Care delivered online in supported states. Placeholder content for review.

Legal

HIPAA Notice of Privacy Practices

Effective September 2026

THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.

This HIPAA Notice of Privacy Practices ("Notice") describes how the independent, licensed healthcare providers and pharmacies you connect with through the West Labs Rx platform (collectively, the "Covered Entities"), and the workforce and service providers that support them, may use and disclose your protected health information ("PHI"). It also describes your rights under the Health Insurance Portability and Accountability Act ("HIPAA") and its Privacy Rule, and the obligations we have to keep your PHI private and secure.

1. Our Legal Duties

The healthcare providers and pharmacies that deliver care through our platform are required by law to: maintain the privacy and security of your PHI; give you this Notice describing their legal duties and privacy practices with respect to PHI; follow the terms of the Notice that is currently in effect; and notify you following a breach of your unsecured PHI. We are required to abide by the more protective of this Notice or applicable state health privacy law.

2. How We May Use and Disclose Your Health Information

The following categories describe different ways we use and disclose PHI for treatment, payment, and healthcare operations. Not every use or disclosure in a category will be listed, but all permitted uses and disclosures fall within one of the categories.

Treatment: We may use and disclose PHI to provide, coordinate, and manage your care. This includes sharing information between the provider who evaluates you, the pharmacy that fills your prescription, and other healthcare professionals involved in your care — for example, reviewing your intake questionnaire and medical history to determine whether a treatment is appropriate, transmitting a prescription to the pharmacy, and answering the pharmacy's questions about your prescription.

Payment: We may use and disclose PHI to bill and collect payment for the services and medications you receive. For example, we may use information about your treatment to process subscription charges, verify eligibility, respond to payment processor inquiries, or handle refunds when a provider does not issue a prescription.

Healthcare operations: We may use and disclose PHI for activities necessary to run the practice and platform, such as quality assessment and improvement, provider credentialing and peer review, training, compliance and audits, business planning, and customer support related to your care.

Business associates: Some services are performed by vendors under contracts called business associate agreements — for example, secure hosting, video visit platforms, e-prescribing, and shipping. These vendors may use and disclose PHI only on our behalf and are contractually required to safeguard it.

Individuals involved in your care: Unless you object, we may disclose to a family member, close personal friend, or other person you identify PHI that is directly relevant to that person's involvement in your care or payment for your care. We may also use PHI to notify such a person of your condition or location.

3. Uses and Disclosures Permitted Without Your Authorization

HIPAA also permits use and disclosure of PHI without your written authorization in certain circumstances, including: public health activities such as reporting of communicable diseases; health oversight activities conducted by government agencies; judicial and administrative proceedings in response to a court or administrative order, subpoena, or discovery request; law enforcement purposes under specific and limited conditions; disclosures about decedents to coroners, medical examiners, and funeral directors; organ and tissue donation purposes; research when reviewed and approved by an institutional review board or privacy board; to avert a serious and imminent threat to your health and safety or the health and safety of others; specialized government functions such as military and veterans' activities; workers' compensation claims; and disclosures required by the Secretary of the U.S. Department of Health and Human Services to investigate or determine our compliance with HIPAA.

Uses and disclosures required by law will be made only in compliance with the applicable legal requirement and, where permitted, will be limited to the minimum necessary PHI.

4. Uses and Disclosures That Require Your Written Authorization

Other uses and disclosures of PHI not described in this Notice will be made only with your written authorization. This includes most uses of PHI for marketing purposes, any sale of PHI, and certain uses of specially protected information where state law is more restrictive. If you provide an authorization, you may revoke it in writing at any time by contacting us, except to the extent we have already taken action in reliance on it.

5. Safeguarding Your Information

We use administrative, technical, and physical safeguards designed to protect PHI against unauthorized use, disclosure, alteration, or destruction. These include: encrypting data in transit and at rest; role-based access controls so that only personnel with a job-related need may access PHI; unique user accounts with authentication requirements; audit logging of access to health records; secure disposal of PHI when it is no longer needed and retention is not required by law; workforce privacy and security training; and contractual safeguards requiring business associates to protect PHI to the same standard we do. You also play a role: keep your account password confidential, and contact us promptly if you suspect unauthorized access to your account.

6. Breach Notification

If a breach of your unsecured PHI occurs, we are required by law to notify you in writing without unreasonable delay and in no case later than 60 days from discovery of the breach. If a breach affects a large number of individuals, we will also notify the Secretary of Health and Human Services and prominent media outlets as required by law.

7. Your Rights Regarding Your Health Information

Right to inspect and copy: You have the right to inspect and receive a copy of the PHI held in the designated record set, including medical and billing records. We may charge a reasonable, cost-based fee as permitted by law. We may deny your request in limited circumstances; if denied, you may have the denial reviewed.

Right to amend: If you believe PHI in your record is incorrect or incomplete, you may request that we amend it. We may deny the request if the record was not created by us, is not part of the record we maintain, would not be available for inspection, or is accurate and complete.

Right to an accounting of disclosures: You may request a list of certain disclosures of your PHI we made in the six years prior to your request, excluding disclosures for treatment, payment, healthcare operations, and certain other purposes. The first accounting in any 12-month period is free; additional requests may be subject to a reasonable fee.

Right to request restrictions: You may request that we restrict or limit the PHI we use or disclose for treatment, payment, or operations, or to persons involved in your care. We are not required to agree to a requested restriction, except that we must honor a request to restrict disclosure of PHI to a health plan for payment or operations purposes if the disclosure is not otherwise required by law and the service has been paid for in full out of pocket.

Right to confidential communications: You may request that we communicate with you about your health matters in a specific way or at a specific location — for example, only by email and not by phone. We will accommodate reasonable requests.

Right to a paper copy: You may request a paper copy of this Notice at any time, even if you have agreed to receive it electronically, by contacting us.

Right to be notified of a breach: You have the right to receive notification of any breach of your unsecured PHI, as described in Section 6.

To exercise any of these rights, contact us through our Contact page. We will respond to your request within the timeframes required by law, and if we cannot fulfill it, we will explain why and describe any review process available to you. You will not be penalized or retaliated against for exercising any right described in this Notice.

8. Complaints

If you believe your privacy rights have been violated, you may file a complaint with us through our Contact page, or with the U.S. Department of Health and Human Services Office for Civil Rights, 200 Independence Avenue SW, Washington, D.C. 20201, by calling 1-877-696-6775, or online at www.hhs.gov/ocr/complaints. We will provide you with the information needed to file a complaint on request. You will not be retaliated against for filing a complaint.

9. Minimum Necessary

When using or disclosing PHI or requesting PHI from others, we will make reasonable efforts to limit PHI to the minimum necessary to accomplish the intended purpose, except for disclosures to or requests by a healthcare provider for treatment, disclosures to you, disclosures made under your authorization, and other uses permitted by the Privacy Rule.

10. Changes to This Notice

We reserve the right to change the terms of this Notice and to make the new terms effective for all PHI we maintain, including PHI created or received before the change. The current version of this Notice, with its effective date, will always be posted on this page. Material changes will be highlighted.

11. Effective Date and Contact

This Notice is effective September 2026. Questions about this Notice or our privacy practices can be sent through our Contact page.