Compliance

HIPAA Notice of Privacy Practices

Effective Date: June 2026

THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.

PeptideMD is committed to protecting the privacy and security of your Protected Health Information (PHI) in compliance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA), as amended by the Health Information Technology for Economic and Clinical Health (HITECH) Act, and their implementing regulations.

1. Our Responsibilities

We are required by law to:

  • Maintain the privacy and security of your PHI.
  • Provide you with this Notice of our legal duties and privacy practices.
  • Notify you following a breach of unsecured PHI.
  • Abide by the terms of this Notice currently in effect.

2. How We May Use and Disclose Your PHI

We may use and disclose your PHI for the following purposes without your written authorization:

Treatment

We may use and disclose PHI to provide, coordinate, and manage your healthcare and related services. This includes sharing information with the licensed healthcare provider conducting your telehealth consultation and the 503A pharmacy that compounds and dispenses your medications.

Payment

We may use and disclose PHI to obtain payment for services rendered, including billing and collection activities. As a cash-pay platform, we do not submit claims to insurance; however, we may use PHI to process your payments through our secure payment processors.

Healthcare Operations

We may use and disclose PHI for operational activities including quality assessment, provider credentialing, customer service, compliance auditing, and platform improvement. Business associates who perform these functions on our behalf sign HIPAA Business Associate Agreements.

Required by Law

We may disclose PHI when required by federal, state, or local law — including reporting to public health authorities, law enforcement, or in response to valid judicial or administrative orders.

3. Uses Requiring Authorization

The following uses and disclosures require your written authorization:

  • Marketing communications involving compensation from third parties.
  • Sale of PHI (we do not sell PHI).
  • Most uses of psychotherapy notes (not applicable to our services).

4. Your HIPAA Rights

You have the following rights regarding your PHI:

Right to Access

You may inspect and obtain a copy of your PHI maintained in our designated record set. Requests must be in writing. We may charge a reasonable, cost-based fee for copies.

Right to Amend

You may request that we amend your PHI if you believe it is incorrect or incomplete. Requests must be in writing with a reason for the amendment. We may deny the request in certain circumstances.

Right to an Accounting of Disclosures

You may request a list of certain disclosures of your PHI we have made for purposes other than treatment, payment, or healthcare operations. The accounting covers six years prior to the request date.

Right to Request Restrictions

You may request restrictions on how we use or disclose your PHI for treatment, payment, or healthcare operations. We are not required to agree to all restrictions, but we must honor requests to restrict disclosures to health plans when you have paid out-of-pocket in full.

Right to Confidential Communications

You may request that we communicate with you through alternative means or at alternative locations. Reasonable requests will be accommodated.

Right to a Paper Copy

You may request a paper copy of this Notice at any time, even if you have agreed to receive it electronically.

5. Security Safeguards

We maintain administrative, physical, and technical safeguards to protect your PHI, including:

  • Encryption of PHI in transit (TLS 1.3) and at rest (AES-256).
  • Multi-factor authentication for systems containing PHI.
  • Role-based access controls limiting PHI access to authorized personnel.
  • Regular security risk assessments and workforce training.
  • Business Associate Agreements with all vendors handling PHI.

6. Breach Notification

In the event of a breach of unsecured PHI, we will notify affected individuals within 60 days of discovery, as required by HIPAA. Notifications will include a description of the breach, the types of information involved, steps we are taking to mitigate harm, and protective actions you can take.

7. Complaints

If you believe your privacy rights have been violated, you may file a complaint with us or with the Secretary of the U.S. Department of Health and Human Services. We will not retaliate against you for filing a complaint.

To file a complaint with us, contact our Privacy Officer at privacy@peptidemd.bio or call (888) 555-0123.

8. Changes to This Notice

We reserve the right to change the terms of this Notice at any time. Changes will apply to all PHI we maintain, including information created or received before the change. The revised Notice will be posted on our website and available upon request.

9. Contact Information

Privacy Officer:

PeptideMD

Email: privacy@peptidemd.bio

Phone: (888) 555-0123