Information We Collect
We collect information in two ways: information you provide directly, and information collected automatically.
- ✓Identity information: name, date of birth, email address, phone number, and mailing address.
- ✓Health and medical information: health history, symptoms, diagnoses, and treatment details necessary to provide medical care.
- ✓Payment information: credit card numbers and billing details, transmitted securely via SSL encryption.
- ✓Account credentials: username and password for your patient portal.
- →Technical data: IP address, device ID, device name, operating system version, and browser type.
- →Usage data: log files, dates of product activation, and technical debug information.
- →Cookies: small files placed on your browser to remember your preferences and enhance your experience.
- →Analytics data: we use Google Analytics to understand how visitors use our site. You may opt out via Google's Ad Settings or the Network Advertising Initiative opt-out page.
How We Use Your Information
We use your personal and health information for the following purposes:
- ✓Medical care: to diagnose conditions, recommend treatments, prescribe medications, and provide medical guidance.
- ✓Communications: appointment reminders, prescription notifications, and care-related messages.
- ✓Customer support: to resolve issues you report to our support team.
- ✓Service improvement: to personalize your experience, optimize our platform, and develop new features.
- ✓Marketing (with consent): to inform you of new products or promotions. You may withdraw consent at any time.
Telemedicine Visits
During a telemedicine visit, our application may request access to your microphone, camera, or phone status. These permissions are used solely to facilitate your consultation.
We do not access these features for any other purpose and strictly comply with all applicable privacy regulations.
How We Share Your Information
We do not sell, rent, or lease your personal information to third parties. We may share your information only in the following limited circumstances:
- →Service providers: third-party vendors who assist in delivering our services (such as our electronic health record system, Tebra EHR), bound by confidentiality agreements.
- →Affiliates and subsidiaries: subject to the same privacy protections described in this Policy.
- →SMS messaging providers: phone carriers and platform providers that help deliver text messages to you. Your SMS opt-in information and consent will never be shared with third parties for unrelated purposes.
- →Facebook advertising: we may use Facebook to advertise our services. Any advertising data collected is used only in aggregate and anonymous form to evaluate campaign effectiveness. We do not use this data to build user profiles or share it with ad networks or data brokers.
- →Legal requirements: when required by law or necessary to protect the rights, safety, or property of our users or the public.
- →Business transfers: in the event of a merger or acquisition, your information may be transferred as part of that transaction.
Where Your Data Is Stored
Your personal data is stored within the United States on secure servers, subject to U.S. laws and regulations that protect your privacy. We use Tebra EHR as our electronic health record platform.
All data storage and processing partners have signed Business Associate Agreements (BAAs) with AngelTelemedicine LLC as required by HIPAA.
Data Security
We take reasonable technical and administrative measures to protect your information from unauthorized access, disclosure, or misuse:
- 🔒SSL/TLS encryption for all data transmitted through our intake forms and patient portal.
- 🔒AES-256 encryption for all protected health information stored at rest.
- 🔒HIPAA Security Rule compliance, including administrative, physical, and technical safeguards.
- 🔒Access controls restricting access to staff and contractors on a strict need-to-know basis.
In the event of a data breach, we will notify you promptly in accordance with applicable law.
Your Health Information Rights
As a patient, you have the following rights under HIPAA and applicable law:
Children's Privacy
We do not knowingly collect personal information from children without verifiable parental consent, in compliance with applicable regulations including COPPA and GDPR.
SMS & Phone Communications
By providing your phone number, you consent to receive text messages and phone calls for appointment reminders, prescription notifications, follow-ups, and promotional messages.
You may opt out at any time by replying STOP to any text message, or by contacting us directly.
Account Deletion
To delete your account, go to the Profile section within the Vigor MD patient portal at vigormd.com. You may also contact us directly to request deletion. Please note that certain information may be retained as required by law or for the ongoing provision of medical care.
Information we collect includes: name, email, phone number, gender, race, and device information (device ID, name, and operating system version). Device information is collected to ensure our app is optimized for your specific device.
You may recover a deleted or deactivated account by signing in with your credentials and completing two-factor authentication, or by contacting us for assistance.
Our HIPAA Compliance Commitments
AngelTelemedicine LLC manages patient information in compliance with HIPAA Rules and the U.S. Department of Health & Human Services (HHS) requirements. Specifically, we commit to:
- ✓Non-disclosure: we will not use or disclose your information in any manner prohibited by law.
- ✓Security: we implement all required HIPAA security measures to prevent unauthorized use or disclosure.
- ✓Breach notification: we will notify you of any breach of your protected health information.
- ✓Access requests: we will assist you in requesting, reviewing, completing, or denying access to your information.
- ✓Subcontractor compliance: any subcontractors with access to your information are bound by the same restrictions that apply to us.
- ✓Regulatory obligations: we will fulfill all HIPAA obligations applicable to our role as your service provider.
- ✓HHS access: we will make our internal practices, books, and records available to HHS as required for compliance oversight.
Your Responsibilities
To help us protect your information, we ask that you:
- →Provide only the minimum personal and health information necessary to receive our services.
- →Use appropriate safeguards to protect information you transmit to us, consistent with HIPAA requirements.
- →Not request that we use or disclose your information in any manner that violates 45 CFR Part 164, Subpart E.
- →Keep your account credentials confidential and notify us immediately of any suspected unauthorized access.
Changes to This Policy
We may update this Privacy Policy from time to time. If we make a material change that adversely affects your rights, we will post a prominent notice on this page for at least 30 days before the change takes effect.
Your continued use of our services after changes are posted constitutes acceptance of the updated Policy.
Contact Us
If you have questions about this Privacy Policy, wish to exercise your rights, or need to report a privacy concern, please contact us: