Patient And Consumer User Privacy Policy
WEHEALTH PATIENT AND CONSUMER USER PRIVACY POLICY
Last updated: June 30, 2026
PLAIN-ENGLISH SUMMARY
WeHealth Technologies LLC d.b.a. WeHealth (“WeHealth,” “we,” “us,” or “our”) is a healthcare technology and consumer wellness technology company. This Patient and Consumer User Privacy Policy (“Privacy Policy”) explains how WeHealth collects, uses, discloses, stores, and protects personal information, health-related information, consumer wellness information, and, where applicable, Protected Health Information (“PHI”).
WeHealth offers different types of technology-enabled services. Some WeHealth services support healthcare providers, medical groups, health plans, clinics, care management organizations, and other healthcare organizations responsible for a patient’s care. Other WeHealth services may include consumer wellness or mobile app features used directly by individuals.
When WeHealth receives, stores, transmits, maintains, or processes PHI on behalf of a healthcare provider, medical group, health plan, clinic, or other covered entity, WeHealth acts as a Business Associate under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) and the Health Information Technology for Economic and Clinical Health Act (“HITECH”). In that role, WeHealth handles PHI in accordance with applicable Business Associate Agreements, HIPAA, HITECH, applicable state privacy laws, and the instructions of the applicable covered entity.
When you use WeHealth consumer wellness or mobile app features directly, WeHealth may collect personal information, health-related information, wellness information, device information, app usage information, user content, and other information you choose to provide. Such consumer wellness information may not always be PHI under HIPAA unless it is created, received, maintained, or transmitted by WeHealth on behalf of a covered entity or otherwise qualifies as PHI under applicable law. Regardless of whether information is PHI, WeHealth treats health-related and wellness information as sensitive information and applies privacy and security safeguards designed to protect it.
WeHealth is not a medical practice, healthcare provider, physician group, pharmacy, pharmacy benefit manager, durable medical equipment supplier, electronic medical record system, electronic health record system, prescribing platform, prescription routing platform, or prescription fulfillment service. WeHealth does not provide medical care, diagnose, treat, prescribe medication, dispense medication, issue medical orders, make clinical decisions, or establish a provider-patient relationship.
Medical care is provided by independent licensed healthcare providers, medical groups, health plans, clinics, or other covered entities responsible for your care. The applicable HIPAA Notice of Privacy Practices is generally provided by your treating healthcare provider, medical group, health plan, clinic, or other covered entity responsible for your care.
WeHealth does not sell PHI. WeHealth does not use PHI for targeted advertising or cross-context behavioral advertising. WeHealth does not sell consumer health information collected through its wellness or mobile app features.
OUR PRIVACY PRINCIPLES
WeHealth recognizes that health-related information is sensitive and personal. We are guided by the following principles:
We are transparent about the information we collect and how we use it.
We use health-related information only for lawful, disclosed, and appropriate purposes.
We apply privacy and security safeguards designed to protect personal information, consumer health information, and PHI.
We limit access to sensitive information to authorized personnel, service providers, and parties with a legitimate need to access it.
We do not sell PHI or consumer health information.
We do not use PHI or consumer health information for targeted advertising or cross-context behavioral advertising.
We do not use precise geolocation information to identify or target individuals seeking healthcare services or supplies.
We provide additional protections for consumer health data where required by state consumer health privacy laws.
1. ROLE OF WEHEALTH
WeHealth provides technology-enabled tools and support services that may assist healthcare providers, medical groups, health plans, clinics, and healthcare organizations with care coordination, remote patient monitoring support, chronic care management support, patient engagement, communication, documentation support, reporting, task management, and related administrative or operational workflows.
WeHealth may also provide consumer wellness and mobile app features, including wellness tracking, health-related self-reporting, educational content, notifications, reminders, user-generated content, artificial intelligence features, automation, and related digital tools.
WeHealth does not independently provide medical care. Any medical care, diagnosis, treatment, clinical decision-making, prescribing, ordering, medical recordkeeping, billing, coding, patient consent, or professional healthcare service is the responsibility of the independent healthcare provider, medical group, health plan, clinic, or covered entity responsible for your care.
2. SCOPE OF THIS PRIVACY POLICY
This Privacy Policy applies to information WeHealth collects through:
- WeHealth websites and mobile applications;
- WeHealth patient-facing, consumer-facing, and provider-supported platform features;
- consumer wellness and mobile app features;
- SMS, phone, email, chat, push notifications, support communications, and other communications with WeHealth;
- onboarding, enrollment, support, account management, and operational activities; and
- related WeHealth services, features, technology tools, and business interactions.
This Privacy Policy does not replace the HIPAA Notice of Privacy Practices of your treating provider, medical group, health plan, clinic, or other covered entity. If you receive healthcare services from a provider or healthcare organization, you should also review that provider’s Notice of Privacy Practices and privacy policies.
Our Platform may contain links to websites, apps, services, or resources that are not owned or controlled by WeHealth. We are not responsible for the privacy practices of those third parties. You should review the privacy policies of any third-party websites, apps, or services that you use.
3. PERSONAL INFORMATION AND SENSITIVE INFORMATION
“Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an individual or household.
“Sensitive Information” may include information such as government identifiers, account login credentials, financial information, precise geolocation, contents of communications, biometric information, health-related information, medical information, consumer health information, information about a known child, and other information treated as sensitive under applicable law.
“Protected Health Information” or “PHI” has the meaning given to that term under HIPAA and generally includes individually identifiable health information created, received, maintained, or transmitted by or on behalf of a covered entity or business associate.
