THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.
1. Our role under HIPAA
JetPatient, Inc. is a healthcare coordination platform. We are not a covered entity under the federal Health Insurance Portability and Accountability Act of 1996 and its implementing regulations, including the Privacy Rule, Security Rule, and Breach Notification Rule (collectively, “HIPAA”). When we handle Protected Health Information (“PHI”) on behalf of a covered entity — for example, a US-based health plan, employer-sponsored plan, or clinic partner — we act as a Business Associate and enter into a Business Associate Agreement (BAA) with that covered entity.
We use the phrase “HIPAA-aligned” throughout our site to describe this posture: we design, operate, and secure our systems in accordance with the administrative, physical, and technical safeguards that HIPAA requires of business associates, even when a specific engagement does not legally require us to do so.
2. What PHI is
“PHI” means individually identifiable health information created or received by or on behalf of a covered entity, relating to your past, present, or future health, healthcare, or payment for healthcare. Examples include diagnoses, medications, clinical notes, images, lab results, insurance information, and treatment plans.
General contact information you provide to JetPatient (such as your name, email, and interest in a procedure) is not, by itself, PHI when collected directly by JetPatient as a marketplace. It may become PHI when combined with clinical details or when exchanged with a covered entity under a BAA.
3. How we may use & disclose PHI
When we hold PHI as a business associate, we may use or disclose PHI only as permitted by our BAA and HIPAA, including:
- Treatment, payment, and healthcare operations of the covered entity we serve.
- Care coordination — to connect you with partner clinicians, schedule consultations, and manage logistics.
- Service delivery — to operate and secure our platform, including authentication, backup, audit logging, and customer support.
- Required by law — to comply with subpoenas, court orders, or other legal processes.
- Public health & safety — to report information as permitted or required by HIPAA and other applicable law.
- With your authorization — any other use or disclosure requires your written authorization, which you may revoke at any time (except to the extent we have already acted in reliance on it).
4. Uses we will not make
- We will not sell PHI.
- We will not use PHI for marketing without your authorization.
- We will not use PHI to train third-party AI models.
5. Your rights regarding your PHI
Subject to applicable law, and to the policies of the covered entity on whose behalf we hold your PHI, you generally have the right to:
- Access a copy of your PHI in a designated record set.
- Amend PHI you believe is inaccurate or incomplete.
- Request an accounting of certain disclosures we have made.
- Request restrictions on certain uses or disclosures.
- Request confidential communications by alternative means or at alternative locations.
- Receive a paper copy of this Notice on request.
- File a complaint (see Section 8) without fear of retaliation.
Many of these rights are exercised directly with the covered entity that owns the record. We will forward requests to the appropriate covered entity and assist as required by our BAA.
6. Safeguards
We implement reasonable and appropriate administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of PHI, including:
- TLS encryption for data in transit and encryption at rest for stored PHI;
- Role-based access controls and least-privilege access policies;
- Audit logging of access to PHI;
- Vendor risk management, including BAAs with subcontractors that access PHI;
- Workforce training, background checks where appropriate, and sanction policies;
- Incident response and disaster recovery procedures.
7. Breach notification
If an unauthorized use or disclosure of unsecured PHI occurs, we will notify the applicable covered entity without unreasonable delay and in no case later than required by our BAA and HIPAA, so that the covered entity can fulfill its own notification obligations to affected individuals, HHS, and (where applicable) the media.
8. Complaints
If you believe your privacy rights have been violated, you may file a complaint with us at privacy@jetpatient.com or with the covered entity that provided your care. You may also file a complaint with the US Department of Health and Human Services, Office for Civil Rights, at hhs.gov/ocr. We will not retaliate against you for filing a complaint.
9. Changes to this Notice
We may change this Notice at any time. A revised Notice will be posted on this page with a new effective date and will apply to PHI we maintain, including PHI created or received before the effective date.
10. Contact
JetPatient Privacy Officer
Email: privacy@jetpatient.com
Security incidents: security@jetpatient.com
Mailing address available on request.
This HIPAA Notice is provided for informational purposes and does not constitute legal advice. Please consult counsel for advice specific to your situation.