Privacy Policy
Effective Date: September 4, 2026
This Privacy Policy explains how AshHEALTH, LLC d/b/a MyAshHealth (“MyAshHealth,” “we,” “us,” or “our”) collects, uses, discloses, and protects information when you use https://myashhealth.com, create an account, communicate with us, or use services made available through MyAshHealth.
This Privacy Policy is separate from our HIPAA Notice of Privacy Practices. Protected health information (“PHI”) that is subject to HIPAA is governed by the HIPAA Notice of Privacy Practices. To the extent this Privacy Policy and the HIPAA Notice address the same PHI differently, the HIPAA Notice and applicable law control.
1. Information We Collect
Depending on how you interact with MyAshHealth, we may collect:
- Identifiers and contact information, such as name, mailing address, email address, telephone number, date of birth, and account identifiers.
- Account and authentication information, including login credentials and account activity.
- Health and clinical information that you provide through intake forms, questionnaires, communications, treatment workflows, prescriptions, or laboratory-related workflows. When this information is PHI, it is handled under HIPAA and our HIPAA Notice of Privacy Practices.
- Transaction and payment-related information. Payment card information may be processed by payment service providers; we may receive transaction status, limited billing information, and records necessary to administer your order.
- Order, prescription, pharmacy, laboratory, shipping, support, and service records associated with services you request.
- Communications with customer support, including email, telephone, SMS, and portal communications.
- Device and technical information, such as IP address, browser type, device type, operating system, referring pages, security logs, and website activity collected through necessary or permitted technologies.
- Information you choose to provide in surveys, forms, inquiries, or other communications.
2. How We Use Information
We use information for purposes such as:
- Providing, administering, supporting, and improving MyAshHealth services and your account.
- Facilitating access to independently licensed healthcare professionals, licensed pharmacies, and independent third-party laboratories.
- Processing orders, payments, refunds, scheduling, customer support, and service communications.
- Authenticating users, preventing fraud, protecting platform security, troubleshooting, auditing, and complying with legal and regulatory obligations.
- Communicating with you about requested services, account activity, appointments, prescriptions, laboratory workflows, orders, and customer support.
- Sending promotional communications where permitted by law and consistent with your communication choices. We do not use PHI for marketing where HIPAA requires an authorization unless a valid authorization has been obtained.
- Creating de-identified or aggregated information where permitted by law for analytics, quality, operational, security, and service-improvement purposes.
3. When We Disclose Information
We may disclose information as necessary and permitted by law to:
- Independently licensed healthcare professionals involved in evaluating or providing services to you.
- Licensed pharmacies involved in dispensing, fulfilling, counseling, shipping, or supporting prescription orders.
- Independent third-party laboratories involved in laboratory ordering, scheduling, collection, testing, reporting, or related services.
- Payment processors, hosting providers, communications vendors, CRM/support providers, security vendors, identity/authentication providers, shipping carriers, professional advisers, and other service providers that perform functions on our behalf.
- Government agencies, regulators, courts, law enforcement, or other persons when disclosure is required or permitted by applicable law.
- Parties involved in a corporate transaction, such as a merger, financing, acquisition, reorganization, or sale of assets, subject to applicable privacy and healthcare-law restrictions.
- Other persons when you direct us to disclose information or provide a legally valid authorization or consent.
Where HIPAA applies, disclosures of PHI are made only as permitted by HIPAA, our HIPAA Notice of Privacy Practices, and other applicable law.
4. SMS and Mobile Information
Mobile telephone numbers, SMS opt-in information, and SMS consent collected by MyAshHealth will not be sold, rented, or shared with third parties or affiliates for their own marketing or promotional purposes.
We may disclose mobile information to service providers that perform telecommunications, messaging, customer-support, technology, hosting, security, and other operational services on our behalf solely as necessary to operate our communications systems or provide services you request. Those service providers are not authorized to use SMS opt-in information for their own marketing purposes.
5. Cookies, Analytics, and Advertising Technologies
We may use cookies and similar technologies that are necessary for website functionality, security, authentication, preferences, and ordinary site performance measurement. We do not currently use social-media advertising or social-media analytics technologies to disclose health information from clinical intake, patient communications, prescription workflows, laboratory workflows, or authenticated patient experiences to social-media platforms for their own advertising or marketing purposes.
If our analytics or advertising practices materially change, we will evaluate the change under HIPAA and other applicable privacy laws and update this Privacy Policy and any required consent mechanisms before implementing the new practice.
6. HIPAA and Health Information
AshHEALTH, LLC d/b/a MyAshHealth is a HIPAA covered entity with respect to PHI maintained by it in its covered-entity capacity. Our uses and disclosures of PHI, your HIPAA rights, and our legal duties are described in our HIPAA Notice of Privacy Practices. Independent healthcare professionals, pharmacies, or laboratories may also provide separate privacy notices that apply to information maintained by those entities.
7. Data Security
We maintain administrative, technical, and physical safeguards designed to protect information appropriate to its sensitivity and the requirements of applicable law. No system can be guaranteed to be completely secure, and you should use appropriate safeguards when communicating electronically. We will provide legally required notices if a reportable breach or security incident occurs.
8. Data Retention
We retain information for as long as reasonably necessary to provide services, maintain business and healthcare records, satisfy legal, regulatory, tax, accounting, contractual, security, and dispute-resolution obligations, and enforce our agreements. Retention periods may differ by data type and applicable healthcare or state-law requirements.
9. Your Choices and Rights
Depending on the information and applicable law, you may have rights to access, correct, obtain copies of, request deletion of, restrict certain uses of, or receive information about disclosures of your information. HIPAA rights relating to PHI are described in the HIPAA Notice of Privacy Practices. Additional state-law rights may apply based on your residence. California residents should review the California Privacy Notice.
You may unsubscribe from promotional emails using the unsubscribe mechanism provided in the message. You may opt out of SMS messages as described in the SMS Terms and Conditions. Service-related communications that are necessary to administer an active account, transaction, treatment workflow, safety matter, or legal obligation may still be sent as permitted by law.
10. Children
MyAshHealth services are intended only for adults age 18 and older. We do not knowingly offer the Site or Services to minors or knowingly collect personal information through the Site for the purpose of providing MyAshHealth services to individuals under 18.
11. Third-Party Websites and Services
The Site may link to or integrate with third-party services. Their privacy practices are governed by their own notices and agreements. We encourage you to review those notices. This section does not change our obligations for PHI or other information where applicable law makes us responsible for a vendor acting on our behalf.
12. Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes in law, technology, vendors, or our practices. We will post the updated policy with a revised effective date and provide additional notice when required by law.
13. Contact Us
Privacy questions or requests may be directed to:
AshHEALTH, LLC d/b/a MyAshHealth
1160 Pittsford Victor Road, Building M, Suite 12, Pittsford, NY 14534
Telephone: (585) 540-1353
Email: Supportteam@AshHealth.fit
Website: https://myashhealth.com
