Privacy Policy
Last updated:
Stackhaus Health respects your privacy. This Privacy Policy explains how we collect, use, share, and protect information when you visit our website, complete forms, or use our online services.
By using this website, you agree to the practices described in this Privacy Policy.
1. Information We Collect
We may collect information you provide directly, including:
- Name
- Email address
- Phone number
- Date of birth
- Contact details
- Health-related information submitted through forms or evaluations
- Payment information
- Account or service-related information
- Messages or inquiries sent through the website
We may also collect technical information automatically, such as:
- IP address
- Browser type
- Device type
- Pages visited
- Time spent on the website
- Referral source
- Cookies and similar tracking data
2. How We Use Your Information
We may use your information to:
- Respond to inquiries
- Process evaluations
- Provide access to services
- Connect you with licensed providers when appropriate
- Coordinate prescriptions, laboratory services, pharmacy services, or follow-up care
- Process payments
- Improve our website and services
- Send service updates or important notices
- Comply with legal, regulatory, or security requirements
3. Health Information, PHI, and HIPAA
Some information you provide may relate to your health, treatment interests, medical history, or eligibility for care. Health information is “protected health information” or “PHI” under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) only when HIPAA applies to the information and the entity creating, receiving, maintaining, or transmitting it.
HIPAA does not apply to every Stackhaus Health service or to all information collected through a website. When Stackhaus Health receives or maintains PHI on behalf of a HIPAA-covered healthcare provider, pharmacy, health plan, or other covered entity as its business associate, we use and disclose that PHI only as permitted by our written agreement with that covered entity and applicable law. Information that is not PHI remains protected under this Privacy Policy and other applicable privacy and security laws.
Licensed provider networks, individual clinicians, pharmacies, laboratories, and other healthcare organizations participating in your care may be independent entities. Their own notices of privacy practices govern the PHI they create or maintain, and they may provide additional privacy notices directly to you.
4. Permitted Uses and Disclosures of PHI
When HIPAA applies, PHI may be used or disclosed as permitted or required by law, including for:
- Treatment and care coordination, including communications among clinicians, pharmacies, laboratories, and other healthcare professionals involved in your care
- Payment activities, such as billing, payment processing, eligibility, and collection activities
- Healthcare operations, such as quality assessment, patient support, compliance, auditing, training, credentialing, and service improvement
- Business associates that perform services involving PHI and are contractually required to protect it
- Public health and safety activities, health oversight, reporting abuse or neglect, responding to a serious and imminent threat, or other disclosures authorized by law
- Judicial, administrative, law-enforcement, workers’ compensation, or other legal proceedings when the applicable legal requirements are met
- Any other purpose for which you provide a valid authorization
We will obtain your written authorization when HIPAA requires it, including for most uses of psychotherapy notes, most uses of PHI for marketing, and the sale of PHI. You may revoke an authorization in writing at any time, except to the extent action has already been taken in reliance on it. We do not sell PHI. Where applicable, substance use disorder records protected by 42 CFR Part 2 are subject to additional consent and disclosure restrictions.
5. PHI Safeguards and Breach Notification
When we handle PHI, we use administrative, technical, and physical safeguards designed to protect its confidentiality, integrity, and availability. These safeguards may include role-based access controls, authentication, encryption where appropriate, workforce training, security monitoring, incident-response procedures, secure disposal, and written agreements requiring service providers to protect PHI.
If we discover a breach of unsecured PHI, we will investigate, mitigate reasonably foreseeable harm, and provide notice to the applicable covered entity and/or affected individuals, the U.S. Department of Health and Human Services, and the media when required by law. Required notices will be provided without unreasonable delay and within applicable legal deadlines. No security program can eliminate every risk, and we cannot guarantee absolute security.
6. Your HIPAA Rights
When HIPAA applies to your information, and subject to legal limitations, you may have the right to:
- Inspect or obtain a paper or electronic copy of designated records
- Ask that inaccurate or incomplete records be amended
- Request restrictions on certain uses or disclosures of PHI; when you pay a healthcare item or service in full out of pocket, the responsible covered entity must generally honor a request not to disclose related information to a health plan for payment or healthcare operations, unless disclosure is required by law
- Request communications by a specific method or at a specific location
- Receive an accounting of certain disclosures of PHI
- Receive a paper or electronic copy of the applicable privacy notice
- Choose a personal representative to act on your behalf
- File a privacy complaint without retaliation
Stackhaus Health may need to route a rights request to the provider, pharmacy, or other covered entity that maintains the official medical or pharmacy record. We will assist with that process when required by our agreements or applicable law. Identity verification may be required before a request is completed.
7. Notice of Privacy Practices for HIPAA-Covered Services
Effective date: August 2, 2026.
This notice describes how medical information about you may be used and disclosed and how you can obtain access to that information. Please review it carefully.
To the extent Stackhaus Health is legally responsible as a HIPAA-covered entity for a particular healthcare service, Sections 3 through 7 and Section 19 of this policy constitute its Notice of Privacy Practices for that service. For care furnished by an independent provider, provider network, pharmacy, laboratory, or other covered entity, that entity’s Notice of Privacy Practices controls its use and disclosure of PHI.
For HIPAA-covered services for which we are the responsible covered entity, we are required by law to maintain the privacy and security of PHI, notify affected individuals following a breach when required, and follow the privacy practices described in the notice currently in effect. We may change this notice and make the revised practices apply to PHI we already maintain as well as PHI we receive in the future. A current copy will be posted on this page, and paper or electronic copies are available upon request.
When your authorization or an opportunity to agree or object is required, we will request it before using or disclosing PHI. This may include certain disclosures to family members or others involved in your care, disaster-relief organizations, marketing communications, or other uses not otherwise permitted by law.
8. Cookies and Tracking
We may use cookies, pixels, analytics tools, and similar technologies to understand website activity, improve user experience, and support marketing or performance tracking.
You can adjust your browser settings to limit or block cookies, but some website features may not work properly.
9. How We Share Information
We may share information with trusted third parties when needed to operate our services, including:
- Licensed healthcare providers
- Pharmacy partners
- Laboratory providers
- Payment processors
- Technology and hosting providers
- Customer support platforms
- Legal, compliance, or regulatory advisors
- Other service providers who help operate the business
We do not sell your personal medical information.
10. Payment Information
Payments may be processed through third-party payment providers. We do not store full payment card details unless required and handled through secure payment systems.
11. Data Security
We use reasonable administrative, technical, and physical safeguards to protect your information. However, no online system is completely secure, and we cannot guarantee absolute security.
12. Your Choices
Depending on your location and applicable law, you may have the right to:
- Request access to your information
- Request corrections
- Request deletion
- Opt out of marketing communications
- Limit certain uses of your information
- Request more details about how your information is handled
To make a request, contact us using the email address provided below.
13. Email and Text Communications
By submitting your contact information, you may receive messages related to your inquiry, evaluation, account, services, or care process.
You may opt out of marketing emails at any time. Service-related or medical-related communications may still be sent when necessary.
14. Third-Party Links
Our website may contain links to third-party websites, tools, or services. We are not responsible for the privacy practices or content of those third parties.
15. Children’s Privacy
Our website and services are intended for adults 18 years or older. We do not knowingly collect personal information from children.
16. Data Retention
We keep personal information only as long as needed to provide services, comply with legal obligations, resolve disputes, and maintain business records.
17. State Privacy Rights
Depending on your state of residence, you may have additional rights under applicable privacy laws. We will respond to valid requests as required by law.
18. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated “Last updated” date.
19. Privacy Complaints and Contact
To exercise a privacy right, request a copy of an applicable Notice of Privacy Practices, or submit a privacy or security complaint, contact our Privacy Contact using the information below. Please write “Privacy Request” in the subject line. We will not retaliate against you for filing a complaint.
If your complaint concerns an independent provider, pharmacy, laboratory, or other covered entity, you may also contact the privacy official identified in that entity’s Notice of Privacy Practices. You may file a HIPAA complaint with the U.S. Department of Health and Human Services Office for Civil Rights through HHS.gov or by calling 1-877-696-6775. Filing a complaint will not affect your eligibility for services.



