Medcare Telehealth Inc
Doing business as Medcare
Effective Date: August 16, 2026
YOUR INFORMATION. YOUR RIGHTS. OUR RESPONSIBILITIES.
This Notice describes how medical information about you may be used and disclosed and how you can obtain access to this information.
Please review it carefully.
This Notice of Privacy Practices ("Notice") applies to Medcare Telehealth Inc, doing business as Medcare, and describes privacy practices relating to Protected Health Information ("PHI") subject to the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations ("HIPAA").
This Notice applies to healthcare services provided through Medcare, including telehealth encounters, live video visits, patient portals, clinical communications, medical records, prescriptions, and related healthcare activities to the extent HIPAA applies.
1. WHAT IS PROTECTED HEALTH INFORMATION?
Protected Health Information, or PHI, generally means individually identifiable information concerning:
- Your past, present, or future physical or mental health or condition;
- Healthcare provided to you; or
- Payment for healthcare provided to you,
when that information is protected under HIPAA.
PHI may include information such as:
- Your name;
- Date of birth;
- Address;
- Telephone number;
- Email address;
- Medical history;
- Symptoms;
- Diagnoses;
- Medications;
- Allergies;
- Prescription information;
- Treatment information;
- Provider notes;
- Laboratory results;
- Pharmacy information;
- Telehealth visit information;
- Billing information;
- Other identifiable health information.
2. YOUR RIGHTS
You have certain rights regarding your health information.
The availability, scope, timing, and limitations of these rights are governed by applicable law.
3. GET A COPY OF YOUR MEDICAL RECORD
You may request to inspect or obtain an electronic or paper copy of certain medical records and other health information maintained about you.
Certain information may be excluded from access where permitted by law.
A reasonable cost-based fee may apply where permitted by law.
Identity verification may be required before records are released.
4. ASK TO CORRECT YOUR MEDICAL RECORD
If you believe that health information about you is incorrect or incomplete, you may request an amendment.
A request may be denied where permitted by law.
If an amendment request is denied, you may have additional rights concerning the disputed information under applicable law.
5. REQUEST CONFIDENTIAL COMMUNICATIONS
You may request that communications regarding your health information be sent to you in a particular way or at a particular location.
For example, you may request communication through a particular telephone number or mailing address.
Such requests are handled in accordance with applicable HIPAA requirements.
6. REQUEST RESTRICTIONS
You may ask Medcare to limit certain uses or disclosures of your PHI for:
- Treatment;
- Payment; or
- Healthcare operations.
Medcare is not required to agree to every requested restriction.
However, certain legally required restrictions must be honored.
For example, where applicable HIPAA requirements are satisfied, you may request that information about a healthcare item or service that you paid for in full out of pocket not be disclosed to a health plan for payment or healthcare operations purposes.
7. GET AN ACCOUNTING OF CERTAIN DISCLOSURES
You may request an accounting of certain disclosures of your PHI made during the period permitted by law.
An accounting does not necessarily include every disclosure.
For example, certain disclosures for treatment, payment, or healthcare operations may not be included.
8. GET A COPY OF THIS NOTICE
You may obtain a paper or electronic copy of this Notice.
A current version may also be made available through:
MedcareTelehealth.org
and through the Medcare patient portal where applicable.
9. CHOOSE SOMEONE TO ACT FOR YOU
If another person has legal authority to act on your behalf, that person may be able to exercise certain privacy rights for you.
This may include:
- A healthcare agent;
- Legal guardian;
- Parent;
- Personal representative;
- Other legally authorized person.
Medcare may request reasonable documentation to verify that authority.
10. FILE A PRIVACY COMPLAINT
You may submit a complaint if you believe your privacy rights have been violated.
You may also file a complaint with the:
U.S. Department of Health and Human Services
Office for Civil Rights
using the complaint procedures provided by HHS.
Medcare may not retaliate against you for filing a good-faith complaint or exercising a right protected by HIPAA.
11. YOUR CHOICES
For certain uses or disclosures, you may have choices regarding whether and how information is shared.
Depending on the circumstances, this may include disclosures to:
- Family members;
- Friends;
- Caregivers;
- Other individuals involved in your care or payment for your care;
- Disaster-relief organizations.
