AURUM← Back
Legal

Notice of Privacy Practices

Effective date: April 2026

THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.

Aurum Health, Inc. is committed to protecting the privacy of your health information. This Notice describes the legal obligations of Aurum Health and our independent physician network partners regarding your Protected Health Information (PHI) under HIPAA and its implementing regulations.

How We May Use and Disclose Your PHI

Treatment

We use and disclose your PHI to provide, coordinate, and manage your health care. This includes sharing your lab results and intake data with the licensed physicians who review your protocol, sharing prescription information with our compounding pharmacy partners to fulfill medications, and sharing specimen data with our laboratory partners (Quest Diagnostics, Labcorp, Getlabs) to process your lab draws.

Payment

We use and disclose your PHI to obtain payment for services, including billing for membership fees, lab panels, and medications, and maintaining records of transactions.

Healthcare Operations

We use and disclose your PHI to support quality improvement, clinical review, and platform improvement. We may use de-identified health information (which is not PHI under HIPAA per 45 CFR §164.514) to improve our AI models and clinical knowledge base.

Required by Law

We will disclose your PHI when required to do so by applicable federal or state law, including in response to a court order, subpoena, or other legal process.

To Avert a Serious Threat to Health or Safety

We may disclose your PHI if we believe in good faith that the disclosure is necessary to prevent or lessen a serious and imminent threat to the health or safety of you or another person.

Other Permitted Uses

  • Public health activities as required or permitted by law
  • Health oversight activities by government agencies
  • Workers’ compensation as required by applicable law
  • Research, subject to an IRB waiver or your written authorization

All other uses and disclosures of your PHI require your written authorization, which you may revoke at any time in writing.

Your Rights Regarding Your PHI

Right to Inspect and Copy

You may inspect and obtain a copy of your PHI, including lab results, intake records, and clinical notes. Submit requests in writing to privacy@aurumhealth.io. We will respond within 30 days. A reasonable cost-based fee may apply for copies.

Right to Amend

If you believe PHI we maintain is incorrect or incomplete, you may request an amendment in writing with a reason. We may deny the request under certain circumstances and will explain any denial in writing.

Right to an Accounting of Disclosures

You may request a list of disclosures of your PHI made in the six years prior to your request, other than disclosures for treatment, payment, or healthcare operations.

Right to Request Restrictions

You may request restrictions on how we use or disclose your PHI. We are not required to agree, except when you have paid out of pocket in full for a service and request we not disclose to a health plan.

Right to Request Confidential Communications

You may request that we communicate with you in a specific way or at a specific location (e.g., email only, not phone). We will accommodate reasonable requests.

Right to a Paper Copy of This Notice

You have the right to a paper copy of this Notice at any time. Email privacy@aurumhealth.io to request one.

Our Duties

  • Maintain the privacy of your PHI
  • Provide you with this Notice of our legal duties and privacy practices
  • Follow the terms of the Notice currently in effect
  • Notify you in the event of a breach of your unsecured PHI

Changes to This Notice

We reserve the right to change this Notice at any time and make new provisions effective for all PHI we maintain. The effective date of the current Notice is shown at the top of this document. We will provide notice to active members of any material changes.

Complaints

If you believe your privacy rights have been violated, you may file a complaint with us or with HHS. You will not be retaliated against for filing a complaint.

  • Aurum Health: privacy@aurumhealth.io
  • HHS Office for Civil Rights: hhs.gov/ocr/privacy/hipaa/complaints/

Contact

Aurum Health Privacy Office

Email: privacy@aurumhealth.io

© 2026 Aurum Health, Inc. All rights reserved.
Privacy PolicyTerms of ServiceHIPAA Notice