Last Updated: April 29, 2026

This HIPAA Notice (this “Notice”) explains how certain health information is handled when you use specific portions of our Services that support healthcare services provided by licensed healthcare providers (“Providers”).

This Notice applies only to pages, portals, or domains where this HIPAA Notice appears in the footer or is otherwise expressly referenced. For all other parts of our website or Services, our Privacy Policy applies.

This Notice is incorporated into and forms part of the Terms and Conditions of Use (the “Terms”) and is subject to all provisions, limitations, disclaimers, and conditions set forth in the Terms. In the event of a conflict between this Notice and the Terms, the Terms shall control unless expressly stated otherwise.

1.          When This Notice Applies

When you use portions of the Services that facilitate medical treatment, telehealth visits, prescriptions, or other healthcare services provided by a Provider, Piper Wellness LLC d/b/a JoinPolly (“Polly,” “we,” “us,” or “our”) may collect, receive, maintain, or transmit health information on behalf of that Provider.

In those circumstances, Polly acts as a “Business Associate” under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), and the Provider acts as the “Covered Entity.” This means:

  • The Provider is responsible for your medical care.
  • The Provider controls your medical record.
  • The Provider is responsible for providing you with a Notice of Privacy Practices (“NOPP”).
  • Polly handles certain health information only on the Provider’s behalf and in accordance with HIPAA and our agreement with the Provider.

2.          How HIPAA Applies

When Polly acts as a Business Associate:

  • We may use and disclose your protected health information (“PHI”) only as permitted by our Business Associate Agreement with the Provider and as allowed by HIPAA.
  • We are required to implement appropriate administrative, physical, and technical safeguards to protect PHI.
  • We may not use or disclose PHI for our own independent purposes, except as permitted by HIPAA (for example, for proper management and administration of our business, or as required by law).
  • We must report certain breaches of unsecured PHI to the Provider.
  • We must ensure that any subcontractors who handle PHI on our behalf agree to similar HIPAA protections.

Importantly, when Polly is acting as a Business Associate, we do not determine how your medical information is used for treatment decisions. Those decisions are made by your Provider.

3.          The Provider’s Notice of Privacy Practices Controls

Your Provider’s NOPP describes:

  • How your medical information may be used and disclosed;
  • Your rights under HIPAA; and
  • The Provider’s legal duties with respect to your PHI.

The Provider’s NOPP governs the use and disclosure of your PHI for treatment, payment, and healthcare operations. If you have questions about how your health information is used or disclosed for medical purposes, please review the NOPP you received from your Provider.

4.          Exercising Your HIPAA Rights

Under HIPAA, you may have rights to:

  • Access or obtain a copy of your medical records;
  • Request amendments to your records;
  • Request restrictions on certain uses or disclosures;
  • Request confidential communications;
  • Receive an accounting of certain disclosures.

Because Polly acts only as a Business Associate, requests to exercise these rights must be directed to your Provider, in accordance with the instructions in the Provider’s NOPP. Polly will cooperate with your Provider in responding to valid HIPAA requests as required by law and our Business Associate Agreement.

5.          What This Notice Does Not Cover

This HIPAA Notice does not apply to:

  • Information you submit through portions of the website that are not identified as HIPAA-covered areas;
  • Information collected for marketing, analytics, or general website functionality outside the context of healthcare services;
  • De-identified information that does not identify you.

Such information is governed by our Privacy Policy.

6.          Questions

If you have questions about this HIPAA Notice or whether a particular portion of the Services is HIPAA-covered, you may contact us at: care@joinpolly.com.