Effective Date: August 15, 2026
YOUR INFORMATION. YOUR RIGHTS. OUR RESPONSIBILITIES.
This Notice describes how medical information about you may be used and disclosed and how you may obtain access to this information.
Please review it carefully.
This Notice of Privacy Practices ("Notice") applies to Medcare Telehealth Inc, doing business as Medcare, and describes privacy practices relating to Protected Health Information ("PHI") subject to the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations ("HIPAA").
This Notice applies to healthcare services provided through Medcare, including telehealth encounters, live video visits, patient portals, clinical communications, medical records, prescriptions, and related healthcare activities to the extent HIPAA applies.
1. WHAT IS PROTECTED HEALTH INFORMATION?
Protected Health Information, or PHI, generally includes individually identifiable information concerning:
- Your past, present, or future physical or mental health or condition;
- Healthcare provided to you; or
- Payment for healthcare provided to you,
when that information is maintained or transmitted by a HIPAA-covered entity or business associate and is otherwise subject to HIPAA.
PHI may include information such as:
- Your name;
- Date of birth;
- Contact information;
- Medical history;
- Symptoms;
- Diagnoses;
- Medications;
- Allergies;
- Prescription information;
- Provider notes;
- Treatment plans;
- Laboratory results;
- Pharmacy information;
- Telehealth visit information;
- Billing information; and
- Other health-related information linked to you.
2. YOUR RIGHTS
When it comes to your health information, you have certain rights under HIPAA.
The availability, scope, timing, and limitations of these rights are governed by applicable law.
3. GET AN ELECTRONIC OR PAPER COPY OF YOUR MEDICAL RECORD
You may request to inspect or obtain an electronic or paper copy of medical records and other health information about you that Medcare maintains and that is subject to a HIPAA right of access.
Certain records or information may be excluded from the right of access as permitted by law.
A reasonable, cost-based fee may apply where permitted by law.
Requests may be subject to identity verification and other procedures permitted by HIPAA.
4. ASK US TO CORRECT YOUR MEDICAL RECORD
If you believe that health information in your medical record is incorrect or incomplete, you may request an amendment.
Medcare may deny an amendment request in circumstances permitted by law.
If a request is denied, you may have the right to submit a statement of disagreement or otherwise have information relating to the request included with the record as permitted by applicable law.
5. REQUEST CONFIDENTIAL COMMUNICATIONS
You may request that Medcare communicate with you about medical matters in a particular way or at a particular location.
For example, you may request that certain communications be sent to a particular phone number or address.
Requests are subject to applicable HIPAA requirements.
6. ASK US TO LIMIT WHAT WE USE OR SHARE
You may request that Medcare limit certain uses or disclosures of PHI for:
- Treatment;
- Payment; or
- Healthcare operations.
Medcare is not required to agree to every requested restriction.
However, where HIPAA requires a restriction to be honored, the applicable legal requirement controls.
For example, HIPAA may require a healthcare provider to agree to certain requests to restrict disclosure to a health plan when the disclosure is for payment or healthcare operations and the healthcare item or service has been paid for in full out of pocket, subject to applicable requirements.
7. REQUEST AN ACCOUNTING OF DISCLOSURES
You may request a list, or accounting, of certain disclosures of your PHI made during the period permitted by law.
The accounting generally does not include every disclosure.
For example, certain disclosures for treatment, payment, or healthcare operations may not be included, subject to applicable law.
8. GET A COPY OF THIS NOTICE
You may request a paper or electronic copy of this Notice.
A current version may also be made available through MedcareTelehealth.org or the Medcare patient portal.
9. CHOOSE SOMEONE TO ACT FOR YOU
If you have given another person medical power of attorney or another person is your legally authorized representative, that person may be permitted to exercise certain privacy rights on your behalf.
Medcare may request documentation or other information reasonably necessary to verify that person's authority.
Special rules may apply to:
- Parents;
- Guardians;
- Minors;
- Personal representatives;
- Individuals legally authorized to make healthcare decisions.
10. FILE A PRIVACY COMPLAINT
You may raise concerns regarding privacy practices or submit a complaint if you believe your privacy rights have been violated.
You may also submit a complaint to the U.S. Department of Health and Human Services, Office for Civil Rights, using the methods made available by HHS.
Medcare may not retaliate against you for exercising a right protected by HIPAA or for filing a complaint in good faith.
11. YOUR CHOICES
For certain health information, you may be given choices about how information is shared.
