
Privacy Policy
Last updated: February 16, 2026
This Privacy Policy ("Policy") describes how Kure Health Inc. ("Kure Health," "we," "us," or "our") collects, uses, discloses, and protects your personal information and, where applicable, your protected health information (PHI) when you visit our website at https://kurehealth.io, use our services, or interact with us in any way. Kure Health is a health and wellness company committed to safeguarding your privacy in compliance with all applicable laws and regulations.
We are committed to transparency about our data practices and to protecting your information in accordance with the Health Insurance Portability and Accountability Act (HIPAA), the California Consumer Privacy Act (CCPA/CPRA), the Health Information Technology for Economic and Clinical Health Act (HITECH), and all other applicable federal and state privacy laws.
By using our website or services, you acknowledge that you have read and understood this Policy. If you do not agree with our practices, please do not use our website or services.
Table of Contents
1. Information We Collect
We collect information in several ways depending on how you interact with Kure Health:
Personal Information You Provide
When you contact us, schedule an appointment, sign up for our newsletter, or use our services, you may provide:
- Full name, email address, phone number, and mailing address
- Date of birth and gender
- Insurance information and billing details
- Emergency contact information
- Employment and demographic information relevant to your care
Health & Medical Information
In connection with providing health and wellness services, we may collect:
- Medical history, current health conditions, and symptoms
- Treatment records, lab results, and diagnostic information
- Prescription and medication information
- Wellness assessment data and health goals
- Biometric data collected during treatments or assessments
- Mental health and behavioral health information
Note: Health and medical information may constitute Protected Health Information (PHI) under HIPAA and is subject to additional protections described in Section 3.
Information Collected Automatically
When you visit our website, we may automatically collect:
- IP address, browser type, device type, and operating system
- Pages visited, time spent, and navigation patterns
- Referring URLs and search terms
- Location data (general geographic area based on IP)
2. How We Use Your Information
We use the information we collect for the following purposes:
Healthcare Services
To provide, coordinate, and manage your health and wellness care, including treatment, payment, and healthcare operations as permitted by HIPAA.
Communication
To respond to your inquiries, send appointment reminders, provide health and wellness information, and communicate about our services.
Service Improvement
To improve our website, services, and patient experience through analytics and quality assurance activities.
Legal & Regulatory Compliance
To comply with applicable laws, regulations, and legal processes, including HIPAA, HITECH, CCPA, and state health privacy laws.
Safety & Fraud Prevention
To protect the safety of our patients, staff, and visitors, and to detect and prevent fraud, abuse, or other harmful activities.
Marketing (Non-PHI Only)
With your consent, to send you information about health and wellness programs, events, educational content, and promotional offers. We will never use your PHI for marketing without your explicit written authorization.
3. HIPAA & Protected Health Information
Our HIPAA Commitment
As a health and wellness provider, Kure Health is committed to compliance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the HITECH Act, and the HIPAA Privacy, Security, and Breach Notification Rules. Where we act as a Covered Entity or Business Associate, we maintain the required safeguards to protect your Protected Health Information (PHI).
What is Protected Health Information (PHI)?
PHI is individually identifiable health information that relates to your past, present, or future physical or mental health condition, the provision of healthcare to you, or past, present, or future payment for healthcare. PHI includes information held or transmitted in any form — electronic, paper, or oral.
Permitted Uses and Disclosures
We may use and disclose your PHI without your authorization for the following purposes as permitted by HIPAA:
- Treatment: To provide, coordinate, or manage your healthcare and related services
- Payment: To obtain payment for healthcare services provided to you
- Healthcare Operations: For quality assessment, compliance activities, audits, and business management
- As Required by Law: When required by federal, state, or local law
- Public Health Activities: For disease prevention, reporting, and public health surveillance
- Health & Safety: To prevent or lessen a serious and imminent threat to health or safety
Authorization Required
For uses and disclosures not described above, we will obtain your written authorization before using or disclosing your PHI. This includes, but is not limited to, marketing communications using PHI, sale of PHI, and most uses of psychotherapy notes. You may revoke your authorization at any time in writing.
Minimum Necessary Standard
When using or disclosing PHI, we apply the "minimum necessary" standard — we limit the PHI used, disclosed, or requested to the minimum amount necessary to accomplish the intended purpose.
Business Associates
We require all third-party vendors and service providers who may access your PHI to sign Business Associate Agreements (BAAs) that obligate them to safeguard your information in compliance with HIPAA.
Breach Notification
In the event of a breach of unsecured PHI, we will notify affected individuals, the U.S. Department of Health and Human Services (HHS), and, where required, the media, in accordance with the HIPAA Breach Notification Rule and the HITECH Act.
6. Your Privacy Rights
Under HIPAA and applicable state laws, you have the following rights regarding your information:
Right to Access
You have the right to inspect and obtain a copy of your PHI maintained by us, subject to certain exceptions.
Right to Amend
You may request that we amend your PHI if you believe it is inaccurate or incomplete.
