Privacy Policy
Secure Medical, Inc. Privacy Policy
Effective Date: September 11, 2026
Last Updated: September 11, 2026
1. Our Commitment to Privacy
Secure Medical, Inc. ("Secure Medical," "SMI," "we," "us," or "our") respects the privacy of individuals who use our websites, applications, technology platforms, patient portals, communication systems, telemedicine-related services, healthcare administration services, and other services that link to this Privacy Policy (collectively, the "Services").
Secure Medical provides technology, administrative, operational, payment-processing, healthcare connectivity, pharmacy coordination, customer-support, and related services that facilitate access to healthcare and telemedicine services.
We recognize that health-related and personal information is sensitive. Secure Medical is committed to collecting, using, maintaining, protecting, and disclosing personal information responsibly and in accordance with applicable federal and state privacy, healthcare, telecommunications, and data-security laws.
This Privacy Policy explains:
- What information we collect;
- How we collect information;
- How and why we use information;
- How information may be disclosed;
- How health information is handled;
- How information is protected;
- How long information may be retained;
- Your privacy rights and choices;
- Our SMS, telephone, and email practices; and
- How to contact Secure Medical regarding privacy matters.
2. Scope of This Privacy Policy
This Privacy Policy applies to personal information collected through websites, branded websites operated or administered using Secure Medical technology, mobile applications, patient portals, online forms, medical questionnaires, telemedicine platforms, telephone communications, text messages, email communications, customer-support interactions, payment systems, and other Services operated, administered, or supported by Secure Medical that link to this Privacy Policy.
Secure Medical may provide technology and administrative services for independently owned healthcare practices, professional medical entities, licensed healthcare professionals, pharmacies, laboratories, healthcare programs, business partners, employers, and other organizations.
Depending upon the particular Service or relationship, Secure Medical may process information on its own behalf or on behalf of another organization.
Additional privacy notices, Notices of Privacy Practices, telemedicine consents, consumer health data privacy policies, pharmacy notices, SMS terms, or other disclosures may apply to a particular healthcare service, platform, or transaction.
If another legally required privacy notice applies to particular information and conflicts with this Privacy Policy, the legally required notice will control with respect to that information.
3. Important Information About HIPAA and Medical Records
Certain health information processed through the Services may constitute Protected Health Information ("PHI") under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA") and its implementing regulations.
HIPAA does not apply to every type of health-related information or to every organization that handles health-related information.
Depending upon the particular Service and relationship involved, Secure Medical may provide services to a healthcare provider, professional medical entity, pharmacy, or other HIPAA-regulated organization as a business associate, subcontractor, technology provider, or other service provider.
When Secure Medical creates, receives, maintains, or transmits PHI on behalf of a HIPAA covered entity or other business associate, Secure Medical uses and discloses that information in accordance with applicable law and contractual requirements, including Business Associate Agreements where required.
The healthcare provider, professional medical entity, pharmacy, or other organization responsible for your healthcare may provide you with a separate Notice of Privacy Practices describing how your PHI may be used and disclosed and explaining your rights regarding your medical information.
This Privacy Policy is not intended to replace a Notice of Privacy Practices required under HIPAA.
4. Secure Medical's Role in Telemedicine
Secure Medical provides technology and administrative infrastructure that may facilitate communications and transactions between patients, independently licensed healthcare professionals, professional medical entities, pharmacies, laboratories, and other healthcare-related organizations.
Unless expressly stated otherwise, Secure Medical does not independently diagnose medical conditions, make medical treatment decisions, determine whether a prescription is medically appropriate, or exercise professional medical judgment.
Clinical decisions are made by appropriately licensed healthcare professionals exercising their independent professional judgment.
Prescription medications are dispensed by appropriately licensed pharmacies.
Secure Medical may facilitate the collection and transmission of medical information, provider communications, prescriptions, payments, pharmacy information, fulfillment information, patient communications, and other information necessary to administer requested Services.
5. Information We Collect
The information Secure Medical collects depends upon how you interact with the Services and the Services you request.
A. Identification and Contact Information
We may collect:
- Name;
- Mailing address;
- Billing address;
- Shipping address;
- Email address;
- Telephone or mobile number;
- Date of birth;
- Age;
- Sex or gender when relevant to requested healthcare services;
- Account identifiers;
- Customer or patient identifiers; and
- Other information reasonably necessary to identify or verify an individual.
B. Health and Medical Information
When you request healthcare or telemedicine services, Secure Medical or healthcare professionals using Secure Medical technology may collect information including:
- Medical history;
- Current and previous medical conditions;
- Symptoms;
- Allergies;
- Current and previous medications;
- Prescription history;
- Treatment history;
- Height and weight;
- Vital information when provided;
- Laboratory information;
- Diagnostic information;
- Photographs or images submitted for medical evaluation;
- Responses to medical questionnaires;
- Healthcare-provider communications;
- Consultation information;
- Medical records obtained with appropriate authorization;
- Pharmacy information;
- Treatment eligibility information;
- Information concerning previous treatment experiences; and
- Other information reasonably necessary to facilitate healthcare services.
