Privacy Policy
Last updated: April 2026
Information We Collect
We collect information you provide directly, information generated as you use our services, and information from third parties.
Personal information: name, date of birth, email address, mailing address, phone number, and payment information.
Health information: medical history, current symptoms, medications, lab results, treatment records, and other information you share with your care team. This information is Protected Health Information (PHI) under HIPAA and is governed by our Notice of Privacy Practices as well as this policy.
Technical and device information: IP address, browser type, operating system, device identifiers, pages visited, referring URLs, session duration, and similar usage data collected through cookies and similar technologies.
How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our telehealth services and patient portal.
- Match you with licensed clinicians, coordinate your care, and manage prescriptions.
- Process payments and manage your subscription.
- Send appointment reminders, service updates, and — with your consent — marketing communications.
- Comply with applicable federal and state laws, including HIPAA, and respond to lawful legal process.
- Detect and prevent fraud, abuse, and security incidents.
We do not sell your personal information or your health information to third parties. We do not share your data for third-party advertising purposes.
Sharing With Third Parties
We share your information only as described here or as further specified in our Notice of Privacy Practices:
- Healthcare providers and care team members — licensed clinicians, pharmacies, labs, and other providers directly involved in your treatment.
- Payment processors — to handle subscription billing and payment transactions securely.
- Cloud infrastructure and hosting providers — HIPAA Business Associates who store and process data on our behalf under signed agreements.
- Analytics and product improvement vendors — to help us understand how our services are used; these vendors receive de-identified or aggregated data where possible and are contractually prohibited from using it for their own commercial purposes.
- Legal and regulatory authorities — when required by law, court order, or government request.
Your Choices and Rights
You have the following rights with respect to your information:
- Access and correction: You may access and update your personal information at any time in your patient portal. You may also request a copy of your records by contacting us.
- Deletion: You may request deletion of your account and personal information, subject to our legal obligations to retain certain records (including medical records as required by state law).
- Opt-out of marketing: You may unsubscribe from marketing emails at any time by clicking the unsubscribe link in any marketing email or by contacting us. We will still send you transactional and service-related communications.
- Data portability: You may request a machine-readable export of personal information we hold about you.
California, Virginia, and Colorado residents may have additional rights under the California Consumer Privacy Act (CCPA/CPRA), the Virginia Consumer Data Protection Act (VCDPA), and the Colorado Privacy Act (CPA), respectively, including the right to know what data we have collected, the right to correct inaccurate data, and the right to opt out of certain data uses. To submit a privacy request, email privacy@bridgewellhealth.example.
Data Retention
We retain your personal information and health information only as long as necessary to provide our services and to comply with our legal obligations. Medical records are retained for the periods required by applicable state and federal law, which typically range from 7 to 10 years. Billing records are retained as required for tax and accounting purposes. When information is no longer needed, we delete or de-identify it in a secure manner.
Children
Our services are not directed at children under the age of 13, and we do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected information from a child under 13, please contact us immediately at privacy@bridgewellhealth.example so we can delete it.
Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email (at the address on your account) and by posting a prominent notice in the patient portal at least 30 days before the changes take effect. Your continued use of the services after the effective date constitutes acceptance of the updated policy.
Contact
If you have questions, concerns, or requests related to this Privacy Policy, please contact our Privacy Officer:
Email: privacy@bridgewellhealth.example
Bridgewell Health, Inc.
Attn: Privacy Officer
Boston, MA
This Privacy Policy supplements Bridgewell Health's HIPAA Notice of Privacy Practices, which governs use and disclosure of your Protected Health Information. Bridgewell Health is licensed to provide telehealth services in 47 states. This website does not provide medical advice.