Legal
Health Universe is committed to protecting the privacy and security of the information entrusted to our platform. This policy describes what we collect, how we use it, and the choices available to you.
This Privacy Policy applies to the Health Universe websites and the Health Universe Platform. Where Health Universe processes Protected Health Information (“PHI”) on behalf of a healthcare organization or professional as a business associate under the Health Insurance Portability and Accountability Act (“HIPAA”), that processing is governed by the applicable negotiated Business Associate Agreement (“BAA”) or, where no negotiated BAA has been executed, the Standard Business Associate Terms in our Terms of Use. Information exchanged through the TEFCA network is also governed by the applicable TEFCA Subparticipant Terms of Participation (“ToP”). If this Privacy Policy conflicts with an executed BAA, the Standard Business Associate Terms, the ToP, or another executed agreement, that agreement controls with respect to the information it governs. Health information that individuals submit about themselves, or about another individual with that individual’s express permission, in a personal capacity is not governed by HIPAA and is handled as described in this policy. Your use of the Health Universe Platform is also subject to our Terms of Use.
When you create an account, we collect information such as your name, email address, organization, and role. For clinicians and other users authorized to access clinical records, we also collect professional verification information, which may include your National Provider Identifier (NPI), state license number, and identity-verification data.
The Health Universe Platform may process identifiable clinical information, including PHI, on behalf of the healthcare organizations and professionals that use it. This may include information submitted to the platform by or on behalf of our customers and clinical records retrieved through connected health information networks, including the Trusted Exchange Framework and Common Agreement (“TEFCA”) network, solely for the Treatment purpose described below. We process PHI as a business associate and use or disclose it only as permitted by the applicable BAA or the Standard Business Associate Terms, the ToP where applicable, and applicable law.
If you use the Health Universe Platform in a personal capacity, you may submit health information about yourself, or about another individual if that individual has given you their express permission; you are responsible for obtaining and honoring that permission. Because you are not acting as a HIPAA covered entity or business associate when submitting this information, HIPAA does not apply to it; it is consumer health data governed by this Privacy Policy and applicable consumer-health privacy laws, including the FTC Health Breach Notification Rule and state health-data privacy laws where applicable. With your consent, we process this information to provide the services you request and, after de-identification, as described in “De-Identified Data” below. We do not sell it in identifiable form, and we will provide breach notifications as required by applicable law. Individual accounts do not include access to TEFCA record retrieval.
We collect operational, performance, availability, usage, integrity, and security data generated by use of the platform, such as log data, device and browser information, and audit records of platform activity.
We use the information we collect to provide, support, secure, and improve the Health Universe Platform; to verify the identity and credentials of users authorized to access clinical records; to maintain audit trails and purpose-of-use records required by HIPAA and TEFCA; to communicate with you about the services; to create De-Identified Data as described below; and to comply with legal obligations. PHI is used and disclosed only as permitted by the applicable BAA or the Standard Business Associate Terms, the ToP where applicable, and applicable law.
We may de-identify information submitted to or generated through the Health Universe Platform, including PHI, and create aggregated and benchmark data, in accordance with applicable law and our agreements with customers. We may use, license, and sell de-identified and aggregated data to third parties, including for analytics, benchmarking, research, service improvement, and the development and training of artificial intelligence products. This applies to information submitted before and after acceptance of our current Terms of Use.
De-identified patient information is de-identified using the HIPAA Safe Harbor method, the HIPAA Expert Determination method, or both, under 45 C.F.R. § 164.514(b). We maintain and use de-identified information only in de-identified form, we do not attempt to re-identify it, and we contractually prohibit recipients from re-identifying it or further disclosing it except to parties bound by the same restrictions.
Information retrieved through the TEFCA network, and records subject to 42 C.F.R. Part 2 that have not been de-identified in accordance with that Part, are never used for these purposes.
