Privacy Policy
Contents
This Privacy Policy describes how Bidwell Health ("we," "us," or "our") collects, uses, stores, and protects your information when you use our online telehealth platform at bidwellhealth.com. This Privacy Policy should be read together with our Terms of Service and our HIPAA Notice of Privacy Practices.
1. Information We Collect
A. Information You Provide
When you create an account, complete an intake, or contact us, we collect the following information that you provide to us. Identity information: Full name, date of birth; Contact information: Email address, phone number; Location information: the state you are in at the time of your visit, and your street address, city, and ZIP code; Health information: Symptoms, medical history, current medications, known allergies, clinical intake responses; Pharmacy information: Pharmacy name and address; Payment information: your card details go directly to our payment processor and we never receive or store your card number; Biological sex, where it is relevant to the condition; Photographs and files you choose to upload, such as a photo of a medication label, scalp photographs for a hair loss visit, or documents you send your clinician in the portal; Consent records, being a record of the consents you gave and when.
If you begin a visit and do not finish it, we do not keep what you entered and we do not email you about it. If you ask us to tell you when we launch in a state we do not yet serve, we keep the email address and state you give us for that purpose and nothing else.
B. Information Collected Automatically
When you visit our website, the following information is collected automatically. Device information: Browser type, operating system; Usage data: Pages visited, time spent on pages; Log data: IP address, access times.
2. How We Use Your Information
Your information is used for the following purposes: Healthcare services: To enable licensed clinicians to evaluate your symptoms, make clinical assessments, and prescribe appropriate treatment; Payment processing: to process your visit payment through our payment processor; Communication: to send visit confirmations, clinician responses, prescription updates, and account notices. We may also send you a message checking how you are doing after treatment, an invitation to leave feedback, and occasional notices about treatment options and other services we offer. You can stop the non-clinical messages at any time using the link in the message; Safety screening: To identify and respond to safety concerns disclosed during intake (e.g., mental health screening responses); Legal compliance: To meet our obligations under federal, state, and local laws and regulations; Platform improvement: to improve our services, using aggregated counts and statistics that do not identify you; Security: To detect, prevent, and respond to fraud, abuse, or security incidents.
3. How We Share Your Information
We do not sell, rent, or trade your personal or health information, and we do not share it with advertisers or data brokers. We share it only with the categories of recipients below, and only as far as each one needs it to do its job. The pharmacy you select receives your prescription. Our payment processor receives your name, email address, phone number, and the network information that comes with an online payment, and it does not receive your symptoms, your diagnosis, or your medications. Our cloud hosting and database providers store and serve your information on our behalf. Our transactional email provider delivers visit updates and account notices to you and receives your name and email address. Our electronic prescribing provider transmits your prescription to your pharmacy. Our pharmacy search provider receives a ZIP code only and receives no health information and no identifying information about you. Our website analytics provider receives the address of the page you viewed, your browser type, and your approximate location. Because our condition pages are named for the condition, that address can indicate the type of care you were looking at. It does not receive your name, your email address, or anything you enter into a visit. Legal and regulatory authorities receive information as required by law, including mandatory reporting obligations, court orders, and subpoenas.
We name these by category rather than by company because the specific vendor in a category can change. Whichever company fills a role, the limits described above are the limits that apply to it.
4. Data Storage and Security
Your connection to this site and your intake submission are encrypted in transit using TLS, and your information is encrypted at rest by our infrastructure providers. Ordinary email is the exception: it is not fully secure in transit, which is why we keep clinical detail out of email. Clinical detail lives in your patient portal, which requires you to sign in, and on your visit status page, which opens from the link we email you without a password. Treat that link like a key and do not forward it.
Your record is visible to the clinician reviewing your visit. Authorized administrative personnel may access it only to the extent necessary to carry out their assigned duties, such as billing or support. Our database blocks all public access to patient records, and our portal issues you a signed token that can load only your own visits. Our database provider maintains its own SOC 2 Type II attestation covering its infrastructure; Bidwell Health does not itself hold a SOC 2 attestation. Payment processing is handled entirely by our payment processor, which is certified PCI DSS Level 1, and we never receive or store your card number. We serve the site over HTTPS only, with HTTP Strict Transport Security and a Content Security Policy.
No method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security. If a breach of security compromises your unsecured personal or health information, we will notify you in writing without unreasonable delay and within the shortest period the applicable law requires, which in several of the states we serve is thirty days from discovery. We will tell you what happened, what information was involved, what we have done about it, and what you can do. Where the law also requires it, we will notify the relevant state attorney general and the applicable federal regulator, including the Department of Health and Human Services or the Federal Trade Commission as the law requires. This commitment applies whether or not the information involved is protected health information under HIPAA.
5. Data Retention
We retain your information according to the following schedule: Medical records: Retained for a minimum of 7 years from the date of your last encounter, or longer if required by applicable state law; Payment and accounting records: generally retained for 7 years for tax, accounting, audit, and legal purposes; Account information: Retained while your account remains active.
You may ask us to delete personal information that is not part of a medical record, and we will. Medical records are different: state law and our professional obligations require us to keep them for the minimum retention period, so we cannot delete those on request, and we will tell you plainly when that is the reason. For consumer health data that is subject to Washington's My Health My Data Act, Washington residents have additional rights, including deletion rights that can extend to archived and backup systems. The Act contains exemptions, including for information protected under HIPAA and for health care information regulated under Washington law, so it does not give you a right to delete the medical record we are required to keep. Those rights and their limits are set out in our Washington Consumer Health Data Privacy Policy. Backups are retained on a rolling schedule and are overwritten in the normal course, and we do not restore deleted information from them.
6. Your Rights
Whatever state you live in, you may ask us for a copy of the personal and health information we hold about you, ask us to correct anything inaccurate or incomplete, ask us to delete what we are not required by law to keep, and ask us to stop sending you non-clinical email. Email privacy@bidwellhealth.com and we will treat your request the same way regardless of your state. We will respond within thirty days. If we need longer we will tell you why within those thirty days and when you can expect an answer. You also have rights under HIPAA, including the right to access your medical records, request an amendment, and obtain an accounting of disclosures, which are described in our HIPAA Notice of Privacy Practices.
Virginia residents
Virginia law protects personally identifiable reproductive or sexual health information, and requires your consent before it is obtained, disclosed, sold, or disseminated. That law contains exemptions, including for information protected under HIPAA and for Virginia health records, so some of what you give us during your care may fall outside it. As a matter of our own policy we do not rely on those exemptions. We ask for your consent at the point the information is collected, we do not bundle it into acceptance of our Terms of Service, and we do not treat continued use of the site as consent. We do not sell this information and we do not use it for advertising. Declining an optional use or disclosure does not affect your care. Some of this information is needed for the clinical assessment itself, so declining to give us that may mean a clinician cannot complete that particular visit, and we would refund the fee.
Washington residents
For consumer health data that is covered by the Washington My Health My Data Act, Washington residents have separate rights, including a right to have that data deleted from our records and from our backups. The Act exempts information protected under HIPAA and health care information regulated under Washington law, so it does not reach the medical record we are required to keep. Those rights, and how to use them, are described in our Washington Consumer Health Data Privacy Policy, which controls over this section for the data it covers.
Other state privacy laws
Several states we serve have comprehensive consumer privacy laws that apply only to companies above a certain size, and Bidwell Health is below those thresholds today. That does not change what we do. The rights described at the start of this section are offered to everyone, and we do not sell your information or run advertising trackers in any state.
7. Cookies and Tracking
Bidwell Health sets no cookies of its own. To keep your place while you complete a visit, our intake forms store your answers in your own browser using session storage, which stays on your device and is cleared when you close the tab. Our patient portal stores your sign-in token the same way, for the length of your session. Our payment processor sets its own cookies on our checkout step for fraud prevention.
We run no advertising or marketing trackers anywhere on this site, including on the intake forms where you describe your symptoms. There is no advertising pixel, no tag manager, and no session recording script. Our website analytics are cookieless and first-party: they count page views and receive no name, no email address, no health information, and no advertising identifier.
8. Children's Privacy
Bidwell Health is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from minors. If we become aware that we have collected information from a person under 18, we will take steps to delete that information promptly, except where we are legally required to retain it, including under applicable medical record obligations.
9. Third-Party Links
Our platform may contain links to third-party websites or services. We are not responsible for the privacy practices of those external sites. We encourage you to review the privacy policies of any third-party sites you visit.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated effective date. For significant changes, we may notify you by email. Where applicable law requires your consent to a new use or disclosure of your information, we will obtain that consent before the change applies to what we already hold about you.
11. Contact
If you have any questions or concerns about this Privacy Policy or how your data is handled, please contact us: Privacy inquiries: privacy@bidwellhealth.com; General support: support@bidwellhealth.com.