ariahealthrx.com

Privacy Policy & Notice of Health Information Privacy Practices

Effective Date: 21 August 2026 | Last Reviewed: 21 August 2026

Aria Health (“Aria Health,” “we,” “us,” or “our”) is dedicated to protecting the privacy, confidentiality, and security of our users’ personal information and health records. This Privacy Policy and Notice of Health Information Privacy Practices (“Notice”) details how we collect, use, process, disclose, and safeguard information obtained through our public website (ariahealthrx.com), our secure clinical intake portal (app.ariahealthrx.com), and related telehealth coordination services.

  1. Scope & HIPAA Business Associate Designation

This document governs two distinct categories of data:

  • General Personal Data: Information collected from visitors browsing our public informational website.
  • Protected Health Information (PHI): Individually identifiable health data created, received, transmitted, or maintained when an individual creates an account, completes an asynchronous medical intake questionnaire, or receives telemedicine services via our clinical portal at app.ariahealthrx.com.

Clinical Entity & Business Associate Role: Aria Health operates as a telehealth technology and administrative care-coordination platform. Medical care is delivered by independent, U.S.-licensed healthcare providers affiliated with independent professional medical practices (“Covered Entities”). In supporting these healthcare practices, Aria Health serves as a Business Associate under the Health Insurance Portability and Accountability Act of 1996, as amended (HIPAA), the Health Information Technology for Economic and Clinical Health (HITECH) Act, and their implementing privacy and security regulations (45 CFR Parts 160 and 164). We execute binding Business Associate Agreements (BAAs) with clinical groups, technical infrastructure vendors, and pharmacy fulfillment partners to enforce strict administrative, physical, and technical safeguards.

  1. Categories of Information We Collect

Data Category

Specific Elements Collected

Personal Identifiers

Legal first and last name, date of birth, biological sex, residential/mailing address, mobile phone number, email address, and government-issued photo identification (for age and identity verification).

Protected Health Information (PHI)

Medical history, current prescriptions, over-the-counter medications, supplement use, allergies, known health conditions, clinical assessment survey answers (e.g., BMI, ED severity, hair thinning patterns), photographic images submitted for clinical review, consultation notes, diagnoses, and e-prescription records.

Payment & Billing Data

Credit/debit card billing address and tokenized payment authorization details. All transactions are processed through Level 1 PCI-DSS compliant payment gateways. Aria Health never stores unencrypted payment card numbers.

Technical & Usage Metadata

IP addresses, device identifiers, browser types, operating systems, and access timestamps collected via secure server logs. Clinical portal logs are strictly segregated from commercial marketing analytics.

  1. Permitted Uses and Disclosures of Health Information

Under HIPAA and our Business Associate obligations, we use and disclose Protected Health Information solely for the following permitted purposes:

  • Treatment & Clinical Evaluations: Transmitting medical intake answers, uploaded imagery, and health metrics directly to licensed medical clinicians to evaluate clinical eligibility, diagnose health concerns, and issue personalized prescription treatment orders.
  • Prescription Dispensing & Pharmacy Fulfillment: Routing approved electronic prescriptions (e-prescriptions) and shipping details to partner state-licensed mail-order compounding and retail pharmacies to dispense and deliver treatments.
  • Healthcare Operations & Platform Administration: Coordinating technical support, verifying patient identities, conducting quality assessments, managing customer care inquiries, and maintaining secure platform infrastructure.
  • Payment & Billing: Collecting consultation fees and medication costs on behalf of clinical providers and dispensing pharmacies.
  • Legal & Regulatory Compliance: Disclosing information when strictly required by state or federal law, such as complying with valid subpoenas, court orders, health oversight audits, or mandatory reporting regulations.

Zero Data Brokerage / Advertising Prohibition: Aria Health does not sell, rent, lease, or trade Protected Health Information. We never disclose patient medical records, intake responses, or clinical histories to third-party data brokers, marketing agencies, or for cross-context behavioral advertising.

  1. Individual Patient Rights Under HIPAA

As a patient receiving telehealth services, you maintain specific federal rights regarding your Protected Health Information:

  1. Right to Inspect and Copy: You have the right to review and obtain electronic or physical copies of your medical and billing records maintained within our designated record sets. Requests are fulfilled within 30 days of verified receipt.
  2. Right to Request Amendments: If you believe that your health record contains inaccurate or incomplete information, you may submit a formal request to amend the record. If your provider determines the record is accurate and declines the amendment, you will receive a written explanation and may submit a statement of disagreement.
  3. Right to an Accounting of Disclosures: You have the right to request an accounting of disclosures of your PHI made for purposes outside of routine treatment, payment, and healthcare operations, covering up to six (6) years prior to the request date.
  4. Right to Request Disclosure Restrictions: You may request limitations on how your PHI is used or disclosed for treatment, payment, or operations. While providers will reasonably accommodate requests where possible, they are not legally obligated to agree to restrictions that interfere with emergency care, safety, or statutory obligations.
  5. Right to Confidential Communications: You have the right to request that our clinical team communicate with you using specific contact methods or alternative addresses (e.g., exclusively via email or a secondary phone number).
  6. Right to a Paper Copy: You may request a hard copy of this Notice at any time, even if you previously agreed to receive it electronically.
  1. Data Security & Technical Safeguards

Aria Health implements administrative, physical, and technical safeguards compliant with the HIPAA Security Rule:

  • Encryption Protocols: All communications and data transmissions across app.ariahealthrx.com are encrypted in transit using Transport Layer Security (TLS 1.2+) and encrypted at rest utilizing AES-256 encryption.
  • Role-Based Access Controls: Access to patient health data is restricted strictly to authorized medical professionals, clinical coordinators, and credentialed technical staff who require access to fulfill operational duties.
  • Audit Trails & Infrastructure Monitoring: Continuous audit logging tracks database read, write, and export operations. Regular vulnerability testing and credential rotations are conducted to prevent unauthorized system access.
  1. Data Retention Standards

We retain personal and health records in accordance with mandatory state medical board record retention laws, federal HIPAA requirements, and applicable statutes of limitations. Medical records are maintained for a minimum statutory period (typically 7 to 10 years from the date of the last clinical encounter), after which records are securely destroyed or permanently de-identified.

  1. Minor & Pediatric Privacy (COPPA Notice)

Our telehealth services, treatments, and clinical consultations are designed strictly for adult individuals aged eighteen (18) and older. We do not knowingly collect personal or medical information from minors under the age of 18. Any account discovered to belong to an underage individual will be immediately deactivated and associated non-clinical records deleted.

  1. Updates to This Notice

We reserve the right to modify this Privacy Policy and HIPAA Notice to reflect changes in legal, technical, or clinical operating standards. Any material changes will be posted to this page with an updated effective date. Continued use of our platform following notice of updates constitutes acknowledgment of the revised terms.

  1. Privacy Officer Contact & Complaint Procedures

If you have questions regarding this Notice, wish to exercise any of your HIPAA privacy rights, or believe your privacy protections have been compromised, please contact our designated Privacy Official:

Aria Health Privacy & Compliance Office

Attn: Privacy Officer

9504 Topanga Canyon Blvd

Chatsworth, CA 91311

Email: privacy@ariahealthrx.com (Subject: Attn: Privacy Officer – HIPAA Inquiry)

General Support: info@ariahealthrx.com

Filing a Formal Complaint: You may also file a formal complaint with the Secretary of the U.S. Department of Health and Human Services via the Office for Civil Rights (OCR) by visiting the HHS.gov HIPAA Complaint Portal, calling 1-800-368-1019, or writing to the OCR Regional Office. Aria Health will never penalize, discriminate, or retaliate against you in any way for filing a privacy complaint.

California Consumer Privacy Notice
(CCPA / CPRA)

Effective Date: 21 August 2026 | Last Reviewed: 21 August 2026

This California Consumer Privacy Notice (“Notice”) supplements the Aria Health Privacy Policy and applies solely to California residents (“consumers,” “you,” or “your”) in compliance with the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (collectively, “CCPA/CPRA”), and the California Confidentiality of Medical Information Act (CMIA).

