Consumer Health Data Notice
How we handle consumer health data outside HIPAA
Effective Date: October 1, 2025
Last Updated: October 15, 2025
This notice describes how Caremaze collects, uses, and shares your consumer health data when we process it outside of HIPAA-covered relationships.
What Is Consumer Health Data?
Consumer health data is personal information that we collect directly from you about your health, healthcare, or payment for healthcare when it is not Protected Health Information (PHI) covered by HIPAA.
When does this apply? This notice applies when you interact with Caremaze directly as a consumer, and not through a healthcare provider acting as a HIPAA Covered Entity.
Categories of Consumer Health Data We Collect
Health and Medical Information
- Appointment requests and reasons for visit
- Symptoms, conditions, or health concerns you describe
- Medications, allergies, or medical history you provide
- Healthcare provider names and specialties
- Referral or care coordination information
Related Personal Information
- Name, contact information (email, phone)
- Date of birth, age
- Insurance plan details (carrier, member ID, group ID)
- Location (coarse, from IP address)
- Device and usage data when linked to health interactions
How We Collect Consumer Health Data
- Directly from you: When you create an account, book appointments, use our voice/phone agents, or communicate with us
- Automatically: Usage data, device information, call transcripts/recordings when you use our Services
- From healthcare providers: When they share information as part of care coordination (and authorized by you)
- From insurers: Eligibility and coverage information you authorize us to obtain
How We Use Consumer Health Data
We use consumer health data to:
- Schedule and coordinate appointments with healthcare providers
- Facilitate care transitions and discharge planning
- Verify insurance eligibility and coverage
- Provide customer support and resolve issues
- Improve our Services through quality assurance and safety reviews
- Prevent fraud and abuse and ensure platform security
- Comply with legal obligations and protect rights and safety
How We Share Consumer Health Data
We share consumer health data only as described below:
Healthcare Providers
We share your appointment details, health information, and contact information with providers to schedule and coordinate your care.
Service Providers
We share data with vendors who help us operate the Services:
- Cloud hosting and data storage
- Communication services (email, SMS, voice)
- Identity verification and fraud prevention
- Customer support tools
- Quality assurance and transcription
All service providers are contractually required to protect your data and use it only for the purposes we specify.
Insurers (With Authorization)
When you provide consent, we share information with your insurance carrier to verify eligibility and coverage.
Legal and Safety
We may disclose data to comply with law, legal process, or to protect rights, safety, and security.
Business Transfers
In a merger, acquisition, or sale of assets, your data may be transferred under the protections of this notice.
We do NOT:
- Sell consumer health data for money
- Share consumer health data for cross-context behavioral advertising
- Use geofencing near healthcare facilities to target you with ads or track you
Your Rights and Choices
Access & Deletion
You have the right to access your consumer health data and request deletion (subject to legal exceptions).
Opt-Out Rights
Where required by law (e.g., Washington, Nevada), you may opt out of certain uses and disclosures of consumer health data.
Withdraw Consent
If we collected consumer health data based on your consent, you may withdraw consent at any time (though this won't affect processing done before withdrawal).
To exercise these rights:
Visit our Privacy Rights Portal or contact:
- Email: support@caremaze.ai
- Phone: +1 (650) 629-3144
- Mail: 380 Portage Ave, Palo Alto, CA 94306
Data Retention
We retain consumer health data only as long as needed for the purposes described in this notice and as required by law:
- Active accounts: Duration of account + 12 months
- Health records: Up to 7 years for legal/compliance requirements
- Call recordings/transcripts: Up to 7 years
When data is deleted, we remove it from active systems and instruct our service providers to do the same.
Security
We protect consumer health data using:
- Encryption in transit and at rest
- Access controls and authentication
- Security monitoring and incident response
- Regular security assessments and training
In case of a breach affecting personal health records, we will notify you as required by the FTC Health Breach Notification Rule and applicable state laws.
State-Specific Requirements
Washington (My Health My Data Act)
Washington residents have specific rights regarding consumer health data, including the right to confirm, access, delete, and withdraw consent. We do not use geofencing around healthcare facilities and obtain consent for collection and sharing as required.
Nevada (SB 370)
Nevada residents may opt out of the sale of certain health information. We do not sell consumer health data.
Other States
Similar rights may be available under comprehensive state privacy laws in California, Virginia, Colorado, Connecticut, and other states. See our Privacy Policy for full details.
HIPAA vs. Consumer Health Data
When HIPAA applies: If a healthcare provider uses our Services and we process PHI on their behalf, we act as a HIPAA Business Associate. In those cases, HIPAA governs our handling of that data.
When consumer health data laws apply: When you use our Services directly (not through a HIPAA Covered Entity), state consumer health data laws apply.
Questions or Concerns?
For questions about this notice or to exercise your rights:
- Visit our Privacy Rights Portal
- Email support@caremaze.ai
- Call +1 (650) 629-3144
- Review our full Privacy Policy