C. Telemedicine Encounter Information
Depending upon the nature of an encounter, information may be exchanged through video, audio, telephone, secure messaging, electronic questionnaires, photographs, files, asynchronous communications, or other telemedicine technologies permitted by applicable law.
We may collect technical and administrative information necessary to establish, secure, document, troubleshoot, or support a telemedicine encounter.
Secure Medical does not record the audio or video portion of a healthcare consultation unless recording is specifically disclosed and legally authorized.
D. Transaction, Order, and Payment Information
We may collect or process:
- Transaction history;
- Products or services requested;
- Order history;
- Payment status;
- Billing information;
- Refund information;
- Shipping and fulfillment information;
- Payment-card information processed through payment providers; and
- Information used to detect or prevent fraudulent or unauthorized transactions.
Payment-card information may be transmitted directly to payment processors and may not be stored by Secure Medical in complete payment-card form.
E. Account and Authentication Information
We may collect usernames, protected authentication credentials, account preferences, account activity, login history, authentication information, security information, and other information necessary to establish and protect your account.
F. Communications
We may collect communications made through:
- Email;
- SMS or MMS;
- Telephone;
- Secure messaging;
- Patient portals;
- Online chat;
- Customer service;
- Support tickets; and
- Other communication channels.
Telephone calls with Secure Medical customer-service or administrative personnel may be monitored or recorded for quality assurance, training, security, fraud prevention, dispute resolution, customer service, and compliance where permitted by law.
G. Device, Usage, and Technical Information
When you interact with our digital Services, we may automatically receive information such as:
- IP address;
- Browser type;
- Operating system;
- Device type;
- Device identifiers;
- Approximate location derived from an IP address;
- Date and time of access;
- Pages or features viewed;
- Links selected;
- Referring websites or advertising sources;
- Session information;
- Application-performance information;
- Security events;
- Diagnostic information; and
- Error information.
H. Location Information
Telemedicine laws generally depend upon the patient's physical location at the time healthcare services are provided. We may therefore request your state or physical location so that an appropriate healthcare professional can determine whether the professional is legally authorized to provide services to you.
We do not collect precise device geolocation unless reasonably necessary for a requested feature, you permit such collection, or such collection is otherwise permitted by applicable law.
I. Information From Other Sources
Subject to applicable law and appropriate authorization, we may receive information from:
- Healthcare professionals;
- Professional medical entities;
- Pharmacies;
- Laboratories;
- Electronic health record systems;
- Electronic prescribing systems;
- Payment processors;
- Identity-verification services;
- Fraud-prevention services;
- Shipping providers;
- Business partners;
- Customer-support providers;
- Employers or benefit sponsors where applicable;
- Other healthcare organizations; and
- Other sources authorized by you or permitted by law.
6. How We Use Information
Secure Medical may use personal information for purposes including:
- Providing and administering the Services;
- Creating and maintaining accounts;
- Verifying identity;
- Determining physical location for telemedicine licensing purposes;
- Connecting patients with licensed healthcare professionals;
- Facilitating healthcare evaluations;
- Facilitating provider-patient communications;
- Supporting electronic medical records;
- Coordinating prescription transmission;
- Coordinating pharmacy fulfillment;
- Processing payments;
- Processing refunds;
- Providing customer service;
- Sending requested or permitted communications;
- Preventing fraud, identity theft, misuse, and unauthorized transactions;
- Authenticating users;
- Maintaining technology and network security;
- Troubleshooting systems;
- Conducting quality assurance;
- Administering healthcare-related operations;
- Improving Services and user experience;
- Complying with healthcare, pharmacy, telemedicine, privacy, licensing, financial, recordkeeping, and other legal requirements;
- Responding to lawful legal or regulatory requests;
- Protecting patients, healthcare professionals, Secure Medical, and others;
- Creating de-identified or aggregated information as permitted by law; and
- Other purposes disclosed when information is collected.
7. Data Minimization and Purpose Limitation
Secure Medical seeks to collect and process information that is reasonably necessary, relevant, and proportionate to the purposes for which the information is collected.
We seek to limit access to sensitive personal information and health information to workforce members, healthcare professionals, pharmacies, service providers, and other persons who reasonably require access for an authorized purpose.
Secure Medical does not intend to use health information for materially unrelated purposes without providing additional notice, obtaining consent where required, or otherwise satisfying applicable legal requirements.
8. Healthcare Providers and Professional Medical Entities
Information submitted in connection with a request for medical care may be made available to healthcare professionals and professional medical entities involved in evaluating or treating you.
Healthcare professionals exercise independent professional medical judgment and are responsible for their own clinical decisions and professional obligations.
Healthcare professionals or professional medical entities may maintain medical records concerning your treatment and may be required by law to retain those records for specified periods.
Your rights concerning medical records may be governed by HIPAA, state medical-record laws, and an applicable Notice of Privacy Practices.
9. Pharmacies and Prescription Fulfillment
If a healthcare professional issues a prescription, information necessary to process, transmit, dispense, ship, or otherwise fulfill the prescription may be provided to an appropriately licensed pharmacy.
This information may include identifying information, prescription information, healthcare-provider information, relevant health information, allergies, medication history, payment information, shipping information, and other information reasonably necessary for lawful pharmacy services.
Pharmacies are responsible for their own professional, legal, licensing, dispensing, and privacy obligations.
10. Service Providers and Business Associates
Secure Medical may engage organizations that provide services including:
- Cloud hosting;
- Healthcare technology;
- Electronic health records;
- Electronic prescribing;
- Telecommunications;
- SMS and email delivery;
- Payment processing;
- Identity verification;
- Fraud prevention;
- Cybersecurity;
- Customer service;
- Shipping and fulfillment;
- Data storage;
- Analytics;
- Professional services;
- Auditing;
- Compliance; and
- Other operational and technology services.
Where a service provider creates, receives, maintains, or transmits PHI on behalf of a HIPAA-regulated entity and qualifies as a business associate, appropriate Business Associate Agreements or other legally required arrangements are used.
We seek to require service providers to process personal information only for authorized purposes and to maintain privacy and security protections appropriate to the information involved.
11. Cookies and Similar Technologies
Secure Medical websites and digital Services may use cookies and similar technologies for purposes including:
- Operating websites;
- Maintaining sessions;
- Authenticating users;
- Remembering preferences;
- Maintaining security;
- Detecting fraud;
- Measuring website performance;
- Understanding how public-facing pages are used;
- Measuring marketing effectiveness where permitted; and
- Improving website functionality.
These technologies may include cookies, pixels, web beacons, software development kits, device identifiers, browser storage, and similar technologies.
Where required by applicable law, users may be provided with controls allowing them to manage optional cookies or tracking technologies.
Secure Medical treats medical questionnaires, authenticated patient areas, prescription information, patient portals, and telemedicine interactions with heightened sensitivity.
We do not knowingly permit third-party advertising technologies to use PHI obtained from patient portals, medical questionnaires, telemedicine consultations, prescription records, or authenticated medical areas for the third party's independent advertising purposes.
12. Analytics, Advertising, and Online Tracking
Secure Medical may use analytics technologies on public-facing portions of its Services to understand website use, evaluate performance, identify technical issues, measure communications or advertising, and improve user experience.
Secure Medical may also advertise its Services through third-party platforms where permitted by law.
Secure Medical does not sell PHI for advertising purposes.
Secure Medical does not authorize PHI to be provided to third-party advertising platforms for their independent advertising purposes unless such disclosure is permitted by law and any authorization required by applicable healthcare privacy law has been obtained.
Where applicable state privacy laws provide rights to opt out of qualifying targeted advertising, sale, sharing, or profiling, eligible users may exercise those rights as described in this Privacy Policy.
13. Protected Health Information and Marketing
Where HIPAA applies, Secure Medical will not use or disclose PHI for marketing in circumstances requiring a HIPAA authorization unless the required authorization has been obtained.
Communications concerning treatment, healthcare operations, care coordination, prescription administration, account administration, or other communications permitted by healthcare privacy law are not necessarily considered marketing.
Consent to receive promotional communications is not a condition of obtaining healthcare services unless otherwise permitted by applicable law.
14. SMS, Telephone, and Email Communications
A. SMS Marketing Program
By affirmatively opting in to receive marketing communications from Secure Medical, Inc. ("Secure Medical") through our website, checkout process, subscription tools, forms, or other enrollment methods, you consent to receive recurring SMS and MMS text messages from Secure Medical at the mobile telephone number you provide.
Messages may include text notifications, marketing and promotional offers, service-related communications, order information, transactional messages, and requests for reviews.
You may receive these messages even if your mobile number is registered on a state or federal Do Not Call list, to the extent permitted by applicable law and based upon the consent you have provided.
Consent to receive marketing text messages is not a condition of purchasing any product, medication, telemedicine consultation, or other Service from Secure Medical.
You will receive a maximum of 8 marketing SMS/MMS messages per month. Transactional or service-related message frequency may vary depending upon your interactions with Secure Medical and the Services you request.
Message and data rates may apply. Secure Medical does not charge you for participating in the SMS program; however, you are responsible for messaging, data, or other charges imposed by your wireless carrier.
B. How to Opt Out of SMS
You may opt out of receiving marketing text messages at any time by replying STOP to any applicable mobile message sent by Secure Medical.
You may also reply STOP to 25283 to stop receiving applicable messages from that messaging program.
