Concierge Pediatrics Parent Application – Privacy Policy

Last Updated: July 24th, 2024

Concierge Pediatrics (“Concierge Pediatrics,” “we,” “us,” or “our”) operates a pediatric concierge healthcare platform that allows parents and their children to manage health information, schedule appointments, obtain AI-assisted second opinions, and interact with our care team (“Services”). This Privacy Policy explains how we collect, use, disclose, and safeguard information when you (as a parent or child user) access or use the Parent Application (“Parent App”).

Because we handle Protected Health Information (“PHI”), we comply with the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”). Where this Privacy Policy conflicts with a Business Associate Agreement or HIPAA requirement, the HIPAA requirement controls.

1. Scope

This Privacy Policy applies to:

It does not apply to third-party websites or services that are not controlled by us (e.g., external links).

2. Information We Collect

We collect the following categories of information:

2.1 Account & Identity Information

2.2 Medical & Health Information (PHI)

2.3 Insurance & Billing

2.4 AI Interaction Data

2.5 Communications & Support

2.6 Device & Usage Data

2.7 Automatically Generated Data

2.8 Children’s Information

Children may access their profiles using the same email/password/MFA flow established by the parent. We obtain verifiable parental consent during account creation. We do not knowingly collect additional personal information directly from a child beyond what is necessary to provide the Services.

3. How We Use Information

We use the information described above to:

  1. Deliver Core Services: Create and maintain parent/child accounts; schedule appointments; administer doctor availability; process urgent requests.
  2. Provide Medical Care: Maintain permanent medical records, support consultations, enable provider notes, facilitate secure sharing through the admin team.
  3. AI Second Opinions: Generate AI outputs using patient data; mark results as “unvetted”; allow doctors to review and rate accuracy.
  4. Billing & Insurance: Process subscriptions, specialist charges, diagnostics, and insurance claims.
  5. Notifications: Send email/SMS alerts for messages and appointments (parents/children may configure channel preference). We do not send notifications for AI results, health reminders, or billing updates.
  6. Security & Compliance: Enforce MFA, session timeouts, encryption, audit logging, fraud prevention, regulatory compliance.
  7. Support & Triage: Enable admin responses to questions, creation of FAQ content, and record-sharing requests.
  8. Legal Obligations: Respond to subpoenas, regulatory inquiries, or enforce our Terms.

We do not sell or rent PHI or personal information.

5. How We Share Information

We share information only as necessary:

All vendors handling PHI must sign appropriate Business Associate Agreements or equivalent contractual safeguards.

6. AI Processing Practices

AI second opinions use available patient data to generate advisory content. Outputs are stored permanently, labeled “unvetted,” and later reviewed by licensed physicians. AI outputs do not replace professional medical judgment. We log prompts and responses for quality assurance. Doctors’ accuracy ratings are aggregated for transparency.

7. Data Retention

When permissible, non-essential data may be de-identified or aggregated. We generally do not honor deletion requests for medical records where prohibited by healthcare regulations.

8. Your Choices & Rights

Parents and (where allowed) children may:

To request record sharing, corrections, or insurance updates, parents may contact the admin team. Some rights (e.g., deletion) may be limited due to healthcare laws.

If you are a resident of a state with additional privacy rights (e.g., California), you may contact us to exercise applicable rights. We do not discriminate for exercising privacy rights.

9. Children’s Privacy (COPPA Notice)

We obtain parental consent before creating child profiles. Children’s access is limited to viewing their own records and appointments; they cannot independently manage payment or administrative settings. Parents may revoke a child’s access by contacting support.

10. Security Measures

We implement reasonable and appropriate safeguards:

No method of transmission or storage is 100% secure; however, we follow industry and HIPAA standards to reduce risk.

11. International Data Transfers

Data is stored and processed in the United States. If you access the Services from outside the U.S., you consent to the transfer and processing of your information in the U.S. under this Privacy Policy.

13. Changes to This Policy

We may update this Privacy Policy periodically. The “Last Updated” date reflects the latest revision. Material changes will be communicated via the Parent App or email.

14. Contact Us

For questions, requests, or complaints about this Privacy Policy or our privacy practices, please contact:

Concierge Pediatrics Privacy Officer
Email: privacy@olliepediatrics.com
Address: 6620 SW 57th Ave Suite 221 Miami, FL, 33143
Phone: (305) 845-9559

If you believe your HIPAA privacy rights have been violated, you may also file a complaint with the U.S. Department of Health & Human Services, Office for Civil Rights.