Loading

 

https://catherineyudnp.com/wp-content/uploads/2018/09/portfolio_03-e1760132146947.jpg

HIPAA-Compliant Privacy Policy for Telehealth Platform

Effective Date: 08/07/2024
Last Updated: 10/10/2025

1. Introduction

Welcome to Catherine Yu DNP, LLC (“we,” “us,” or “our”). We provide telehealth and virtual care services through our website and mobile applications (collectively, the “Platform”).

We are committed to protecting your privacy and the confidentiality of your health information in accordance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the Health Information Technology for Economic and Clinical Health Act (HITECH), and all applicable state and federal privacy laws.

This Privacy Policy explains how we collect, use, share, and protect your information when you use our telehealth services.

2. Information We Collect

We collect information necessary to provide safe and effective telehealth services, including Protected Health Information (PHI), Personal Information, and Technical Information.
   
A. Protected Health Information (PHI)
– Medical records, diagnoses, treatment plans, prescriptions, and clinical notes
– Photos, images, or documents uploaded for consultation
– Information you provide during virtual visits, chats, or video sessions

B. Personal Information
– Name, date of birth, contact details, address
– Login credentials and profile information
– Payment and billing information

C. Technical Information
– IP address, browser type, operating system
– Device identifiers and usage analytics
– Session logs for telehealth calls (excluding audio/video content)

3. How We Use Your Information

We use your information only as permitted by HIPAA and applicable law, including to:
– Provide and coordinate telehealth services and care
– Schedule and conduct video consultations
– Verify your identity and manage your account
– Process billing and insurance claims
– Communicate with you regarding appointments, follow-ups, or support
– Improve security, usability, and performance of our Platform
– Comply with legal, regulatory, and reporting obligations

We do not sell, rent, or market your health information to third parties.

4. How We Share Your Information

We may share your PHI only as allowed under HIPAA, including:
– With your healthcare providers for treatment and care coordination
– With your consent when you authorize release of information
– For payment and healthcare operations
– With Business Associates under HIPAA-compliant agreements
– As required by law

5. Video and Communication Privacy

All video, audio, and chat communications conducted through our Platform are encrypted end-to-end using HIPAA-compliant technology.
We do not record or store telehealth sessions unless you have provided explicit written consent.

6. Data Security

We maintain strong administrative, physical, and technical safeguards to protect your PHI, including encryption, secure storage, multi-factor authentication, and regular security audits.

7. Your Rights Under HIPAA

You have the right to:
– Access and request a copy of your health information
– Request corrections to your records
– Request restrictions on certain uses or disclosures
– Receive an accounting of disclosures
– Request confidential communications by alternative means or addresses
– File a complaint without retaliation

8. Data Retention and Deletion

We retain your PHI as long as required by federal and state medical record retention laws or as necessary to provide care. When no longer needed, data is securely deleted or de-identified.

9. Cookies and Tracking Technologies

Our website and mobile app may use limited cookies or analytics tools to improve performance and user experience. These do not access or store PHI.

10. Contact Us

If you have questions, requests, or complaints regarding your privacy, please contact:

Catherine Yu DNP, LLC
Privacy Officer: Catherine Yu
Email: help@catherineyu.com
Phone: 978-709-2373
Mailing Address: 4411 Bee Ridge Rd, suite 591, Sarasota, FL 34233

You may also file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights (OCR) at:
https://www.hhs.gov/ocr/privacy/hipaa/complaints/

11. Changes to This Policy

We may update this Privacy Policy periodically. Updates will be posted on our website and app with the “Last Updated” date. Continued use of the Platform after updates constitutes acceptance of the revised policy.

 

Top