Last updated: April 23, 2026 · Effective: April 23, 2026
THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.
PropPilot ("we," "us," "our") is a healthcare marketplace that facilitates connections between patients and independently licensed healthcare providers. In the course of providing our services, we create, receive, maintain, and transmit Protected Health Information ("PHI") about you.
This Notice of Privacy Practices ("Notice") describes how we may use and disclose your PHI and your rights regarding your PHI. We are required by:
To the extent PropPilot acts as a Business Associate of covered entity healthcare providers on our platform, we are directly subject to HIPAA's Privacy Rule (45 CFR Part 164, Subpart E) and Security Rule (45 CFR Part 164, Subpart C) with respect to PHI we handle on their behalf.
We are required by law to follow the privacy practices described in this Notice. We will not use or share your health information other than as described here unless you provide written authorization.
"Protected Health Information" (PHI) means individually identifiable health information that relates to: (1) your past, present, or future physical or mental health condition; (2) the provision of healthcare to you; or (3) past, present, or future payment for the provision of healthcare, when that information is created or received by a covered entity or business associate.
We use and disclose your PHI to facilitate healthcare treatment and services. This includes sharing your health assessment data — including current weight, health history, current medications, and relevant contraindications — with the licensed physician on our platform who is evaluating your eligibility for GLP-1 receptor agonist therapy. Providers may also share clinical information back with us (including prescription details and clinical notes) to coordinate your ongoing care and ensure continuity of treatment.
We may use and disclose your PHI to facilitate payment for healthcare services. This includes verifying your eligibility for services, processing Subscription Fee payments, and sharing minimum necessary prescription and patient information with dispensing pharmacies to enable billing and fulfillment of your prescriptions.
We may use and disclose your PHI for our healthcare operations, including:
Because our services are delivered via telehealth, your PHI may be transmitted electronically across our secure platform infrastructure. All electronic transmission of PHI is encrypted in transit using TLS 1.2 or higher. Providers access your PHI through our HIPAA-compliant platform; no PHI is transmitted via unsecured channels such as standard email or unencrypted messaging.
Under HIPAA, we are permitted or required to use or disclose your PHI without your written authorization in certain circumstances:
All uses and disclosures of your PHI not described in this Notice require your prior written authorization, including:
You may revoke an authorization at any time by submitting a written revocation to our Privacy Officer (contact information in Section 10). Revocation will not apply to uses or disclosures already made in reliance on your prior authorization before we received your revocation.
We disclose PHI to vendors and contractors who perform services on our behalf that involve access to PHI ("Business Associates"). These include our telehealth infrastructure provider, cloud hosting vendor, and any other subcontractors who access PHI in the course of providing services to us. We require all Business Associates to execute a Business Associate Agreement (BAA) that:
When a licensed Provider issues a prescription through our platform, we transmit the minimum necessary PHI required to fulfill that prescription to a licensed dispensing pharmacy. This disclosure is made for treatment and payment purposes under HIPAA. Pharmacies receiving PHI through our platform are required to execute a BAA and are independently subject to HIPAA's requirements as covered entities. We disclose only the PHI necessary to fulfill the specific prescription — we do not disclose your full health history, assessment data, or other PHI to pharmacies.
When using or disclosing PHI — or requesting PHI from another covered entity or business associate — we make reasonable efforts to limit the PHI to the minimum amount necessary to accomplish the intended purpose, consistent with 45 CFR §164.502(b) and §164.514(d). This standard applies to all routine disclosures. It does not apply to disclosures to or requests by a treating Provider, disclosures required by law, or disclosures made pursuant to your written authorization.
You have the right to inspect and obtain a copy of your PHI that we maintain in a "designated record set." We will respond to access requests within 30 days of receipt (or within 60 days if we notify you in writing that additional time is needed, with one 30-day extension). We may charge a reasonable, cost-based fee for paper copies consistent with applicable state law.
We may deny access in limited circumstances — for example, if a licensed healthcare professional has determined that access is reasonably likely to cause substantial harm to you or another person. If access is denied, we will explain the basis for denial, whether the denial is reviewable, and how you can request a review.