Depending upon the circumstances, this may include information shared with:
- Family members;
- Friends;
- Caregivers;
- Others involved in your healthcare or payment for your care;
- Disaster-relief organizations.
When you are not able to communicate your preference, disclosures may be made where permitted by HIPAA based on professional judgment, your best interests, emergency circumstances, or other legally permitted grounds.
12. MARKETING
Uses or disclosures of PHI for marketing may require written authorization in circumstances specified by HIPAA.
Not every communication about healthcare constitutes "marketing" under HIPAA.
Communications concerning treatment, care coordination, healthcare products or services, refill reminders, or other matters may be treated differently under applicable law.
13. SALE OF PHI
A sale of PHI may require written authorization where required by HIPAA.
Whether a particular transaction constitutes a "sale of PHI" is determined under applicable law.
14. FUNDRAISING
If Medcare conducts fundraising activities using PHI in a manner permitted by HIPAA, applicable opt-out rights and other legal requirements apply.
15. HOW MEDCARE MAY USE OR DISCLOSE YOUR INFORMATION
HIPAA permits or requires Medcare to use and disclose PHI for a variety of purposes.
The following are common examples.
16. TREATMENT
Medcare may use or disclose your PHI to provide, coordinate, or manage your healthcare.
For example, information may be shared with:
- Physicians;
- Nurse practitioners;
- Physician assistants;
- Nurses;
- Pharmacies;
- Laboratories;
- Specialists;
- Hospitals;
- Other healthcare providers involved in your care.
Examples may include:
- Sending a prescription to a pharmacy;
- Sharing records with another treating healthcare professional;
- Reviewing laboratory results;
- Coordinating follow-up care;
- Making a referral.
HIPAA generally permits covered healthcare providers to disclose PHI to other healthcare providers for treatment purposes without a separate HIPAA authorization, subject to applicable law.
17. PAYMENT
Medcare may use or disclose PHI for payment-related activities.
This may include:
- Determining eligibility or coverage;
- Billing;
- Processing healthcare claims;
- Collecting payment;
- Coordinating benefits;
- Responding to payment inquiries;
- Conducting other payment activities permitted by law.
18. HEALTHCARE OPERATIONS
Medcare may use or disclose PHI for healthcare operations permitted by HIPAA.
Examples may include:
- Quality assessment;
- Quality improvement;
- Training;
- Credentialing;
- Licensing;
- Compliance;
- Auditing;
- Business planning;
- Healthcare fraud and abuse detection;
- Patient safety activities;
- Legal services;
- Administrative activities;
- Technology operations;
- Other legally permitted healthcare operations.
19. BUSINESS ASSOCIATES
Medcare may use third parties to perform functions or provide services involving PHI.
These may include organizations providing:
- Electronic health record systems;
- Telehealth technology;
- Patient portal technology;
- Cloud hosting;
- Electronic prescribing;
- Billing;
- Customer support;
- Information technology;
- Cybersecurity;
- Data storage;
- Other services.
Where HIPAA requires a Business Associate Agreement or other contractual safeguard, applicable requirements govern the arrangement.
20. PUBLIC HEALTH AND SAFETY
Medcare may disclose PHI for public-health or safety activities as permitted or required by law.
Examples may include:
- Reporting certain diseases;
- Reporting adverse events;
- Reporting product problems;
- Preventing or controlling disease;
- Reporting suspected abuse or neglect;
- Preventing or reducing a serious threat to health or safety;
- Other legally authorized public-health activities.
21. HEALTH OVERSIGHT
PHI may be disclosed to health oversight agencies for activities authorized by law.
These activities may include:
- Audits;
- Investigations;
- Inspections;
- Licensing proceedings;
- Disciplinary actions;
- Government oversight;
- Other legally authorized oversight activities.
22. LEGAL PROCEEDINGS
PHI may be disclosed in response to judicial or administrative proceedings when permitted or required by applicable law.
This may include circumstances involving:
- Court orders;
- Subpoenas;
- Discovery requests;
- Administrative proceedings;
- Other lawful process.
HIPAA and other applicable laws may impose conditions or limitations on these disclosures.
23. LAW ENFORCEMENT
PHI may be disclosed for certain law-enforcement purposes where permitted by law.
Examples may include disclosures:
- Required by law;
- Pursuant to certain court orders, warrants, subpoenas, or administrative requests;
- Concerning certain victims of crime;
- Concerning certain deaths;
- Concerning criminal conduct;
- To identify or locate certain persons;
- For other legally permitted law-enforcement purposes.