  1. Statutory Exemption & Relationship to Medical Data (HIPAA / CMIA)

Under California Civil Code § 1798.145(c)(1), the CCPA does not apply to:

  • Protected Health Information (PHI) collected by a Covered Entity or Business Associate governed by the Health Insurance Portability and Accountability Act of 1996 (HIPAA).
  • Medical Information governed by the California Confidentiality of Medical Information Act (CMIA) (Cal. Civ. Code § 56 et seq.).

Important Clarification: When you submit medical history, clinical photos, or health questionnaire data via app.ariahealthrx.com, that health information is classified as PHI and is protected under HIPAA, the CMIA, and our Notice of Health Information Privacy Practices. Non-medical personal information collected through our public website (ariahealthrx.com) is governed by this California Privacy Notice.

  1. Categories of Personal Information Collected (Preceding 12 Months)

Statutory Category

Examples of Data Elements Collected

Disclosed for Business Purpose?

A. Identifiers

Name, postal address, email address, phone number, IP address, and unique online account identifiers.

Yes (IT hosting, logistics, communication vendors)

B. Personal Records (Cal. Civ. Code § 1798.80(e))

Billing name, tokenized payment card details, and contact numbers.

Yes (PCI-DSS payment gateways, billing processors)

C. Protected Classifications

Age, biological sex, gender.

Yes (Identity verification services)

D. Commercial Information

Records of consultations initiated, product categories viewed, and transaction histories.

Yes (Operational analytics and platform maintenance)

E. Internet / Network Activity

Browsing history on public pages, search queries, interaction with site widgets, and server logs.

Yes (Cloud infrastructure, web security services)

F. Geolocation Data

Approximate physical location derived from IP address (non-precise).

Yes (State-specific provider licensing routing)

G. Inferences

Consumer profile preferences reflecting interest in specific wellness categories.

No

H. Sensitive Personal Information

Account log-in credentials in combination with password.

Yes (Authentication security infrastructure)

  1. Business and Commercial Purposes for Processing

We process personal information for the following business purposes:

  • Fulfilling telehealth administrative requests, processing orders, and delivering customer support.
  • Authenticating user accounts and verifying patient identities against state licensing databases.
  • Monitoring platform integrity, detecting cybersecurity incidents, and debugging errors.
  • Complying with California state regulatory filings and statutory legal obligations.
  1. Statement on Sale and Sharing of Personal Information
  • No Sale of Personal Data: Aria Health does not sell consumer personal information for monetary or other valuable consideration.
  • No Cross-Context Behavioral Sharing: We do not share consumer personal information or medical browsing data with third parties for cross-context behavioral advertising.
  • No Minors Under 16: We do not knowingly sell or share personal information of consumers under sixteen (16) years of age.
  1. Your California Consumer Privacy Rights

Subject to verification and statutory exceptions, California residents hold the following legal rights:

  • Right to Know / Access: You may request that we disclose the categories and specific pieces of personal information collected, the sources of collection, the business purposes for collecting the data, and the third parties with whom it was disclosed over the past 12 months.
  • Right to Delete: You may request the deletion of personal information we have collected from you, subject to legal recordkeeping obligations (such as mandatory medical chart retention laws).
  • Right to Correct: You may request that we correct inaccurate personal information maintained in our administrative records.
  • Right to Limit Sensitive Personal Information: You have the right to limit the use of Sensitive Personal Information to only those uses necessary to perform requested services.
  • Right to Non-Discrimination: Aria Health will never deny services, charge different rates, or provide a different level of quality because you exercised any of your rights under California privacy law.
  1. How to Exercise Your California Rights

To submit a verifiable consumer request:

  • Online Form: Visit our California Privacy Rights Request Portal
  • Email Request: Send an email to privacy@ariahealthrx.com with the subject line: “California Privacy Rights Request”
  • Mailing Address:
    Aria Health
    Attn: California Privacy Compliance
    9504 Topanga Canyon Blvd
    Chatsworth, CA 91311

Verification Process: To safeguard your data, we verify your identity by matching data points provided in your request with existing account information. If you designate an authorized agent to submit a request on your behalf, the agent must provide proof of written authorization and power of attorney. We confirm receipt of requests within ten (10) business days and provide a substantive response within forty-five (45) calendar days.

Scroll to Top