Provider Privacy Policy
HEALTHCARE PROVIDER PRIVACY POLICY
WeHealth Technologies LLC d.b.a. WeHealth
Last updated: June 30, 2026
Purpose. The purpose of this Healthcare Provider Privacy Policy (“Privacy Policy”) is to describe how WeHealth Technologies LLC d.b.a. WeHealth (“WeHealth,” “we,” “us,” or “our”) collects, uses, discloses, protects, and retains information in connection with provider-facing access to WeHealth websites, mobile applications, support tools, communications, and related technology-enabled services (collectively, the “Platform”). This Privacy Policy applies to healthcare providers, medical groups, clinics, health plans, healthcare organizations, administrators, staff users, contractors, agents, and other professional users who access or use the Platform (collectively, “Providers,” “you,” or “your”).
PLAIN-ENGLISH SUMMARY
This summary is provided for convenience and is not a substitute for the full Privacy Policy. Providers should read the entire Privacy Policy before creating an account, submitting information, or using the Platform.
WeHealth is a healthcare technology company. WeHealth is not a medical practice, healthcare provider, pharmacy, EMR/EHR, prescribing platform, prescription routing platform, or official medical record system unless expressly agreed in a separate written agreement and legally permitted.
WeHealth may collect Provider account information, business contact information, login credentials, billing/payment information, technical usage information, and support communications.
Providers may submit patient information, including Protected Health Information (“PHI”), through the Platform for care coordination, remote patient monitoring support, chronic care management support, documentation support, reporting, task management, and related workflows.
Business Associate role: To the extent WeHealth receives, stores, transmits, maintains, or processes PHI on behalf of a Provider, medical group, health plan, or other covered entity, WeHealth acts as a Business Associate under HIPAA and HITECH and handles PHI in accordance with applicable Business Associate Agreements and applicable law.
WeHealth does not sell PHI. WeHealth does not use PHI for targeted advertising or cross-context behavioral advertising.
Providers remain responsible for their own covered entity obligations, patient notices, patient consents, medical records, EMR/EHR documentation, prescribing, billing, coding, workforce access controls, and compliance with applicable law.
ROLE OF WEHEALTH
WeHealth provides technology-enabled tools and support services that may assist healthcare providers, medical groups, health plans, and other healthcare organizations with care coordination, remote patient monitoring support, chronic care management support, patient engagement, communication, documentation support, reporting, task management, and related administrative or operational workflows.
WeHealth is not a medical practice, healthcare provider, physician group, pharmacy, pharmacy benefit manager, durable medical equipment supplier, electronic medical record system, electronic health record system, prescribing platform, prescription routing platform, or prescription fulfillment service. WeHealth does not provide medical care, diagnose, treat, prescribe medication, dispense medication, issue medical orders, make clinical decisions, or establish a provider-patient relationship.
The Platform may support documentation and workflow activity, but it is not intended to replace a Provider’s EMR/EHR or other legally required medical recordkeeping system unless expressly agreed in a separate written agreement and legally permitted.
ACKNOWLEDGMENT
By using the Platform, you acknowledge that you have reviewed this Privacy Policy and understand that your use of the Platform is also subject to WeHealth’s Terms of Use, applicable written agreements with WeHealth, and any applicable Business Associate Agreement. Please do not use the Platform if you do not agree to comply with the Terms of Use or any applicable agreement governing your use of the Platform.
SCOPE
This Privacy Policy applies to information we collect through the Platform and through related provider-facing communications, support, onboarding, implementation, account management, and operational activities. This Privacy Policy applies to Provider information and, where applicable, patient information or PHI submitted, uploaded, transmitted, maintained, or processed through the Platform or related WeHealth services.
This Privacy Policy does not replace any HIPAA Notice of Privacy Practices or other privacy notice that a Provider, medical group, health plan, or other covered entity is required to provide to its patients or members. Providers remain responsible for their own privacy notices, patient rights processes, patient communications, and compliance obligations.
The Platform may contain links to websites, applications, or services not owned or controlled by WeHealth. WeHealth is not responsible for the privacy practices of third-party websites or services. Providers should review the privacy notices of any third-party services they access.
ACCESSIBILITY
WeHealth attempts to make its information accessible to all individuals. If you use special adaptive equipment and encounter problems when using the Platform, please contact us at 888-525-0650. WeHealth strives to make its communications accessible to individuals with special needs, including individuals with visual, hearing, cognitive, and motor impairments.
