Legal
This notice describes how protected health information may be used and disclosed across the WhiteLabelMD platform and how you can get access to it.
Last updated: September 2, 2026
WhiteLabelMD provides technology and administrative services to telehealth brands, provider groups, pharmacies, and labs. In most engagements WhiteLabelMD acts as a business associate under HIPAA, and the treating provider group or pharmacy is the covered entity responsible for its own notice of privacy practices.
Protected health information, or PHI, is individually identifiable health information created or received in connection with treatment, payment, or healthcare operations. This includes intake responses, clinical notes, prescriptions, lab results, and related billing records.
PHI may be used or disclosed for the following purposes.
We maintain administrative, physical, and technical safeguards, including access controls, encryption in transit and at rest, audit logging, workforce training, and executed business associate agreements with subcontractors that handle PHI.
Individuals generally have the following rights regarding their PHI.
If unsecured PHI is breached, affected individuals and the applicable covered entity will be notified in accordance with the HIPAA Breach Notification Rule.
Direct requests to the treating provider group or pharmacy identified in your care records. You may also contact WhiteLabelMD and we will route the request to the responsible covered entity. You may file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights.