Legal

HIPAA, CCPA, and GDPR Compliance Statement

At DecodeMD, we are committed to protecting your privacy and securing your data. This policy outlines our current status and obligations under the Health Insurance Portability and Accountability Act (HIPAA), the California Consumer Privacy Act (CCPA/CPRA), and the General Data Protection Regulation (GDPR) applicable to users in the United States, California, the European Union (EU), and the United Kingdom (UK).

1. HIPAA Disclaimer

DecodeMD is currently not a Covered Entity or Business Associate under HIPAA, and we do not claim HIPAA compliance at this time. Therefore, we do not provide HIPAA-compliant services, and users are expressly advised:

Do not submit, upload, or transmit any Protected Health Information (PHI) as defined under HIPAA. We do not offer Business Associate Agreements (BAAs).

DecodeMD is intended solely for educational and informational use, not for diagnosis, treatment, or clinical communication. All use of DecodeMD is at the user's own discretion and risk with respect to healthcare data privacy. We are actively exploring infrastructure enhancements and regulatory pathways toward offering a HIPAA-compliant version in the future.

2. Prohibited Use of PHI

Under HIPAA, "Protected Health Information" includes any individually identifiable health data, such as:

Users must not upload PHI to DecodeMD. Any data that constitutes PHI under HIPAA is submitted in violation of this policy and may be deleted or anonymized without notice.

3. Data Practices Under CCPA & CPRA (California Residents)

In accordance with the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), DecodeMD provides California residents with the following rights:

Rights you have:

To submit a request under CCPA, email: privacy@decodemd.co. DecodeMD will verify your identity before fulfilling CCPA-related requests. We will never discriminate against you for exercising your rights.

4. Data Practices Under GDPR (EU/UK Residents)

If you reside in the European Economic Area (EEA) or the United Kingdom, the General Data Protection Regulation (GDPR) grants you the following rights:

We process personal data under the following legal bases: Consent (Art. 6(1)(a)), Contractual necessity (Art. 6(1)(b)), and Legitimate interests (Art. 6(1)(f)).

To exercise any GDPR-related rights, contact us at: privacy@decodemd.co. You also have the right to lodge a complaint with your local supervisory authority.

5. Data Collection and Retention

We collect limited personal data through:

We do not:

Submitted input is processed via secure APIs (e.g., OpenAI), with data logging disabled where applicable. All personal data is stored only temporarily, encrypted in transit via SSL/TLS, and deleted after processing or inactivity.

6. International Transfers and Safeguards

If you access DecodeMD from outside the United States, you acknowledge and consent that your data may be transferred to and processed in the U.S. and other jurisdictions. For data originating from the EU/UK, we use:

7. Security Practices

DecodeMD implements reasonable administrative, technical, and physical safeguards, including:

However, no method of data transmission is 100% secure. By using DecodeMD, you acknowledge these risks.

8. Changes to This Policy

We may revise this Compliance Statement from time to time. Updates will be posted on this page, and your continued use of DecodeMD constitutes your agreement to the revised terms.

9. Contact Information

To request access, correction, deletion, or more information regarding your data and rights, please contact:

Email: support@decodemd.co

Account & Data Deletion
Keith Bell, Founder
3904 Mill Rd
Collegeville, PA 19426

DecodeMD is committed to evolving toward full compliance with applicable health data and consumer privacy laws. Until such time, we respectfully request users do not transmit PHI or personally identifiable health data via this service.