Privacy Policy

Vanguard Precision Health, PLLC ("we," "us," or "our") Website: vgprecisionhealth.com Effective Date: March 14, 2026 Last Updated: September 30, 2026

1. Introduction

This Privacy Policy explains how we collect, use, disclose, and protect information when you visit vgprecisionhealth.com, use our patient portal, mobile applications, or online tools, or otherwise interact with us online (the "Services").

Please read it carefully. If you do not agree with this Policy, please do not use the Services.

Important: This Privacy Policy applies to information collected through our Services. If we provide you with health care, your medical records are also governed by our Notice of Privacy Practices under the Health Insurance Portability and Accountability Act ("HIPAA"), available at [LINK]. If there is a conflict regarding your protected health information, the Notice of Privacy Practices controls.

2. HIPAA and Protected Health Information

Some information we handle is "Protected Health Information" or "PHI" under HIPAA (45 C.F.R. Parts 160 and 164). PHI is individually identifiable health information that relates to your health condition, care, or payment for care and is held by us as a covered entity or business associate.

PHI is used and disclosed only as permitted by HIPAA or as you authorize in writing.

We do not sell PHI or use or disclose it for marketing without your written authorization, except as HIPAA permits.

You may revoke an authorization at any time in writing, except to the extent we have already acted on it.

Information you provide through the Services that is not PHI (for example, general browsing data or a newsletter signup by a non-patient) is governed by this Privacy Policy and applicable consumer protection laws, including Section 5 of the FTC Act, the FTC Health Breach Notification Rule (16 C.F.R. Part 318), and state law.

3. Information We Collect

3.1 Information You Provide to Us

Identifiers and contact information: name, email, phone number, mailing address, date of birth.

Account information: username, password, security questions.

Health information: symptoms, conditions, medications, medical history, appointment details, test results, provider messages, and information entered in forms or symptom checkers.

Insurance and payment information: insurer, member ID, billing address, payment card details (processed by our payment processor).

Communications: messages, survey responses, support requests, and call recordings where permitted by law.

Job applicant information, if you apply through our site.

3.2 Information Collected Automatically

Device and usage data: IP address, browser type, operating system, device identifiers, pages viewed, links clicked, referring URLs, and date/time of visits.

Approximate location derived from your IP address. We collect precise geolocation only with your consent.

Cookies, pixels, and similar technologies (see Section 6).

3.3 Information from Other Sources

Health care providers, laboratories, pharmacies, and health plans (as permitted by law).

Health information exchanges and referral partners.

Identity verification and fraud-prevention services.

3.4 Sensitive Information

Some data we collect is considered "sensitive" or "consumer health data" under state laws, including health conditions, diagnoses, treatment, reproductive or sexual health information, biometric data, and precise geolocation. We use sensitive information only for the purposes described in this Policy, and where required, with your consent.

4. How We Use Information

We use information to:

Provide, schedule, and manage care and Services, and operate the patient portal.

Communicate with you about appointments, results, billing, and your care.

Process payments and verify insurance.

Verify your identity and secure accounts.

Respond to inquiries and provide support.

Improve, test, and maintain the Services.

Conduct quality assessment, compliance, and operations activities.

Detect and prevent fraud, security incidents, and illegal activity.

Comply with legal obligations and respond to lawful requests.

Send communications you have agreed to receive. Marketing that involves PHI is sent only with your authorization.

5. How We Disclose Information

We do not sell your personal information or PHI. We may share information as follows:

Treatment, payment, and health care operations: with your providers, health plans, and others as HIPAA permits.

Service providers and business associates: vendors that host our systems, process payments, send messages, provide analytics, or support our operations. They are contractually required to protect the information, and where they handle PHI, they sign a HIPAA Business Associate Agreement.

Legal and regulatory: to comply with law, subpoenas, court orders, or government requests; to report public health matters, abuse, or neglect; and to protect rights, safety, and security.

Business transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to applicable law.

With your consent or at your direction: for example, when you ask us to send records to another provider or app.

De-identified or aggregated data: information that cannot reasonably identify you, disclosed in accordance with HIPAA de-identification standards (45 C.F.R. § 164.514) or applicable state law. We will not attempt to re-identify it.

Substance use disorder records. Records covered by 42 C.F.R. Part 2 receive additional protections and are disclosed only as that regulation allows.

Other sensitive records. Certain records (such as mental health, HIV/AIDS, genetic, and reproductive health information) may receive additional protection under federal or state law, and we comply with the stricter rule where it applies.

6. Cookies, Tracking Technologies, and Analytics

We and our vendors may use cookies, web beacons, pixels, SDKs, and similar tools to operate the Services, remember preferences, measure performance, and improve the site.

Authenticated pages (such as the patient portal and appointment or billing pages): we do not use third-party advertising or marketing trackers that would disclose PHI to third parties without a HIPAA-compliant agreement or your authorization.

Unauthenticated pages: we use only [analytics tools, e.g., list vendors] configured to limit collection of identifiable health information.

We do not use tracking technologies to share health information with advertising platforms for targeted advertising.

Your choices: You can manage cookies through your browser settings or our cookie banner/preference tool at [LINK]. Blocking some cookies may affect functionality.

Do Not Track and Global Privacy Control. We honor opt-out preference signals such as the Global Privacy Control (GPC) where required by law. Because there is no uniform standard for "Do Not Track" browser signals, we otherwise do not respond to them.