Where an unsubscribe link is included in a message, you may also use that link to manage your messaging preferences.
After submitting a valid opt-out request, you may receive a final confirmation message acknowledging your request. After your opt-out has been processed, you will no longer receive marketing messages from that SMS program unless you subsequently provide new consent.
Opting out of marketing communications does not necessarily prevent Secure Medical from sending non-marketing communications necessary to complete a transaction, respond to a request initiated by you, administer healthcare services, provide security information, or otherwise communicate as permitted by applicable law.
C. SMS HELP and Customer Support
For assistance with the Secure Medical SMS program, reply HELP to 25283.
You may also contact Secure Medical at:
Email: marketing@securemedical.com
Telephone: 800-550-0793
D. Mobile Information and SMS Consent Privacy
Secure Medical respects the privacy of information provided in connection with its SMS and MMS messaging programs.
Secure Medical does not sell, rent, share, or provide your mobile telephone number, SMS opt-in information, or SMS consent information to third parties or affiliates for their own marketing or promotional purposes.
Mobile information and text messaging originator opt-in data and consent will not be shared with third parties or affiliates for marketing or promotional purposes.
This restriction applies notwithstanding any other provision of this Privacy Policy that generally describes information sharing with service providers, business partners, affiliates, healthcare organizations, or other third parties.
Secure Medical may disclose mobile information to vendors and service providers acting on our behalf when reasonably necessary to operate and support the messaging program, including telecommunications providers, wireless carriers, SMS platform providers, communications technology providers, and customer-support providers.
Such organizations may use the information only to provide services to Secure Medical and are not authorized to use Secure Medical mobile opt-in information or SMS consent for their own marketing or promotional purposes.
E. SMS Consent Is Specific to Secure Medical
Your consent to receive SMS or MMS marketing communications applies specifically to Secure Medical and the Secure Medical messaging program for which you provided consent.
Your SMS marketing consent is not sold, rented, transferred, or automatically assigned to another company, advertiser, lead generator, affiliate, brand, or unrelated third party.
A telephone number obtained through an order, account registration, customer-service interaction, healthcare transaction, or other source does not by itself constitute consent to receive marketing text messages where separate consent is required by applicable law.
F. Transactional and Service-Related Messages
In addition to marketing messages for which you have provided appropriate consent, Secure Medical may send transactional or service-related communications concerning Services you have requested.
These communications may include:
- Account verification and security notifications;
- Order confirmations and updates;
- Payment or billing notifications;
- Shipping and delivery information;
- Customer-service communications;
- Telemedicine appointment or consultation reminders;
- Requests for information necessary to complete a requested Service;
- Prescription or pharmacy-related administrative communications;
- Notifications concerning secure messages or patient portal activity; and
- Other communications necessary to administer a transaction or Service requested by you.
Transactional and service-related messages will be sent only as permitted by applicable law.
G. Changes to Telephone Numbers or Short Codes
Secure Medical may change the telephone number, short code, or other sending identifier used for its messaging services from time to time.
When appropriate, Secure Medical will notify you of such a change.
Messages sent to an outdated telephone number or short code, including STOP or HELP requests, may not be received after a messaging number or short code has changed.
Please refer to our most recent communications for the current method of contacting Secure Medical or managing your messaging preferences.
H. Carrier Disclaimer
Wireless carriers are not liable for delayed or undelivered messages.
To the extent permitted by applicable law, Secure Medical is not responsible for failed, delayed, duplicated, or misdirected delivery of information through a wireless carrier or telecommunications provider where such failure is outside Secure Medical's reasonable control.
Message delivery is subject to the availability and operation of wireless carrier networks and is not guaranteed.
If you have questions about your text or data plan, contact your wireless provider.
I. Telephone Number Changes and Reassignment
You represent that you are the subscriber or customary user of the mobile telephone number provided to Secure Medical or that you otherwise have authority to provide the number and consent to communications at that number.
If you change, deactivate, transfer, or relinquish your telephone number, please promptly update your information or notify Secure Medical at marketing@securemedical.com or 800-550-0793.
This helps prevent communications intended for you from being delivered to another person who later receives your previous telephone number.
J. SMS and Healthcare Privacy
SMS and MMS messages generally are not encrypted in the same manner as a secure patient portal. Anyone with access to your mobile device, telephone account, lock-screen notifications, or messages may be able to view communications sent to your device.
Secure Medical seeks to limit sensitive medical information transmitted directly through ordinary SMS or MMS communications and may direct you to a secure website, patient portal, healthcare provider, or other protected communication method when appropriate.
Text messaging is not intended for medical emergencies or urgent medical communications.
If you believe you are experiencing a medical emergency, call 911 or seek immediate emergency medical care.
K. Telephone Communications
Secure Medical may contact you by telephone regarding transactions or Services you have requested, including account matters, healthcare administration, customer-service inquiries, prescriptions, pharmacy coordination, orders, billing, fraud prevention, security, and related matters.
