Legal

Privacy Policy

Last updated: July 2, 2026

1. Who we are

VanguardHealth ("VanguardHealth", "we", "us") is a health technology company building EHR and telemedicine infrastructure. Reach our privacy officer at privacy@vanguardhealth.com.

2. What we collect

  • Provider data: Name, NPI, clinical role, facility association.
  • Patient data: Protected Health Information (PHI) processed strictly as a Business Associate under HIPAA.
  • Platform data: IP addresses, audit logs, and anonymized telemetry.

3. How we use your data

We process data solely to deliver, secure, and improve our clinical infrastructure services. VanguardHealth operates as a Business Associate (BA) on behalf of Covered Entities. We never sell patient data.

4. Telemedicine & Video

Telehealth sessions are end-to-end encrypted. Video and audio streams are never recorded unless explicitly initiated by the provider and consented to by the patient.

5. Sharing

We share data with infrastructure sub-processors (e.g., AWS Healthcare) governed by strict Business Associate Agreements (BAAs).

6. Security & Compliance

Data is encrypted in transit (TLS 1.3) and at rest (AES-256). Our infrastructure is SOC2 Type II certified, HIPAA compliant, and subject to annual third-party penetration testing.

7. Data Subject Rights

Patients seeking access, correction, or deletion of their PHI should contact their healthcare provider directly. Providers can manage their accounts by emailing privacy@vanguardhealth.com.

8. Changes

We will notify providers of material changes to this policy via email and in-platform alerts.