Consumer Health Data Privacy Policy

Effective Date: 09/04/2025

Paloma Health values your privacy and is committed to safeguarding your consumer health data. This Consumer Health Data Privacy Policy (“Policy”) explains how we collect, use, share, and protect your consumer health data, and the rights you may have under applicable laws such as the Washington My Health My Data Act, California Consumer Privacy Act (CCPA/CPRA), and similar state laws.

This Policy applies where required by law and supplements our HIPAA Notice of Privacy Practices. When we act as a healthcare provider and collect or use your protected health information (PHI), that information is governed by HIPAA and our HIPAA Notice, not this Policy.

1. Categories of Consumer Health Data We Collect

Depending on how you interact with us, we may collect:

  • Identifiers & contact information: name, address, email, phone, date of birth.
  • Medical information: lab results (e.g., thyroid panels, hormone levels), diagnoses, medications, treatment history, and symptoms.
  • Biometric & reproductive data: height, weight, BMI, menstrual cycle, menopause status, fertility and hormonal data.
  • Insurance & payment information: insurance coverage, claims, billing details.
  • Technical data: IP address, device identifiers, cookies, usage and browsing activity on our website/app related to health services.
  • Inferred or derived data: information we generate through analytics, such as engagement levels or patterns in lab results.

2. Sources of Consumer Health Data

We collect consumer health data from multiple sources:

  • Directly from you: when you create an account, schedule a visit, complete questionnaires, upload labs, or communicate with us.
  • Automatically collected: through your use of our website or app (cookies, device information, IP address).
  • Inferred or generated: by analyzing your inputs, lab results, or usage patterns.
  • Third parties: such as labs, pharmacies, insurers, or service providers.

3. Purposes for Collecting and Using Consumer Health Data

We use your data for purposes including:

  • Providing and coordinating healthcare services and at-home testing.
  • Reviewing and interpreting lab results.
  • Ordering medications and coordinating care with pharmacies.
  • Processing insurance claims and payments.
  • Delivering secure account access and communication.
  • Improving services, conducting analytics, and performing quality assurance.
  • Marketing, personalization, and educational outreach (with your consent where required).
  • Compliance with laws, regulations, and contractual obligations.

4. Sharing of Consumer Health Data

We may share consumer health data with:

  • Healthcare providers: Paloma clinicians, affiliated practitioners.
  • Labs & pharmacies: to process orders and dispense medication.
  • Insurance companies: to verify eligibility and process claims.
  • Vendors & service providers: cloud hosting, analytics, secure messaging, and customer support (under contracts with confidentiality obligations).
  • Regulators & legal authorities: where required by law.

We may also use or share de-identified or aggregated data (which cannot reasonably be linked back to you) for analytics, research, or service improvement.

We do not sell consumer health data without your consent.

5. Retention of Consumer Health Data

We keep consumer health data for as long as necessary to provide services, comply with law, resolve disputes, and meet medical recordkeeping requirements. Retention periods may vary based on state law.

6. Your Rights

Depending on your state of residence, you may have the right to:

  • Access the health data we hold about you.
  • Correct inaccuracies.
  • Delete consumer health data, subject to medical/legal recordkeeping obligations.
  • Withdraw consent for certain uses.
  • Portability: request a copy in a usable format.
  • Appeal a denied request.

You can exercise your rights by contacting us at: privacy@palomahealth.com.

7. Data Security

We use administrative, technical, and physical safeguards to protect consumer health data, including encryption and access controls. While we work to secure your data, no system is 100% secure.

8. Changes to This Policy

We may update this Policy to reflect changes in practices or laws. Updated versions will be posted with a revised effective date.

9. Contact Us

If you have questions about this Policy or your consumer health data, contact us at:

Paloma Health

Email: privacy@palomahealth.com

Mail: [Insert address]