Profile Health, Inc.
Effective Date: November 10, 2025
1. Who we are
This Privacy Policy explains how Profile Health, Inc. (“Profile,” “we,” “us,” or “our”) collects, uses, discloses, and protects information in connection with:
- our website
- our software platform
- patient intake flows
- any data shared with us by clinics, healthcare providers, or via HIE networks
We are a Delaware C-Corp registered in California.
We are a Business Associate to our clinic customers.
2. Who this Policy applies to
This Policy applies to:
- Clinics / Covered Entities
- Patients whose data is processed by our platform
- Website visitors
Clinics remain responsible for obtaining patient consent as required by law.
3. The types of data we collect
We may collect personal information, including Protected Health Information (PHI), such as:
- name, contact information, demographics
- genomics / DNA data
- blood biomarkers
- specialty lab results
- medication + supplement history
- Carequality / HIE data imports
- symptoms, health history, past medical notes
- appointment + intake information
- communications and form submissions
We also collect non-PHI technical information such as:
- browser type, device, IP
- usage logs
- pages visited
4. How we use information
We use the information we collect to:
- provide and improve our Services
- support care coordination for clinics
- enable intake, triage, chart review, and decision support workflows
- send notifications and reminders (including SMS and email)
- respond to support requests
- maintain platform security and integrity
- comply with legal obligations
We do not sell PHI.
We do not use PHI for advertising.
5. SMS / texting
By providing a mobile number, you consent that:
- we may send automated SMS related to intake, scheduling, or account use
- message frequency may vary
- standard carrier rates may apply
6. HIPAA + Business Associate role
We acknowledge that we process PHI on behalf of Covered Entities.
Our permitted uses and disclosures of PHI are governed by our Business Associate Agreement (BAA) with each clinic.
If these terms conflict with a BAA, the BAA controls.
7. How we share information
We may share information with:
- clinics and healthcare providers who manage the patient relationship
- vendors or subprocessors who support our infrastructure (e.g., secure hosting, SSO, communications, analytics)
Vendors are only permitted to use PHI to support our services on our behalf, not for their own purposes.
We may also disclose information when required by law (e.g., court order).
8. Data retention
We retain information as long as necessary to:
- provide the Services
- comply with legal / regulatory requirements
- fulfill BAAs
Clinics may request deletion or export consistent with their legal rights.
9. Data security
We maintain administrative, technical, and physical safeguards designed to protect information.
However, no system is completely secure.
We cannot guarantee absolute security of information transmitted to or from us.
10. Your rights
If you are a patient, your rights regarding your PHI (including access, amendment, and restrictions) are governed primarily by your healthcare provider's policies.
Requests must generally go through the clinic.
11. Children's privacy
We do not knowingly collect information from children under 13 unless authorized by a clinic under applicable law.
12. Changes to this Policy
We may update this Privacy Policy.
When we do, we will revise the “Effective Date” at the top.
13. Contact
Questions about this Policy may be sent to: