← Back to Login

Privacy Policy & HIPAA Notice

Last updated: March 27, 2026

Health Agent ("we," "our," "the Service") is committed to protecting your privacy and complying with the Health Insurance Portability and Accountability Act (HIPAA). This policy explains how we collect, use, protect, and share your information.

1. Information We Collect

Account Information

Patient Health Information (PHI)

Usage Data

2. How We Use Your Information

HIPAA Notice of Privacy Practices

This notice describes how medical information about you may be used and disclosed and how you can get access to this information.

PHI De-identification

When your messages are processed by our AI system, all 18 HIPAA Safe Harbor identifiers are removed before data leaves our servers. The AI service receives only de-identified clinical information (symptoms, medications, conditions). Your identity is never exposed to third-party AI processors.

Permitted Uses of PHI

Your Rights Under HIPAA

To exercise any of these rights, contact us at privacy@healthagent.app

3. How We Protect Your Data

SafeguardImplementation
Encryption in TransitTLS 1.3 on all connections
Encryption at RestAES-256 encryption for stored health data
PHI De-identificationHIPAA Safe Harbor method before AI processing
Access ControlsAuthentication required, session management
Audit LoggingAll PHI access logged with timestamps, user IDs, IP addresses
Breach DetectionAutomated monitoring for unusual access patterns
Consent TrackingDocumented patient authorization for data access
Cloud InfrastructureGoogle Cloud with signed HIPAA Business Associate Agreement

4. Third-Party Data Processors

ServicePurposePHI Exposure
Google CloudHosting, storageEncrypted at rest (BAA signed)
Anthropic (Claude AI)AI processingDe-identified only — no PHI transmitted
Google CalendarAppointment schedulingAppointment titles/dates only (with user consent)
ResendEmail deliveryRecipient email addresses only
VAPIPhone call facilitationPhone numbers and call context

5. Data Retention

6. Data Sharing

We never sell your personal or health information. We share data only:

7. Children's Privacy

Health Agent is not intended for use by individuals under 18. Caregivers may add minor patients under their legal care.

8. California Residents (CCPA)

California residents have additional rights including the right to know what data is collected, the right to delete, and the right to opt out of data sales. We do not sell personal information.

9. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email. Continued use after changes constitutes acceptance.

10. Contact Us

For privacy questions, HIPAA requests, or to exercise your data rights: