HIPAA Notice of Privacy Practices
Last updated: March 26, 2026
Important Notice
This Notice of Privacy Practices ("Notice") describes how Protected Health Information ("PHI") may be used and disclosed in connection with services accessed through Ondra Health Inc. and explains your rights regarding that information.
Ondra Health Inc. ("Ondra Health," "we," "us," or "our") operates as a non-clinical platform. Healthcare services are provided by independent licensed providers, and prescription fulfillment is handled by independent pharmacies.
Ondra Health does not provide medical care, does not make clinical decisions, and does not establish provider-patient relationships.
Scope of This Notice
Health information submitted as part of a medical intake, patient portal, or telehealth experience is collected, stored, and maintained by third-party healthcare entities that are subject to the Health Insurance Portability and Accountability Act of 1996 ("HIPAA").
This Notice is provided to:
- explain how HIPAA applies within the Ondra Health ecosystem
- clarify how PHI may be used and disclosed
- direct you to the entities responsible for handling your PHI
Ondra Health is not the primary covered entity with respect to medical services and does not maintain medical records as a healthcare provider.
Healthcare Entities Responsible for PHI
PHI submitted in connection with healthcare services accessed through Ondra Health is handled by the following entities:
Licensed Healthcare Providers
Medical services are provided by independent licensed healthcare providers and provider groups. These providers:
- establish the provider-patient relationship
- make all clinical decisions
- maintain medical records
- are responsible for HIPAA compliance
Technology Platform
Secure intake forms, patient portals, and telehealth workflows are supported by third-party technology platforms. These platforms:
- securely collect and store PHI
- transmit PHI on behalf of providers
- operate in accordance with HIPAA requirements where applicable
Pharmacy Partners
Prescriptions issued by providers are fulfilled by state-licensed pharmacies or legally authorized dispensing entities. These pharmacies:
- maintain dispensing records
- handle medication-related PHI
- comply with pharmacy and HIPAA regulations
Ondra Health's Limited Role in PHI
Ondra Health does not function as a healthcare provider. However, Ondra Health may:
- access limited health-related information when necessary to provide customer support
- assist with care coordination or operational inquiries
- facilitate communication between users and third-party providers or pharmacies
Ondra Health does not:
- make treatment decisions
- create or control medical records as a provider
- use PHI for independent clinical purposes
Any access to PHI is limited to what is necessary for support and administrative purposes.
Use and Disclosure of PHI
PHI is primarily used and disclosed by licensed healthcare providers, pharmacies, and their authorized partners for purposes permitted by law, including:
a. Treatment
Providing, coordinating, or managing healthcare and related services.
b. Payment
Billing, payment processing, eligibility checks, and related financial activities.
c. Healthcare Operations
Quality improvement, audits, compliance, credentialing, training, and administrative functions.
d. As Required by Law
Federal, state, or local legal requirements.
e. Public Health and Safety
Preventing or controlling disease, reporting adverse events, or public health activities.
f. Health Oversight Activities
Audits, investigations, inspections, and regulatory compliance.
g. Judicial and Administrative Proceedings
Court orders, subpoenas, and lawful processes.
h. Law Enforcement
As permitted by applicable law.
i. Other Permitted Uses
Including research (where approved), organ donation, workers' compensation, military activities, or correctional settings, where legally allowed.
These uses are governed by the provider or pharmacy, not Ondra Health.
Your Rights Regarding PHI
To the extent HIPAA applies, you may have the following rights:
Right to Access and Copy
You may request access to your PHI held by your provider or pharmacy.
Right to Amend
You may request corrections to your PHI if it is inaccurate or incomplete.
Right to an Accounting of Disclosures
You may request a list of certain disclosures of your PHI.
Right to Request Restrictions
You may request limits on how your PHI is used or disclosed.
Right to Confidential Communications
You may request communication through specific methods or locations.
Right to Receive a Copy of Notices
You may obtain a copy of your provider's Notice of Privacy Practices.
Right to Breach Notification
You will be notified if a breach of unsecured PHI occurs.
These rights are exercised through your licensed provider or pharmacy, not directly through Ondra Health.
Transmission and Security of PHI
PHI transmitted through authorized systems is protected using reasonable administrative, technical, and physical safeguards, which may include:
- encrypted connections (SSL or equivalent)
- secure patient portals
- access controls and authentication measures
Ondra Health applies reasonable safeguards to any limited information it may access, but does not serve as the primary system of record for PHI.
No method of transmission or storage is completely secure.
State-Specific Privacy Protections
Certain states provide additional protections for sensitive health information, including:
- mental health records
- HIV/AIDS-related information
- substance use treatment records
- genetic testing information
- reproductive health data
Where applicable, providers and pharmacies are responsible for complying with these additional state-specific laws.
Residents of certain states (including California) may have additional rights under laws such as the Confidentiality of Medical Information Act (CMIA).
Changes to This Notice
Ondra Health reserves the right to update this Notice at any time. Changes will be effective upon posting and will apply to both existing and future information, as permitted by law.
Complaints
If you believe your privacy rights have been violated, you may file a complaint with:
- your healthcare provider
- your pharmacy
- or the U.S. Department of Health and Human Services (HHS)
You will not be retaliated against for filing a complaint.
Contact Information
For general questions about this Notice or Ondra Health services:
Ondra Health Inc.
355 S Grand Ave, Suite 2450
Los Angeles, CA 90071
United States
Email: care@ondra.health
For questions about your medical records or PHI, please contact your provider or pharmacy directly through the patient portal.