Effective Date: April 12, 2026 · Last Updated: April 12, 2026
TeloLife is fully committed to compliance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and its implementing regulations, including the Privacy Rule (45 CFR Part 164 Subpart E), the Security Rule (45 CFR Part 164 Subparts A and C), and the Breach Notification Rule (45 CFR Part 164 Subpart D). As a HIPAA-covered entity and Business Associate, the protection of your Protected Health Information (PHI) is fundamental to everything we do.
The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is a federal law that establishes national standards to protect sensitive patient health information from being disclosed without the patient's consent or knowledge. HIPAA applies to covered entities — including healthcare providers, health plans, and healthcare clearinghouses — and their business associates.
HIPAA is implemented through three core rules:
TeloLife operates as a HIPAA-covered entity by facilitating the delivery of healthcare services through our telehealth platform. We connect patients with independent, licensed physician groups and licensed compounding pharmacies who provide clinical care and dispense medications.
In this role, TeloLife:
Protected Health Information (PHI) is any individually identifiable health information that is created, received, maintained, or transmitted by TeloLife in connection with the provision of healthcare services. PHI includes information that relates to:
PHI can exist in any form — electronic, paper, or oral — and includes identifiers such as name, date of birth, address, phone number, email address, Social Security number, medical record numbers, health plan information, and any other data that could reasonably identify an individual in connection with their health information.
Electronic PHI (ePHI) refers to PHI created, stored, transmitted, or received in electronic form, which is governed specifically by the HIPAA Security Rule.
HIPAA permits covered entities to use and disclose PHI without patient authorization for Treatment, Payment, and Healthcare Operations (TPO):
All disclosures not covered by the above require your written authorization. You have the right to revoke any authorization at any time in writing. TeloLife will not use or disclose your PHI for marketing purposes or sell your PHI without your explicit written authorization.
TeloLife applies the HIPAA minimum necessary standard to all uses and disclosures of PHI. We limit access to PHI to only the information reasonably necessary to accomplish the intended purpose.
As a TeloLife patient, you have the following rights regarding your Protected Health Information:
Request a copy of your medical records and health information in the format of your choice, including electronic format.
Request corrections to inaccurate or incomplete PHI in your medical records. We will respond within 60 days.
Receive a list of certain disclosures we have made of your PHI for purposes other than treatment, payment, or operations.
Request restrictions on how we use or disclose your PHI. We will consider all requests, though we are not always obligated to agree.
Request that we communicate with you through alternative means or at an alternative location (e.g., a different email address or phone number).
Receive a paper or electronic copy of this HIPAA Compliance Policy and our Notice of Privacy Practices at any time upon request.
To exercise any of these rights, contact our Privacy Officer at privacy@telolife.com. We will respond within 30 days as required by HIPAA regulations.
TeloLife implements the following administrative safeguards to protect PHI in accordance with the HIPAA Security Rule:
TeloLife has designated a Privacy Officer and a Security Officer responsible for the development, implementation, and enforcement of HIPAA policies and procedures.
All TeloLife staff with access to PHI complete mandatory HIPAA training upon hire and annually thereafter. Access to PHI is granted on a strict need-to-know basis using role-based access controls.
We conduct regular risk analyses to identify potential vulnerabilities to ePHI. Identified risks are addressed through documented risk management plans reviewed at least annually.
Comprehensive written HIPAA policies and procedures are maintained, reviewed regularly, and retained for a minimum of six years from the date of creation or last effective date.
TeloLife maintains a documented incident response plan and contingency plan including data backup, disaster recovery, and emergency mode operations to ensure continuity of PHI protection.
Physical access to facilities where ePHI is stored or processed is restricted to authorized personnel only, using appropriate access controls.
All workstations and devices with access to ePHI are subject to use policies, including screen lock requirements, encryption, and remote wipe capabilities for mobile devices.
PHI stored on physical media (hard drives, USB devices, paper records) is disposed of securely using methods that prevent unauthorized access, including certified data destruction for electronic media.
All ePHI transmitted between your browser and our servers is protected using 256-bit TLS/SSL encryption. ePHI stored on our systems is encrypted at rest using AES-256 encryption.
Every system user is assigned a unique identifier. Multi-factor authentication (MFA) is required for access to all systems containing ePHI. Automatic session timeouts are enforced on all patient-facing systems.
Comprehensive audit logs are maintained for all access to, and activity involving, ePHI. Logs are reviewed regularly for unauthorized or unusual access patterns.
Our infrastructure is protected by firewalls, intrusion detection systems, and regular penetration testing. ePHI integrity is protected through mechanisms that detect unauthorized modification or destruction.
HIPAA requires that covered entities enter into written Business Associate Agreements (BAAs) with all third-party vendors and service providers that create, receive, maintain, or transmit PHI on their behalf. TeloLife complies fully with this requirement.
All TeloLife Business Associates are contractually required to:
No vendor or service provider receives access to PHI without a fully executed BAA in place.
TeloLife complies fully with the HIPAA Breach Notification Rule. In the event of a breach of unsecured PHI, TeloLife will:
Individual breach notifications will include: a description of what happened, what types of information were involved, steps individuals should take to protect themselves, what TeloLife is doing to investigate and mitigate the breach, and contact information for our Privacy Officer.
If you believe your PHI may have been improperly accessed or disclosed, please contact our Privacy Officer immediately at privacy@telolife.com.
TeloLife maintains a comprehensive HIPAA workforce training program that includes:
TeloLife maintains records of all training activities as required by HIPAA for a minimum of six years.
If you believe that your HIPAA privacy or security rights have been violated by TeloLife, you have the right to file a complaint. You may do so without fear of retaliation of any kind.
To file a complaint with TeloLife: Contact our Privacy Officer in writing at privacy@telolife.com. We will acknowledge receipt within 5 business days and respond fully within 30 days.
To file a complaint with HHS: You may file a complaint directly with the U.S. Department of Health and Human Services Office for Civil Rights (OCR):
TeloLife will not retaliate against any individual who files a complaint in good faith with TeloLife or HHS OCR.
TeloLife reserves the right to update this HIPAA Compliance Policy at any time to reflect changes in the law, regulations, or our practices. Material changes will be communicated to patients via email and posted on our website with a new effective date. We will always maintain the most current version of this policy on our website. Prior versions are available upon request from our Privacy Officer.
For all HIPAA-related questions, requests, concerns, or complaints, please contact TeloLife's Privacy Officer: