TeloLife Back to TeloLife
HIPAA Compliant
Compliance & Privacy

HIPAA Compliance Policy

Effective Date: April 12, 2026  ·  Last Updated: April 12, 2026

TeloLife is fully committed to compliance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and its implementing regulations, including the Privacy Rule (45 CFR Part 164 Subpart E), the Security Rule (45 CFR Part 164 Subparts A and C), and the Breach Notification Rule (45 CFR Part 164 Subpart D). As a HIPAA-covered entity and Business Associate, the protection of your Protected Health Information (PHI) is fundamental to everything we do.

Table of Contents

  1. What Is HIPAA?
  2. Our Role as a Covered Entity
  3. What Is Protected Health Information (PHI)?
  4. How We Use and Disclose PHI
  5. Your Rights Under HIPAA
  6. Administrative Safeguards
  7. Physical Safeguards
  8. Technical Safeguards
  9. Business Associate Agreements
  10. Breach Notification
  11. Employee Training & Accountability
  12. Complaints & Enforcement
  13. Policy Updates
  14. Contact Our Privacy Officer

1What Is HIPAA?

The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is a federal law that establishes national standards to protect sensitive patient health information from being disclosed without the patient's consent or knowledge. HIPAA applies to covered entities — including healthcare providers, health plans, and healthcare clearinghouses — and their business associates.

HIPAA is implemented through three core rules:

  • The Privacy Rule — Establishes standards for the use and disclosure of Protected Health Information and gives patients rights over their health information.
  • The Security Rule — Sets standards for safeguarding electronic Protected Health Information (ePHI) through administrative, physical, and technical controls.
  • The Breach Notification Rule — Requires covered entities to notify affected individuals, HHS, and in some cases the media, following a breach of unsecured PHI.

2Our Role as a Covered Entity

TeloLife operates as a HIPAA-covered entity by facilitating the delivery of healthcare services through our telehealth platform. We connect patients with independent, licensed physician groups and licensed compounding pharmacies who provide clinical care and dispense medications.

In this role, TeloLife:

  • Maintains and transmits Protected Health Information in electronic form (ePHI)
  • Operates as a Business Associate to our licensed physician group partners where applicable
  • Requires all vendors and service providers with access to PHI to execute Business Associate Agreements (BAAs)
  • Designates a Privacy Officer responsible for the development and implementation of HIPAA-compliant policies and procedures
  • Conducts regular risk assessments and audits to ensure ongoing compliance

3What Is Protected Health Information (PHI)?

Protected Health Information (PHI) is any individually identifiable health information that is created, received, maintained, or transmitted by TeloLife in connection with the provision of healthcare services. PHI includes information that relates to:

  • An individual's past, present, or future physical or mental health condition
  • The provision of healthcare to an individual
  • Past, present, or future payment for healthcare services

PHI can exist in any form — electronic, paper, or oral — and includes identifiers such as name, date of birth, address, phone number, email address, Social Security number, medical record numbers, health plan information, and any other data that could reasonably identify an individual in connection with their health information.

Electronic PHI (ePHI) refers to PHI created, stored, transmitted, or received in electronic form, which is governed specifically by the HIPAA Security Rule.

4How We Use and Disclose PHI

Permitted Uses Without Authorization (TPO)

HIPAA permits covered entities to use and disclose PHI without patient authorization for Treatment, Payment, and Healthcare Operations (TPO):

  • Treatment: Sharing PHI with licensed clinicians, pharmacists, care coordinators, and other members of your care team to provide and coordinate your healthcare.
  • Payment: Processing payment transactions, verifying insurance or HSA/FSA eligibility, and submitting billing information as required.
  • Healthcare Operations: Quality assurance, training, compliance activities, and operational management of our telehealth platform using de-identified or appropriately protected data.

Other Permitted Disclosures

  • As required by federal, state, or local law
  • To public health authorities for disease prevention or control
  • To law enforcement as required or permitted by law
  • To avert a serious and imminent threat to health or safety
  • For research, with appropriate authorizations and safeguards

Disclosures Requiring Your Authorization

All disclosures not covered by the above require your written authorization. You have the right to revoke any authorization at any time in writing. TeloLife will not use or disclose your PHI for marketing purposes or sell your PHI without your explicit written authorization.

Minimum Necessary Standard

TeloLife applies the HIPAA minimum necessary standard to all uses and disclosures of PHI. We limit access to PHI to only the information reasonably necessary to accomplish the intended purpose.

5Your Rights Under HIPAA

As a TeloLife patient, you have the following rights regarding your Protected Health Information:

Right to Access

Request a copy of your medical records and health information in the format of your choice, including electronic format.

Right to Amend

Request corrections to inaccurate or incomplete PHI in your medical records. We will respond within 60 days.

Right to an Accounting

Receive a list of certain disclosures we have made of your PHI for purposes other than treatment, payment, or operations.

Right to Restrict

Request restrictions on how we use or disclose your PHI. We will consider all requests, though we are not always obligated to agree.

Right to Confidential Communications

Request that we communicate with you through alternative means or at an alternative location (e.g., a different email address or phone number).

Right to a Copy of This Notice

Receive a paper or electronic copy of this HIPAA Compliance Policy and our Notice of Privacy Practices at any time upon request.

To exercise any of these rights, contact our Privacy Officer at privacy@telolife.com. We will respond within 30 days as required by HIPAA regulations.

6Administrative Safeguards

TeloLife implements the following administrative safeguards to protect PHI in accordance with the HIPAA Security Rule:

Designated Privacy & Security Officers

TeloLife has designated a Privacy Officer and a Security Officer responsible for the development, implementation, and enforcement of HIPAA policies and procedures.

Workforce Training & Access Management

All TeloLife staff with access to PHI complete mandatory HIPAA training upon hire and annually thereafter. Access to PHI is granted on a strict need-to-know basis using role-based access controls.

Risk Analysis & Management

We conduct regular risk analyses to identify potential vulnerabilities to ePHI. Identified risks are addressed through documented risk management plans reviewed at least annually.

Policies, Procedures & Documentation

Comprehensive written HIPAA policies and procedures are maintained, reviewed regularly, and retained for a minimum of six years from the date of creation or last effective date.

Incident Response & Contingency Planning

TeloLife maintains a documented incident response plan and contingency plan including data backup, disaster recovery, and emergency mode operations to ensure continuity of PHI protection.

7Physical Safeguards

Facility Access Controls

Physical access to facilities where ePHI is stored or processed is restricted to authorized personnel only, using appropriate access controls.

Workstation & Device Controls

All workstations and devices with access to ePHI are subject to use policies, including screen lock requirements, encryption, and remote wipe capabilities for mobile devices.

Media Controls & Disposal

PHI stored on physical media (hard drives, USB devices, paper records) is disposed of securely using methods that prevent unauthorized access, including certified data destruction for electronic media.

8Technical Safeguards

Encryption In Transit & At Rest

All ePHI transmitted between your browser and our servers is protected using 256-bit TLS/SSL encryption. ePHI stored on our systems is encrypted at rest using AES-256 encryption.

Unique User Identification & Authentication

Every system user is assigned a unique identifier. Multi-factor authentication (MFA) is required for access to all systems containing ePHI. Automatic session timeouts are enforced on all patient-facing systems.

Audit Controls & Activity Logging

Comprehensive audit logs are maintained for all access to, and activity involving, ePHI. Logs are reviewed regularly for unauthorized or unusual access patterns.

Network Security & Integrity Controls

Our infrastructure is protected by firewalls, intrusion detection systems, and regular penetration testing. ePHI integrity is protected through mechanisms that detect unauthorized modification or destruction.

9Business Associate Agreements

HIPAA requires that covered entities enter into written Business Associate Agreements (BAAs) with all third-party vendors and service providers that create, receive, maintain, or transmit PHI on their behalf. TeloLife complies fully with this requirement.

All TeloLife Business Associates are contractually required to:

  • Use and disclose PHI only as permitted by the BAA and HIPAA
  • Implement appropriate administrative, physical, and technical safeguards to protect ePHI
  • Report any security incident or breach involving PHI to TeloLife without unreasonable delay
  • Make their HIPAA compliance practices available to the Secretary of HHS upon request
  • Return or destroy all PHI upon termination of the business relationship

No vendor or service provider receives access to PHI without a fully executed BAA in place.

10Breach Notification

TeloLife complies fully with the HIPAA Breach Notification Rule. In the event of a breach of unsecured PHI, TeloLife will:

  • Notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery of the breach, by first-class mail or email (if the individual has agreed to electronic notice).
  • Notify the U.S. Department of Health and Human Services (HHS) via the HHS online portal. For breaches affecting 500 or more individuals in a state or jurisdiction, we will also notify prominent media outlets in that area.
  • Notify the Secretary of HHS annually for breaches affecting fewer than 500 individuals.

Individual breach notifications will include: a description of what happened, what types of information were involved, steps individuals should take to protect themselves, what TeloLife is doing to investigate and mitigate the breach, and contact information for our Privacy Officer.

If you believe your PHI may have been improperly accessed or disclosed, please contact our Privacy Officer immediately at privacy@telolife.com.

11Employee Training & Accountability

TeloLife maintains a comprehensive HIPAA workforce training program that includes:

  • Mandatory HIPAA Privacy and Security training for all employees and contractors upon hire
  • Annual refresher training and policy updates for all workforce members
  • Role-specific training for personnel with elevated PHI access
  • Documented sanctions for workforce members who violate HIPAA policies, up to and including termination and referral for civil or criminal prosecution
  • Confidentiality agreements signed by all workforce members with PHI access

TeloLife maintains records of all training activities as required by HIPAA for a minimum of six years.

12Complaints & Enforcement

If you believe that your HIPAA privacy or security rights have been violated by TeloLife, you have the right to file a complaint. You may do so without fear of retaliation of any kind.

To file a complaint with TeloLife: Contact our Privacy Officer in writing at privacy@telolife.com. We will acknowledge receipt within 5 business days and respond fully within 30 days.

To file a complaint with HHS: You may file a complaint directly with the U.S. Department of Health and Human Services Office for Civil Rights (OCR):

  • Online: www.hhs.gov/ocr/complaints
  • Phone: 1-800-368-1019 (TDD: 1-800-537-7697)
  • Mail: 200 Independence Avenue, S.W., Washington, D.C. 20201

TeloLife will not retaliate against any individual who files a complaint in good faith with TeloLife or HHS OCR.

13Policy Updates

TeloLife reserves the right to update this HIPAA Compliance Policy at any time to reflect changes in the law, regulations, or our practices. Material changes will be communicated to patients via email and posted on our website with a new effective date. We will always maintain the most current version of this policy on our website. Prior versions are available upon request from our Privacy Officer.

14Contact Our Privacy Officer

For all HIPAA-related questions, requests, concerns, or complaints, please contact TeloLife's Privacy Officer:

TeloLife Privacy Officer

privacy@telolife.com
TeloLife, Inc.  ·  United States

© 2026 TeloLife. All Rights Reserved.  ·  Privacy Policy  ·  California Privacy Notice  ·  Terms of Service  ·  Medical Disclaimer  ·  HIPAA Policy  ·  Cancellation & Refund Policy  ·  Return to Site