1. INFORMATION WE COLLECT
1.1 Provider Information
We collect information that Providers submit or make available to us, including information provided when creating or modifying a Provider account, registering for Platform access, executing agreements, onboarding staff users, requesting support, contacting customer service, using Platform features, or otherwise communicating with WeHealth. This information may include:
Provider or organization name; individual professional name; business address; mailing address; billing address; email address; telephone number; job title; NPI or other professional/business identifiers, if provided; and other business contact information.
Account credentials, usernames, authentication information, role/permission information, and administrative user information.
Billing, payment, bank, credit card, invoice, tax, payer, or account-related information, where applicable.
Support tickets, implementation materials, onboarding information, customer service communications, training requests, and other information you provide to WeHealth.
1.2 Patient Information Submitted by Providers
Providers may submit, upload, transmit, or make available patient information through the Platform. This may include patient names, contact information, demographic information, insurance or payer information, medical history, conditions, symptoms, clinical readings, device-related information, care coordination notes, remote patient monitoring information, chronic care management information, forms, consents, documents, messages, reports, and other information that may constitute PHI.
Providers are responsible for ensuring that any patient information or PHI submitted to WeHealth is submitted lawfully and that the Provider has the necessary rights, permissions, consents, authorizations, notices, or other legal basis to provide such information to WeHealth.
1.3 Information Collected Automatically
When you access or use the Platform, WeHealth may automatically collect technical and usage information, including log-on activity, search terms, page views, clicks, downloads, user preferences, device information, IP address, approximate location information, cookie or session identifiers, authentication information, browser type, browser version, operating system, and other technical information related to Platform usage, performance, and security.
1.4 Cookies and Similar Technologies
WeHealth may use cookies, web beacons, tracking pixels, and similar technologies to operate the Platform, maintain user sessions, store preferences, improve Platform quality and performance, support security, monitor usage trends, and gather aggregate information about Platform usage. Some Platform features may not function properly if cookies are disabled.
We do not use PHI for targeted advertising or cross-context behavioral advertising. We may use analytics tools to understand and improve Platform performance for operational purposes.
1.5 California Privacy Rights
We collect Provider Personal Information as defined by applicable California privacy laws, including the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), where applicable. Provider Personal Information may include payment information, personal contact information, business information, login credentials, usage details, and technical details.
We do not sell PHI. We do not sell personal information as defined under applicable California privacy laws. We may disclose information to service providers, contractors, business associates, and subcontractors as permitted by law, including for operating, securing, supporting, and improving the Platform; processing transactions; and fulfilling legal obligations.
California residents may have rights under applicable California privacy laws to request access to, correction of, deletion of, and portability of their personal information, and to request information about disclosures of personal information. These rights are subject to applicable exceptions, including exceptions applicable to PHI governed by HIPAA. We do not discriminate against individuals for exercising applicable privacy rights. Requests may be submitted using the contact information in Section 9.
1.6 Children
Provider accounts are intended for adults and authorized professional users. The Platform is not intended for use by children under 13 years of age, and we do not knowingly collect personal information directly from children under 13 through provider accounts. If you believe we have collected information from a child under 13 in a manner not permitted by law, please contact us.
2. HIPAA, BUSINESS ASSOCIATE ROLE, AND PROVIDER RESPONSIBILITIES
2.1 HIPAA and Business Associate Role
HIPAA and HITECH impose requirements on covered entities and business associates to protect PHI. To the extent WeHealth receives, stores, transmits, maintains, or processes PHI on behalf of a Provider, medical group, health plan, or other covered entity, WeHealth acts as a Business Associate under HIPAA and HITECH and handles such PHI in accordance with applicable Business Associate Agreements, HIPAA, HITECH, applicable state privacy laws, and the instructions of the applicable covered entity.
WeHealth will use PHI only for the purposes for which it was engaged by the applicable covered entity, and not for independent use or purposes, except as needed for the proper management and administration of WeHealth or as otherwise permitted by applicable law and the applicable Business Associate Agreement.
Providers remain responsible for their own covered entity obligations under HIPAA, including patient notices, patient rights requests, workforce access controls, appropriate uses and disclosures of PHI, medical recordkeeping, and maintaining complete and accurate medical records.
2.2 Provider Responsibilities
Providers, medical groups, health plans, clinics, and other professional users are responsible for complying with all laws, rules, regulations, licensure requirements, payer requirements, professional standards, patient consent requirements, documentation requirements, billing requirements, and privacy/security obligations applicable to their services.
Providers are responsible for determining whether they are authorized to use the Platform for a particular patient, program, service, or workflow, and for obtaining any required patient consent, authorization, disclosure, or notice before submitting, uploading, transmitting, or making available any PHI or other patient information through the Platform.
Providers remain responsible for maintaining complete, accurate, timely, and legally compliant medical records in their own EMR/EHR or other legally required recordkeeping system. Providers are responsible for determining what information must be entered into their official medical record and for complying with all applicable record retention requirements.
