Legal
Privacy Policy
Your privacy is the foundation of our care. This policy explains what information Bright Wellness Health collects, how we use it, and the controls you have over your personal health data.
Last updated: January 2024 · Effective since founding in 2022
1. Information We Collect
Bright Wellness Health collects information necessary to provide coordinated health and wellness management services:
- Personal information: Name, date of birth, address, phone number, email address, and emergency contacts.
- Health information: Medical history, current medications, lab results, specialist referrals, and care plans — collected with your explicit consent.
- Insurance information: Policy numbers, coverage details, and claims documentation, used solely for coordination and advocacy.
- Usage data: How you interact with our member portal, telehealth platform, and communications — used to improve service quality.
- Communication records: Records of calls, messages, and emails with our care team, retained for continuity of care.
2. How We Use Your Information
We use your information exclusively for the following purposes:
- Providing and coordinating your health and wellness care, including specialist referrals and telehealth consultations.
- Managing your membership, billing, and insurance coordination on your behalf.
- Sending appointment reminders, care plan updates, and clinical communications.
- Complying with applicable federal and state healthcare regulations, including HIPAA.
- Improving our services through aggregated, de-identified analytics.
- Responding to your inquiries and providing customer support.
We never sell your personal or health information to third parties. Not now, not ever.
3. Information Sharing & Disclosure
We share your information only in the following limited circumstances:
- With your healthcare providers: Only with your explicit consent, to coordinate care across specialists.
- With your insurance provider: Only as necessary for claims processing and prior authorization, with your authorization on file.
- With service partners: Telehealth platform providers, lab networks, and pharmacy partners — all bound by HIPAA-compliant Business Associate Agreements.
- As required by law: In response to valid legal processes, or to protect the safety of any person as required by federal or state law.
4. Data Security & HIPAA Compliance
All health information is stored in HIPAA-compliant, end-to-end encrypted systems. Access is restricted to authorized care team members directly involved in your care. We maintain full audit trails of every record access and provide you with visibility into who has viewed your information.
Our technical safeguards include 256-bit AES encryption at rest, TLS 1.3 in transit, multi-factor authentication for staff access, and quarterly third-party security audits.
5. Your Rights & Controls
You have the following rights regarding your personal and health information:
- Access: Request a complete copy of your records at any time, free of charge, within 30 days.
- Correction: Request correction of any inaccurate or incomplete information.
- Restriction: Limit how your information is used or shared, beyond what is legally required for care.
- Revocation: Revoke provider access to your records at any time from your member portal.
- Deletion: Request deletion of your account and personal data, subject to medical record retention laws.
- Newsletter unsubscribe: Click here to unsubscribe from marketing communications at any time.
To exercise any of these rights, contact us at info@brightwellnesshealth.com or call (605) 223-2425.
6. Cookies & Tracking
Our website uses essential cookies to enable core functionality (such as remembering your session) and analytics cookies to understand how visitors use our site. We do not use cookies for targeted advertising. You can control cookies through your browser settings at any time.
7. Data Retention
We retain your health information for the duration of your membership and for the period required by federal and state medical record retention laws — typically 7 to 10 years after your last interaction. After this period, we securely delete or anonymize your data.
8. Children's Privacy
Our services are designed for adults and families with dependents under 26. We collect information about minors only through a parent or legal guardian who has provided consent. Parents may review, correct, or delete their child's information at any time.
9. Changes to This Policy
We may update this Privacy Policy periodically. We will notify members of any material changes via email at least 30 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.
10. Contact Us
If you have any questions about this Privacy Policy or how we handle your information, please contact our Privacy Officer: