HIPAA, CCPA, and GDPR Compliance Statement
At DecodeMD, we are committed to protecting your privacy and securing your data. This policy outlines our current status and obligations under the Health Insurance Portability and Accountability Act (HIPAA), the California Consumer Privacy Act (CCPA/CPRA), and the General Data Protection Regulation (GDPR) applicable to users in the United States, California, the European Union (EU), and the United Kingdom (UK).
1. HIPAA Disclaimer
DecodeMD is currently not a Covered Entity or Business Associate under HIPAA, and we do not claim HIPAA compliance at this time. Therefore, we do not provide HIPAA-compliant services, and users are expressly advised:
Do not submit, upload, or transmit any Protected Health Information (PHI) as defined under HIPAA. We do not offer Business Associate Agreements (BAAs).
DecodeMD is intended solely for educational and informational use, not for diagnosis, treatment, or clinical communication. All use of DecodeMD is at the user's own discretion and risk with respect to healthcare data privacy. We are actively exploring infrastructure enhancements and regulatory pathways toward offering a HIPAA-compliant version in the future.
2. Prohibited Use of PHI
Under HIPAA, "Protected Health Information" includes any individually identifiable health data, such as:
- Full names, email addresses, phone numbers
- Medical record numbers or health plan identifiers
- Dates directly linked to an individual (e.g., DOB, admission date)
- Geolocation data, facial images, biometric identifiers
Users must not upload PHI to DecodeMD. Any data that constitutes PHI under HIPAA is submitted in violation of this policy and may be deleted or anonymized without notice.
3. Data Practices Under CCPA & CPRA (California Residents)
In accordance with the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), DecodeMD provides California residents with the following rights:
Rights you have:
- Right to Know — what personal data we collect, how we use it, and whether we disclose or sell it (we do not)
- Right to Delete — request deletion of personal data collected about you
- Right to Correct — request correction of inaccurate personal data
- Right to Opt Out — of the sale or sharing of personal information (DecodeMD does not sell or share personal data)
- Right to Limit Use of Sensitive Personal Information — applicable only where sensitive data is collected (DecodeMD currently does not collect sensitive identifiers)
To submit a request under CCPA, email: privacy@decodemd.co. DecodeMD will verify your identity before fulfilling CCPA-related requests. We will never discriminate against you for exercising your rights.
4. Data Practices Under GDPR (EU/UK Residents)
If you reside in the European Economic Area (EEA) or the United Kingdom, the General Data Protection Regulation (GDPR) grants you the following rights:
- Right of Access — to the personal data we process about you
- Right to Rectification — of inaccurate or incomplete data
- Right to Erasure ("right to be forgotten") — in certain conditions
- Right to Restrict Processing — under specific legal grounds
- Right to Data Portability
- Right to Object — to data processing for legitimate interests
- Right to Withdraw Consent — at any time without affecting prior lawful processing
We process personal data under the following legal bases: Consent (Art. 6(1)(a)), Contractual necessity (Art. 6(1)(b)), and Legitimate interests (Art. 6(1)(f)).
To exercise any GDPR-related rights, contact us at: privacy@decodemd.co. You also have the right to lodge a complaint with your local supervisory authority.
5. Data Collection and Retention
We collect limited personal data through:
- Session-based text input (processed and discarded in real time)
- IP addresses and device/browser metadata
- Aggregated analytics (via privacy-respecting tools)
We do not:
- Collect names, emails, or account data unless voluntarily provided
- Store PHI
- Use your data to train AI models
- Sell or share your data for cross-context advertising
Submitted input is processed via secure APIs (e.g., OpenAI), with data logging disabled where applicable. All personal data is stored only temporarily, encrypted in transit via SSL/TLS, and deleted after processing or inactivity.
6. International Transfers and Safeguards
If you access DecodeMD from outside the United States, you acknowledge and consent that your data may be transferred to and processed in the U.S. and other jurisdictions. For data originating from the EU/UK, we use:
- Standard Contractual Clauses (SCCs)
- Legitimate interest assessments
- Privacy-focused processors who meet GDPR adequacy standards
7. Security Practices
DecodeMD implements reasonable administrative, technical, and physical safeguards, including:
- TLS encryption for data in transit
- Firewalled infrastructure and server hardening
- Limited access to sensitive systems via role-based access controls
However, no method of data transmission is 100% secure. By using DecodeMD, you acknowledge these risks.
8. Changes to This Policy
We may revise this Compliance Statement from time to time. Updates will be posted on this page, and your continued use of DecodeMD constitutes your agreement to the revised terms.
9. Contact Information
To request access, correction, deletion, or more information regarding your data and rights, please contact:
Email: support@decodemd.co
Account & Data DeletionKeith Bell, Founder
3904 Mill Rd
Collegeville, PA 19426
DecodeMD is committed to evolving toward full compliance with applicable health data and consumer privacy laws. Until such time, we respectfully request users do not transmit PHI or personally identifiable health data via this service.