If you are unable to communicate your preference, information may be shared where permitted by HIPAA based on professional judgment, your best interests, an emergency, or another legally authorized basis.
12. MARKETING
Certain uses or disclosures of PHI for marketing may require your written authorization.
Not every healthcare-related communication is considered marketing under HIPAA.
Different rules may apply to communications involving:
- Treatment;
- Care coordination;
- Healthcare products or services;
- Prescription refill reminders;
- Other healthcare communications.
13. SALE OF PHI
Certain transactions involving the sale of PHI may require written authorization under HIPAA.
Whether a particular transaction constitutes a sale of PHI is determined under applicable law.
14. FUNDRAISING
If PHI is used for fundraising in a manner permitted by HIPAA, applicable notice and opt-out rights apply.
15. HOW YOUR INFORMATION MAY BE USED OR SHARED
HIPAA permits or requires PHI to be used or disclosed for a number of purposes.
Common examples are described below.
16. TREATMENT
Your PHI may be used or disclosed to provide, coordinate, or manage your healthcare.
Information may be shared with healthcare professionals or organizations involved in your treatment, including:
- Physicians;
- Nurse practitioners;
- Physician assistants;
- Nurses;
- Pharmacies;
- Laboratories;
- Specialists;
- Hospitals;
- Other treating healthcare professionals.
Examples may include:
- Sending a prescription to a pharmacy;
- Sharing relevant records with another treating provider;
- Reviewing laboratory information;
- Coordinating follow-up care;
- Making referrals.
17. PAYMENT
PHI may be used or disclosed for payment-related activities.
Examples may include:
- Billing;
- Processing healthcare claims;
- Determining eligibility or coverage;
- Collecting payment;
- Coordinating benefits;
- Responding to payment inquiries;
- Other permitted payment activities.
18. HEALTHCARE OPERATIONS
PHI may be used or disclosed for healthcare operations permitted by HIPAA.
Examples may include:
- Quality assessment;
- Quality improvement;
- Credentialing;
- Licensing;
- Training;
- Compliance;
- Auditing;
- Patient-safety activities;
- Fraud and abuse detection;
- Business planning;
- Legal services;
- Administrative activities;
- Technology operations;
- Other legally permitted healthcare operations.
19. BUSINESS ASSOCIATES
Medcare may use third parties that perform functions involving PHI.
These may include providers of:
- Electronic health record technology;
- Patient portals;
- Telehealth technology;
- Video technology;
- Cloud hosting;
- Data storage;
- Electronic prescribing;
- Billing;
- Cybersecurity;
- Information technology;
- Customer support;
- Other services.
Where HIPAA requires a Business Associate Agreement or another safeguard, applicable requirements govern the relationship.
20. PUBLIC HEALTH AND SAFETY
PHI may be disclosed for public-health and safety activities as permitted or required by law.
Examples may include:
- Disease reporting;
- Public-health surveillance;
- Reporting adverse events;
- Reporting product problems;
- Preventing or controlling disease;
- Reporting suspected abuse or neglect;
- Preventing or reducing a serious threat to health or safety;
- Other legally authorized activities.
21. HEALTH OVERSIGHT
PHI may be disclosed to healthcare oversight agencies for activities authorized by law.
These may include:
- Audits;
- Investigations;
- Inspections;
- Licensing proceedings;
- Disciplinary actions;
- Government oversight;
- Other authorized activities.
22. LEGAL PROCEEDINGS
PHI may be disclosed in connection with judicial or administrative proceedings where permitted or required by law.
Examples may include:
- Court orders;
- Subpoenas;
- Discovery requests;
- Administrative proceedings;
- Other lawful process.
Additional conditions or protections may apply depending on the information involved.
23. LAW ENFORCEMENT
PHI may be disclosed for certain law-enforcement purposes where permitted by law.
Examples may include disclosures:
- Required by law;
- Pursuant to certain court orders or warrants;
- In response to certain subpoenas or administrative requests;
- Concerning certain victims of crime;
- To identify or locate certain persons;
- Concerning certain deaths;
- In other legally authorized circumstances.
24. CORONERS, MEDICAL EXAMINERS, AND FUNERAL DIRECTORS
PHI may be disclosed to coroners, medical examiners, or funeral directors where permitted by law and relevant to their duties.
25. ORGAN, EYE, AND TISSUE DONATION
PHI may be disclosed to organizations involved in organ, eye, or tissue donation or transplantation where permitted by law.
26. WORKERS' COMPENSATION
PHI may be disclosed as authorized by and to the extent necessary to comply with workers' compensation laws or similar programs.
27. SPECIALIZED GOVERNMENT FUNCTIONS
PHI may be disclosed for certain specialized government functions where permitted by HIPAA.
Depending on applicable law, these may include:
- Military activities;
- National-security activities;
- Protective services;
- Correctional institutions;
- Certain government programs.
28. WHEN REQUIRED BY LAW
PHI may be used or disclosed when federal, state, or other applicable law requires the use or disclosure.
29. PEOPLE INVOLVED IN YOUR CARE
Where permitted by law, relevant PHI may be disclosed to people involved in your healthcare or payment for your care.
This may include:
- Family members;
- Relatives;
- Friends;
- Caregivers;
- Other individuals identified by you.
The information shared may be limited to information relevant to that person's involvement.
30. FAMILY MEMBERSHIP DOES NOT REMOVE INDIVIDUAL PRIVACY RIGHTS
Medcare may offer a Family Membership that permits multiple eligible family members to share membership benefits.
A Family Membership does not automatically give one adult family member unrestricted access to another adult family member's PHI.
The person managing or paying for the Family Membership may have access to administrative information such as:
- Membership status;
- Billing;
- Number of shared visits remaining;
- Family members associated with the membership.
That does not automatically authorize access to another adult patient's:
- Diagnoses;
- Provider notes;
- Prescription information;
- Medical history;
- Laboratory results;
- Private provider communications;
- Other protected medical information.
Access to another patient's PHI depends upon applicable law, patient authorization, parental rights, guardianship, personal-representative status, and other legally recognized authority.
31. MINORS
Privacy rights involving minors may vary based upon:
- Age;
- State law;
- Type of healthcare service;
- Parental authority;
- Guardian status;
- Whether the minor may independently consent to healthcare;
- Other legally relevant circumstances.
A parent or guardian does not necessarily have unrestricted access to every category of a minor's health information in every circumstance.
32. TELEHEALTH
Medcare may use electronic technologies to provide healthcare through telehealth.
PHI associated with telehealth may include:
- Patient identification;
- Provider identification;
- Reason for visit;
- Symptoms;
- Clinical observations;
- Medical history;
- Diagnoses;
- Treatment recommendations;
- Prescription information;
- Technical session information;
- Other healthcare information.
HIPAA requirements may apply to PHI created, received, maintained, or transmitted in connection with telehealth.
33. ELECTRONIC COMMUNICATIONS
Healthcare information may be communicated through systems including:
- Patient portals;
- Email;
- Text messaging;
- Telephone;
- Video;
- Electronic prescribing;
- Other electronic technologies.
Privacy and security requirements may vary based upon the system, circumstances, patient preferences, and applicable law.
34. SUBSTANCE USE DISORDER RECORDS
Certain substance-use-disorder ("SUD") patient records may receive additional confidentiality protections under 42 U.S.C. § 290dd-2 and 42 CFR Part 2.
Where Medcare creates, maintains, or receives records subject to Part 2, additional protections may apply.
Uses and disclosures of Part 2 records are subject to applicable federal law.
Part 2 records generally receive additional protections regarding their use in civil, criminal, administrative, or legislative proceedings against a patient.
Where required, Medcare's treatment, payment, and healthcare operations involving Part 2 records are subject to applicable consent, redisclosure, notice, and other requirements.
35. SPECIALLY PROTECTED INFORMATION
Federal or state law may provide additional protections for certain categories of health information.
Depending upon applicable law, additional protections may apply to information concerning:
- Mental health;
- Substance use disorder;
- HIV or other communicable conditions;
- Genetic information;
- Reproductive or sexual healthcare;
- Minor healthcare;
- Other specially protected information.
Where a more protective law applies and is not preempted, the more protective requirement controls.
36. AUTHORIZATIONS
Certain uses or disclosures of PHI may require your written authorization.
