1 Who we are and what this policy covers
TeleHeadache LLC ("TeleHeadache," "we," "us," or "our") operates the TeleHeadache website and supporting platform and provides clinical services through its authorized clinicians. This policy explains how we handle information in connection with those services.
This policy describes personal information handled through teleheadache.com, our assessment and patient portal, membership administration, support, and communications that link to this policy. It explains what we collect, why we use it, the circumstances in which we disclose it, and how you can contact us or exercise privacy rights.
This policy does not govern a pharmacy, insurer, outside clinician, payment provider, or other third party acting independently under its own privacy notice. A provider we engage to perform services for us remains subject to its applicable contractual and legal duties. Information that has been lawfully deidentified is no longer personal information under this policy, except where applicable law provides otherwise.
Back to top ↑2 Your medical information has additional protections
Medical information maintained by our clinical practice may be protected health information, or “PHI,” under the Health Insurance Portability and Accountability Act and its regulations, commonly called HIPAA. Our Notice of Privacy Practices explains uses and disclosures of PHI, your healthcare privacy rights, our legal duties, and complaint options. That notice governs PHI if this policy describes it differently. Applicable laws providing greater protection also apply.
Not every interaction with a public website is a healthcare encounter, and not all website information is PHI. Other privacy and consumer-protection laws may protect information outside HIPAA. This policy is a notice of our practices; accepting website terms or a cookie banner is not a HIPAA authorization or a substitute for consent required for a particular use.
Back to top ↑3 Information you provide
The information we collect depends on the services you use. It can include:
- Identity and contact details: your name, date of birth, email, telephone number, address, identity-verification information, emergency contact, and communication preferences.
- Account information: account identifiers, authentication and verification records, security preferences, consent and acknowledgment records, and account-recovery activity.
- Health information: headache history, symptoms, diagnoses, medications, allergies, prior treatments, medical history, relevant pregnancy or breastfeeding information, assessment answers, uploaded records, clinical messages, treatment plans, prescriptions, and headache-tracker entries.
- Location information: your stated physical location when seeking care, home address, and billing or shipping address. A shipping address does not establish where you are physically located for telehealth.
- Insurance and pharmacy information: benefit identifiers, insurance-card information, preferred pharmacy, coverage and prior-authorization information, medication-access communications, and prescription or delivery status.
- Membership and payments: selected plan, transaction identifiers, billing contact information, payment status, renewal and cancellation records, refunds, and the payment details required by the payment method you choose.
- Communications and requests: support messages, privacy and accessibility requests, feedback, and information you choose to include in a business inquiry.
Please provide only information relevant to your request. Use the patient portal for clinical information. Do not submit medical records, photographs of identification, insurance cards, payment-card details, or urgent medical concerns through a general website contact form or social-media message.
Back to top ↑4 Information received from other sources
We may receive information from your treating clinicians, pharmacies, insurers, pharmacy benefit managers, medication-access programs, and people you authorize to assist you. Examples include records relevant to your headache care, prescription processing updates, coverage decisions, and information needed to complete a prior authorization.
Service providers may supply identity-verification results, payment confirmations, delivery or communication status, fraud indicators, or technical support information. If someone acts for you, we may request information establishing that person's identity and authority. We use information from these sources for the purposes described in this policy and subject to the restrictions that apply to the information.
Back to top ↑5 Information collected through technology
Our services may collect internet protocol addresses, browser and device details, operating system, language, referring page, access times, pages or features used, session identifiers, approximate network location, errors, and security events. These records help deliver pages, protect accounts, investigate failures, and understand service performance.
Cookies and similar technologies can maintain a session, remember preferences, preserve security settings, and record privacy choices. Their presence does not mean that clinical information may be used for advertising. We do not use advertising pixels or advertising session replay in assessments, account registration, patient portal, clinical messaging, or other clinical workflows.
We do not continuously track your movements. Any request for precise device location must identify its purpose and obtain the permission or consent required by law. Approximate network location can be inaccurate and does not replace your location attestation for care.
Back to top ↑6 Why we use information
We use information to create and maintain accounts; check identity, age, service eligibility, and physical location; receive and organize assessments; support clinician review; provide treatment and follow-up; maintain clinical records; coordinate prescriptions and pharmacy communications; administer membership, payments, and cancellations; and respond to requests.
We also use information to send service notices, troubleshoot technology, detect fraud or misuse, protect patients and accounts, evaluate care quality, train authorized personnel, conduct audits, manage legal obligations, and establish or defend legal rights. Uses of PHI must satisfy the Notice of Privacy Practices and applicable law even when a similar purpose appears in this policy.
We may develop aggregate or deidentified reports for service planning, quality improvement, and operational analysis. We do not treat information as deidentified merely because a name has been removed. Any deidentification must meet the legal standard that applies, and we do not attempt to identify individuals from information we represent as deidentified except as permitted by law to test the deidentification process.
Back to top ↑7 When we disclose information
Care and medication access. Authorized clinicians and support personnel may receive information needed for their work. We may disclose information to treating providers, pharmacies, insurers, benefit managers, and medication-access programs as permitted by law. For example, a pharmacy may need your prescription and contact details, while a payer may need clinical information supporting a medication request.
Service providers. We use providers for functions such as hosting, authentication, clinical technology, electronic prescribing, communications, payments, technical support, security, and professional advice. Providers receive information appropriate to their service and are subject to applicable agreements, including a business associate agreement when HIPAA requires one. A contract alone does not permit a disclosure that the law prohibits.
At your direction. We may disclose information when you request or authorize it, or when a person with verified legal authority acts for you. We obtain additional authorization when the law requires it.
Legal and safety purposes. We may disclose information to comply with applicable law, valid legal process, regulatory oversight, required reporting, or legally permitted safety and fraud-prevention activities. A request from a government agency or lawyer does not automatically entitle the requester to your records. PHI and specially protected records remain subject to their additional restrictions.
Business transactions. Information may be reviewed or transferred in a proposed or completed merger, acquisition, financing, reorganization, or transfer of a practice, subject to applicable confidentiality duties and legal restrictions. A transaction does not eliminate your privacy rights or authorize unrestricted use of medical records.
Back to top ↑8 Advertising, sale, and marketing choices
We do not sell personal information. We do not disclose personal information for cross-context behavioral advertising or use patient lists, assessments, diagnoses, medications, or portal activity to create advertising audiences. These commitments do not prevent the disclosures needed to operate the services as described above, subject to applicable law.
If you choose to receive promotional email, you may unsubscribe using the message's instructions or contact us. Marketing permission is separate from clinical consent and membership enrollment. Declining promotional communications does not prevent you from receiving available care. We may still send necessary account, service, billing, safety, and legal notices through appropriate channels.
We will obtain any separate authorization required before using an identifiable patient story, image, or testimonial. Publishing a review yourself does not give us blanket permission to reveal your patient status or medical information in a response.
Back to top ↑10 Clinical software, automation, and recording
Approved software may assist with organizing assessment answers, identifying missing information, drafting summaries, flagging potential safety concerns, and routing work. A licensed clinician remains responsible for diagnosis, treatment, prescribing, and other clinical decisions. Automated output is not a guarantee of accuracy or a replacement for clinician judgment.
We do not provide identifiable patient information to train publicly available general-purpose artificial-intelligence models. Use of a software provider in a clinical workflow must be consistent with the provider's authorized function, applicable agreements, and privacy law. We do not record video visits by default. Any proposed recording or transcription that requires additional notice or consent will be disclosed before it begins.
Back to top ↑11 Communications and independent services
Email, text messaging, voicemail, and shared devices can expose information to other people. Service notifications can reveal that you have a relationship with TeleHeadache even when they do not include clinical details. Tell us if you need a different contact method or destination. Healthcare requests for confidential communications are addressed in the Notice of Privacy Practices.
Optional promotional text messages require the applicable separate permission. Follow the opt-out instructions in a message or contact support to change available communication choices. Message and data charges from your carrier may apply. Opting out of a communication channel does not itself cancel membership; the Membership, Cancellation and Refund Policy explains cancellation.
If you follow a link to an independent website, authorize an outside application, or send records to a third party, that recipient's privacy practices may differ from ours. Review the recipient's notice before providing information. Our privacy duties still apply to information we retain.
Back to top ↑12 Retention, account closure, and deletion
We retain information for the period appropriate to its purpose and legal requirements. Relevant factors include medical-record obligations, continuity of care, billing and tax requirements, consent documentation, security investigations, disputes, and legal preservation duties. Different categories can have different retention periods.
Closing an account or canceling a membership does not automatically erase medical records, prior transactions, or information we must preserve. Information retained after closure remains subject to applicable protections. Where deletion is required and no exception applies, we will process the request under applicable law, including any requirements concerning vendors and backup copies. We do not promise immediate deletion from every system.
Back to top ↑13 Your privacy requests and rights
You may contact us to ask what information we hold, request a copy, seek correction, request deletion where available, withdraw applicable consent, or ask about choices concerning sensitive information or optional processing. Depending on where you live, the information involved, and the law's applicability, you may have additional rights, including portability, an authorized-agent request, or an appeal of a denied request. HIPAA medical-record rights follow the separate Notice of Privacy Practices.
Send requests to admin@teleheadache.com. Identify the right you wish to exercise and a safe way to contact you; do not include unnecessary clinical or identity documents in the initial email. We will explain any identity or authority verification reasonably needed, respond within the applicable legal period, and explain material reasons if a request cannot be honored. You may request review of our decision by replying to the response or contacting the Privacy Officer. Where applicable, we will explain the available appeal process and regulator complaint route.
We will not unlawfully discriminate or retaliate because you exercise a privacy right. A request to stop processing information necessary for a service can affect whether we can continue providing that service. We will explain relevant limitations rather than treating a request as permission to disregard record-retention duties.
Back to top ↑14 Security, children, and international visitors
We use administrative, technical, and physical safeguards appropriate to the information and services involved. No internet service can guarantee that every transmission or storage system will be free from risk. Protect your credentials, use a device you trust, sign out of shared devices, and report suspected account misuse promptly to contact@teleheadache.com. We will provide security-incident or breach notices when applicable law requires them.
TeleHeadache clinical services are intended for adults age 18 and older. We do not knowingly enroll children in the adult service. Contact us if you believe a child has submitted information without appropriate authorization so we can assess the circumstances and take legally appropriate action.
Our services are intended for people in authorized United States locations. Accessing a webpage from another country does not make clinical care available there. Personal information may be processed where our authorized providers operate, subject to applicable legal and contractual safeguards; contact the Privacy Officer with questions about an applicable international transfer.
Back to top ↑15 Changes and contact information
We may revise this policy to reflect changes in services, practices, or law. The current version and its effective date will appear here. We will provide additional notice or obtain consent when required; posting a revised policy does not by itself supply a legally required authorization for a new use of previously collected information.
Privacy Officer — TeleHeadache LLC
Email: admin@teleheadache.com
For general service questions, contact contact@teleheadache.com. For a medical emergency, call 911; privacy and support channels are not emergency services.
Back to top ↑