Legal
Privacy Policy
Last updated: July 2, 2026
1. Who we are
VanguardHealth ("VanguardHealth", "we", "us") is a health technology company building EHR and telemedicine infrastructure. Reach our privacy officer at privacy@vanguardhealth.com.
2. What we collect
- Provider data: Name, NPI, clinical role, facility association.
- Patient data: Protected Health Information (PHI) processed strictly as a Business Associate under HIPAA.
- Platform data: IP addresses, audit logs, and anonymized telemetry.
3. How we use your data
We process data solely to deliver, secure, and improve our clinical infrastructure services. VanguardHealth operates as a Business Associate (BA) on behalf of Covered Entities. We never sell patient data.
4. Telemedicine & Video
Telehealth sessions are end-to-end encrypted. Video and audio streams are never recorded unless explicitly initiated by the provider and consented to by the patient.
5. Sharing
We share data with infrastructure sub-processors (e.g., AWS Healthcare) governed by strict Business Associate Agreements (BAAs).
6. Security & Compliance
Data is encrypted in transit (TLS 1.3) and at rest (AES-256). Our infrastructure is SOC2 Type II certified, HIPAA compliant, and subject to annual third-party penetration testing.
7. Data Subject Rights
Patients seeking access, correction, or deletion of their PHI should contact their healthcare provider directly. Providers can manage their accounts by emailing privacy@vanguardhealth.com.
8. Changes
We will notify providers of material changes to this policy via email and in-platform alerts.