Where authorization is required, it generally identifies matters such as:
- Information to be used or disclosed;
- The person authorized to disclose it;
- The intended recipient;
- The purpose;
- Expiration;
- Other legally required information.
You generally may revoke an authorization in writing, subject to applicable exceptions, including actions already taken in reliance on the authorization.
37. OTHER USES AND DISCLOSURES
Uses and disclosures of PHI not otherwise permitted or required by law may require authorization.
Nothing in this Notice authorizes a use or disclosure prohibited by applicable law.
38. MEDCARE'S RESPONSIBILITIES
Where Medcare Telehealth Inc is acting as a HIPAA-covered entity, it is subject to applicable obligations concerning PHI.
These obligations include applicable requirements concerning:
- Privacy of PHI;
- Uses and disclosures;
- Patient rights;
- Notices of privacy practices;
- Safeguards;
- Breach notification;
- Other HIPAA requirements.
If a breach of unsecured PHI occurs, applicable federal and state notification requirements govern.
39. SECURITY OF ELECTRONIC PHI
Electronic PHI may be subject to administrative, physical, and technical security requirements.
Applicable security measures may involve:
- Access controls;
- Authentication;
- Audit controls;
- Transmission security;
- Workforce access controls;
- Security incident procedures;
- Risk management;
- Other legally required safeguards.
No electronic system can be guaranteed to be entirely free from technological or cybersecurity risk.
Nothing in this Notice limits any security obligation imposed by law.
40. CHANGES TO THIS NOTICE
Medcare Telehealth Inc may revise this Notice and its privacy practices as permitted by law.
A revised Notice may apply to PHI already maintained by Medcare as well as information received after the revised Notice becomes effective, to the extent permitted by law.
Material changes are subject to applicable HIPAA requirements.
The current version may be made available through:
MedcareTelehealth.org
and through other appropriate Medcare channels.
41. EFFECTIVE DATE
This Notice is effective:
August 16, 2026
42. PRIVACY QUESTIONS, REQUESTS, AND COMPLAINTS
Privacy questions, privacy requests, medical-record requests, or complaints may be submitted using the contact methods made available by Medcare Telehealth Inc through:
MedcareTelehealth.org
or through the Medcare patient portal where available.
Identity, authority, guardianship, parentage, personal-representative status, or other legal authority may be verified where appropriate before a request is processed.
43. COMPLAINTS TO HHS
You may also file a privacy complaint with the:
U.S. Department of Health and Human Services
Office for Civil Rights
using the complaint methods made available by HHS.
Medcare may not retaliate against you for exercising rights protected by HIPAA or for filing a good-faith privacy complaint.
44. ACKNOWLEDGMENT OF RECEIPT
Where applicable, Medcare may request acknowledgment that you received this Notice.
An acknowledgment of receipt means only that you received or had access to the Notice.
It does not mean that you:
- Waive privacy rights;
- Agree to uses or disclosures requiring separate authorization;
- Consent to unrestricted use of your medical information;
- Give up any right provided by applicable law.
If acknowledgment is not obtained, applicable HIPAA documentation requirements continue to apply.
45. RELATIONSHIP TO OTHER MEDCARE DOCUMENTS
This Notice specifically addresses privacy rights and practices relating to PHI under HIPAA.
Medcare may separately maintain:
- Privacy Policy;
- Terms of Service;
- Membership Terms;
- Telehealth Consent;
- Medical Emergency Disclaimer;
- Accessibility Statement;
- Clinical consents;
- Other legally required notices.
These documents serve different purposes.
Where a matter specifically concerns PHI governed by HIPAA, this Notice and applicable law govern to the extent required.
46. LEGAL INTERPRETATION
This Notice is intended to satisfy applicable HIPAA Notice of Privacy Practices requirements.
Nothing in this Notice is intended to:
- Expand Medcare Telehealth Inc's obligations beyond applicable law;
- Waive a legal defense, privilege, exemption, immunity, limitation, or right available under applicable law;
- Create contractual rights beyond those established by applicable law;
- Restrict a legally permitted use or disclosure beyond what applicable law requires unless expressly stated;
- Waive or restrict any patient's non-waivable legal rights.
If any provision of this Notice conflicts with controlling federal or state law, controlling law governs.
