject to HIPAA's requirements as covered entities. We disclose only the PHI necessary to fulfill the specific prescription — we do not disclose your full health history, assessment data, or other PHI to pharmacies.

Minimum Necessary Standard

When using or disclosing PHI — or requesting PHI from another covered entity or business associate — we make reasonable efforts to limit the PHI to the minimum amount necessary to accomplish the intended purpose, consistent with 45 CFR §164.502(b) and §164.514(d). This standard applies to all routine disclosures. It does not apply to disclosures to or requests by a treating Provider, disclosures required by law, or disclosures made pursuant to your written authorization.

6. Your Rights Regarding Your PHI

You Have the Right To:

  • Inspect and obtain a copy of your PHI in our designated record set
  • Request that we amend inaccurate or incomplete PHI we maintain
  • Request restrictions on how we use or disclose your PHI
  • Request an accounting of certain disclosures we have made of your PHI
  • Request that we communicate with you about your PHI in a specific way or at a specific location
  • Receive a paper copy of this Notice at any time, even if you previously agreed to receive it electronically
  • File a complaint with us or with HHS if you believe your privacy rights have been violated

Right to Access (45 CFR §164.524)

You have the right to inspect and obtain a copy of your PHI that we maintain in a "designated record set." We will respond to access requests within 30 days of receipt (or within 60 days if we notify you in writing that additional time is needed, with one 30-day extension). We may charge a reasonable, cost-based fee for paper copies consistent with applicable state law.

We may deny access in limited circumstances — for example, if a licensed healthcare professional has determined that access is reasonably likely to cause substantial harm to you or another person. If access is denied, we will explain the basis for denial, whether the denial is reviewable, and how you can request a review.

You have the right to receive electronic copies of your PHI in a readily producible electronic format when that information is maintained electronically, consistent with the HITECH Act's enhanced access rights.

Right to Amend (45 CFR §164.526)

You have the right to request that we amend PHI that you believe is inaccurate or incomplete. Your request must be in writing and must state the reason(s) for the amendment. We may deny your request if: the information was not created by us; we do not maintain the information; the information is not part of a designated record set; or we determine the information is accurate and complete. If we deny your request, we will provide a written explanation and describe your right to submit a statement of disagreement.

Right to Request Restrictions (45 CFR §164.522)

You have the right to request restrictions on certain uses and disclosures of your PHI for treatment, payment, or healthcare operations purposes. We are not required to agree to your restriction request except in one circumstance: if you have paid for a service in full out-of-pocket and you request that we not disclose PHI related to that service to your health plan, we must agree to that restriction.

Right to an Accounting of Disclosures (45 CFR §164.528)

You have the right to request an accounting of certain disclosures we have made of your PHI during the six (6) years prior to your request date (or a shorter period if you specify). This right does not apply to disclosures made: for treatment, payment, or healthcare operations; pursuant to a valid authorization you provided; to you directly; to persons involved in your care; for national security purposes; as part of a limited data set; or prior to April 14, 2003.

You may request one accounting per 12-month period at no charge. Additional accountings within the same 12-month period may be subject to a reasonable fee.

Right to Confidential Communications (45 CFR §164.522(b))

You have the right to request that we communicate with you about your PHI by alternative means or at an alternative location. For example, you may request that we contact you only by email rather than postal mail, or only at a specific phone number. We will accommodate reasonable requests that specify how or where you wish to receive communications and will not ask you to explain your reason for the request.

Right to a Copy of This Notice (45 CFR §164.520)

You have the right to receive a paper copy of this Notice at any time. Contact our Privacy Officer using the information in Section 10 to request a paper copy.

7. Our Obligations

PropPilot is required by law to:

  • Maintain the privacy and security of your PHI
  • Provide you with this Notice of our legal duties and privacy practices with respect to PHI
  • Abide by the terms of the Notice currently in effect
  • Not use or disclose your PHI other than as described in this Notice, unless you authorize it in writing
  • Notify you promptly following a breach of unsecured PHI, as described in Section 8
  • Provide you with access to your PHI in electronic form when requested and when technically feasible
  • Train our workforce on HIPAA privacy requirements and the terms of this Notice

We reserve the right to change the terms of this Notice. Any revised Notice will be effective for all PHI we maintain, including PHI created or received prior to the revision. If we make a material change to this Notice, we will: (a) make the revised Notice available on our website; (b) post a notice on our website that the Notice has been changed; and (c) notify patients by email if the change materially affects how we handle their PHI.