Information that is publicly available, de-identified, aggregated, or anonymized may not be Personal Information under certain laws.
4. HEALTHCARE SERVICES VS. CONSUMER WELLNESS SERVICES
4.1 Provider-Supported Healthcare Services
Some WeHealth services are provided in support of healthcare providers, medical groups, health plans, clinics, and other healthcare organizations responsible for patient care. These services may include care coordination support, remote patient monitoring support, chronic care management support, patient engagement, communication, documentation support, reporting, task management, operational support, and related technology-enabled workflows.
When WeHealth receives, stores, transmits, maintains, or processes PHI on behalf of a healthcare provider, medical group, health plan, clinic, or other covered entity, WeHealth acts as a Business Associate under HIPAA and HITECH and handles such information in accordance with applicable Business Associate Agreements, HIPAA, HITECH, applicable state privacy laws, and the instructions of the applicable covered entity.
4.2 Consumer Wellness and Mobile App Services
Other WeHealth services may be consumer wellness or mobile app features used directly by individuals. These features may include wellness tracking, self-entered health information, reminders, educational information, general wellness content, device or app-based data, user-generated content, AI-supported features, or other consumer-facing digital tools.
Information collected through consumer wellness features may include health-related or wellness information, but it may not always be PHI under HIPAA unless it is created, received, maintained, or transmitted by WeHealth on behalf of a covered entity or otherwise qualifies as PHI under applicable law. Regardless of whether information is PHI, WeHealth treats health-related and wellness information as sensitive information and applies privacy and security safeguards designed to protect it.
Consumer wellness features are for general wellness, educational, informational, and self-management purposes only. They are not medical advice, diagnosis, treatment, prevention, emergency monitoring, or professional healthcare services.
5. HOW WE COLLECT INFORMATION
We may collect information in several ways, including:
- directly from you when you create an account, use the Platform, submit forms, communicate with us, use consumer wellness features, or contact support;
- from healthcare providers, medical groups, health plans, clinics, care coordinators, caregivers, authorized representatives, or healthcare organizations involved in your care or program;
- from remote patient monitoring devices, connected devices, mobile applications, health apps, wearable devices, integrations, or app permissions that you enable;
- from service providers and vendors that support our Platform, communications, payment processing, hosting, analytics, security, and customer support;
- from app stores or payment processors when you purchase or subscribe to consumer app features;
- from website, app, browser, device, cookie, log, and analytics technologies; and
- from public, business, or third-party sources where permitted by law and relevant to the services.
If you submit information about another person, you represent that you have the authority to do so and permit WeHealth to use that information in accordance with this Privacy Policy and applicable law.
6. INFORMATION WE COLLECT
The categories of information we may collect include:
| Category | Examples | Primary Purposes | Potential Recipients |
| Identity and Contact Information | Name, date of birth, age, mailing address, service address, email address, telephone number, emergency contact, caregiver or authorized representative information. | Account creation, identity verification, communication, service eligibility, support, compliance. | Healthcare providers, health plans, service providers, communication vendors, support vendors, legal/compliance advisors. |
| Account and Access Information | User ID, login credentials, authentication data, account preferences, app settings, registration status, consent status, and access activity. | Account administration, authentication, security, troubleshooting, fraud prevention. | Hosting providers, security vendors, IT support vendors, professional advisors. |
| Health Information / PHI | Symptoms, diagnoses, conditions, care notes, care plans, medication information, allergies, treatment information, clinical observations, RPM/CCM information, provider-submitted information, patient communications, and other health information. | Provider-supported services, care coordination support, RPM/CCM support, reporting, documentation support, legal and contractual obligations. | Treating providers, health plans, covered entities, service providers/subcontractors under appropriate agreements, legal/compliance recipients as permitted by law. |
| Consumer Wellness Information | Wellness goals, habits, activity information, sleep information, hydration, mood, nutrition, weight, exercise, self-entered health information, wellness check-ins, and other consumer wellness data. | Consumer app features, personalization, wellness reminders, service improvement, AI/model improvement subject to this Policy and applicable controls. | Service providers, analytics providers, support vendors, app infrastructure vendors, legal/compliance recipients as permitted by law. |
| RPM / Device / Sensor Data | Blood pressure, pulse oximetry, weight, glucose readings if applicable, temperature if applicable, heart rate, device status, timestamps, device identifiers, transmission status, and related monitoring data. | RPM workflows, patient engagement, reporting, device support, troubleshooting, care coordination support. | Treating providers, healthcare organizations, device vendors, hosting providers, support vendors, subcontractors under appropriate agreements. |
| Communications | SMS messages, phone call information, voicemails, emails, chat messages, app messages, support requests, forms, consents, uploaded files, documents, images, notes, and other communications. | Support, account notices, care/wellness reminders, compliance, quality assurance, documentation support. | Communication vendors, support vendors, providers or care teams where applicable, legal/compliance recipients. |
| Insurance, Payment, and Eligibility Information | Payer name, member ID, eligibility information, plan information, payment information, subscription information, transaction status, billing-related information, or claims-related information where applicable. | Eligibility checks, billing support, subscription management, payment processing, fraud prevention, compliance. | Payment processors, app stores, providers, health plans, billing vendors, professional advisors. |
