Legal

Privacy Policy

Effective date: June 12, 2026

Translations are provided for convenience. The English version of this document is authoritative.

Simple MD ("Simple MD," "we," "us," or "our") operates a telehealth platform that connects patients with licensed clinicians and supports pharmacies, laboratories, and sponsoring organizations in delivering care. This Privacy Policy explains how we collect, use, disclose, and safeguard information — including Protected Health Information ("PHI") — when you use the Simple MD website, patient portal, clinician workspace, and related services (collectively, the "Services").

Placeholder notice. This document is provided as a starting template and must be reviewed by qualified legal counsel before public reliance. It does not constitute legal advice.

1. Information we collect

1.1 Information you provide

  • Account details: name, email, phone, date of birth, address, government ID where required.
  • Health information you submit through intakes, messages, uploaded photos, or visits.
  • Payment information processed by our payment processor (we do not store full card numbers).
  • Communications with our support, clinical, and operations teams.

1.2 Information from clinicians, pharmacies, labs, and partners

  • Clinical notes, prescriptions, lab orders and results, shipment status, and other care records generated on your behalf.

1.3 Information collected automatically

  • Device, browser, IP address, and usage logs needed to operate and secure the Services.
  • Cookies and similar technologies — see Section 7.

2. How we use information

  • To provide telehealth visits, fulfill prescriptions, schedule appointments, and coordinate care.
  • To verify identity and prevent fraud, abuse, or misuse of the Services.
  • To send service, safety, refill, appointment, and billing communications.
  • To operate, maintain, secure, and improve the platform and to comply with our legal obligations.

3. Protected Health Information (PHI) and HIPAA

When Simple MD acts as a Business Associate to a covered entity, or when we facilitate the creation of clinical records on behalf of treating providers, we handle PHI in accordance with the Health Insurance Portability and Accountability Act ("HIPAA") Privacy and Security Rules and applicable state law. We maintain administrative, physical, and technical safeguards designed to protect PHI, including encryption in transit and at rest, access controls, audit logging, role-based access, and least-privilege provisioning. Workforce members receive HIPAA training and are bound by confidentiality obligations.

4. How we share information

  • Treating clinicians — to evaluate, treat, and follow up on your care.
  • Pharmacies and fulfillment partners — to fill and ship prescribed treatments.
  • Laboratories and diagnostic partners — to order and return results.
  • Sponsoring organizations (B2B accounts) — limited operational and eligibility data only; PHI is shared only as permitted by HIPAA and your authorizations.
  • Service providers — hosting, communications, analytics, and payment processors operating under written agreements (including Business Associate Agreements where applicable).
  • Legal and safety — when required by law, subpoena, or to prevent imminent harm.
  • Business transfers — in connection with a merger, acquisition, or sale of assets, subject to applicable law.

We do not sell PHI. We do not use PHI for advertising.

5. Your choices and rights

Depending on your jurisdiction, you may have rights to access, correct, delete, or obtain a copy of your information; to restrict or object to certain processing; and to withdraw consent. To exercise rights, contact us using the details in Section 10. Patients may also have HIPAA-specific rights described in our Notice of Privacy Practices.

6. Data retention

We retain medical records for the period required by applicable law and professional standards (typically several years after the last interaction, longer for minors). Operational and account records are retained only as long as needed for the purposes described here.

7. Cookies and tracking

We use strictly necessary cookies to operate the Services (authentication, security, session continuity) and limited analytics cookies to understand usage. We do not use third-party advertising cookies. You can manage cookies through your browser settings.

8. Security

We use industry-standard measures, including TLS for data in transit, encryption at rest for sensitive fields, row-level access policies, audit logging, and continuous monitoring. No system is perfectly secure; you are responsible for protecting your account credentials and notifying us of any suspected compromise.

9. Children

The Services are intended for adults and, where supported, minors under the direct supervision of a parent or legal guardian. We do not knowingly collect information from children under 13 without verified parental consent.

10. Contact us

Questions about this Policy or our privacy practices may be directed to our Privacy Office at privacy@simple-md.com.

11. Changes

We may update this Policy from time to time. Material changes will be posted here with a revised effective date.