WHITEGLOVEMD

PRIVACY · SECURITY · PATIENT RIGHTS

Your medical record should move with purpose—not exposure.

A useful privacy program is more than a badge. It defines why information is collected, who needs it, how access is limited, and what you can ask us to do.

THE STANDARD

Privacy, security, and breach response are different obligations.

The HIPAA Privacy Rule addresses uses and disclosures of protected health information. The Security Rule addresses safeguards for electronic PHI. The Breach Notification Rule addresses required notice after certain breaches of unsecured PHI.

WHITEGLOVEMD uses a defined consent, record, review, and delivery workflow to support those responsibilities. Security is an ongoing operating discipline; no website can honestly promise that all risk has been eliminated.

HOW THE PROGRAM IS ORGANIZED

Three layers of protection.

HIPAA is technology-neutral. Useful safeguards combine people, process, and technical controls appropriate to the information and risk.

01

Administrative safeguards

Privacy responsibilities, workforce expectations, access review, incident handling, and vendor oversight support the way protected health information is handled.

  • Minimum-necessary access
  • Privacy and security procedures
  • Role and vendor review
02

Technical safeguards

Secure sign-in, role-limited access, encrypted transmission and storage, and activity records help protect electronic information across the platform.

  • Access controls
  • Encryption
  • Activity logging
03

Operational safeguards

The case workflow separates intake, record collection, physician review, and report delivery so access can follow a defined purpose rather than broad availability.

  • Case-specific workflow
  • Authorized participants
  • Controlled delivery

THE RECORD JOURNEY

Access follows the case.

The purpose changes at each stage. The workflow should make that purpose visible and keep the record from becoming broadly available.

  1. 01

    Authorization

    Before records are requested or reviewed, the patient or authorized representative completes the applicable consent and medical-record authorization steps.

  2. 02

    Collection

    Records may be uploaded through the secure portal or obtained through an authorized release. The records team works from the facilities and sources identified for the case.

  3. 03

    Clinical review

    Assigned clinical reviewers access the information needed for the review. The case is organized around the question presented, the available record, and the selected service.

  4. 04

    Delivery and follow-up

    The report and any consultation materials are delivered through the approved workflow. Requests involving access, correction, restrictions, or confidential communication go to the privacy team.

YOUR RIGHTS

You can ask questions of the record—and of us.

Some rights and response duties depend on the information and WHITEGLOVEMD’s role. The privacy team will route each request through the applicable process.

01

Access

Request access to or a copy of protected health information maintained by WHITEGLOVEMD, subject to applicable limits.

02

Amendment

Ask that information be amended if you believe it is inaccurate or incomplete.

03

Accounting

Request an accounting of certain disclosures of protected health information.

04

Restrictions

Request limits on certain uses or disclosures; not every requested restriction must be accepted.

05

Confidential communication

Ask to receive communications through a particular method or at a particular address.

06

Complaint

Raise a concern with the Privacy Officer or file a complaint with the HHS Office for Civil Rights without retaliation.

MAKE A PRIVACY REQUEST

Tell us what you need. We will verify, route, and respond.

To protect the record, we may need to verify identity or authority before releasing information or acting on a request.

No retaliation for a good-faith privacy complaint.

FAQ

Privacy questions, answered plainly.

For the broader handling of personal information, read the Privacy Policy.

Read the privacy policy
What is protected health information?

Protected health information, often called PHI, is individually identifiable health information maintained or transmitted by a HIPAA covered entity or its business associate in a form covered by the HIPAA Rules. The exact legal analysis depends on the entity, information, and context.

Is HIPAA a one-time certification?

No. HIPAA is a set of federal privacy, security, and breach-notification requirements, not a one-time product badge. HHS describes compliance as an ongoing process involving risk analysis, reasonable and appropriate safeguards, documentation, and periodic evaluation.

Who can access the records for my review?

Access is intended to be limited to authorized people and service providers with a role in the case or the operation of the service. The specific participants can include assigned physicians, records or support personnel, and contracted technology providers operating under applicable privacy obligations.

How do I request access, an amendment, or confidential communication?

Email privacy@whiteglovemd.com or call (855) 688-3160. Identify the request and the best secure way to follow up. Additional identity verification may be required before protected information is released or changed.

How do I report a privacy concern?

Contact the WHITEGLOVEMD Privacy Officer at privacy@whiteglovemd.com or (855) 688-3160. You may also file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights. You will not be retaliated against for making a good-faith complaint.

A DIRECT LINE TO PRIVACY

You should not have to guess where to send a concern.

Contact the Privacy Officer for access, amendment, confidential-communication, restriction, accounting, or complaint questions.

Email the Privacy Officer