| Technical, Usage, and Security Information | IP address, browser type, device type, operating system, mobile device identifiers, app version, cookie/session IDs, log-in activity, clicks, views, crash logs, diagnostic data, authentication records, security logs, and usage patterns. | Security, troubleshooting, analytics, platform performance, fraud prevention, service improvement. | Hosting providers, analytics providers, security vendors, IT service providers, professional advisors. |
| Location and Service Eligibility Information | State, ZIP code, service address, location information you provide, approximate location derived from IP address, and information needed to determine whether services are available in your jurisdiction. | Service availability, jurisdiction eligibility, compliance, fraud prevention, account support. | Providers, health plans, service providers, legal/compliance recipients as permitted by law. |
| User Content | Text, questions, responses, notes, messages, files, documents, links, images, photos, screenshots, audio, video, or other content you choose to submit, upload, create, edit, store, use, or share through WeHealth features. | Consumer wellness features, support, AI/automation features, quality improvement, troubleshooting, compliance. | Service providers, AI/automation infrastructure providers where applicable, support vendors, legal/compliance recipients as permitted by law. |
| App Store / Subscription Information | Subscription status, in-app purchase status, transaction identifiers, app store account-related information, and limited payment or purchase information received from Apple, Google, Stripe, or other payment processors where applicable. | Subscription access, payment support, fraud prevention, accounting, customer support. | App stores, payment processors, accounting vendors, support vendors, professional advisors. |
7. INFORMATION FROM HEALTHCARE PROVIDERS, HEALTH PLANS, CAREGIVERS, AND AUTHORIZED REPRESENTATIVES
If you participate in a provider-supported healthcare program, WeHealth may receive information about you from your treating provider, medical group, health plan, clinic, care coordinator, caregiver, authorized representative, or other healthcare organization. This may include PHI and other information needed to support care coordination, RPM/CCM workflows, patient engagement, reporting, documentation support, communication, and related operational activities.
Your treating provider, medical group, health plan, clinic, or covered entity is responsible for determining whether it is legally authorized to provide your information to WeHealth, obtaining any required consent or authorization, providing any required notices, and maintaining your official medical record.
If you are a caregiver, family member, or authorized representative submitting information about another person, you represent that you have the authority or permission required to provide that information to WeHealth.
8. HEALTH APP, DEVICE, AND MOBILE DATA
If WeHealth offers features that connect to third-party health apps, device platforms, wearable devices, remote patient monitoring devices, or mobile operating system health features, we may request permission to access or receive information from those sources.
Depending on the features you use, this may include information such as heart rate, blood pressure, blood oxygen, weight, glucose readings, activity, sleep, device status, timestamps, or related health/wellness data.
You may be able to manage permissions through your device settings, operating system settings, third-party app settings, or connected device settings. If you disable access, some WeHealth features may not function properly.
WeHealth does not sell PHI. WeHealth does not sell consumer health information. WeHealth does not use PHI for targeted advertising or cross-context behavioral advertising. WeHealth does not use health information received from connected health apps or devices for targeted advertising.
9. HOW WE USE INFORMATION
9.1 To Provide and Operate WeHealth Services
- create and manage accounts;
- provide access to the Platform;
- support care coordination, RPM, CCM, patient engagement, communication, documentation, and reporting workflows;
- support consumer wellness and mobile app features;
- display readings, reports, reminders, tasks, or alerts;
- provide customer support;
- troubleshoot technical issues;
- maintain, secure, and improve the Platform;
- manage subscriptions or payments where applicable; and
- perform services under applicable agreements.
9.2 To Support Providers and Healthcare Organizations
When WeHealth acts as a Business Associate, we may use PHI to perform services for or on behalf of the applicable healthcare provider, medical group, health plan, clinic, or covered entity, as permitted by the applicable Business Associate Agreement, HIPAA, HITECH, applicable state privacy laws, and the instructions of the covered entity.
9.3 To Communicate with You
We may use information to send account notices, service updates, appointment reminders, care coordination messages, RPM/CCM program reminders, wellness reminders, push notifications, SMS/text messages, phone calls, emails, support responses, security notices, consent or authorization requests, and other communications related to the Platform or services.
9.4 To Improve, Secure, and Develop WeHealth Technology
We may use information to improve Platform quality and performance, conduct analytics, troubleshoot errors, monitor security, prevent fraud or misuse, develop new features, test and improve workflows, conduct quality assurance, maintain backups and audit logs, support AI, automation, and machine learning features as described in this Privacy Policy, and generate de-identified, aggregated, or anonymized information.
9.5 To Comply with Law and Protect Rights
We may use information to comply with applicable laws, regulations, subpoenas, legal process, or government requests; enforce our Terms of Use and agreements; detect, prevent, or respond to fraud, security, or technical issues; protect the rights, property, safety, or security of WeHealth, users, patients, providers, customers, or the public; and respond to privacy, security, compliance, or legal inquiries.
10. AI, MACHINE LEARNING, ANALYTICS, AND PRODUCT IMPROVEMENT
WeHealth may use data to operate, maintain, secure, troubleshoot, improve, and develop the Platform, including analytics, automation, artificial intelligence, machine learning, and related technology-enabled features.
When WeHealth receives, stores, transmits, maintains, or processes PHI on behalf of a healthcare provider, medical group, health plan, clinic, or other covered entity, WeHealth uses such PHI only as permitted by applicable Business Associate Agreements, HIPAA, HITECH, applicable state privacy laws, and the instructions of the applicable covered entity. WeHealth does not use PHI to train general-purpose AI models or for independent commercial product development unless permitted by applicable law, applicable agreements, and any required consents or authorizations.
