Health Information & HIPAA-Aligned Practices
Last updated: June 28, 2026
We are not a HIPAA covered entity, but we treat your health information with HIPAA-aligned care. This page explains how we protect it and where your legal rights come from.
Are we covered by HIPAA?
HIPAA's privacy and security rules apply to “covered entities” (health plans, health-care providers, and clearinghouses) and their business associates. CureMeridian is a research and matching platform. We do not provide medical care, bill for treatment, or process insurance claims, so we are generally not a HIPAA covered entity, and this page is not a covered-entity Notice of Privacy Practices. Even though HIPAA may not require it, your health information is sensitive, so we choose to protect it with HIPAA-aligned safeguards.
Where your rights come from
Your legal rights over your health information come from our Privacy Policy (which covers special-category health data under GDPR Art. 9 and your access, correction, deletion, and objection rights) and our Consumer Health Data notice (which covers US state health-privacy laws such as Washington's My Health My Data Act). Please use those pages to understand and exercise your rights.
How we use your health information
Matching:
We use the health information you provide to match you with suitable hospitals and procedures abroad. Our AI processes only de-identified data, and we share your inquiry with a hospital only with your explicit consent.
Platform operations:
We use de-identified data to operate and improve the platform and our AI models.
Legal and safety:
We may use or disclose your information where required by law, in response to a court order or lawful authority request, or to prevent a serious and imminent threat to someone's safety.
How we protect it
We apply HIPAA-aligned safeguards: AES-256-GCM encryption at rest, TLS in transit, strict role-based access controls and audit logging, and de-identification of your data before any external AI processing. We require our vendors to protect your data under written data processing agreements. No system is completely secure, so while we use industry-standard safeguards we cannot guarantee absolute security.
If there is a data breach
If your health information is involved in a breach, we will notify you and the relevant authorities as required by the US FTC Health Breach Notification Rule, applicable state breach-notification laws, and, for affected individuals in the EU or UK, the GDPR (within 72 hours of the relevant authority where required).
Questions or complaints
If you have a question or believe we have mishandled your health information, please contact us first at contact@curemeridian.com. You may also contact the US Federal Trade Commission or your state attorney general, or, in the EU or UK, your local data protection authority. We will not retaliate against you for raising a concern.