We do not sell personal information or PHI, and we do not share personal or medical information with third parties without appropriate authorization except as described in this policy. We may share information with: (a) service providers and subprocessors that support the platform under contracts requiring confidentiality and security protections consistent with this policy and, where applicable, HIPAA; (b) connected health information networks, in order to fulfill Treatment-purpose record requests as described below; (c) legal and regulatory authorities where required by law; and (d) a successor entity in connection with a merger, acquisition, or sale of assets, subject to this policy. We may share, license, and sell de-identified and aggregated data as described in “De-Identified Data” above; such data does not include personally identifiable information.
Health Universe participates in the TEFCA network as a Participant of Kno2, a Qualified Health Information Network (QHIN). Through this connectivity, authorized clinicians and healthcare organizations may retrieve a patient’s clinical records from participating organizations nationwide solely for the Treatment exchange purpose as defined under the TEFCA Common Agreement. Every query is purpose-of-use tagged, logged, encrypted, and audit-tracked. Health Universe accesses, uses, and retains TEFCA-retrieved information only as necessary to fulfill the Treatment-purpose request and deliver the results to the requesting organization, consistent with the ToP and applicable Standard Operating Procedures. TEFCA-retrieved information is never de-identified, aggregated, licensed, sold, or used to train artificial intelligence models. Individuals who have questions about records exchanged through TEFCA, or who wish to exercise choices regarding health information exchange, should contact their healthcare provider, and may find more information about TEFCA at HealthIT.gov.
We retain personal information only as long as needed for the purposes described in this policy, to comply with legal, regulatory, and contractual obligations, and to resolve disputes. Clinical information retrieved through the TEFCA network is not retained as a system of record: Health Universe may purge retrieved records when they are no longer needed to provide the services, in accordance with our retention practices, the applicable BAA, the Standard Business Associate Terms, or the ToP, and applicable law. De-identified and aggregated data is not personal information and may be retained indefinitely. We retain compliance documentation, such as audit logs and privacy and security program records, for the periods required by HIPAA and TEFCA, which is generally six years for required documentation.
We maintain a written information security program with administrative, technical, and physical safeguards designed to protect the security, confidentiality, and integrity of the information we process, consistent with the HIPAA Security Rule, TEFCA requirements, and industry frameworks. Safeguards include encryption in transit and at rest, role-based access controls, identity verification for clinical-record access, audit logging, and regular review and updating of our security measures. No system is perfectly secure; we will notify affected customers and individuals of security incidents as required by applicable law and our agreements.
Our websites use cookies and similar technologies. Necessary cookies enable core site functionality and cannot be disabled. Functional cookies remember your preferences. Performance cookies help us understand how visitors use the site so we can improve it. Interest-based cookies may be used to personalize content. You can control cookies through your browser settings; disabling some cookies may affect site functionality.
You may access, correct, or request deletion of your account information by contacting us. Depending on where you live, you may have additional rights under applicable privacy laws, including rights to know, delete, correct, or limit certain uses of your personal information; we will honor verified requests as required by law. Deletion requests apply to identifiable information and do not extend to data that has already been de-identified. Acceptance of our Terms of Use is a condition of using the Health Universe Platform; if you do not accept them, your access will end and you may request an export of your information as described in the Terms of Use. For requests concerning clinical records, including records retrieved through health information networks, please contact your healthcare provider or the organization that holds your medical record, as Health Universe processes that information on their behalf and is not the medical-records custodian.
The Health Universe Platform is intended for use by healthcare professionals and other authorized adult users. It is not directed to children, and we do not knowingly collect personal information directly from children. Patient records processed on behalf of our customers may include information about minors receiving care; that information is handled as PHI under the applicable BAA or the Standard Business Associate Terms and applicable law.
If you believe you have identified a security vulnerability in the Health Universe Platform or our websites, please report it to security@healthuniverse.com. We appreciate responsible disclosure and will work promptly to investigate and remediate confirmed issues.
We may update this Privacy Policy from time to time by posting a revised version with an updated “Last updated” date. Material changes will be communicated through the platform or by other reasonable means, and material changes to how we use data will be presented for your affirmative acceptance. If you have questions about this policy or our privacy practices, please contact us at security@healthuniverse.com or at Health Universe, Inc., 2261 Market Street #5116, San Francisco, CA 94114.
Last updated · September 28, 2026