Notice of Privacy Practices
Effective Date: January 1, 2025 | Last Updated: May 2026
THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.
1. Who We Are
MedRevolve LLC ("MedRevolve," "we," "us," or "our") operates as a healthcare technology platform connecting patients with licensed healthcare providers. We are a Business Associate (BA) under HIPAA and work with Covered Entities (licensed providers) who use our platform. This Notice applies to all Protected Health Information (PHI) we create, receive, maintain, or transmit in connection with healthcare services.
2. Your Protected Health Information (PHI)
PHI includes any information that identifies you and relates to your health status, healthcare provision, or payment for healthcare. This includes:
- Your name, address, date of birth, Social Security Number
- Medical history, diagnoses, treatment plans, prescriptions
- Lab results, consultation notes, provider communications
- Payment and billing information linked to healthcare services
- Video consultation recordings (with your explicit consent)
3. How We May Use and Disclose Your PHI
Without Your Authorization:
- Treatment: To provide, coordinate, or manage your healthcare and related services. Providers on our platform may share your information with other treating providers.
- Payment: To obtain payment for healthcare services, including billing insurance, processing credit card payments (via Stripe, our PCI-DSS compliant payment processor), and managing collections.
- Healthcare Operations: Quality assessment, training, accreditation, licensing, and general platform administration.
- As Required by Law: To comply with federal, state, or local laws including reporting requirements for certain communicable diseases or abuse situations.
- Public Health Activities: Reporting disease outbreaks or other public health threats to authorized agencies.
- Business Associates: We share PHI with third-party service providers who assist in our operations (e.g., Stripe for payments, Google for scheduling/email). All Business Associates have signed HIPAA Business Associate Agreements (BAAs) with us.
With Your Written Authorization (required for):
- Marketing purposes (unless permitted by law)
- Sale of PHI
- Most disclosures of psychotherapy notes
- Any use or disclosure not described in this Notice
4. Business Associates with Signed BAAs
The following third-party vendors have executed HIPAA Business Associate Agreements with MedRevolve:
- Stripe, Inc. — payment processing
- Google LLC — Google Workspace, Google Calendar, Google Meet (video consultations)
- Twilio Inc. — SMS appointment reminders and communications
- HubSpot, Inc. — CRM (de-identified data only; PHI not shared with HubSpot)
- Partner pharmacies — prescription fulfillment (covered entities)
5. Your Rights Regarding Your PHI
- Right to Access: You have the right to inspect and obtain a copy of your PHI. We will respond within 30 days. A reasonable fee may apply for copies.
- Right to Amend: You may request correction of PHI you believe is inaccurate or incomplete. We may deny the request in certain circumstances.
- Right to an Accounting of Disclosures: You may request a list of disclosures of your PHI made in the past 6 years (excluding treatment, payment, and healthcare operations).
- Right to Request Restrictions: You may ask us to limit how we use or disclose your PHI, though we are not required to agree to all restrictions.
- Right to Confidential Communications: You may request that we communicate with you by alternative means or at an alternative location.
- Right to a Paper Copy of This Notice: You may request a paper copy at any time, even if you agreed to receive it electronically.
- Right to Opt Out of Fundraising: You may opt out of receiving fundraising communications at any time.
6. Data Retention
Medical records and PHI are retained for a minimum of 7 years from the date of service, or for minor patients, until the patient reaches age 21 (whichever is longer), in accordance with applicable state and federal requirements. Payment records are retained for 7 years. After the retention period, records are securely destroyed using NIST-compliant methods.
7. Data Breach Notification
In the event of a breach of unsecured PHI, we will notify you in writing within 60 days of discovering the breach, as required by the HIPAA Breach Notification Rule (45 CFR Part 164, Subpart D). If the breach affects 500 or more individuals in a state, we will also notify the Secretary of HHS and prominent media outlets in that state. A log of all breaches affecting fewer than 500 individuals will be submitted to HHS annually.
8. Security Measures
MedRevolve implements administrative, physical, and technical safeguards to protect your PHI, including: AES-256 encryption at rest and in transit (TLS 1.2+), role-based access controls, audit logging, multi-factor authentication for all staff accessing PHI, annual security risk assessments, and staff HIPAA training.
9. Our Duties
We are required by law to maintain the privacy and security of your PHI, provide you with this Notice, follow the terms of this Notice, and notify you in the event of a breach. We may change this Notice and the new Notice will be effective for PHI already held. The current Notice will always be available at medrevolve.com/HIPAANotice.
10. Complaints
If you believe your privacy rights have been violated, you may file a complaint with us or with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights. We will not retaliate against you for filing a complaint.
MedRevolve Privacy Officer:
Email: privacy@medrevolve.com
Phone: (704) 426-3311
Address: Charlotte, North Carolina, United States
HHS Office for Civil Rights:
www.hhs.gov/hipaa/filing-a-complaint