Where required by applicable law, Secure Medical will obtain appropriate consent before using automated dialing technology, artificial or prerecorded voice technology, or similar technology for marketing purposes.
Telephone calls with Secure Medical personnel may be monitored or recorded for quality assurance, training, security, fraud prevention, dispute resolution, customer service, and compliance purposes where permitted by applicable law. Where legally required, notice or consent will be provided.
L. Email Communications
Secure Medical may send email communications relating to your account, requested Services, telemedicine activity, prescriptions, pharmacy coordination, transactions, orders, payments, customer service, security, and administrative matters.
Where you have elected to receive promotional emails, Secure Medical may send information regarding products, Services, programs, or offers that may be of interest to you.
Marketing emails will include an appropriate method for unsubscribing from promotional communications.
Unsubscribing from marketing emails does not prevent Secure Medical from sending transactional, account, healthcare-administration, security, or legally required communications.
M. Messaging Program Changes
Secure Medical may modify, suspend, or discontinue all or part of an SMS or MMS messaging program.
Where required by applicable law or carrier requirements, Secure Medical will provide appropriate notice or obtain additional consent before materially changing a messaging program.
N. SMS Program Contact Information
Secure Medical, Inc.
5801 S. McClintock Drive, Suite 107
Tempe, Arizona 85283
Telephone: 800-550-0793
Email: marketing@securemedical.com
SMS Summary: Message frequency varies. Maximum of 8 marketing SMS/MMS messages per month. Message and data rates may apply. Reply STOP to cancel. Reply HELP to 25283 for help. Carriers are not liable for delayed or undelivered messages. Consent to receive marketing text messages is not a condition of purchase.
15. Artificial Intelligence and Automated Technologies
Secure Medical may use automated technologies, algorithms, or artificial intelligence-enabled tools to support non-clinical functions such as fraud detection, cybersecurity, administrative workflows, customer-service routing, quality assurance, operational analytics, document processing, and technology improvement.
Secure Medical does not authorize an automated system to independently replace the professional medical judgment of a licensed healthcare professional in determining whether prescription treatment or other medical care is appropriate for a patient.
Where personal information or health-related information is processed using automated technologies, Secure Medical seeks to apply privacy, security, access-control, contractual, and data-minimization safeguards appropriate to the information involved.
Secure Medical does not intentionally use identifiable PHI to train publicly available general-purpose artificial intelligence models.
16. Consumer Health Data
Certain states have adopted laws regulating "consumer health data" that may apply to health-related information not regulated as PHI under HIPAA.
Consumer health data may include information that identifies or may be used to infer an individual's past, present, or future physical or mental health status.
Depending upon applicable law, this may include information concerning:
- Health conditions;
- Symptoms;
- Diagnoses;
- Treatments;
- Medications;
- Medical procedures;
- Reproductive or sexual health;
- Mental or behavioral health;
- Biometric information associated with health;
- Health-related location information; and
- Information inferred from other information concerning an individual's health.
Secure Medical does not sell consumer health data unless expressly authorized by an individual in a manner satisfying applicable law.
Where required, Secure Medical will obtain appropriate consent before collecting or sharing consumer health data for purposes requiring consent.
Residents of states providing consumer health data rights may have additional rights to access, correct, delete, withdraw consent, or obtain information regarding consumer health data.
Secure Medical maintains a separate Consumer Health Data Privacy Policy where required by applicable law.
17. Sensitive Personal Information
Health information and other information may be considered sensitive personal information under applicable law.
Sensitive information may include:
- Health information;
- Precise geolocation;
- Financial-account information;
- Government identification information;
- Genetic information;
- Certain biometric information;
- Racial or ethnic origin;
- Religious beliefs;
- Citizenship or immigration information;
- Sexual orientation or sex-life information; and
- Other categories designated sensitive by applicable law.
Secure Medical processes sensitive information only for reasonably necessary, authorized, and legally permitted purposes.
Where applicable law requires consent before processing sensitive personal information, Secure Medical will obtain appropriate consent unless a legal exception applies.
18. We Do Not Sell Medical Information
Secure Medical does not sell Protected Health Information.
Secure Medical does not sell medical records.
Secure Medical does not sell identifiable consumer health information to data brokers.
Secure Medical does not sell identifiable consumer health information to unrelated third parties for their independent marketing of unrelated products or services.
Information may nevertheless be provided to healthcare providers, pharmacies, laboratories, technology providers, payment processors, communications providers, fulfillment providers, and other organizations when reasonably necessary to provide Services requested by you, administer healthcare, process transactions, maintain security, comply with law, or for another legally permitted purpose.
19. De-Identified and Aggregated Information
Where permitted by law, Secure Medical may create information that has been de-identified or aggregated so that it is not reasonably linkable to a particular individual.
