Privacy Policy
Effective Date: 12/15/2025
At WhisprHealth ("we," "us," or "our"), your privacy is our priority. This Privacy Policy explains how we collect, use, and share information when you use our website and telehealth services.
Protected Health Information (PHI) & HIPAA
Because we facilitate medical care, much of the data we collect is "Protected Health Information" (PHI) governed by the Health Insurance Portability and Accountability Act (HIPAA).
This Privacy Policy generally describes our data practices. However, specific medical data is governed by our Notice of Privacy Practices (NPP). If there is a conflict between this Policy and the NPP regarding PHI, the NPP prevails.
1. Information We Collect
A. Information You Provide
- Account Information: Name, email address, phone number, shipping address, and password.
- Health Information: Medical history, symptoms, images (e.g., ID or condition photos), and communications with Providers.
- Payment Information: We utilize third-party payment processors (e.g., Stripe) to handle payment data. We do not store full credit card numbers.
B. Automatically Collected Information
We may use cookies, pixels, and standard server logs to collect IP addresses, browser types, device information, and site usage data.
2. How We Use Your Information
We use your information for the following business purposes:
- Treatment: Facilitating telehealth consultations with Providers and processing pharmacy orders.
- Payment: Processing subscription billing and insurance claims (if applicable).
- Platform Operations: Improving our website, debugging technical issues, and preventing fraud.
- Communication: Sending you order confirmations, appointment reminders, and health-related updates.
3. How We Share Your Information
We do not sell your Personal Information or PHI to third parties.
- Healthcare Providers: We share your data with the licensed medical group to provide your treatment.
- Pharmacies: We share prescription info to fulfill your orders.
- Service Providers: We use vendors for hosting (e.g., AWS), customer support, and marketing. These vendors are bound by Business Associate Agreements (BAAs) where required by HIPAA.
- Legal Requirements: We may disclose info if required by law (e.g., a subpoena) or to protect the safety of users.
4. State Privacy Rights (California & Others)
Residents of certain states (including California, Virginia, Colorado) may have additional rights regarding their personal data, such as:
- The right to know what personal information we collect.
- The right to delete personal information (subject to medical record retention laws).
- The right to correct inaccurate information.
Note that HIPAA-protected health information is often exempt from state consumer privacy requests (like CCPA) because it is already regulated by federal law.
5. Data Security
We implement administrative, physical, and technical safeguards to protect your information, including encryption of data in transit and at rest. However, no internet transmission is completely secure.
6. Children's Privacy
Our Platform is not intended for individuals under the age of 18. We do not knowingly collect personal information from children.
7. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through a prominent notice on our website.
8. Contact Us
If you have questions about this Privacy Policy or your medical records, please contact our Privacy Officer:
WhisprHealth Privacy Team
Email: privacy@whisprhealth.com
Address: 725 5th Avenue, New York, NY, 10022