WHITEGLOVEMD

PRIVACY & DATA PROTECTION

How your information is handled.

WHITEGLOVEMD is built on trust. This policy explains which information is collected, why it is used, how it is protected, when it may be shared, and the choices available to you.

POLICYPrivacy
LAST UPDATED
PRIVACY CONTACTPrivacy Officer

POLICY CONTENTS

Find the section you need.

Use the links below to move directly to a topic. Every section remains part of this Privacy Policy.

01

Information collected

Information We Collect

The information involved depends on how you use the website, platform, and clinical review services.

  • Personal identification information: name, email address, phone number, date of birth, and mailing address provided during account creation or case submission.
  • Medical records: catheterization reports, echocardiograms, CT scans, surgical notes, lab results, medication lists, and other clinical documents uploaded or transmitted for case review.
  • Payment information: processed securely through Stripe. WHITEGLOVEMD does not store credit card numbers on our servers.
  • Usage data: anonymized analytics about how you interact with our platform, used solely to improve the user experience. This data is never linked to your medical records.
  • Communication records: messages exchanged through our secure portal, consultation notes, and support interactions.
Back to contents
02

How it is used

How We Use Your Information

Information is used to provide, coordinate, and improve the service and to meet applicable obligations.

  • To perform clinical case reviews and generate your WHITEGLOVE Insights™ report.
  • To facilitate Heart Team consultations between you and your reviewing physicians.
  • To communicate case updates, scheduling information, and delivery notifications.
  • To process payments and provide financial documentation for HSA/FSA reimbursement.
  • To improve our Clintelligence™ AI engine using de-identified, aggregated data only — never your personal information.
  • To comply with legal obligations, including HIPAA audit trails and regulatory reporting requirements.
Back to contents
03

Security measures

How We Protect Your Data

The policy describes technical, administrative, and access controls for information handled through the service.

  • AES-256 encryption protects all data at rest. TLS 1.3 encryption protects all data in transit.
  • All data processors and subprocessors are bound by signed Business Associate Agreements (BAAs).
  • Access to medical records is restricted to physicians and clinical staff directly assigned to your case.
  • Multi-factor authentication is required for all clinical and administrative access.
  • Comprehensive audit logging tracks every access, modification, and export of protected health information.
  • Regular penetration testing and vulnerability assessments are conducted by third-party security firms.
  • Our infrastructure is aligned with SOC 2 Type II controls and HITRUST CSF standards.
Back to contents
04

Your rights

Your Rights

You can contact the Privacy Officer to exercise the rights described below.

  • Access: You may request a copy of all personal and medical data we hold about you at any time.
  • Correction: You may request corrections to inaccurate or incomplete personal information.
  • Deletion: You may request deletion of your data, subject to legal retention requirements for medical records.
  • Portability: You may request your data in a structured, machine-readable format.
  • Restriction: You may request that we limit processing of your data in certain circumstances.
  • To exercise any of these rights, contact our Privacy Officer at privacy@whiteglovemd.com.
Back to contents
05

Data sharing

Data Sharing & Third Parties

This section explains the limited circumstances in which information may be shared.

  • We never sell your personal or medical data to third parties.
  • We never share your data for marketing purposes.
  • We share data only with: (1) physicians assigned to your case, (2) data processors bound by BAAs (Supabase, Stripe, Resend), and (3) as required by law.
  • Text messaging (SMS): phone numbers and SMS opt-in consent collected for text messaging are used only to send you the messages you signed up for (appointment, account, and customer-care messages) and will not be shared with third parties or affiliates for marketing purposes.
  • De-identified, aggregated data may be used for clinical research and quality improvement. This data cannot be traced back to any individual patient.
Back to contents
06

Cookies & tracking

Cookies & Tracking

Cookies and analytics are used for core platform functionality and to understand the website experience.

  • We use essential cookies required for platform functionality (authentication, session management).
  • We use anonymized analytics to understand how users navigate our site and improve the experience.
  • We do not use third-party advertising trackers or sell data to ad networks.
  • You may disable non-essential cookies through your browser settings without affecting core platform functionality.
Back to contents

QUESTIONS BEFORE YOU BEGIN?

Understand the process before you share a record.

See how records are gathered and reviewed, or request a conversation about whether the service fits your situation.

POLICY VERSION

Privacy questions and rights requests

privacy@whiteglovemd.com