WeHealth may use de-identified, aggregated, or anonymized information to improve, develop, test, and train analytics tools, automation features, artificial intelligence systems, machine learning models, and related products or services. De-identified information is information that does not identify an individual and has been de-identified in accordance with applicable legal requirements, including HIPAA de-identification standards where applicable.
For consumer wellness or mobile app features used directly by individuals, WeHealth may use personal information, consumer health information, wellness information, user content, app usage information, and device information to operate, personalize, improve, develop, test, and train WeHealth’s technology, including AI, machine learning, automation, and wellness-related features, as described in this Privacy Policy and subject to any privacy controls, consent settings, or opt-out rights that may apply. Where consumer health data laws require consent for a particular collection, sharing, or use, WeHealth will obtain consent or limit the activity to what is necessary to provide a product or service you requested or as otherwise permitted by law.
WeHealth does not sell PHI. WeHealth does not sell consumer health information. WeHealth does not use PHI or consumer health information for targeted advertising or cross-context behavioral advertising.
11. AI AND AUTOMATED OUTPUTS
The Platform may include artificial intelligence, machine learning, automation, or other technology-enabled features that generate summaries, suggestions, alerts, reminders, reports, text, classifications, risk indicators, wellness feedback, or other outputs (“Automated Outputs”).
Automated Outputs may be incomplete, inaccurate, delayed, or inappropriate for a particular user, patient, condition, or clinical situation. Automated Outputs are provided for informational, operational, wellness, or support purposes only and are not medical advice, diagnosis, treatment, prescribing guidance, emergency monitoring, or a substitute for professional clinical judgment.
Users should not rely on Automated Outputs as the sole basis for medical decisions, treatment decisions, medication decisions, emergency decisions, or decisions that may have legal, financial, clinical, or material impact on an individual.
Healthcare providers remain solely responsible for reviewing, validating, and exercising independent professional judgment before relying on or using any Automated Output in connection with patient care.
12. HOW WE SHARE INFORMATION
12.1 With Healthcare Providers, Health Plans, and Healthcare Organizations
If you participate in provider-supported healthcare services, WeHealth may share information with your treating provider, medical group, health plan, clinic, care team, care coordinator, or other healthcare organization involved in your care or responsible for the applicable program.
12.2 With Service Providers and Subcontractors
We may share information with vendors, service providers, contractors, subcontractors, hosting providers, analytics providers, customer support providers, communication providers, payment processors, security providers, and other third parties that help us operate, maintain, support, secure, and improve the Platform.
Where a third party creates, receives, maintains, or transmits PHI on behalf of WeHealth, WeHealth requires appropriate written agreements, including business associate or subcontractor business associate terms where required by HIPAA.
12.3 With Your Consent or Direction
We may share information when you consent to or direct the sharing, including when you ask us to share information with a healthcare provider, caregiver, family member, authorized representative, or third-party service.
12.4 For Legal, Compliance, Security, or Safety Reasons
We may disclose information if we have a good-faith belief that access, use, preservation, or disclosure is reasonably necessary to comply with law, regulation, subpoena, legal process, or enforceable governmental request; enforce our Terms of Use or other agreements; investigate potential violations; detect, prevent, or address fraud, security, or technical issues; protect rights, property, safety, or security; or comply with HIPAA, HITECH, applicable state privacy laws, or applicable Business Associate Agreements.
To the extent a request involves PHI, WeHealth will handle such request in accordance with HIPAA, applicable Business Associate Agreements, applicable state privacy laws, and applicable legal requirements.
12.5 Change of Control
If the ownership of all or substantially all of our business changes, or we transfer assets relating to our business or the Platform to a third party, such as by merger, acquisition, corporate reorganization, bankruptcy proceeding, or similar transaction, information may be transferred to the successor entity as permitted by applicable law and applicable agreements. Any PHI will continue to be protected in accordance with applicable Business Associate Agreements, HIPAA, HITECH, applicable state privacy laws, and this Privacy Policy.
13. NO SALE OF PHI OR CONSUMER HEALTH INFORMATION
WeHealth does not sell PHI. WeHealth does not sell consumer health information collected through consumer wellness or mobile app features. WeHealth does not use PHI or consumer health information for targeted advertising or cross-context behavioral advertising. WeHealth does not use health information received from connected health apps, RPM devices, or consumer wellness features for targeted advertising.
We may use cookies, analytics tools, and similar technologies for operational purposes, security, troubleshooting, performance measurement, user preferences, and service improvement. Where required by law, we will provide applicable choices or obtain required consent.
14. COOKIES, ANALYTICS, AND SIMILAR TECHNOLOGIES
We and our service providers may use cookies, web beacons, pixels, SDKs, mobile identifiers, log files, and similar technologies to operate, secure, and improve the Platform.
These technologies may help us keep you signed in, remember preferences, secure your account, understand Platform usage, monitor performance, diagnose bugs or crashes, prevent fraud or misuse, improve user experience, and measure the effectiveness of communications or features.
You may be able to disable cookies through your browser or device settings. Some features may not work properly if cookies or similar technologies are disabled. Our Platform may not recognize “Do Not Track” signals or similar mechanisms. We do not engage in cross-context behavioral advertising using PHI or consumer health information.
