Legal · Privacy
Privacy Policy
How MyOrbit Health, Inc. collects, uses, stores, discloses, and protects information — including Protected Health Information — across this website and the MyOrbitHealth platform.
Last updated · August 13, 2026
The short version
We are infrastructure. When you receive care through a clinic built on MyOrbitHealth, that clinic — an independently owned professional entity — is the Covered Entity that controls your medical record, and we act as its Business Associate under HIPAA. On this marketing website, we are the business responsible for the information you give us.
We do not sell personal information. We do not share it for cross-context behavioral advertising. We do not put advertising pixels on health-related or logged-in pages. Until you allow analytics, our measurement runs in cookieless consent mode, storing no identifiers on your device, and we honor Global Privacy Control automatically.
01
Who this policy covers and who it does not
This policy applies to information we handle as a business in our own right: visitors to myorbithealth.com, prospective and current partner organizations, applicants, and contacts of our customers.
Information handled on behalf of a clinic
When we process Protected Health Information inside a partner clinic's instance, we do so only as directed by that clinic under a Business Associate Agreement and our Data Processing Addendum. That clinic's Notice of Privacy Practices — not this policy — governs how your medical information may be used and disclosed for treatment, payment, and healthcare operations. Requests to amend or obtain a copy of a medical record must go to the treating entity; if you send one to us, we will route it to them and tell you we have done so.
Not for children
The website and our services are not directed to children under 13, and we do not knowingly collect their personal information for our own purposes. Pediatric care delivered by a partner clinic is handled by that clinic through a parent or guardian.
02
Information we collect
| Category | Examples | Source | Why we collect it |
|---|---|---|---|
| Identifiers | Name, business email, phone number, company, IP address, device and browser identifiers | You; your device | Respond to inquiries, provision accounts, secure the service |
| Commercial information | Services considered or purchased, plan tier, invoices, transaction history | You; our billing processor | Perform the contract, billing, accounting |
| Professional or employment information | Role, license type and state, NPI, practice affiliation, applicant materials | You; verification sources | Credentialing support, provider onboarding, hiring |
| Internet and network activity | Pages viewed, referring URL, aggregate interaction events, error diagnostics | Your device (consent-gated for analytics) | Site reliability, security, product improvement |
| Audio and visual | Recorded sales or support calls where you are notified and consent | You | Quality assurance and training |
| Sensitive personal information | Health-related information, precise treatment interest, government identifiers where required for credentialing | You; the partner clinic | Deliver the requested service; not used to infer characteristics about you |
| Inferences | Aggregate product interest signals at the organization level | Derived | Prioritize product and documentation work |
We do not collect biometric identifiers, we do not use facial recognition, and we do not purchase personal information from data brokers.
Business credit and application screening
When an organization applies to become a partner, we collect business application information — including entity details, licensure, ownership, and, where relevant to credit terms, a business creditworthiness check on the entity rather than a consumer credit report on you personally. Scheduling and application intake is handled through our scheduling vendor. We do not obtain consumer credit reports on patients, and we do not use consumer credit information to determine eligibility for care.
03
How we use information
- Provide, secure, operate, and support the platform and this website.
- Respond to inquiries, schedule calls, and evaluate partner applications.
- Process payments and maintain financial and tax records.
- Detect, investigate, and prevent fraud, abuse, and security incidents.
- Comply with legal obligations, including HIPAA, state telehealth law, and pharmacy and prescribing rules.
- Measure and improve the site and product where you have allowed analytics.
- Send service and security notices; send marketing only where permitted, with an unsubscribe in every marketing email.
We do not use Protected Health Information for our own marketing, we do not use it to train general-purpose models, and we do not monetize it. Aggregated or de-identified data may be used to improve reliability and to publish statistics that cannot reasonably be re-identified.
04
How and when we disclose information
- Service providers and subprocessors under written terms limiting them to our instructions — see our published subprocessor list.
