Privacy Policy
Effective Date: June 1, 2026
Information We Collect
Care Bridge Medical, Inc. ("Care Bridge," "we," "us," or "our") collects information you provide directly when you create an account, submit a case, or communicate with us. We also collect certain information automatically when you use our platform.
Information you provide directly includes:
- Account information such as your name, email address, phone number, and date of birth
- Medical records, diagnostic reports, imaging studies, lab results, and other clinical documents you upload
- Health information you provide through intake forms, symptom questionnaires, and consultations
- Payment information processed through our secure payment provider (Stripe)
- Communications with Care Bridge staff, care coordinators, and physicians through our secure messaging system
Information Collected Automatically
When you use our platform, we automatically collect:
- Device information including browser type, operating system, and device identifiers
- Usage data such as pages visited, features used, and session duration
- Log data including IP addresses, access times, and referring URLs
How We Use Your Information
We use your information to provide, maintain, and improve our medical second opinion services. Specifically, we use your information to:
- Facilitate physician review of your medical records and delivery of second opinion reports
- Match you with appropriate specialist physicians
- Enable real-time bilingual translation during video consultations
- Process payments and provide reimbursement support documentation
- Communicate with you about your cases, appointments, and account
- Maintain audit logs as required by healthcare regulations
- Improve our platform and develop new features
HIPAA Compliance
Care Bridge is fully compliant with the Health Insurance Portability and Accountability Act (HIPAA). We implement administrative, physical, and technical safeguards to protect your protected health information (PHI). Our HIPAA compliance program includes:
- Designation of a Privacy Officer responsible for HIPAA compliance
- Regular risk assessments and security audits
- Workforce training on privacy and security practices
- Documented policies and procedures for PHI handling
- Breach notification procedures in compliance with HIPAA requirements
Encryption and Security
We employ industry-standard encryption to protect your data:
- All data at rest is encrypted using AES-256 encryption
- All data in transit is encrypted using TLS 1.3
- Encryption keys are managed through AWS Key Management Service (KMS) with automatic key rotation
- Database connections use encrypted channels exclusively
Cross-Border Data Transfer
Care Bridge serves patients in Asian jurisdictions including Taiwan, Hong Kong, and Singapore. Your data is transferred to and stored on servers located in the United States. By using our services, you consent to this cross-border transfer of your personal and health information.
We take appropriate measures to ensure that your data receives adequate protection in accordance with applicable data protection laws, including maintaining HIPAA-compliant infrastructure and entering into appropriate data processing agreements.
Third-Party Service Providers
We engage third-party service providers who may access your information in the course of providing services to us. All third-party providers who may access PHI are required to sign Business Associate Agreements (BAAs) before accessing any protected health information. Our third-party providers include:
- Cloud infrastructure providers for secure data storage and processing
- Payment processors for secure transaction handling (no PHI is included in payment metadata)
- AI service providers for translation, document organization, and administrative assistance (under BAA)
- Communication service providers for secure notifications (all notifications are zero-PHI)
Data Retention
We retain your medical records and consultation data for the period required by applicable healthcare regulations and as necessary to provide our services. Account information is retained for as long as your account remains active.
When you request account deletion, we will remove your personal information within 30 days, subject to legal and regulatory retention requirements. Certain anonymized or aggregated data may be retained for analytical purposes.
Your Rights
Under HIPAA and applicable privacy laws, you have the right to:
- Access your protected health information and request copies of your medical records
- Request corrections to inaccurate health information
- Request restrictions on certain uses and disclosures of your PHI
- Receive an accounting of disclosures of your PHI
- Request confidential communications through alternative means or at alternative locations
- File a complaint if you believe your privacy rights have been violated
Children's Privacy
Care Bridge is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a minor, please contact us immediately so we can take appropriate steps to remove that information.
Contact Us
If you have questions about this Privacy Policy or wish to exercise your privacy rights, please contact us at:
Care Bridge Medical, Inc.
Email: privacy@carebridge.dev
Please do not include any medical information or protected health information in email communications. Use the secure portal for all medical communications.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable laws. We will notify you of any material changes by posting the updated policy on our platform and updating the effective date. Your continued use of Care Bridge after such changes constitutes your acceptance of the revised policy.
Last Updated: June 1, 2026