15. SMS, PHONE CALLS, EMAILS, AND PUSH NOTIFICATIONS
By creating an account, enrolling in a program, or providing your mobile number through an applicable consent form, you provide your prior express written consent to receive automated, pre-recorded, artificial voice, and/or non-automated calls and text messages from WeHealth and its authorized agents related to Platform access, account notices, appointment reminders, care coordination, RPM/CCM support, wellness reminders, service updates, and, where separately permitted, promotional messages. Message and data rates may apply. Consent to marketing messages is not a condition of purchasing goods or services.
Clinical and Chart Notifications. WeHealth may send text messages (SMS), email notifications, and push notifications to notify you when your healthcare provider, care team, or care coordinator uploads laboratory results, imaging results, clinical documents, care plan updates, prescription information, referrals, messages, or other information to your account or care record through the Platform. These are care-related and account-related communications and may be sent by SMS, email, push notification, or other available communication method. You may manage certain notification preferences through your app settings or account settings where applicable, but care-related notifications may still be sent by one or more methods where required by your care program, provider instructions, or applicable law.
You may opt out of non-essential promotional messages at any time by replying STOP or contacting us using the information in the “Contact Us” section below. Transactional, account-related, care-related, or legally required communications may still be sent where permitted by law.
If you enable push notifications, we may send app notifications related to your account, service activity, wellness reminders, device readings, program reminders, or other features. You may manage push notifications through your device or app settings.
WeHealth will comply with applicable federal and state communications laws, including the Telephone Consumer Protection Act (“TCPA”), where applicable. Separate written consent may be required on applicable intake, enrollment, or consent forms for certain categories of communications.
16. APP STORE, PAYMENT, AND SUBSCRIPTION INFORMATION
If you purchase or subscribe to consumer wellness or mobile app features through Apple App Store, Google Play, Stripe, or another third-party payment processor, your payment may be processed by that third party and subject to that third party’s terms and privacy policy.
WeHealth may receive limited information related to your purchase, subscription status, transaction identifier, product purchased, renewal status, cancellation status, or payment status. WeHealth may use this information to provide access to paid features, manage subscriptions, provide support, prevent fraud, and maintain business records.
WeHealth does not store full payment card information unless expressly stated and processed through appropriate payment systems.
17. PATIENT RIGHTS AND PRIVACY REQUESTS
17.1 HIPAA Rights Related to PHI
If your information is PHI maintained by WeHealth on behalf of a healthcare provider, medical group, health plan, clinic, or other covered entity, HIPAA-related rights such as access, amendment, restriction, accounting of disclosures, and complaints are generally handled by the applicable covered entity responsible for your care.
Our Platform may not recognize all “Do Not Track” signals. Where required by applicable law, WeHealth will honor legally recognized opt-out preference signals, such as Global Privacy Control, for activities subject to such opt-out requirements.
If WeHealth receives a privacy rights request directly from you regarding PHI maintained on behalf of a covered entity, WeHealth may direct you to the applicable provider, medical group, health plan, clinic, or covered entity, or may assist the covered entity in responding as required by applicable law, applicable Business Associate Agreements, and applicable agreements.
17.2 Consumer Privacy Requests
For personal information or consumer wellness information that WeHealth collects directly from you outside of a covered entity relationship, you may have the right, depending on applicable law, to request access, correction, deletion, portability, restriction, objection, withdrawal of consent, or information about how your information is used or disclosed.
We may need to verify your identity before responding to a request. We may deny or limit a request where permitted by law, including where information must be retained for legal, security, fraud prevention, operational, billing, dispute resolution, compliance, or contractual reasons.
18. PRIVACY REQUEST PROCESS
To protect your information, we may need to verify your identity before responding to a privacy request. Depending on the request, we may ask for information such as your name, email address, phone number, account information, or other information needed to verify your identity.
You may authorize another person to submit a request on your behalf where permitted by law. Authorized agents submitting requests on behalf of a California resident or other applicable state resident must provide written proof of authorization and may be required to verify their own identity and your identity directly with us. We may require proof that the person is authorized to act for you and may also require you to verify your identity directly with us.
We may deny or limit a request where permitted by law, including where we cannot verify your identity, where the request relates to PHI maintained on behalf of a covered entity, where deletion would interfere with legal or regulatory obligations, where retention is needed for security, fraud prevention, billing, dispute resolution, compliance, or contractual obligations, or where honoring the request would adversely affect the privacy or rights of others.
Where required by applicable law, you may have the right to appeal our decision regarding a privacy request. We will not discriminate against you for exercising privacy rights, but some choices or requests may affect our ability to provide certain services or features.
19. STATE PRIVACY RIGHTS
Certain state privacy laws may provide residents with additional rights regarding personal information, consumer health information, or sensitive personal information. Depending on your state and the type of information involved, these rights may include:
- the right to know or access personal information collected about you;
- the right to request correction of inaccurate personal information;
- the right to request deletion of personal information;
- the right to receive a copy of certain information in portable format;
- the right to opt out of certain uses or disclosures;
- the right to limit certain uses of sensitive personal information where applicable;
- the right to withdraw consent where processing is based on consent;
- the right to appeal certain decisions where required by law; and
- the right not to be discriminated against for exercising applicable privacy rights.
These rights may be subject to exceptions, including exceptions for PHI governed by HIPAA, information maintained on behalf of a covered entity, legal retention obligations, security and fraud prevention, or other lawful bases. To submit a privacy request, please contact us using the information in the “Contact Us” section below.
California Residents
California residents may have rights under the California Consumer Privacy Act (“CCPA”), as amended by the California Privacy Rights Act (“CPRA”), including rights to request access, correction, deletion, portability, and information about how personal information is collected, used, disclosed, or sold/shared.