- Partner clinics and their providers, where necessary to deliver care you requested.
- Pharmacies, laboratories, and e-prescribing networks, where a clinician directs a prescription or order.
- Payment processors, for billing partner organizations.
- Professional advisors, auditors, and insurers under confidentiality obligations.
- Government or law enforcement, where legally compelled — we assess each request, seek to narrow overbroad demands, and notify the affected customer unless prohibited by law.
- An acquirer, in connection with a merger, financing, or sale of assets, subject to this policy or a successor policy with materially equivalent protections.
We have not sold personal information or shared it for cross-context behavioral advertising in the preceding twelve months, and we do not do so knowingly with respect to any individual under 16.
05
Consumer health data
Washington's My Health My Data Act, Nevada SB 370, and comparable laws regulate consumer health data held outside HIPAA. Where those laws apply to us, we collect consumer health data only to provide a service you requested or with your consent, obtain separate authorization before any sale (we do not sell it), and do not use geofencing around any healthcare facility to collect data, deliver advertising, or send notifications.
To exercise consumer health data rights — including confirmation, a list of third parties, deletion, and withdrawal of consent — email privacy@myorbithealth.com with “Consumer health data” in the subject line.
07
Your privacy rights
Depending on your state of residence, you may have the right to know or access the personal information we hold, to receive a portable copy, to correct inaccuracies, to delete, to opt out of sale, sharing, targeted advertising, and profiling with legal effects, to limit the use of sensitive personal information, and to be free from retaliation for exercising any of these rights.
How to submit a request
- Email privacy@myorbithealth.com with the subject “Privacy rights request” and tell us the right you are exercising and your state of residence.
- We verify identity proportionate to the sensitivity of the request, using information we already hold. We do not require an account.
- An authorized agent may submit on your behalf with written permission; we may contact you to confirm.
- We respond within 45 days, extendable once by another 45 days with notice.
Limits on deletion
We may decline or partially fulfill a request where the law requires retention — most commonly medical records, prescription records, and audit logs subject to HIPAA, state record-retention rules, or pharmacy regulation. Where PHI is involved, the request is directed to the Covered Entity clinic, whose HIPAA rights process applies. We will tell you the basis for any denial and how to appeal it.
Opt-out signals
We honor Global Privacy Control as a valid opt-out of sale, sharing, and targeted advertising. Because we do not sell or share personal information, an opt-out request results in confirmation of that status and suppression of optional measurement for you.
08
Retention
| Record type | Retention |
|---|---|
| Website inquiry and marketing contact records | Up to 24 months after last interaction, or until you opt out |
| Partner application and diligence records | Term of the relationship plus 7 years |
| Billing, tax, and accounting records | 7 years, as required by law |
| Security and access audit logs | At least 6 years, per HIPAA documentation requirements |
| Analytics measurement (consent-based) | Up to 14 months at the vendor, then deleted |
| Protected Health Information | As directed by the Covered Entity clinic and applicable state medical-record law |
When a retention period ends, we delete or de-identify the information. Backups age out on their own schedule after deletion from primary systems.
09
Security and location of data
We encrypt data in transit and at rest, restrict access on a least-privilege basis with multi-factor authentication, log access to PHI, and test our controls — described in detail on our security page. No method of transmission or storage is perfectly secure, and we do not claim otherwise; we do commit to notifying affected parties promptly if something goes wrong.
Our services are offered in the United States and data is stored in the United States. We do not offer services to individuals in the European Economic Area or the United Kingdom, and Protected Health Information is not transferred outside the United States.
10
Changes and contact
We will post material changes on this page with a new effective date and, where the change materially affects how we use information already collected, provide additional notice. Continued use after the effective date constitutes acceptance.
MyOrbit Health, Inc. · Privacy team · privacy@myorbithealth.com · Legal: legal@myorbithealth.com · Security: security@myorbithealth.com. Postal address available on request. California residents may also contact us by email for a copy of this notice in an accessible format.