Health Clinic Able ("we," "us," or "our") is committed to protecting your privacy and your protected health information (PHI). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, use our services, or interact with us in any way. We comply with the Health Insurance Portability and Accountability Act (HIPAA), the California Consumer Privacy Act (CCPA), and all applicable U.S. state and federal privacy laws.
We collect several categories of information to deliver and improve our services:
We use the information we collect to:
We do not sell, rent, or trade your personal information. We disclose PHI only as permitted by HIPAA:
Our website uses essential cookies for login and session management, analytics cookies (Google Analytics 4 with IP anonymization) to understand usage, and optional marketing cookies that you may opt out of via the cookie banner. You can disable non-essential cookies at any time through your browser settings.
We protect your information with enterprise-grade safeguards including AES-256 encryption at rest, TLS 1.3 in transit, multi-factor authentication, SOC 2 Type II certified infrastructure, annual penetration testing, and employee HIPAA training with signed confidentiality agreements. While no system is perfectly secure, we continuously invest in layered defenses to minimize risk.
We retain medical records in accordance with state law (typically 7–10 years after last visit, or until a minor reaches 21). Marketing and newsletter data is retained until you unsubscribe or request deletion. Financial records are kept for 7 years per IRS requirements.
Depending on your state of residence, you may have the right to:
To exercise any right, email privacy@healthclinicable.com.
Our services are intended for individuals 18 and older (or minors with a parent/guardian account holder). We do not knowingly collect information from children under 13 without verifiable parental consent.
Our website may contain links to external sites (e.g., patient portals, lab portals). We are not responsible for their privacy practices and encourage you to review their policies before submitting any information.
All personal and health data is stored and processed within the United States on U.S.-based infrastructure. We do not transfer PHI outside the U.S. without a compliant data-processing agreement.
We may update this Privacy Policy periodically. Material changes will be posted on this page with a revised "Last updated" date. Continued use of our services constitutes acceptance of the updated policy.
For privacy questions, HIPAA complaints, or to exercise your rights:
You can unsubscribe from our newsletter at any time.
Unsubscribe Back to Home