We do not sell PHI. We do not sell personal information as defined under applicable California privacy laws. We do not use PHI or consumer health information for targeted advertising or cross-context behavioral advertising.
Because WeHealth does not sell or share personal information for cross-context behavioral advertising, WeHealth does not currently provide a separate “Do Not Sell or Share My Personal Information” link. If WeHealth changes its practices in a manner that requires such a link or other opt-out mechanism, WeHealth will update this Privacy Policy and provide the required choice.
Where required by applicable law, WeHealth will honor browser-based or device-based opt-out preference signals, including Global Privacy Control (“GPC”) signals, for activities subject to such opt-out requirements.
Nevada Residents
Nevada residents may have the right to opt out of certain sales of covered information under Nevada law. WeHealth does not sell PHI, consumer health information, or covered information as defined under applicable Nevada law. WeHealth does not currently engage in covered sales that would require a separate Nevada opt-out mechanism. If our practices change, we will update this Privacy Policy and provide any required opt-out mechanism. Nevada residents may also submit an opt-out or privacy request by contacting us using the information in the “Contact Us” section below.
Washington and Other Consumer Health Privacy Laws
Certain state laws may provide additional rights regarding consumer health data. Please see Section 20, Consumer Health Data Privacy Notice for Certain States, for additional disclosures regarding consumer health data where applicable.
20. CONSUMER HEALTH DATA PRIVACY NOTICE FOR CERTAIN STATES
This section applies to consumer health data processed through WeHealth consumer wellness or mobile app features to the extent state consumer health data privacy laws apply, including Washington’s My Health My Data Act and similar state consumer health privacy laws. This section does not replace HIPAA or any applicable Business Associate Agreement. Where information is PHI that WeHealth processes on behalf of a covered entity, HIPAA, HITECH, applicable Business Associate Agreements, and the instructions of the covered entity govern that PHI to the extent applicable.
20.1 Consumer Health Data
“Consumer Health Data” means personal information that is linked or reasonably linkable to an individual and that identifies or may reveal an individual’s past, present, or future physical or mental health status, health condition, treatment, diagnosis, healthcare service, health-related behavior, or other health-related information as defined under applicable law.
Consumer Health Data may include information you provide directly, information generated through consumer wellness or mobile app features, device or sensor information, health-related communications, and inferences or derived information created from other data through analytics, algorithms, machine learning, or similar technology where such information identifies or is reasonably linkable to an individual’s health status.
20.2 Categories of Consumer Health Data We May Collect
Depending on the services or features you use, WeHealth may collect the following categories of Consumer Health Data:
- information relating to health conditions, wellness status, symptoms, diagnoses, treatment, care plans, or health-related needs;
- information relating to social, behavioral, psychological, lifestyle, or wellness interventions, goals, reminders, or habits;
- information relating to medications, medication reminders, medication lists, or medication-related questions;
- bodily functions, vital signs, measurements, readings, or device-generated data, such as blood pressure, pulse oxygen, heart rate, weight, glucose if applicable, temperature if applicable, activity, sleep, and related timestamps;
- consumer wellness information, including nutrition, hydration, mood, activity, exercise, sleep, weight, goals, and self-entered health or wellness information;
- communications with WeHealth, including messages, chats, calls, forms, survey responses, support requests, uploaded files, images, screenshots, or other user content that includes health-related information;
- biometric information, if a feature you use collects or derives biometric information and such information identifies you as defined by applicable law;
- precise location information, if enabled by you and if used in a way that could reasonably indicate an attempt to obtain healthcare services or supplies;
- information that identifies you as seeking, receiving, or being eligible for healthcare, care coordination, wellness, remote monitoring, or related services; and
- proxy, derivative, inferred, or emergent data derived from non-health information through analytics, algorithms, machine learning, or similar technology where such information identifies or is reasonably linkable to your health status.
20.3 Sources of Consumer Health Data
We may collect Consumer Health Data from the following sources:
- directly from you when you use consumer wellness or mobile app features, create an account, submit forms, enter information, complete surveys or check-ins, communicate with us, or contact support;
- from healthcare providers, medical groups, health plans, clinics, care coordinators, caregivers, authorized representatives, or healthcare organizations involved in your care or program, where applicable;
- from remote patient monitoring devices, connected devices, wearables, mobile applications, health apps, device permissions, integrations, or sensors that you enable or connect;
- from service providers, vendors, processors, contractors, and technology partners that support our Platform, communications, hosting, analytics, security, customer support, payments, and operations;
- from app stores, payment processors, and subscription platforms, where applicable;
- from websites, apps, browsers, devices, cookies, logs, analytics tools, and security technologies; and
- from other sources where you authorize the collection or where collection is permitted by law.
20.4 Purposes for Collecting, Using, or Processing Consumer Health Data
We may collect, use, or process Consumer Health Data only as permitted by applicable law, including as necessary to provide a product or service you requested, with your consent where required, or as otherwise legally permitted. Purposes may include:
- providing, operating, maintaining, personalizing, and supporting consumer wellness and mobile app features;
- providing account access, user support, reminders, notifications, communications, and requested services;
- displaying, organizing, analyzing, or summarizing health or wellness information that you provide or authorize us to receive;
- supporting care coordination, RPM/CCM workflows, provider-supported services, or healthcare organization workflows where applicable;
- troubleshooting, debugging, securing, and improving the Platform;
- conducting analytics, audits, quality assurance, product improvement, and business operations;
- developing, testing, improving, and training AI, machine learning, automation, and analytics tools, subject to this Privacy Policy, applicable law, applicable agreements, consent settings, and any required authorizations;
- creating de-identified, aggregated, or anonymized information where permitted by law;
- preventing, detecting, protecting against, and responding to security incidents, identity theft, fraud, misuse, harassment, malicious activity, deceptive activity, or illegal activity;
- complying with law, legal process, regulatory obligations, contractual obligations, and enforcing our rights and agreements.
