Privacy & security
Draft — pending attorney review

HIPAA Notice of Privacy Practices.

How CounterMend collects, uses, and safeguards the protected health information of members; the limited situations where we may disclose it without your authorisation; and the rights you have over your records. The text on this page is a draft prepared by the Practice; the finalised notice will replace this draft once counsel approves it.

PLACEHOLDER
PLACEHOLDER — pending attorney review.
This Notice of Privacy Practices is a draft prepared by CounterMend. It has not yet been reviewed or finalised by counsel. Don’t rely on it as the binding policy; the finalised notice will be posted here once approved. Until that happens the page exists to give members an honest preview of how their health information is handled.
Questions or complaints
How to contact us about this notice.

Send privacy questions, amendment requests, restriction requests, or complaints to the address below. You can also file a complaint directly with the U.S. Department of Health and Human Services, Office for Civil Rights; we will not retaliate against you for filing one.

Privacy contact
countermend@polsia.app
U.S. Department of Health and Human Services, Office for Civil Rights
File a complaint with HHS OCR

Notice of Privacy Practices — sections

  1. Section 1

    Introduction.

    This Notice of Privacy Practices ("Notice") describes how CounterMend ("we," "us," or "the Practice") may use and disclose your protected health information ("PHI") to carry out treatment, payment, or healthcare operations, and for other purposes as permitted or required by law. It also describes your rights regarding your PHI and how you can exercise those rights.

    We are required to follow the terms of the Notice currently in effect and to give you a copy of this Notice. We’re also required to notify affected individuals following a breach of unsecured PHI.

    This Notice is effective as of [DATE_TO_BE_SET_BY_ATTORNEY]. The current version of the Notice, along with prior versions, will be available on request.

  2. Section 2

    Our duties.

    We are required by law to maintain the privacy of your PHI, give you this Notice of our legal duties and privacy practices, follow the terms of the Notice currently in effect, and notify you if we become aware that your unsecured PHI has been breached.

    We have designated a privacy contact responsible for receiving privacy questions, requests, and complaints. Until a formal Privacy Officer is appointed, the privacy contact for the Practice is reachable at countermend@polsia.app. The privacy contact will respond to enquiries within a reasonable time and will coordinate any required breach notifications, member-facing notifications, and regulator-facing notifications on the Practice’s behalf.

    We will not use or disclose your PHI in a way that materially differs from the terms of this Notice without first revising the Notice and making the revised Notice available to you.

  3. Section 3

    How we collect protected health information.

    We collect PHI only as needed to provide pharmacist-led health coaching to our members. The categories below describe the PHI we collect and the typical source of each category. We don’t collect PHI for marketing, fundraising, or commercial resale, and we don’t buy, sell, or trade member data with third parties.

    • Intake and enrolment information you provide directly: chronic conditions, current medications (prescription, OTC, and supplements), allergies, lifestyle context, and goals. Provided by you on the membership join form or directly to your pharmacist.
    • Visit and consultation content: notes from scheduled coaching visits (video, in-person, or phone), the written care plan issued after each visit, and the asynchronous messages you send through the member messaging channel.
    • Visit recordings when you opt in: video or audio from a coaching session is recorded only with your explicit, recorded opt-in for that specific visit, and the recording is stored with the same protections as the rest of your record.
    • Lab and clinical records you forward: PDFs, photos, or faxes you send to us so your pharmacist can review them during coaching. The originals stay with the originating clinician; we retain only what you forward us.
    • Operational metadata: appointment timestamps, billing records tied to your membership, and the audit trail of who in the Practice accessed your record and when. Operational metadata is required by law and supports our internal accountability.
  4. Section 4

    How we use and disclose protected health information.

    The Practice uses and discloses PHI for treatment, payment, and healthcare operations as described below. We do not use or disclose PHI for marketing, fundraising, or sale of PHI without your separate, written authorisation. We do not participate in research that would require using your PHI without first obtaining your specific authorisation.

    Treatment — coordinating your coaching, sharing relevant information with your other clinicians when you ask us to, generating your written care plan, and managing non-controlled prescriptions within the scope of your pharmacist’s licence.

    Payment — issuing HSA/FSA-eligible invoices for your membership, processing recurring membership billing, and responding to payment questions or disputes from you or your payment provider.

    Healthcare operations — internal quality assurance, peer review among Practice pharmacists, training new pharmacists on care-plan documentation, audit trails of record access, and the legal and accounting operations required to run a cash-pay healthcare practice.