8. Breach Notification

PropPilot is required by the HIPAA Breach Notification Rule (45 CFR Part 164, Subpart D), as strengthened by the HITECH Act, to notify you if your unsecured PHI is breached.

What Constitutes a Breach

A "breach" is an acquisition, access, use, or disclosure of PHI in a manner not permitted by the HIPAA Privacy Rule that compromises the security or privacy of the PHI. We presume any impermissible access, acquisition, use, or disclosure of PHI to be a breach unless we can demonstrate a low probability that the PHI has been compromised based on a four-factor risk assessment specified in 45 CFR §164.402.

Notification Timeline

Following discovery of a breach of unsecured PHI, we will:

  • Notify affected individuals no later than 60 calendar days after discovery of the breach. Notice will be provided by first-class mail to your last known address (or by email if you have previously specified email as your preferred contact method and have not objected to electronic notification).
  • Notify HHS: For breaches affecting 500 or more individuals, we will notify the U.S. Department of Health and Human Services (HHS) within 60 days of discovery. For breaches affecting fewer than 500 individuals, we will report to HHS on an annual basis.
  • Notify media: If a breach affects 500 or more residents of a state or jurisdiction, we will provide notice to a prominent media outlet serving that area within 60 days of discovery.

Content of Breach Notification

Our breach notification to you will include, to the extent possible:

  • A brief description of what happened, including the date of the breach and the date of discovery
  • A description of the types of unsecured PHI involved (e.g., name, date of birth, diagnosis, prescription information)
  • Steps you should take to protect yourself from potential harm
  • A description of what we are doing to investigate the breach, mitigate harm, and prevent future occurrences
  • Contact information for questions and to report concerns

State Breach Notification Laws

Many states impose breach notification requirements that are more stringent than federal HIPAA standards, including shorter notification windows. We will comply with the most protective standard applicable to residents of those states. California residents, for example, may be entitled to notification under the California Data Breach Notification Law (California Civil Code §1798.82) in addition to HIPAA protections.

9. How to File a Complaint

If you believe your privacy rights under HIPAA have been violated, you have the right to file a complaint — with us, or directly with the federal government. We will not retaliate against you for filing a complaint.

File a Complaint with PropPilot

Contact our Privacy Officer at support@proppilot-13.polsia.app with a description of your concern. We will acknowledge your complaint within 5 business days and will investigate and respond within 30 days. If we are unable to resolve your complaint within 30 days, we will notify you in writing of the additional time needed and the reason for the delay.

File a Complaint with the U.S. Department of Health and Human Services

You may file a complaint directly with the Office for Civil Rights (OCR), which enforces HIPAA:

  • Online: www.hhs.gov/ocr/privacy/hipaa/complaints
  • Phone: 1-800-368-1019
  • TDD/TYY: 1-800-537-7697
  • Mail: U.S. Department of Health and Human Services, 200 Independence Avenue, S.W., Room 509F, HHH Building, Washington, D.C. 20201

Filing a complaint with HHS will not affect your ability to receive services from PropPilot. There is no charge to file a HIPAA complaint with OCR.

10. Contact Our Privacy Officer

For questions about this Notice, to exercise your HIPAA rights, or to file a privacy complaint, contact our Privacy Officer:

PropPilot Privacy Officer
Email: support@proppilot-13.polsia.app

We will respond to all privacy-related requests within 30 days of receipt. For requests that cannot be fulfilled within 30 days, we will notify you in writing of the reason for the delay and an estimated completion date.

For general privacy questions not related to your PHI, please see our Privacy Policy.

PropPilot

Doctor-led weight loss with verified providers, personalized GLP-1 treatment, and integrated lifestyle coaching.

Platform

  • How It Works
  • Pricing
  • FAQ

Legal

  • Privacy Policy
  • Cookie preferences
  • Terms of Service
  • HIPAA Notice
  • Refund Policy
  • Telehealth Consent

Contact

  • support@proppilot-13.polsia.app
© 2026 PropPilot. All rights reserved. Built with Polsia
PropPilot is a healthcare marketplace connecting patients with independently licensed healthcare providers. Prescriptions are issued only after consultation with a licensed physician who determines medical appropriateness. This site does not provide medical advice — consult your physician before starting any treatment.
We value your privacy

We use essential cookies to make PropPilot work and, with your permission, analytics cookies to improve it. You can accept all, reject non-essential, or choose your preferences.

Cookie preferences

Choose which categories of cookies PropPilot may set on this browser. Your selection is stored locally and can be changed any time from the footer.