Secure Medical may use de-identified or aggregated information for:
- Analytics;
- Quality improvement;
- Product or technology development;
- Service improvement;
- Security;
- Statistical analysis;
- Healthcare operations where permitted; and
- Other lawful purposes.
When information is maintained as de-identified information under applicable privacy law, Secure Medical will not attempt to re-identify it except where permitted by law, including where necessary to evaluate the effectiveness of de-identification methods.
20. Legal, Regulatory, and Safety Disclosures
Secure Medical may use or disclose information when reasonably necessary to:
- Comply with federal, state, or local law;
- Comply with healthcare licensing requirements;
- Comply with pharmacy requirements;
- Respond to lawful subpoenas, warrants, court orders, or governmental requests;
- Respond to regulatory investigations or audits;
- Investigate or report suspected fraud or unlawful activity;
- Protect patient or public safety;
- Protect the rights, safety, or property of Secure Medical or others;
- Prevent or investigate cybersecurity incidents;
- Investigate unauthorized access or misuse;
- Establish, exercise, or defend legal claims; or
- Comply with other legal obligations.
Where information is protected by HIPAA or another healthcare confidentiality law, Secure Medical will apply any additional requirements applicable to that information.
21. Business Transfers
If Secure Medical is involved in a merger, acquisition, corporate restructuring, financing, sale of assets, bankruptcy, or similar business transaction, information may be transferred or disclosed as part of that transaction as permitted by applicable law.
Any successor organization receiving personal information remains subject to applicable privacy laws and contractual obligations concerning the information.
22. Information Security
Secure Medical maintains administrative, technical, and physical safeguards designed to protect information against unauthorized access, acquisition, disclosure, alteration, destruction, loss, or misuse.
Depending upon the systems and information involved, safeguards may include:
- Encryption during transmission;
- Encryption or other protections for stored sensitive information;
- Access controls;
- Role-based permissions;
- Least-privilege access principles;
- Multi-factor authentication where appropriate;
- Password and authentication protections;
- Network security controls;
- Logging and monitoring;
- Security testing;
- Vulnerability management;
- Backup and recovery procedures;
- Incident-response procedures;
- Workforce privacy and security training;
- Confidentiality requirements;
- Vendor-security requirements; and
- Risk-assessment and risk-management processes.
No method of electronic transmission, storage, or security can guarantee absolute security. Secure Medical therefore evaluates its security measures based upon the sensitivity of the information, identified risks, available technologies, and applicable legal requirements.
23. Data Breaches and Security Incidents
Secure Medical maintains procedures for identifying, investigating, mitigating, and responding to suspected privacy or security incidents.
If an incident involving personal information, PHI, consumer health data, or other protected information requires notification under applicable law, Secure Medical will provide required notifications to affected individuals, healthcare organizations, regulators, government agencies, or other parties within legally required time periods.
24. Data Retention
Secure Medical retains personal information for as long as reasonably necessary to provide requested Services and fulfill the purposes described in this Privacy Policy, or for longer periods where required or permitted by applicable law.
Retention periods may consider:
- Medical-record requirements;
- Prescription and pharmacy requirements;
- HIPAA requirements;
- Business Associate Agreement requirements;
- Telemedicine requirements;
- Financial and accounting requirements;
- Fraud prevention;
- Security requirements;
- Consent and opt-out records;
- Contractual obligations;
- Regulatory requirements;
- Dispute resolution; and
- The establishment or defense of legal claims.
A request to delete information may therefore be subject to exceptions where Secure Medical, a healthcare provider, pharmacy, or another organization is legally required or legally permitted to retain the information.
25. Your Privacy Rights
Depending upon your state of residence, the information involved, and applicable law, you may have rights to:
- Confirm whether Secure Medical processes personal information about you;
- Access certain personal information;
- Request correction of inaccurate personal information;
- Request deletion of certain information;
- Obtain a portable copy of certain information;
- Withdraw certain previously provided consents;
- Opt out of qualifying sales of personal information;
- Opt out of certain targeted advertising;
- Opt out of certain profiling producing legal or similarly significant effects;
- Limit certain uses of sensitive personal information where applicable;
- Request information regarding certain disclosures;
- Use an authorized agent where permitted;
- Appeal certain decisions concerning privacy requests; and
- Exercise applicable privacy rights without unlawful discrimination or retaliation.
Privacy rights are subject to applicable legal limitations, verification requirements, and exemptions.
Different rights may apply to medical records or PHI maintained on behalf of a healthcare provider. Those rights may be described in the healthcare provider's Notice of Privacy Practices.
26. Exercising Your Privacy Rights
Privacy requests may be submitted to:
Secure Medical, Inc. Privacy Office
Email: marketing@securemedical.com
Telephone: 800-550-0793
5801 S. McClintock Drive, Suite 107
Tempe, Arizona 85283
Please identify the nature of your request and provide sufficient information for Secure Medical to reasonably identify the information or account involved.
