Individual Access Services

Privacy and Security Notice

Effective Date: May 1, 2026   ·   Last Updated: May 1, 2026

Please read this notice carefully. This Privacy and Security Notice (“Notice”) explains how Theta Health, Inc. (“Theta Health,” “we,” “us,” or “our”) collects, uses, and protects your individually identifiable information when you use our Individual Access Services (IAS) to access your health records through the TEFCA health information network. By enabling IAS, you confirm that you have read and agree to this Notice.

Theta Health does not provide bidirectional services. You will have the ability to request access to your health information via TEFCA Exchange. You will not be able to use Theta Health to share your health information with other participants in TEFCA.

1. What Is Individual Access Services (IAS)?

TEFCA (Trusted Exchange Framework and Common Agreement) enables individuals to securely access their own health information held at healthcare organizations across the United States. Through our IAS integration, Theta Health can request and retrieve your clinical records — such as visit summaries, lab results, medications, and diagnoses — from participating healthcare organizations on your behalf, and make them available to you within the Theta Health app.

Theta Health connects to the TEFCA network through CommonWell Health Alliance, our Qualified Health Information Network (QHIN). CommonWell serves as the gateway through which health record queries are routed to participating healthcare organizations. All data exchanged through TEFCA is subject to the TEFCA Common Agreement and applicable U.S. Department of Health and Human Services (HHS) guidance.

2. Information We Access and Use

When you enable IAS, Theta Health may access and process the following categories of individually identifiable health information:

All demographic data submitted to the health information network on your behalf is verified by our identity verification partner (CLEAR) prior to use. We only submit verified data for health record retrieval.

3. How We Use Your Information

We will not use your individually identifiable information to assert any claim against you, except for the collection of applicable fees. We do not use your health information for targeted advertising or marketing purposes.

4. How We Share Your Information

We do not sell your individually identifiable health information. We do not share it with third parties for their own marketing or advertising purposes.

Service Providers

We work with third-party service providers that help us operate IAS, including cloud infrastructure (Amazon Web Services, for encrypted document storage) and identity verification (CLEAR / Alclear Healthcare, LLC). These providers are contractually required to process your information only on our behalf, in accordance with this Notice and commercially reasonable security requirements.

TEFCA Network

To retrieve your records, your verified identity and demographics are transmitted to CommonWell Health Alliance (our QHIN) and onward to participating healthcare organizations solely to locate and retrieve your records. All such disclosures through TEFCA are in accordance with the permitted and required uses and disclosures specified in the TEFCA Common Agreement and applicable HHS guidance.

Legal Requirements

We may be required to disclose your information in response to a valid legal demand such as a subpoena, court order, or search warrant. Unless prohibited by applicable law, we will provide written or electronic notice to you within three (3) business days of receiving such a demand, so that you have the opportunity to seek a protective order or other remedy. If we make your information available to law enforcement agencies, we will similarly notify you within three (3) business days unless legally prohibited.

De-identification

We may de-identify your health information in accordance with applicable law. De-identified data may be used for analytics, product improvement, or research, and is no longer subject to this Notice.

Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred. We will notify you before such a transfer takes effect.

5. Data Retention

We retain your individually identifiable health information for as long as your account is active or as necessary to provide the service:

Our obligations under this Notice continue for as long as we maintain your individually identifiable information.

6. How We Protect Your Information

Theta Health uses commercially reasonable efforts to protect your information from unauthorized or illegal access, modification, use, or destruction. No system is completely secure. Please use a strong password and contact us immediately if you suspect unauthorized access.

7. Regulatory Framework

Theta Health is not directly subject to the Health Insurance Portability and Accountability Act (HIPAA) Rules as a Covered Entity or Business Associate. In the IAS context, you are authorizing Theta Health to retrieve your own health records on your behalf; Theta Health does not have a direct contractual relationship with the healthcare organizations holding your records.

Theta Health’s handling of your individually identifiable health information in connection with IAS is governed by the FTC Health Breach Notification Rule (16 CFR Part 318), this Notice, and the TEFCA Common Agreement. Healthcare organizations holding your records may be HIPAA Covered Entities, and their HIPAA Notices of Privacy Practices govern how they handle your data at their facilities.

Theta Health voluntarily maintains security and privacy practices consistent with HIPAA standards as part of its overall compliance posture.

8. Your Rights

You have the following rights with respect to your individually identifiable health information maintained by Theta Health in connection with IAS:

To exercise these rights, contact us via Section 11 or visit Settings → Privacy in the Theta Health app. We will inform you if applicable law prohibits us from honoring a deletion request.

9. Security Incident Notification

If a TEFCA security incident or breach of unencrypted individually identifiable information occurs affecting your data, Theta Health will notify you as promptly as possible.

Our notification will include, to the extent known:

Notification will be sent to your registered email address and/or via in-app notification. We will not send duplicative notifications where applicable law already requires us to notify you of the same incident.

10. Your Consent and How to Revoke It

If we make material changes to this Notice, we will notify you and request fresh consent before those changes apply to your information.

How to Revoke Your Consent

You may revoke consent and disconnect IAS at any time. Revocation will not affect actions already taken in reliance on your prior consent. After revocation, Theta Health will stop retrieving new health records on your behalf; you will no longer be able to use IAS to sync new records. Health records already retrieved and stored in the app prior to revocation will remain accessible to you in the app. You may separately request deletion of your health records at any time under Section 8.

Steps to revoke consent and disconnect IAS:

  1. Open the Theta Health app
  2. Tap Settings in the bottom navigation
  3. Tap Data SourcesHealth Information Network
  4. Tap Disconnect at the bottom of the screen
  5. Confirm your choice when prompted

You may also revoke consent by contacting us using the information in Section 11.

11. Contact Us & Privacy Complaints

For questions about this Notice, to exercise your rights, or to submit a privacy-related complaint, please contact us:

Channel Contact
Toll-free (855) 952-9225
Email support@thetahealth.ai
Web thetahealth.ai/contact
Mail Theta Health, Inc., 303 Twin Dolphin Drive, Suite 6054, Redwood City, CA 94065

We maintain a documented process for receiving, tracking, and responding to all privacy complaints, including the final disposition of each complaint. We will respond within 45 days.

12. Updates to This Notice

We may update this Notice from time to time. We will post changes on this page no later than the effective date of each change. For material changes, we will:

In any dispute over whether a change is material, Theta Health bears the burden of demonstrating it was immaterial.

13. Fees

Theta Health does not currently charge any fees for accessing Individual Access Services. If fees are introduced in the future, this Notice will be updated with the applicable fee schedule and effective date, and you will be notified in advance.

This Notice is effective as of May 1, 2026. Prior versions are available upon request — support@thetahealth.ai