24. CORONERS, MEDICAL EXAMINERS, AND FUNERAL DIRECTORS
Medcare may disclose PHI to coroners, medical examiners, or funeral directors where permitted by law and where the information is relevant to their duties.
25. ORGAN AND TISSUE DONATION
PHI may be disclosed to organizations involved in organ, eye, or tissue donation or transplantation where permitted by law.
26. WORKERS' COMPENSATION
PHI may be disclosed as authorized by and to the extent necessary to comply with laws relating to workers' compensation or similar programs.
27. GOVERNMENT FUNCTIONS
PHI may be disclosed for certain specialized government functions permitted by HIPAA.
Depending on applicable law, these may include matters involving:
- Military activities;
- National security;
- Protective services;
- Correctional institutions;
- Certain government benefit programs.
28. WHEN REQUIRED BY LAW
Medcare may use or disclose PHI when federal, state, or other applicable law requires the use or disclosure.
29. PERSONAL REPRESENTATIVES AND PEOPLE INVOLVED IN YOUR CARE
Where permitted by HIPAA, Medcare may disclose relevant PHI to:
- Family members;
- Relatives;
- Close personal friends;
- Caregivers;
- Other individuals identified by you,
when they are involved in your care or payment for your healthcare.
The amount of information disclosed may be limited to information relevant to that person's involvement.
30. FAMILY MEMBERSHIPS DO NOT REMOVE INDIVIDUAL PRIVACY RIGHTS
Medcare may offer family memberships that allow multiple eligible family members to share membership benefits or visits.
A family membership does not automatically give one adult family member unrestricted access to another adult family member's PHI.
For example, the person who pays for a family membership may be able to see membership-related information such as:
- Membership status;
- Billing information;
- Number of included visits remaining;
- Names of eligible family members.
That does not automatically authorize access to another adult patient's:
- Diagnoses;
- Provider notes;
- Prescriptions;
- Medical history;
- Test results;
- Private clinical communications;
- Other PHI.
Access is determined by HIPAA, applicable state law, patient authorization, parental rights, guardianship, personal representative status, and other legally recognized authority.
31. MINORS
The privacy rights of minors may differ depending upon applicable law.
Factors may include:
- The minor's age;
- The type of healthcare;
- State law;
- Whether a parent or guardian consented to the healthcare;
- Whether the minor was legally authorized to consent independently;
- Other circumstances recognized by law.
A parent or guardian does not necessarily have unrestricted access to every category of a minor's health information in every circumstance.
32. TELEHEALTH
Medcare may use electronic technologies to provide telehealth healthcare.
PHI created, received, maintained, or transmitted in connection with telehealth may be subject to HIPAA and other applicable privacy requirements.
Telehealth information may include:
- Patient identification;
- Provider identification;
- Visit details;
- Symptoms;
- Clinical observations;
- Diagnoses;
- Treatment recommendations;
- Prescription information;
- Technical session information;
- Other information related to the encounter.
Telehealth technologies and associated vendors are subject to applicable HIPAA requirements where they create, receive, maintain, or transmit PHI on behalf of a HIPAA-regulated entity.
33. ELECTRONIC COMMUNICATIONS
Healthcare-related information may be communicated through methods including:
- Patient portals;
- Email;
- Text messaging;
- Telephone;
- Video;
- Electronic prescribing;
- Other electronic systems.
Privacy and security requirements vary depending upon the technology, circumstances, patient preferences, and applicable law.
34. SUBSTANCE USE DISORDER RECORDS
Certain records relating to substance use disorder treatment may receive additional confidentiality protections under 42 U.S.C. § 290dd-2 and 42 CFR Part 2.
Where Medcare maintains or receives records subject to Part 2, additional restrictions and rights may apply.
Part 2 records may not be used or disclosed in civil, criminal, administrative, or legislative proceedings against a patient except as specifically authorized or permitted by applicable law.
Where required, Medcare's treatment, payment, and healthcare operations involving Part 2 records are subject to the applicable consent, redisclosure, notice, and other requirements established by federal law.
Additional federal and state protections may also apply.
35. MORE PROTECTIVE STATE LAWS
HIPAA establishes federal privacy requirements.
Some states provide greater privacy protection for particular categories of health information.
Where applicable state law provides greater protection and is not preempted by HIPAA, the more protective requirement may apply.
Special protections may apply to categories such as:
- Mental health information;
- Substance use disorder information;
- HIV-related information;
- Genetic information;
- Reproductive or sexual health information;
- Minor health information;
- Other specially protected healthcare information.