20.5 Sharing Consumer Health Data
We may share Consumer Health Data only as permitted by applicable law, including as necessary to provide a product or service you requested, with your consent where required, with processors or service providers acting on our behalf, or as otherwise legally permitted. Categories of recipients may include:
- healthcare providers, medical groups, health plans, clinics, care teams, care coordinators, or healthcare organizations involved in your care or program, where applicable;
- service providers, processors, contractors, subcontractors, hosting providers, cloud providers, communications vendors, analytics providers, customer support vendors, payment processors, security providers, and technology vendors that help us operate, maintain, secure, support, or improve the Platform;
- parties with whom you have a direct relationship or whom you direct or authorize us to share information with, such as caregivers, family members, authorized representatives, connected apps, or third-party services;
- government agencies, regulators, law enforcement, courts, or other parties where required or permitted by law; and
- successor entities in connection with a merger, acquisition, corporate reorganization, bankruptcy, or similar transaction, subject to applicable law and privacy protections.
Where required by HIPAA, WeHealth requires appropriate Business Associate or subcontractor Business Associate terms. Where state consumer health privacy laws require processor or service provider contracts, WeHealth uses written agreements designed to restrict processing to permitted purposes and require appropriate confidentiality and security protections.
20.6 Consumer Health Data Rights
Depending on your state and the services you use, you may have rights regarding Consumer Health Data, including the right to confirm whether WeHealth collects, shares, or sells Consumer Health Data about you; access or obtain a copy of Consumer Health Data; request deletion; request correction or amendment where applicable; withdraw consent where processing is based on consent; receive information about third parties or affiliates with whom Consumer Health Data has been shared or sold where required by law; and appeal a denial of a privacy request where required by law.
Requests are subject to verification. We may ask for information reasonably necessary to verify your identity and authenticate your request. We may deny or limit a request where permitted by law, including where we cannot verify your identity, where the request relates to PHI maintained on behalf of a covered entity, where retention is required or permitted for legal, compliance, security, fraud prevention, billing, dispute resolution, contractual, or operational reasons, or where honoring the request would adversely affect the privacy or rights of others.
Where applicable law requires a response within a specific time period, including 45 days under certain consumer health data laws, WeHealth will respond within the legally required timeframe or inform you of any permitted extension. Where applicable law provides a right to appeal a denied request, you may appeal by contacting us using the information in the “Contact Us” section below and stating that you are appealing a privacy request decision.
20.7 Consent, Withdrawal, and Additional Controls
Where WeHealth is required to obtain consent to collect or share Consumer Health Data for a specified purpose, we will request consent in a manner designed to disclose the categories of Consumer Health Data involved, the purpose of the collection or sharing, the categories of recipients, and how you may withdraw consent from future collection or sharing. Withdrawing consent may affect our ability to provide certain services or features.
If you enable connected devices, health apps, app permissions, push notifications, or similar features, you may be able to withdraw or modify permissions through your device settings, app settings, operating system settings, or by contacting us.
20.8 No Sale, No Consumer Health Data Targeted Advertising, and No Health Geofencing
WeHealth does not sell PHI. WeHealth does not sell Consumer Health Data. WeHealth does not use PHI or Consumer Health Data for targeted advertising or cross-context behavioral advertising.
WeHealth does not use geofencing technology around healthcare facilities for the purpose of identifying, tracking, collecting Consumer Health Data from, or targeting advertisements or messages to individuals seeking healthcare services or supplies.
WeHealth will not unlawfully discriminate against you for exercising rights available under applicable consumer health data privacy laws.
21. CHILDREN AND MINORS
Consumer wellness and mobile app features are intended for users who are at least 18 years old, unless otherwise stated or permitted with appropriate parental or guardian involvement.
Provider-supported healthcare services for minors may be available only through a parent, legal guardian, authorized representative, treating provider, medical group, health plan, clinic, or other covered entity responsible for the minor’s care.
We do not knowingly collect personal information from children under 13 through consumer wellness features without appropriate parental or guardian consent. If we learn that we have collected personal information from a child under 13 without required consent, we will take steps to delete the information or handle it as required by applicable law.
If you believe a child has provided information to WeHealth without appropriate consent, please contact us.
22. SECURITY OF YOUR INFORMATION
We use reasonable administrative, technical, and physical safeguards designed to protect the confidentiality, integrity, and availability of information we receive, maintain, use, or transmit.
Sensitive information transmitted through the Platform, including PHI, patient information, consumer health information, transaction information, and other confidential information, is processed using Secure Socket Layer or Transport Layer Security technology, commonly referred to as SSL/TLS, where applicable.
Our safeguards may include access controls, authentication, logging, monitoring, encryption where appropriate, workforce training, vendor/subcontractor protections, backup procedures, and incident response processes.
However, no website, mobile app, platform, device, or electronic transmission is completely secure. We cannot guarantee that information will never be accessed, disclosed, altered, or destroyed. You are responsible for maintaining the confidentiality of your login credentials, securing your device, using appropriate device security settings, and promptly notifying us of any suspected unauthorized access or misuse.
