Individual Access Services
Please read this notice carefully. This Privacy and Security Notice (“Notice”) explains how Theta Health, Inc. (“Theta Health,” “we,” “us,” or “our”) collects, uses, and protects your individually identifiable information when you use our Individual Access Services (IAS) to access your health records through the TEFCA health information network. By enabling IAS, you confirm that you have read and agree to this Notice.
TEFCA (Trusted Exchange Framework and Common Agreement) enables individuals to securely access their own health information held at healthcare organizations across the United States. Through our IAS integration, Theta Health can request and retrieve your clinical records — such as visit summaries, lab results, medications, and diagnoses — from participating healthcare organizations on your behalf, and make them available to you within the Theta Health app.
Theta Health connects to the TEFCA network through CommonWell Health Alliance, our Qualified Health Information Network (QHIN). CommonWell serves as the gateway through which health record queries are routed to participating healthcare organizations. All data exchanged through TEFCA is subject to the TEFCA Common Agreement and applicable U.S. Department of Health and Human Services (HHS) guidance.
When you enable IAS, Theta Health may access and process the following categories of individually identifiable health information:
All demographic data submitted to the health information network on your behalf is verified by our identity verification partner (CLEAR) prior to use. We only submit verified data for health record retrieval.
We will not use your individually identifiable information to assert any claim against you, except for the collection of applicable fees. We do not use your health information for targeted advertising or marketing purposes.
We do not sell your individually identifiable health information. We do not share it with third parties for their own marketing or advertising purposes.
We work with third-party service providers that help us operate IAS, including cloud infrastructure (Amazon Web Services, for encrypted document storage) and identity verification (CLEAR / Alclear Healthcare, LLC). These providers are contractually required to process your information only on our behalf, in accordance with this Notice and commercially reasonable security requirements.
To retrieve your records, your verified identity and demographics are transmitted to CommonWell Health Alliance (our QHIN) and onward to participating healthcare organizations solely to locate and retrieve your records. All such disclosures through TEFCA are in accordance with the permitted and required uses and disclosures specified in the TEFCA Common Agreement and applicable HHS guidance.
We may be required to disclose your information in response to a valid legal demand such as a subpoena, court order, or search warrant. Unless prohibited by applicable law, we will provide written or electronic notice to you within three (3) business days of receiving such a demand, so that you have the opportunity to seek a protective order or other remedy. If we make your information available to law enforcement agencies, we will similarly notify you within three (3) business days unless legally prohibited.
We may de-identify your health information in accordance with applicable law. De-identified data may be used for analytics, product improvement, or research, and is no longer subject to this Notice.
In the event of a merger, acquisition, or sale of assets, your information may be transferred. We will notify you before such a transfer takes effect.
We retain your individually identifiable health information for as long as your account is active or as necessary to provide the service:
Our obligations under this Notice continue for as long as we maintain your individually identifiable information.
Theta Health uses commercially reasonable efforts to protect your information from unauthorized or illegal access, modification, use, or destruction. No system is completely secure. Please use a strong password and contact us immediately if you suspect unauthorized access.
Theta Health is not directly subject to the Health Insurance Portability and Accountability Act (HIPAA) Rules as a Covered Entity or Business Associate. In the IAS context, you are authorizing Theta Health to retrieve your own health records on your behalf; Theta Health does not have a direct contractual relationship with the healthcare organizations holding your records.
Theta Health’s handling of your individually identifiable health information in connection with IAS is governed by the FTC Health Breach Notification Rule (16 CFR Part 318), this Notice, and the TEFCA Common Agreement. Healthcare organizations holding your records may be HIPAA Covered Entities, and their HIPAA Notices of Privacy Practices govern how they handle your data at their facilities.
Theta Health voluntarily maintains security and privacy practices consistent with HIPAA standards as part of its overall compliance posture.
You have the following rights with respect to your individually identifiable health information maintained by Theta Health in connection with IAS:
To exercise these rights, contact us via Section 11 or visit Settings → Privacy in the Theta Health app. We will inform you if applicable law prohibits us from honoring a deletion request.
If a TEFCA security incident or breach of unencrypted individually identifiable information occurs affecting your data, Theta Health will notify you as promptly as possible.
Our notification will include, to the extent known:
Notification will be sent to your registered email address and/or via in-app notification. We will not send duplicative notifications where applicable law already requires us to notify you of the same incident.
If we make material changes to this Notice, we will notify you and request fresh consent before those changes apply to your information.
You may revoke consent and disconnect IAS at any time. Revocation will not affect actions already taken in reliance on your prior consent. After revocation, Theta Health will stop retrieving new health records on your behalf; you will no longer be able to use IAS to sync new records. Health records already retrieved and stored in the app prior to revocation will remain accessible to you in the app. You may separately request deletion of your health records at any time under Section 8.
Steps to revoke consent and disconnect IAS:
You may also revoke consent by contacting us using the information in Section 11.
For questions about this Notice, to exercise your rights, or to submit a privacy-related complaint, please contact us:
| Channel | Contact |
|---|---|
| Toll-free | (855) 952-9225 |
| support@thetahealth.ai | |
| Web | thetahealth.ai/contact |
| Theta Health, Inc., 303 Twin Dolphin Drive, Suite 6054, Redwood City, CA 94065 |
We maintain a documented process for receiving, tracking, and responding to all privacy complaints, including the final disposition of each complaint. We will respond within 45 days.
We may update this Notice from time to time. We will post changes on this page no later than the effective date of each change. For material changes, we will:
In any dispute over whether a change is material, Theta Health bears the burden of demonstrating it was immaterial.
Theta Health does not currently charge any fees for accessing Individual Access Services. If fees are introduced in the future, this Notice will be updated with the applicable fee schedule and effective date, and you will be notified in advance.