Notice: RemedyNowRX services are currently only available in Oklahoma. Check back soon to see if your state has been added!

Back to Home

HIPAA Compliance

Effective Date: April 19, 2026 | Last Updated: April 19, 2026

RemedyNowRX is committed to full compliance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and its implementing regulations, including the Privacy Rule, Security Rule, and Breach Notification Rule. This page outlines how we protect your Protected Health Information (PHI) and your rights as a patient.

1. What Is HIPAA?

HIPAA is a federal law that establishes national standards for the protection of sensitive patient health information. It governs how covered entities — such as healthcare providers, health plans, and healthcare clearinghouses — and their business associates handle PHI. RemedyNowRX operates as a covered entity and takes its obligations under HIPAA seriously.

2. What Is Protected Health Information (PHI)?

PHI includes any individually identifiable health information we create, receive, maintain, or transmit, including but not limited to:

  • Your name, date of birth, address, phone number, and email
  • Medical history, diagnoses, and treatment information
  • Medication records and prescription history
  • Health assessment responses submitted through our platform
  • Identity verification documents (e.g., driver's license)
  • Payment information linked to healthcare services

3. The HIPAA Privacy Rule

The Privacy Rule establishes standards for the use and disclosure of PHI. RemedyNowRX uses and discloses PHI only as permitted or required by HIPAA, including:

  • Treatment: Sharing PHI with licensed physicians and pharmacists for the purpose of reviewing and fulfilling your medication request.
  • Payment: Using PHI to process billing and insurance-related activities.
  • Healthcare Operations: Internal quality assurance, compliance auditing, and staff training.
  • Legal Requirements: Disclosures required by law, such as public health reporting or court orders.

We will never sell your PHI or use it for marketing purposes without your explicit written authorization.

4. The HIPAA Security Rule

The Security Rule requires appropriate administrative, physical, and technical safeguards to protect electronic PHI (ePHI). Our safeguards include:

  • Administrative Safeguards: Workforce training on privacy and security policies, access management protocols, and regular risk assessments.
  • Physical Safeguards: Restricted physical access to systems that store ePHI, workstation security controls, and device management policies.
  • Technical Safeguards: End-to-end TLS/SSL encryption for data in transit, encryption of data at rest, multi-factor authentication, and role-based access controls.
  • Audit Controls: Logging and monitoring of access to ePHI to detect unauthorized activity.

5. Business Associate Agreements (BAAs)

Any third-party vendors or service providers who may access PHI on our behalf are required to sign a Business Associate Agreement (BAA). These agreements obligate our business associates to protect PHI in accordance with HIPAA standards. We do not share PHI with any vendor that has not executed a BAA.

6. Breach Notification

In the event of a breach of unsecured PHI, RemedyNowRX will notify affected individuals without unreasonable delay and no later than 60 days following discovery of the breach, as required by the HIPAA Breach Notification Rule. Notification will be provided via email or written notice and will include a description of the breach, the types of information involved, steps you should take to protect yourself, and what we are doing to investigate and mitigate the breach. If a breach affects 500 or more individuals, we will also notify the U.S. Department of Health & Human Services (HHS) and, where required, prominent media outlets.

7. Your HIPAA Rights

As a patient, HIPAA grants you the following rights regarding your PHI:

  • Right of Access: Request a copy of your health records in electronic or paper format.
  • Right to Amend: Request corrections to inaccurate or incomplete PHI.
  • Right to an Accounting of Disclosures: Obtain a list of certain disclosures we have made of your PHI.
  • Right to Request Restrictions: Ask us to limit how we use or disclose your PHI (we may not always be able to agree to such restrictions).
  • Right to Confidential Communications: Request that we communicate with you through alternative means or at an alternative location.
  • Right to File a Complaint: Submit a complaint to RemedyNowRX or directly to the HHS Office for Civil Rights (OCR) if you believe your privacy rights have been violated.

To exercise any of these rights, contact our Privacy Officer at privacy@remedynowrx.com.

8. Notice of Privacy Practices

As a HIPAA-covered entity, we maintain a Notice of Privacy Practices (NPP) that describes how we may use and disclose your PHI and your rights with respect to that information. You may request a copy of our full NPP by contacting us at the information below. A copy is also provided during the patient assessment process.

9. Filing a Complaint with HHS

If you believe RemedyNowRX has violated your HIPAA privacy rights, you have the right to file a complaint with the U.S. Department of Health & Human Services, Office for Civil Rights (OCR). You will not be retaliated against for filing a complaint. To file a complaint with HHS OCR, visit www.hhs.gov/hipaa/filing-a-complaint or call 1-800-368-1019.

10. Contact Our Privacy Officer

For questions, concerns, or to exercise your HIPAA rights, please contact our designated Privacy Officer:

RemedyNowRX — Privacy Officer

Email: privacy@remedynowrx.com

Website: www.remedynowrx.com