Secure Medical may verify your identity before fulfilling certain requests. The verification process may vary depending upon the sensitivity of the information and nature of the request.
Secure Medical will not ask you to provide your account password by email as part of the verification process.
If applicable law permits an authorized agent to submit a request on your behalf, Secure Medical may request information reasonably necessary to verify the agent's authority.
27. Privacy Request Appeals
If Secure Medical denies a privacy request and applicable law provides a right to appeal, you may submit an appeal by contacting marketing@securemedical.com.
Please identify the communication as a Privacy Request Appeal and provide sufficient information for Secure Medical to identify the previous request.
Secure Medical will review and respond to eligible appeals within the period required by applicable law.
28. State Privacy Rights
Privacy laws in several U.S. states provide residents with additional rights relating to personal information.
Secure Medical will honor applicable privacy rights to the extent required by law.
State privacy laws may distinguish between ordinary personal information, sensitive information, consumer health data, medical records, and PHI regulated by HIPAA.
Accordingly, the rights available to you and the organization responsible for responding to your request may depend upon the particular information involved.
Secure Medical may provide supplemental state-specific notices when appropriate.
29. New Jersey Residents
New Jersey residents may have additional rights under the New Jersey Data Privacy Act with respect to personal data subject to that law.
Subject to applicable requirements and exceptions, eligible New Jersey consumers may have the right to:
- Confirm whether personal data is being processed;
- Access personal data;
- Correct inaccuracies;
- Delete certain personal data;
- Obtain certain personal data in a portable format;
- Opt out of qualifying targeted advertising;
- Opt out of qualifying sales of personal data;
- Opt out of certain qualifying profiling activities; and
- Appeal certain privacy-request decisions.
Information subject to HIPAA may be treated differently or may qualify for statutory exemptions under applicable state privacy law.
New Jersey patients using telemedicine Services may be required to provide their physical location so that the treating healthcare provider can determine whether the provider is legally authorized to provide healthcare services to a patient located in New Jersey.
Secure Medical may also process information as reasonably necessary to satisfy applicable New Jersey telemedicine, healthcare, professional licensing, recordkeeping, and privacy requirements.
30. California Residents
California residents may have additional rights under the California Consumer Privacy Act, as amended, with respect to personal information subject to that law.
Depending upon applicable requirements, exemptions, and circumstances, California residents may have rights concerning:
- Access to personal information;
- Categories and specific pieces of information collected;
- Correction;
- Deletion;
- Information regarding categories of recipients;
- Sale or sharing of personal information;
- Cross-context behavioral advertising;
- Certain uses of sensitive personal information; and
- Non-discrimination for exercising applicable rights.
PHI, medical information, and other information regulated by certain healthcare privacy laws may be subject to statutory exemptions.
31. Washington and Nevada Consumer Health Data
Washington and Nevada provide additional protections for certain consumer health data that may fall outside HIPAA.
Secure Medical provides a separate Consumer Health Data Privacy Policy where required by law.
Such a policy may describe:
- Categories of consumer health data collected;
- Sources of consumer health data;
- Purposes for collection and use;
- Categories of consumer health data shared;
- Categories of organizations with which consumer health data is shared;
- Applicable consent requirements;
- Consumer health data rights;
- How requests may be submitted;
- How consent may be withdrawn where applicable; and
- Applicable appeal procedures.
32. Universal Opt-Out Preference Signals
Where required by applicable state privacy law and applicable to Secure Medical's processing activities, Secure Medical will recognize legally required universal opt-out preference signals for qualifying targeted advertising, sale, or sharing activities.
Universal opt-out signals generally do not prevent information processing reasonably necessary to provide a healthcare service, transaction, product, account, or other Service requested by you.
33. Children's and Minors' Privacy
Secure Medical's Services are generally intended for adults unless a particular healthcare program expressly permits a parent, legal guardian, or other legally authorized representative to request Services for a minor.
Where Services are available for minors, information will be collected, used, and disclosed in accordance with applicable federal and state laws relating to parental consent, minor consent, confidentiality, medical records, and healthcare decision-making.
A person creating an account or requesting healthcare services on behalf of a minor represents that the person has appropriate legal authority to do so.
Secure Medical does not knowingly use children's personal information for targeted advertising in violation of applicable law.
34. Reproductive, Sexual, Behavioral, Substance-Use, and Other Sensitive Health Information
Secure Medical recognizes that certain categories of healthcare information may receive heightened federal or state confidentiality protections.
Such information may include:
- Reproductive health information;
- Sexual health information;
- Mental or behavioral health information;
- Substance-use-disorder information;
- Genetic information;
- HIV or communicable-disease information; and
- Other specially protected medical information.
Where heightened confidentiality requirements apply, Secure Medical will process and disclose such information in accordance with applicable legal requirements.