7. Your Choices

Communications: You may opt out of marketing emails by using the unsubscribe link, and out of text messages by replying STOP. We may still send you necessary service or care-related messages.

Account information: You may update your account details in your profile settings.

Cookies: See Section 6.

8. Your HIPAA Rights

Regarding your PHI, you have the right to:

Access and obtain a copy of your records, including in electronic form (45 C.F.R. § 164.524).

Request amendment of information you believe is incorrect (§ 164.526).

Receive an accounting of certain disclosures (§ 164.528).

Request restrictions on certain uses and disclosures, including a right to restrict disclosures to your health plan for services you paid for in full out of pocket (§ 164.522).

Request confidential communications by alternative means or locations.

Receive a paper copy of our Notice of Privacy Practices.

File a complaint with us or with the U.S. Department of Health and Human Services Office for Civil Rights (www.hhs.gov/ocr/complaints). We will not retaliate against you for filing a complaint.

To exercise these rights, contact our Privacy Officer using the details in Section 15.

9. State Privacy Rights

Depending on where you live, you may have additional rights under state laws, including (but not limited to) California, Colorado, Connecticut, Virginia, Texas, Oregon, and other states with comprehensive privacy laws, as well as Washington's My Health My Data Act and Nevada's consumer health data law. Data that is PHI under HIPAA is generally exempt from these laws, but rights may apply to other personal information we collect.

Where applicable, you may have the right to:

Know/access the personal information we have collected about you.

Delete personal information, subject to legal exceptions.

Correct inaccurate information.

Opt out of the sale or sharing of personal information, targeted advertising, and certain profiling. (We do not sell personal information or share it for cross-context behavioral advertising.)

Limit the use of sensitive personal information.

Withdraw consent to the collection or sharing of consumer health data.

Not be discriminated against for exercising your rights.

Appeal our decision on a request, where state law provides that right.

How to submit a request: Email contact@vgprecisionhealth.com. We will verify your identity before responding, and we will respond within the time required by law (generally 45 days). You may use an authorized agent, subject to verification.

California Notice at Collection (CCPA/CPRA)

In the past 12 months, we have collected the categories of information described in Section 3 (identifiers, customer records, protected classifications, commercial information, internet activity, geolocation, professional information, and sensitive personal information). We have disclosed these categories for business purposes to the recipients described in Section 5. We have not sold or shared personal information for cross-context behavioral advertising. We retain information as described in Section 10. California residents may also request information about disclosures to third parties for their direct marketing purposes under California's "Shine the Light" law (Cal. Civ. Code § 1798.83).

Washington and Nevada Consumer Health Data

Where these laws apply, we collect and share consumer health data only as needed to provide the Services you request or with your consent. You may request a list of the third parties and affiliates with whom we have shared or sold your consumer health data, and request deletion of that data, using the methods above.

10. Data Retention

We retain information for as long as needed to provide the Services, meet legal, medical-record, tax, and audit requirements, resolve disputes, and enforce our agreements. Medical record retention periods vary by state and record type, and HIPAA requires us to retain certain compliance documentation for six years. When information is no longer needed, we securely delete or de-identify it.

11. Security

We use administrative, technical, and physical safeguards designed to protect information, consistent with the HIPAA Security Rule (45 C.F.R. Part 164, Subpart C), including:

Encryption of data in transit and at rest where appropriate.

Access controls, unique user IDs, and audit logging.

Workforce training and confidentiality obligations.

Risk assessments and vendor oversight.

No system is completely secure, and we cannot guarantee absolute security. Please protect your password, use a unique and strong password, and do not share your login credentials. Avoid sending sensitive health information by regular email or unsecured text.

12. Data Breach Notification

If a breach of your unsecured PHI occurs, we will notify you, HHS, and (where required) the media, in accordance with the HIPAA Breach Notification Rule (45 C.F.R. §§ 164.400–414). For personal health information not covered by HIPAA, we will comply with the FTC Health Breach Notification Rule and applicable state breach notification laws.

13. Children's Privacy

The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13 through the website without verifiable parental consent, as required by the Children's Online Privacy Protection Act (COPPA). Parents and legal guardians may access and manage a minor's health information as permitted by HIPAA and state law. If you believe a child under 13 has provided us information without consent, contact us at the address below and we will delete it.

14. Third-Party Links and Services

The Services may link to websites, apps, or tools operated by third parties (for example, pharmacies, payment processors, or health-information resources). We do not control them and are not responsible for their privacy practices. Please review their policies. If you direct us to send your health information to a third-party app, that app's use of it is governed by its own policies, and HIPAA may not apply to it.

15. Not for Emergencies

The Services are not for medical emergencies. If you believe you are experiencing a medical emergency, call 911 or go to the nearest emergency room. If you or someone you know is in crisis, call or text 988 (Suicide & Crisis Lifeline). Information on this website is for general informational purposes and is not a substitute for professional medical advice, diagnosis, or treatment.

16. Changes to This Policy

We may update this Policy from time to time. We will post the updated version with a new "Last Updated" date and, where required by law, provide additional notice or obtain your consent for material changes affecting how we use health information you have already provided.

17. Contact Us

Privacy Officer Vanguard Precision Health, PLLC Email: contact@vgprecisionhealth.com

To file a HIPAA complaint with the federal government: U.S. Department of Health and Human Services, Office for Civil Rights 200 Independence Avenue, S.W., Washington, D.C. 20201 1-877-696-6775 | www.hhs.gov/ocr/complaints