You have the right to receive electronic copies of your PHI in a readily producible electronic format when that information is maintained electronically, consistent with the HITECH Act's enhanced access rights.
You have the right to request that we amend PHI that you believe is inaccurate or incomplete. Your request must be in writing and must state the reason(s) for the amendment. We may deny your request if: the information was not created by us; we do not maintain the information; the information is not part of a designated record set; or we determine the information is accurate and complete. If we deny your request, we will provide a written explanation and describe your right to submit a statement of disagreement.
You have the right to request restrictions on certain uses and disclosures of your PHI for treatment, payment, or healthcare operations purposes. We are not required to agree to your restriction request except in one circumstance: if you have paid for a service in full out-of-pocket and you request that we not disclose PHI related to that service to your health plan, we must agree to that restriction.
You have the right to request an accounting of certain disclosures we have made of your PHI during the six (6) years prior to your request date (or a shorter period if you specify). This right does not apply to disclosures made: for treatment, payment, or healthcare operations; pursuant to a valid authorization you provided; to you directly; to persons involved in your care; for national security purposes; as part of a limited data set; or prior to April 14, 2003.
You may request one accounting per 12-month period at no charge. Additional accountings within the same 12-month period may be subject to a reasonable fee.
You have the right to request that we communicate with you about your PHI by alternative means or at an alternative location. For example, you may request that we contact you only by email rather than postal mail, or only at a specific phone number. We will accommodate reasonable requests that specify how or where you wish to receive communications and will not ask you to explain your reason for the request.
You have the right to receive a paper copy of this Notice at any time. Contact our Privacy Officer using the information in Section 10 to request a paper copy.
PropPilot is required by law to:
We reserve the right to change the terms of this Notice. Any revised Notice will be effective for all PHI we maintain, including PHI created or received prior to the revision. If we make a material change to this Notice, we will: (a) make the revised Notice available on our website; (b) post a notice on our website that the Notice has been changed; and (c) notify patients by email if the change materially affects how we handle their PHI.
PropPilot is required by the HIPAA Breach Notification Rule (45 CFR Part 164, Subpart D), as strengthened by the HITECH Act, to notify you if your unsecured PHI is breached.
A "breach" is an acquisition, access, use, or disclosure of PHI in a manner not permitted by the HIPAA Privacy Rule that compromises the security or privacy of the PHI. We presume any impermissible access, acquisition, use, or disclosure of PHI to be a breach unless we can demonstrate a low probability that the PHI has been compromised based on a four-factor risk assessment specified in 45 CFR §164.402.
Following discovery of a breach of unsecured PHI, we will:
Our breach notification to you will include, to the extent possible:
Many states impose breach notification requirements that are more stringent than federal HIPAA standards, including shorter notification windows. We will comply with the most protective standard applicable to residents of those states. California residents, for example, may be entitled to notification under the California Data Breach Notification Law (California Civil Code §1798.82) in addition to HIPAA protections.
If you believe your privacy rights under HIPAA have been violated, you have the right to file a complaint — with us, or directly with the federal government. We will not retaliate against you for filing a complaint.
Contact our Privacy Officer at support@proppilot-13.polsia.app with a description of your concern. We will acknowledge your complaint within 5 business days and will investigate and respond within 30 days. If we are unable to resolve your complaint within 30 days, we will notify you in writing of the additional time needed and the reason for the delay.
You may file a complaint directly with the Office for Civil Rights (OCR), which enforces HIPAA:
Filing a complaint with HHS will not affect your ability to receive services from PropPilot. There is no charge to file a HIPAA complaint with OCR.
For questions about this Notice, to exercise your HIPAA rights, or to file a privacy complaint, contact our Privacy Officer:
PropPilot Privacy Officer
Email: support@proppilot-13.polsia.app
We will respond to all privacy-related requests within 30 days of receipt. For requests that cannot be fulfilled within 30 days, we will notify you in writing of the reason for the delay and an estimated completion date.
For general privacy questions not related to your PHI, please see our Privacy Policy.