Nothing in this Privacy Policy authorizes a use or disclosure prohibited by applicable healthcare confidentiality law.
35. Government and Law-Enforcement Requests
Secure Medical evaluates government, regulatory, and law-enforcement requests for personal information and health information in accordance with applicable law.
Secure Medical does not voluntarily disclose confidential health information merely because it has been requested by law enforcement.
Disclosures are made when permitted or required by applicable law and subject to applicable HIPAA, healthcare privacy, consumer health data, and other confidentiality requirements.
Where legally permitted and appropriate, Secure Medical may seek clarification or narrowing of requests that are overly broad or inconsistent with applicable privacy protections.
36. Links and Third-Party Websites
Secure Medical Services may contain links to websites, applications, resources, or services operated independently by third parties.
Secure Medical is not responsible for the independent privacy practices of third-party websites or services that are not operated by or on behalf of Secure Medical.
Users should review the privacy practices of third-party organizations before providing information directly to those organizations.
37. International Use
Unless expressly stated otherwise for a particular Service, Secure Medical's consumer healthcare and telemedicine Services are primarily intended for individuals located in jurisdictions within the United States where the applicable Service may legally be provided.
Healthcare Services should not be requested from a jurisdiction in which the applicable provider or Service is not authorized to operate.
38. Privacy by Design and Governance
Secure Medical seeks to incorporate privacy and security considerations into the design, development, deployment, and operation of its technology and Services.
Privacy and security practices may include:
- Data minimization;
- Purpose limitation;
- Role-based access;
- Least-privilege access;
- Vendor review;
- Security assessments;
- Privacy assessments;
- Data-protection assessments where required;
- Incident-response planning;
- Workforce education and training;
- Policy review; and
- Periodic review of privacy and security practices.
39. Do Not Track and Browser Controls
Some browsers provide "Do Not Track" settings or similar signals. Because there has historically not been a single universally adopted standard governing all such signals, Secure Medical's response to traditional Do Not Track signals may vary.
Where applicable privacy law requires recognition of a qualifying universal opt-out mechanism, Secure Medical will process the mechanism as required by applicable law.
You may also manage certain cookies through available browser settings or cookie-management tools made available through applicable Secure Medical websites.
40. Your Responsibility to Protect Your Account
You are responsible for maintaining the confidentiality of your account credentials and for taking reasonable steps to protect the privacy of devices and accounts you use to access Secure Medical Services.
You should promptly notify Secure Medical if you believe your account or credentials have been compromised.
Do not send account passwords, Social Security numbers, complete payment-card information, or other highly sensitive information through ordinary email or SMS unless specifically instructed through an appropriate secure process.
41. Changes to This Privacy Policy
Secure Medical may update this Privacy Policy periodically to reflect changes in:
- Our Services;
- Technology;
- Business operations;
- Privacy practices;
- Legal or regulatory requirements; or
- Other relevant circumstances.
The date of the most recent revision will appear at the top of this Privacy Policy.
If a change materially affects the manner in which Secure Medical processes personal information, Secure Medical will provide additional notice or obtain consent where required by applicable law.
Changes to this Privacy Policy will not retroactively authorize Secure Medical to use PHI or other protected information in a manner prohibited by applicable law.
42. Questions, Privacy Requests, and Complaints
If you have questions, concerns, requests, or complaints concerning this Privacy Policy or Secure Medical's privacy practices, please contact:
Secure Medical, Inc.
Attn: Privacy Office
5801 S. McClintock Drive, Suite 107
Tempe, Arizona 85283
Telephone: 800-550-0793
Email: marketing@securemedical.com
If your concern involves PHI or medical records maintained by a healthcare provider or professional medical entity, the applicable Notice of Privacy Practices may provide additional information concerning how to exercise your rights or submit a complaint.
Secure Medical will not unlawfully discriminate or retaliate against you for exercising an applicable privacy right or filing a good-faith privacy complaint.
43. Additional Privacy and Healthcare Notices
Depending upon the Service you use, the information involved, and your state of residence, additional notices or consents may apply, including:
- HIPAA Notice of Privacy Practices;
- Consumer Health Data Privacy Policy;
- Telemedicine Informed Consent;
- State-Specific Telemedicine Notices;
- Cookie and Tracking Technology Notice;
- SMS Terms and Consent;
- Prescription and Pharmacy Notices;
- Healthcare Provider Notices;
- Authorization Forms; and
- Other legally required disclosures or consents.
If there is a conflict between this Privacy Policy and a legally required healthcare privacy notice governing particular protected information, the legally required healthcare privacy notice will control with respect to that information.
44. Contact Secure Medical
Secure Medical, Inc.
5801 S. McClintock Drive, Suite 107
Tempe, Arizona 85283
Telephone: 800-550-0793
Email: marketing@securemedical.com
For SMS assistance, reply HELP to 25283.
To stop applicable Secure Medical marketing SMS messages, reply STOP.