The short version
- We do not sell your health information, ever, and we do not use it for advertising.
- Your visit is protected health information under HIPAA.
- The tick identification tool is separate and holds no medical record. Photos there are deleted after identification unless you choose otherwise.
- You can request your records, corrections, or a copy at any time.
This summary is for orientation only. The policy below is what governs.
Tickortreat LLC (“Tickortreat,” “we,” “us,” or “our”) is committed to protecting the privacy of our patients and website visitors. This Privacy Policy describes how we collect, use, disclose, and protect your information when you use our telehealth service and website.
Information we collect
Patient information
When you submit a visit through our platform, we collect personal and health information necessary to provide care, including:
- Name, date of birth, sex, weight, and contact information
- The state you are physically located in at the time of the visit
- Information about the tick bite: timing, location on the body, tick type, and attachment duration
- Photographs of the tick and the bite site
- Medical history, including allergies, medications, pregnancy status, and medical conditions
- Preferred pharmacy information
- Payment information, processed securely through Stripe. We do not store credit card numbers
Website information
When you visit our website we may automatically collect basic usage data such as browser type, device type, pages visited, and referring URL.
How we use your information
- To provide telehealth evaluations and prescribe medication when clinically appropriate
- To communicate with you about your visit, including confirmations, follow-ups, and clinical information
- To process payment for our services
- To send prescriptions to your preferred pharmacy
- To improve our service and clinical protocols
- To comply with legal and regulatory requirements
Protected health information
Your health information is protected under the Health Insurance Portability and Accountability Act (HIPAA). We maintain administrative, technical, and physical safeguards to protect your PHI, including encryption of data in transit and at rest, role-based access controls, and audit logging.
We do not sell your health information. We do not share your health information for marketing purposes. We will never use your health data for advertising.
How we share your information
We share your information only in the following circumstances:
- Healthcare providers: with licensed clinicians who review your visit and prescribe treatment
- Pharmacies: to transmit prescriptions to the pharmacy you select
- Service providers: with vendors who help us operate our platform, such as hosting, payment processing and e-prescribing, all of whom are bound by Business Associate Agreements as required by HIPAA
- Legal requirements: when required by law, regulation, court order, or governmental authority
- Your consent: with your explicit written consent
The tick identification tool
Our photo-based tick identification tool runs separately from our clinical service, and the separation is deliberate rather than incidental.
- Nothing you submit to the identification tool reaches a clinician, enters a medical record, or affects whether you can be seen.
- No identifier, cookie or analytics identity is shared between the identification tool and the clinical service. A visit never pre-fills from an identification, and will ask you for the information it needs from scratch.
- Submissions are not protected health information, because they are not part of a clinical encounter. We treat the photographs with care regardless.
- Photographs are deleted after identification unless you explicitly choose to let us keep them. Declining is the default and does not change the result you receive.
- If you do consent, your photograph and any date and general area you supplied may be retained in a research collection used to improve tick identification. No name, no email, and no link to any medical visit is attached.
- You may request deletion of a submission at any time.
Data security
- Encryption of health data in transit (TLS) and at rest (AES-256)
- HIPAA-compliant hosting with signed Business Associate Agreements
- Role-based access controls limiting who can view patient data
- Audit logging of access to patient records
- Regular security reviews
Data retention
We retain patient records in accordance with applicable state and federal requirements. Medical records are retained for a minimum of seven years for adults, and for minors until the age of majority plus the applicable state retention period. You may request a copy of your records at any time.
Your rights
- Access your health information and request copies of your records
- Request corrections to inaccurate information
- Request restrictions on how your information is used or disclosed
- Receive an accounting of disclosures of your health information
- File a complaint if you believe your privacy rights have been violated
Children’s privacy
Our service is used by parents and guardians on behalf of minor children. We collect health information about minors only as provided by their parent or legal guardian as part of a telehealth visit. We do not knowingly collect personal information directly from children under 13.
Cookies, tracking and advertising
Our clinical service uses only essential cookies necessary for the functioning of the site. We do not place advertising cookies, retargeting pixels, or social media tracking scripts on any page where you provide health information, and we never use health information for advertising or audience targeting.
Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version on this page with a revised “Last updated” date. Your continued use of our service after changes are posted constitutes acceptance of the updated policy.
Questions, or to exercise your rights
Tickortreat LLC · Townshend, Vermont
hello@tickortreat.com
