Privacy Policy
Onir Health, LLC ("Onir Health," "we," "us," or "our") is committed to protecting the privacy and security of your personal and health information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, use our mobile application, or engage with our telehealth services. By using our services, you consent to the practices described below. Onir Health is a HIPAA-covered entity. In addition to this general Privacy Policy, your protected health information (PHI) is governed by our Notice of Privacy Practices in Section 4 below.
Information We Collect
- Identity information (full name, date of birth, sex, government-issued ID details).
- Contact information (email address, phone number, mailing address).
- Health and medical information (medical history, current medications, substance use history, symptoms, and questionnaire responses).
- Payment information: credit or debit card number and billing address (processed by our payment processor — we do not store full card numbers).
- Account credentials (username and password).
- Communications you send to our care team or support staff.
- Device and browser information (IP address, browser type, operating system).
- Usage data (pages visited, time spent, links clicked, referring URLs).
- Cookies and similar tracking technologies (see Section 8).
We may receive information about you from our clinical and pharmacy partners in the course of providing services, including consultation notes, prescription records, and lab results.
How We Use Your Information
We use the information we collect for:
- Providing telehealth services — facilitating consultations, processing prescriptions, and coordinating pharmacy fulfillment.
- Identity verification to comply with applicable law and protect patient safety.
- Payment processing for subscriptions and services.
- Communications — appointment reminders, care updates, prescription status, support responses.
- Legal and regulatory compliance — HIPAA, state telehealth laws, DEA regulations.
- Service improvement using de-identified or aggregated data only.
- Safety — detecting fraud, abuse, or threats.
- Marketing with your consent (opt-out available at any time).
How We Share Your Information
These partners may only use your PHI to provide services on our behalf and are contractually prohibited from using it for any other purpose.
ZenPayments (powered by Authorize.net), PCI-DSS-compliant. Onir Health does not store full card numbers or CVV codes on our servers.
AWS (hosting), SendGrid (email), Twilio (SMS), and identity verification services receive only the minimum information necessary.
We may disclose information when required by law, court order, or government authority; to protect rights or safety; or in connection with a merger or acquisition.
We do not sell, rent, or trade your personal information or PHI to any third party.
Notice of Privacy Practices (HIPAA)
As a HIPAA-covered entity, Onir Health is required to maintain the privacy of your protected health information (PHI).
- Right to access — request a copy of your PHI (medical history, consultation notes, prescription records).
- Right to amendment — request correction of inaccurate PHI.
- Right to accounting of disclosures — list of certain disclosures within the past six years.
- Right to restrict disclosures — request restrictions on use or disclosure for treatment, payment, or healthcare operations.
- Right to confidential communications — request communication in a specific way or at a specific location.
- Right to file a complaint — with us or with HHS; we will not retaliate.
To exercise any of these rights: support@onirhealth.com.
We notify affected individuals within 60 days of discovering a breach, as required by the HIPAA Breach Notification Rule.
Data Security
- AES-256 encryption of PHI at rest.
- TLS 1.2+ for all data in transit.
- Role-based access controls.
- HIPAA-compliant AWS infrastructure with executed BAA.
- Audit logging of all PHI access.
- Regular security reviews.
No method is 100% secure; we cannot guarantee absolute security.
Data Retention
PHI retained a minimum of 7 years from the date of last service, or longer if required by state law. Non-health personal information is retained while your account is active or as needed for legal obligations.
State-Specific Privacy Rights
Rights to know, delete, correct, and opt out of sale or sharing. Health information subject to HIPAA is exempt from certain CCPA provisions. Contact support@onirhealth.com.
Virginia, Colorado, Connecticut, Texas, and others — we honor verifiable requests consistent with applicable law.
Cookies and Tracking Technologies
- Essential cookies — core functionality.
- Analytics cookies — traffic analysis.
- Marketing cookies — with consent only.
You may control cookies via browser settings. Disabling certain cookies may affect site functionality.
Children's Privacy
Services are intended for adults 18+. We do not knowingly collect information from minors. If we discover we have, we will delete it promptly.
Changes to This Policy
We may update this policy. Material changes will be posted with a new effective date and, where required by law, direct notice. Continued use after the effective date constitutes acceptance.
Contact Us
Onir Health, LLC — Privacy Officer
103 Southern Oaks Dr, Plant City, FL 33563
support@onirhealth.com · www.onirhealth.com
To file a complaint with HHS: www.hhs.gov/ocr/privacy/hipaa/complaints