Consumer Health Data Privacy Policy
Last updated: June 28, 2026 | Version 1.1
This policy applies to “consumer health data” as defined by US state laws including Washington's My Health My Data Act, Nevada SB370, and Connecticut law. It supplements our Privacy Policy, and where the two differ for consumer health data, this policy controls.
1. What We Collect
Consumer health data is information linked to your health that you provide or that we derive. The categories we may collect are:
- the procedures and treatments you research or ask about;
- health conditions, symptoms, and diagnoses you choose to tell us;
- treatment and surgical history, medications, and allergies you enter;
- your status as someone seeking a specific kind of care; and
- inferences we draw from the above to match you with suitable hospitals.
We do not collect precise geolocation or biometric data for health purposes.
2. Where We Collect It From
- directly from you, when you use the cost estimator, chat with Robin, submit an inquiry, or complete your profile;
- automatically, from your use of the platform, such as the procedures and destinations you view; and
- as inferences we derive from that information.
3. How We Use It
Only to provide the services you request: matching you with hospitals, generating cost estimates, and, with your consent, introducing you to hospitals. We do not use consumer health data to target advertising.
4. Who We Share It With, and “Sale”
When you consent to be introduced to a hospital, we share your consumer health data with that hospital, which pays us a fee. Under some state laws this is a “sale” of consumer health data, and it requires your valid authorization, separate from general consent. We will obtain that authorization before any such sale and will not sell your consumer health data without it.
The categories of consumer health data we share, and with whom, are:
- the hospital you choose to be introduced to (your inquiry details and the health information it needs to assess your case), only with your authorization;
- our service providers (cloud hosting and AI providers), who process it only on our instructions under written agreements and never for their own purposes.
We do not share consumer health data with advertisers or data brokers.
5. Your Rights
You have the right to:
- confirm whether we are processing your consumer health data and access it;
- delete your consumer health data;
- withdraw your consent to our collection and use; and
- withdraw any authorization to sell, at any time.
We will not deny you services, charge you a different price, or provide a different quality of service because you exercised these rights. To exercise them, use your account settings or email contact@curemeridian.com. To protect your data, we may need to verify your identity first. We respond within 45 days and may extend once by a further 45 days for complex requests, with notice. If we deny a request, you may appeal by replying to our response. When you ask us to delete your data, we will also direct our service providers to delete it. We honor Global Privacy Control signals.
6. Authorized Agents
You may use an authorized agent to submit a request on your behalf. We may ask the agent for proof that you authorized them to act for you, and we may ask you to verify your own identity directly.
7. No Geofencing
We do not use geofencing to identify or track you around health-care facilities, or to send you advertising or notifications based on your proximity to them.
8. Security and Contact
We protect consumer health data with AES-256-GCM encryption and strict access controls. No system is completely secure, so while we use industry-standard safeguards we cannot guarantee absolute security. Questions: contact@curemeridian.com.