Providers are responsible for ensuring that only authorized workforce members access the Platform, that access rights are appropriate to each user’s role, that login credentials are not shared, and that access is promptly removed when no longer appropriate.
2.3 Information Providers Must Provide to Patients
Providers are responsible for informing patients, where required by applicable law, that patient information may be submitted, uploaded, transmitted, maintained, or processed through WeHealth for technology-enabled care coordination, remote patient monitoring support, chronic care management support, communication, documentation support, reporting, task management, and related administrative or operational workflows.
Providers are responsible for providing any required Notice of Privacy Practices or other privacy notice to patients and for obtaining any required patient consent, authorization, disclosure, or acknowledgment before using the Platform for a patient or submitting patient information to WeHealth.
3. HOW WE USE INFORMATION
WeHealth may use Provider information, technical information, and, where applicable, patient information or PHI as permitted by applicable law, applicable Business Associate Agreements, applicable written agreements, and this Privacy Policy. We may use information to:
Operate, maintain, secure, support, troubleshoot, improve, and administer the Platform.
Provide technology-enabled care coordination, remote patient monitoring support, chronic care management support, patient engagement, communication, documentation support, reporting, task management, and related operational workflows.
Create, manage, authenticate, and administer Provider accounts and user permissions.
Provide customer support, training, onboarding, implementation, account management, and technical assistance.
Process payments, invoices, orders, subscriptions, or other account-related transactions, where applicable.
Communicate with Providers about Platform updates, security notices, account notices, service information, support requests, and other administrative matters.
Monitor Platform usage, quality, security, reliability, and performance.
Detect, prevent, investigate, or address fraud, misuse, security incidents, technical issues, or unauthorized access.
Comply with legal obligations, enforce applicable Terms of Use or agreements, and protect the rights, property, or safety of WeHealth, Providers, users, patients, customers, or the public as permitted or required by law.
WeHealth may use de-identified, aggregated, anonymized, or otherwise legally permitted information to improve, develop, test, and train analytics, automation, AI, machine learning, reporting, workflow, and security features. PHI is used only as permitted by applicable Business Associate Agreements, HIPAA/HITECH, applicable law, and applicable agreements.
WeHealth does not use PHI for targeted advertising, cross-context behavioral advertising, or sale to third parties.
4. HOW WE SHARE INFORMATION
4.1 Authorized Personnel and Support Access
WeHealth personnel, contractors, and authorized service providers may access Provider information or PHI only where reasonably necessary to operate, maintain, support, troubleshoot, secure, improve, or administer the Platform; provide services under applicable agreements; comply with law; or address security, compliance, or support issues.
4.2 Service Providers and Subcontractors
We may disclose information to third-party service providers, contractors, vendors, hosting providers, analytics providers, payment processors, communication providers, support vendors, and other parties that help us operate, secure, support, and improve the Platform. These parties may access information only as needed to provide services to WeHealth and are subject to appropriate contractual obligations.
Where a third-party service provider creates, receives, maintains, or transmits PHI on behalf of WeHealth, WeHealth requires appropriate written agreements, including business associate or subcontractor business associate terms where required by HIPAA.
4.3 Disclosures with Consent or Direction
We may disclose information when we have your consent, authorization, or direction, or when disclosure is permitted by applicable law, the applicable Business Associate Agreement, or another applicable agreement.
4.4 Legal, Compliance, Fraud Prevention, and Security
We may disclose information if we have a good-faith belief that access, use, preservation, or disclosure is reasonably necessary to:
- Meet any applicable law, regulation, subpoena, legal process, or enforceable governmental request.
- Enforce applicable Terms of Use or agreements, including investigation of potential violations.
- Detect, prevent, investigate, or address fraud, security, privacy, compliance, or technical issues.
- Protect against harm to the rights, property, or safety of WeHealth, Providers, users, patients, customers, or the public as required or permitted by law.
To the extent a request involves PHI, WeHealth will handle such request in accordance with HIPAA, applicable Business Associate Agreements, applicable state privacy laws, and applicable legal requirements.
4.5 Change of Control
If the ownership of all or substantially all of our business changes, or we transfer assets relating to our business or the Platform to a third party, such as by merger, acquisition, corporate reorganization, bankruptcy proceeding, or similar transaction, information may be transferred to the successor entity as permitted by applicable law and applicable agreements. Any PHI will continue to be protected in accordance with applicable Business Associate Agreements, HIPAA, HITECH, applicable state privacy laws, and this Privacy Policy.
5. ACCESS, CORRECTION, ACCOUNT CLOSURE, AND PATIENT RIGHTS REQUESTS
5.1 Provider Access and Account Updates
Providers may access and update certain account information by signing into the Platform. If you have questions about information we maintain about you or need to update information that is not available through your account, you may contact us using the contact information in Section 9.
5.2 Communications — Administrative, Security, and Authentication
WeHealth may send administrative, account, security, support, and authentication communications, including one-time passcodes, two-factor authentication codes, security alerts, login confirmations, and account notices, by email, SMS, phone, app notification, or other available communication method. Security and authentication messages may be required for Platform access and may still be sent even if a user opts out of marketing communications.
Providers may opt out of marketing and promotional emails by using the opt-out or unsubscribe feature included in those emails. We may still send administrative, transactional, security, account, or service-related communications where permitted by law.
5.3 Account Closure
Providers may request closure of their Provider account by contacting us. We may retain information as needed for legal, security, fraud prevention, backup, archival, accounting, compliance, contractual, and business purposes, and as required or permitted by applicable law and applicable agreements.
5.4 Patient Rights Requests
If WeHealth receives a privacy rights request directly from a patient regarding PHI maintained on behalf of a Provider, medical group, health plan, or other covered entity, WeHealth may direct the patient to the applicable Provider or covered entity, or may assist the Provider or covered entity in responding, as required by applicable law, the applicable Business Associate Agreement, and applicable agreements.
6. SECURITY AND RETENTION
6.1 Security
WeHealth uses reasonable administrative, technical, and physical safeguards designed to protect the confidentiality, integrity, and availability of information received, used, maintained, or transmitted by WeHealth.
Sensitive information transmitted through the Platform, including PHI, patient information, transaction information, and other confidential information, is processed using Secure Socket Layer or Transport Layer Security (SSL/TLS) encryption where applicable.
No website, application, system, or electronic transmission is completely secure. We cannot guarantee that information will never be accessed, disclosed, altered, or destroyed despite safeguards. Providers are responsible for maintaining the confidentiality of login credentials, using appropriate access controls, and promptly notifying WeHealth of any suspected unauthorized access, security incident, or misuse of the Platform.
Providers should not send PHI to WeHealth through unapproved or unsecured communication channels unless specifically authorized by WeHealth and permitted by applicable law and applicable agreement. WeHealth will provide breach or security incident notices as required by applicable law, applicable Business Associate Agreements, and applicable agreements.
6.2 Retention of Provider Information
WeHealth retains Provider information for the period necessary to fulfill the purposes described in this Privacy Policy, provide services, maintain accounts, support business operations, comply with legal obligations, resolve disputes, enforce agreements, prevent fraud, maintain security, and meet accounting, audit, backup, archival, or compliance requirements, unless a longer retention period is required or permitted by law.
6.3 Retention of Patient Information and PHI
WeHealth retains patient information and PHI in accordance with applicable Business Associate Agreements, applicable written agreements, HIPAA, HITECH, applicable state privacy laws, and operational requirements. WeHealth is not responsible for a Provider’s official medical record retention obligations unless expressly agreed in a separate written agreement and legally permitted.
Residual copies of information may remain in backup, archival, disaster recovery, or security systems for a limited period of time, after which the information will be deleted or placed beyond use where deletion is not reasonably feasible.
7. USE OF PLATFORM OUTSIDE THE UNITED STATES
The Platform is intended for use in the United States and is not intended to be used by Providers residing outside the United States. We do not intentionally market or direct the Platform to Providers located outside the United States, the European Union, the European Economic Area, the United Kingdom, or Switzerland. If we process personal information subject to non-U.S. privacy laws, we will do so as required by applicable law and applicable agreements.
8. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time. The updated version will be posted on the Platform or otherwise made available. If changes are material, we may provide a more prominent notice in our discretion or as required by applicable law or applicable agreement. The date above indicates when this Privacy Policy was last updated.
9. CONTACT US
If you have any questions or concerns regarding this Privacy Policy, please contact us by calling 888-525-0650 and asking to speak to the Privacy and Security Officer. To the extent you are required to send a written request to exercise any right described in this Privacy Policy, submit your request to:
WeHealth Technologies LLC
Attn: Compliance Officer
9525 Church Ave
Brooklyn, NY 11212
Phone: 888-525-0650
Email: [email protected]
Privacy and security requests may be submitted using the contact information above. Formal legal notices should be sent by certified mail or nationally recognized courier to the address above. Email may be used for operational communications but may not constitute formal legal notice unless expressly permitted by applicable law or a written agreement.
You may also make a complaint to your local data protection authority, where applicable.
All materials © 2026 WeHealth Technologies LLC unless otherwise noted. All rights reserved. | v3