  5. Section 5

    Special situations that require your written authorisation.

    Most disclosures of your PHI require only the permissions described in Section 4. The situations below require your separate, written authorisation before we may use or disclose your PHI for the listed purpose. You may revoke any authorisation in writing at any time, and we will honour the revocation going forward.

    • Marketing communications — we don’t market to members or prospective members today, and we never use PHI to send marketing on behalf of third parties. Any future marketing use of PHI will require your specific written authorisation.
    • Sale of PHI — we will not sell your PHI. Any future sale of PHI would require your specific written authorisation and a clear disclosure of the consideration received.
    • Psychotherapy notes — we are not a behavioural-health practice and don’t maintain psychotherapy notes. If that ever changes, uses and disclosures of psychotherapy notes will require your specific written authorisation except as otherwise permitted by law.
    • Fundraising communications — we don’t fundraise from members or former members. Any future fundraising use of PHI would require your specific written authorisation and an opt-out in every communication.
  6. Section 6

    Disclosures we may make without your authorisation.

    We may use or disclose your PHI without your authorisation when the law requires or permits it in the situations listed below. Each disclosure is limited to the minimum information necessary to accomplish the purpose, and we keep records of these disclosures as required by HIPAA.

    • Public-health authorities — disclosures to a public-health authority authorised by law to collect or receive information for the purpose of preventing or controlling disease, injury, or disability, including reports of births, deaths, adverse events, and product-tracking recalls.
    • U.S. Food and Drug Administration (FDA) — disclosures relating to FDA-regulated products or activities, including adverse-event reporting, product-defect tracking, and post-market surveillance.
    • Law enforcement — disclosures in response to a valid court order, warrant, subpoena, summons, or similar process; to identify or locate a suspect, fugitive, material witness, or missing person; or to report a crime, the location of a crime, the victims of a crime, or the identity, description, or location of the person who committed the crime.
    • Court orders and judicial proceedings — disclosures in the course of a judicial or administrative proceeding in response to an order of a court or administrative tribunal, or in response to a subpoena, discovery request, or other lawful process.
    • Workers’ compensation — disclosures to the extent necessary to comply with state workers’ compensation laws that provide benefits for work-related injuries or illness.
    • Serious threats to health or safety — disclosures to a person reasonably able to prevent or lessen a serious and imminent threat to your health or safety, or to the health and safety of the public or another person.
  7. Section 7

    Your rights as a member.

    You have the rights listed below with respect to your PHI. To exercise any of these rights, contact the privacy contact at countermend@polsia.app. We will respond to your request within the timeframes required by HIPAA and will explain any extension or fee in writing.

    • Right to access and copy — you may request to see and obtain a copy of your PHI that is maintained in a designated record set, including your visit notes, care plan, and the message history tied to your membership. A reasonable, cost-based fee may apply for copies.
    • Right to amend — if you believe your PHI is incorrect or incomplete, you may request that we amend it. We will respond within 60 days; if we deny your request we will explain why in writing and you may submit a written statement of disagreement.
    • Right to an accounting of disclosures — you may request a list of certain disclosures of your PHI that we have made in the prior six years. The list does not include disclosures made for treatment, payment, or healthcare operations, or disclosures made to you or with your authorisation.
    • Right to request restrictions — you may request that we restrict the use or disclosure of your PHI for treatment, payment, or healthcare operations, or disclosures to persons involved in your care. We are not required to agree to a restriction, except when you pay for a service out of pocket in full and ask us not to disclose that information to a health plan.
    • Right to confidential communications — you may request that we contact you at a specific address, telephone number, or email address, or in a specific manner (for example, only by mail). We will accommodate reasonable requests.
    • Right to a copy of this notice — you may request a paper copy of this Notice at any time, even if you previously agreed to receive it electronically.
    • Right to complain — you may complain to the Practice (countermend@polsia.app) or to the U.S. Department of Health and Human Services, Office for Civil Rights, if you believe we have violated your privacy rights. We will not retaliate against you for filing a complaint.
  8. Section 8

    Changes to this notice.

    We reserve the right to change this Notice at any time. Any change will apply to all PHI we already hold, including PHI created or received before the change. When we make a material change we will update the effective date at the top of this Notice, post the revised Notice at /hipaa-notice, and, where required by HIPAA, notify active members through the member messaging channel with a short summary of what changed.

    A copy of the Notice currently in effect is always available at /hipaa-notice and on request from the privacy contact at countermend@polsia.app. Prior versions of the Notice are retained on file and can be produced on request.