You should not send PHI, consumer health information, payment information, passwords, or other sensitive information through unapproved or unsecured communication channels unless specifically authorized by WeHealth and permitted by applicable law.
WeHealth will provide notice of data security incidents as required by applicable law, HIPAA/HITECH where applicable, Business Associate Agreements, and applicable agreements.
23. RETENTION OF INFORMATION
We retain information for the period necessary to fulfill the purposes described in this Privacy Policy, provide the Platform and services, comply with applicable laws, comply with Business Associate Agreements, resolve disputes, enforce agreements, maintain business records, prevent fraud, support security, and meet operational requirements.
Where WeHealth maintains PHI on behalf of a covered entity, retention may be governed by the applicable Business Associate Agreement, provider agreement, covered entity instructions, HIPAA/HITECH, applicable state privacy laws, and other legal requirements.
WeHealth is not the official medical record system for providers unless expressly agreed in a separate written agreement and legally permitted. Your treating provider, medical group, health plan, clinic, or covered entity is responsible for maintaining official medical records where required by law.
When information is no longer needed and deletion is permitted, we may delete, de-identify, aggregate, anonymize, or securely retain it in backup or archival systems for a limited period consistent with legal and operational requirements.
24. DE-IDENTIFIED, AGGREGATED, AND ANONYMIZED INFORMATION
We may create, use, disclose, and retain de-identified, aggregated, or anonymized information for lawful purposes, including analytics, quality improvement, research and development, product improvement, security, fraud prevention, AI/model development, benchmarking, and business operations.
Where information is derived from PHI, WeHealth will de-identify the information in accordance with applicable HIPAA de-identification standards where required. We will not attempt to re-identify de-identified information except as permitted by law for validation, security, compliance, or other legally permitted purposes.
25. NO EMERGENCY USE
The Platform, including any remote patient monitoring features, wellness features, readings, alerts, reminders, reports, device-related information, AI-generated outputs, or automated notifications, is not intended for medical emergencies, emergency monitoring, continuous real-time monitoring, or immediate response to urgent clinical events.
If you believe you are experiencing a medical emergency, call 911 immediately or go to the nearest emergency department. Do not use the Platform to request emergency medical care.
You should contact your treating healthcare provider directly for medical questions, changes in condition, treatment concerns, medication questions, or care instructions.
26. SERVICE AVAILABILITY AND JURISDICTIONS
WeHealth technology-supported services are available only in approved jurisdictions through participating healthcare providers, medical groups, health plans, clinics, healthcare organizations, or consumer app offerings where legally permitted.
Service availability may vary by state, program, provider licensure, payer arrangement, patient location, user location, app functionality, and applicable law.
WeHealth currently supports technology-enabled services for users or patients located in the following U.S. states: Alabama, Alaska, Arizona, Arkansas, California, Colorado, Connecticut, Delaware, Florida, Georgia, Hawaii, Idaho, Illinois, Indiana, Iowa, Kansas, Kentucky, Louisiana, Maine, Maryland, Massachusetts, Michigan, Minnesota, Missouri, Montana, Nebraska, Nevada, New Hampshire, New Mexico, New York, North Carolina, North Dakota, Ohio, Oklahoma, Oregon, Pennsylvania, Rhode Island, South Carolina, South Dakota, Tennessee, Texas, Utah, Vermont, Virginia, Washington, West Virginia, Wisconsin, and Wyoming.
WeHealth does not currently support technology-enabled services for users or patients located in New Jersey or Mississippi.
WeHealth does not knowingly provide or support services in jurisdictions where the applicable service is not legally permitted or where the participating provider, healthcare organization, or other authorized party is not permitted to provide the applicable service. WeHealth may decline, suspend, restrict, or terminate access to the Platform or any service if WeHealth determines that the user, patient, provider, service location, payer arrangement, or requested service is outside an approved jurisdiction or otherwise presents a legal, regulatory, privacy, security, payer, or compliance concern.
27. USERS OUTSIDE THE UNITED STATES
The Platform is intended for use in the United States. We do not intentionally market or direct the Platform to individuals located outside the United States unless expressly stated.
If you access or use the Platform from outside the United States, you understand that your information may be processed and stored in the United States or other jurisdictions where privacy laws may differ from those in your location.
If we process personal information subject to non-U.S. privacy laws, we will do so as required by applicable law and applicable agreements.
28. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time. Any changes will be posted on this page or otherwise made available through the Platform. If we make material changes, we may provide a more prominent notice, such as by email, app notification, website notice, or other reasonable means.
Your continued use of the Platform after changes are posted means that you acknowledge the updated Privacy Policy, unless additional consent is required by law.
29. CONTACT US
If you have questions or concerns about this Privacy Policy, our privacy practices, or your privacy rights, please contact us:
WeHealth Technologies LLC
Attn: Compliance Officer
9525 Church Ave
Brooklyn, NY 11212
Phone: 888-525-0650
Email: [email protected]
You may also have the right to file a complaint with your healthcare provider, health plan, applicable regulator, state attorney general, data protection authority, or the U.S. Department of Health and Human Services Office for Civil Rights, depending on the nature of your concern and applicable law.
Privacy requests may be submitted using the contact information above. Formal legal notices should be sent by certified mail or nationally recognized courier to the address above. Email may be used for operational communications but may not constitute formal legal notice unless expressly permitted by applicable law or a written agreement.
All materials © 2026 WeHealth Technologies LLC unless otherwise noted. All rights reserved.