Right to an Accounting of Disclosures
You may request a list of certain disclosures we have made of your PHI (excluding those for treatment, payment, or healthcare operations).
Right to Request Restrictions
You may request restrictions on certain uses and disclosures of your PHI. While we are not required to agree to all requests, we must comply with requests to restrict disclosures to a health plan for services you have paid for in full out of pocket.
Right to Confidential Communications
You may request that we communicate with you about health matters using a specific method or at a certain location.
Right to File a Complaint
If you believe your privacy rights have been violated, you may file a complaint with us or with the U.S. Department of Health and Human Services. We will not retaliate against you for filing a complaint.
Right to Opt Out
You may opt out of marketing communications at any time by using the unsubscribe link in our emails or contacting us directly.
To exercise any of these rights, please contact us at info@kurehealth.io.
7. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):
- Right to Know: You may request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purpose for collecting it, and the categories of third parties with whom we share it.
- Right to Delete: You may request deletion of your personal information, subject to certain exceptions.
- Right to Correct: You may request correction of inaccurate personal information.
- Right to Opt Out of Sale/Sharing: We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising purposes.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights.
- Right to Limit Use of Sensitive Personal Information: You may request that we limit the use and disclosure of your sensitive personal information.
Note: Medical information governed by HIPAA, the Confidentiality of Medical Information Act (CMIA), or collected as part of a clinical trial is exempt from certain CCPA requirements. However, we extend the spirit of these protections to all personal information we handle.
8. Data Security
We implement administrative, technical, and physical safeguards designed to protect your personal information and PHI, including:
Encryption
Data encrypted in transit (TLS/SSL) and at rest using industry-standard encryption protocols.
Access Controls
Role-based access controls ensuring only authorized personnel can access sensitive information.
Audit Trails
Comprehensive logging and monitoring of access to PHI and sensitive systems.
Staff Training
Regular HIPAA privacy and security training for all workforce members.
Incident Response
Documented breach response and notification procedures in compliance with HIPAA and state laws.
Vendor Management
Business Associate Agreements and security assessments for all vendors handling PHI.
While we strive to protect your information, no method of transmission over the internet or electronic storage is 100% secure. We encourage you to take steps to protect your own information, such as using strong passwords and keeping your login credentials confidential.
9. Data Retention
We retain your personal information and PHI for as long as necessary to fulfill the purposes described in this Policy, comply with legal obligations, resolve disputes, and enforce our agreements. Specific retention periods include:
- Medical Records: Retained in accordance with applicable federal and state medical record retention laws (typically a minimum of 6–10 years from the last date of service, or longer for minors).
- HIPAA Documentation: Policies, procedures, and compliance documentation retained for a minimum of 6 years as required by HIPAA.
- Website Data: Analytics and cookie data retained for up to 26 months unless you request earlier deletion.
- Marketing Data: Retained until you unsubscribe or request deletion.
10. Children's Privacy
Our website is not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13 through our website without verified parental consent, in compliance with the Children's Online Privacy Protection Act (COPPA).
When providing healthcare services to minors, we handle their health information in accordance with HIPAA, applicable state minor consent laws, and parental access rules. If you believe we have inadvertently collected information from a child under 13 through our website, please contact us immediately at info@kurehealth.io.
11. Third-Party Links & Services
Our website may contain links to third-party websites, services, or applications that are not operated by Kure Health. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party service before providing your information. This includes social media platforms such as LinkedIn and Instagram where Kure Health maintains a presence.
12. Telehealth & Digital Health Services
If we offer telehealth or digital health services, the following applies:
- Telehealth sessions are conducted using HIPAA-compliant platforms with end-to-end encryption.
- We comply with applicable state telehealth laws, including informed consent requirements.
- Recordings of telehealth sessions, if any, are treated as part of your medical record and protected accordingly.
- Digital health tools and patient portals use secure authentication and access controls.
13. State-Specific Disclosures
In addition to federal laws, we comply with state-specific health privacy laws where applicable, including but not limited to:
Florida
Florida's health information privacy laws, the Florida Information Protection Act (FIPA), and data breach notification requirements under Florida Statute §501.171.
California
The Confidentiality of Medical Information Act (CMIA), CCPA/CPRA, and California's data breach notification law (Civil Code §1798.82).
Other States
We comply with applicable state health privacy and data protection laws in every state where we provide services, including emerging comprehensive privacy laws in states such as Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), and others.
14. Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or regulatory guidance. When we make material changes, we will update the "Last Updated" date at the top of this Policy and, where required by law, provide you with additional notice. We encourage you to review this Policy periodically. Your continued use of our website or services after any changes indicates your acceptance of the updated Policy.
15. Contact Us
If you have questions about this Privacy Policy, wish to exercise your privacy rights, or need to report a privacy concern, please contact us:
Kure Health Inc.
Attn: Privacy Officer
621 S Spring Street, Downtown Los Angeles, CA 90014
Email: info@kurehealth.io
To file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights, visit hhs.gov/hipaa/filing-a-complaint.