36. USES AND DISCLOSURES REQUIRING AUTHORIZATION
Certain uses or disclosures of PHI require written authorization unless another legal basis permits the use or disclosure.
Where authorization is required, the authorization generally describes:
- The information involved;
- Who may disclose it;
- Who may receive it;
- The purpose;
- The expiration;
- Other legally required information.
You may generally revoke an authorization in writing, subject to exceptions permitted by law, including actions already taken in reliance on the authorization.
37. OTHER USES AND DISCLOSURES
Uses and disclosures of PHI not described in this Notice may be made with your authorization or as otherwise permitted or required by applicable law.
38. MEDCARE'S RESPONSIBILITIES
Medcare Telehealth Inc is subject to applicable HIPAA obligations regarding PHI where Medcare is acting as a HIPAA-covered entity.
Applicable responsibilities include obligations concerning:
- Privacy of PHI;
- Permitted uses and disclosures;
- Patient privacy rights;
- Notice of privacy practices;
- Safeguards;
- Breach notification;
- Other requirements imposed by applicable law.
If a breach of unsecured PHI occurs, notification requirements are governed by HIPAA and other applicable law.
39. ELECTRONIC HEALTH INFORMATION SECURITY
Electronic PHI may be subject to administrative, physical, and technical security requirements under HIPAA.
Security practices may include safeguards relating to:
- Access control;
- Authentication;
- Audit controls;
- Transmission security;
- Workforce access;
- Security incident procedures;
- Risk management;
- Other measures required by applicable law.
No electronic environment can be made entirely free from technological or cybersecurity risk.
Nothing in this Notice limits security obligations imposed by law.
40. CHANGES TO THIS NOTICE
Medcare Telehealth Inc may change this Notice and its privacy practices as permitted by law.
A revised Notice may apply to PHI maintained by Medcare, including PHI created or received before the effective date of the revised Notice, to the extent permitted by law.
Material changes to this Notice are subject to the requirements of HIPAA.
The current version may be made available through MedcareTelehealth.org and other appropriate locations.
41. EFFECTIVE DATE
This Notice is effective:
August 15, 2026
42. PRIVACY QUESTIONS, REQUESTS, AND COMPLAINTS
Privacy-related questions, requests, complaints, and requests concerning medical records may be submitted using the privacy or contact methods made available by Medcare Telehealth Inc through:
MedcareTelehealth.org
or through the Medcare patient portal.
Identity or legal authority may be verified before certain requests are processed.
43. COMPLAINTS TO THE U.S. DEPARTMENT OF HEALTH AND HUMAN SERVICES
Individuals may also file a complaint with the:
U.S. Department of Health and Human Services Office for Civil Rights
using the complaint procedures made available by HHS.
A person's healthcare rights under HIPAA are not conditioned upon refraining from filing a privacy complaint.
44. ACKNOWLEDGMENT OF RECEIPT
Applicable healthcare providers with direct treatment relationships generally must make a good-faith effort to obtain a patient's written acknowledgment of receipt of the Notice of Privacy Practices, except in circumstances where HIPAA provides otherwise.
Electronic acknowledgment may be used where legally appropriate.
A patient's acknowledgment confirms receipt of the Notice.
It does not constitute authorization for uses or disclosures that otherwise require separate authorization.
45. IMPORTANT DISTINCTION BETWEEN THIS NOTICE AND OTHER MEDCARE POLICIES
This Notice addresses the use and disclosure of Protected Health Information under HIPAA.
Medcare may separately maintain:
- A Website Privacy Policy;
- Terms of Service;
- Membership Terms;
- Telehealth Consent;
- Clinical consents;
- Other privacy or consumer notices.
Those documents serve different purposes.
If a conflict concerns PHI governed by HIPAA, HIPAA and this Notice control to the extent required by applicable law.
46. LEGAL INTERPRETATION
This Notice is intended to satisfy applicable requirements of the HIPAA Privacy Rule governing Notices of Privacy Practices.
Nothing in this Notice is intended to:
- Expand Medcare Telehealth Inc's obligations beyond applicable law;
- Waive a defense, privilege, exemption, immunity, limitation, or right available under applicable law;
- Create contractual rights beyond those established by applicable law;
- Restrict a permitted use or disclosure beyond what applicable law requires unless expressly stated;
- Modify a patient's non-waivable rights.
To the extent any provision conflicts with controlling federal or state law, controlling law governs.
