Skip to main content
    Legal page header

    Privacy Policy

    Last updated: February 16, 2026

    This Privacy Policy ("Policy") describes how Kure Health Inc. ("Kure Health," "we," "us," or "our") collects, uses, discloses, and protects your personal information and, where applicable, your protected health information (PHI) when you visit our website at https://kurehealth.io, use our services, or interact with us in any way. Kure Health is a health and wellness company committed to safeguarding your privacy in compliance with all applicable laws and regulations.

    We are committed to transparency about our data practices and to protecting your information in accordance with the Health Insurance Portability and Accountability Act (HIPAA), the California Consumer Privacy Act (CCPA/CPRA), the Health Information Technology for Economic and Clinical Health Act (HITECH), and all other applicable federal and state privacy laws.

    By using our website or services, you acknowledge that you have read and understood this Policy. If you do not agree with our practices, please do not use our website or services.

    1. Information We Collect

    We collect information in several ways depending on how you interact with Kure Health:

    Personal Information You Provide

    When you contact us, schedule an appointment, sign up for our newsletter, or use our services, you may provide:

    • Full name, email address, phone number, and mailing address
    • Date of birth and gender
    • Insurance information and billing details
    • Emergency contact information
    • Employment and demographic information relevant to your care

    Health & Medical Information

    In connection with providing health and wellness services, we may collect:

    • Medical history, current health conditions, and symptoms
    • Treatment records, lab results, and diagnostic information
    • Prescription and medication information
    • Wellness assessment data and health goals
    • Biometric data collected during treatments or assessments
    • Mental health and behavioral health information

    Note: Health and medical information may constitute Protected Health Information (PHI) under HIPAA and is subject to additional protections described in Section 3.

    Information Collected Automatically

    When you visit our website, we may automatically collect:

    • IP address, browser type, device type, and operating system
    • Pages visited, time spent, and navigation patterns
    • Referring URLs and search terms
    • Location data (general geographic area based on IP)

    2. How We Use Your Information

    We use the information we collect for the following purposes:

    Healthcare Services

    To provide, coordinate, and manage your health and wellness care, including treatment, payment, and healthcare operations as permitted by HIPAA.

    Communication

    To respond to your inquiries, send appointment reminders, provide health and wellness information, and communicate about our services.

    Service Improvement

    To improve our website, services, and patient experience through analytics and quality assurance activities.

    Legal & Regulatory Compliance

    To comply with applicable laws, regulations, and legal processes, including HIPAA, HITECH, CCPA, and state health privacy laws.

    Safety & Fraud Prevention

    To protect the safety of our patients, staff, and visitors, and to detect and prevent fraud, abuse, or other harmful activities.

    Marketing (Non-PHI Only)

    With your consent, to send you information about health and wellness programs, events, educational content, and promotional offers. We will never use your PHI for marketing without your explicit written authorization.

    3. HIPAA & Protected Health Information

    Our HIPAA Commitment

    As a health and wellness provider, Kure Health is committed to compliance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the HITECH Act, and the HIPAA Privacy, Security, and Breach Notification Rules. Where we act as a Covered Entity or Business Associate, we maintain the required safeguards to protect your Protected Health Information (PHI).

    What is Protected Health Information (PHI)?

    PHI is individually identifiable health information that relates to your past, present, or future physical or mental health condition, the provision of healthcare to you, or past, present, or future payment for healthcare. PHI includes information held or transmitted in any form — electronic, paper, or oral.

    Permitted Uses and Disclosures

    We may use and disclose your PHI without your authorization for the following purposes as permitted by HIPAA:

    • Treatment: To provide, coordinate, or manage your healthcare and related services
    • Payment: To obtain payment for healthcare services provided to you
    • Healthcare Operations: For quality assessment, compliance activities, audits, and business management
    • As Required by Law: When required by federal, state, or local law
    • Public Health Activities: For disease prevention, reporting, and public health surveillance
    • Health & Safety: To prevent or lessen a serious and imminent threat to health or safety

    Authorization Required

    For uses and disclosures not described above, we will obtain your written authorization before using or disclosing your PHI. This includes, but is not limited to, marketing communications using PHI, sale of PHI, and most uses of psychotherapy notes. You may revoke your authorization at any time in writing.

    Minimum Necessary Standard

    When using or disclosing PHI, we apply the "minimum necessary" standard — we limit the PHI used, disclosed, or requested to the minimum amount necessary to accomplish the intended purpose.

    Business Associates

    We require all third-party vendors and service providers who may access your PHI to sign Business Associate Agreements (BAAs) that obligate them to safeguard your information in compliance with HIPAA.

    Breach Notification

    In the event of a breach of unsecured PHI, we will notify affected individuals, the U.S. Department of Health and Human Services (HHS), and, where required, the media, in accordance with the HIPAA Breach Notification Rule and the HITECH Act.

    4. How We Share Your Information

    We do not sell your personal information or PHI. We may share your information in the following circumstances:

    Service Providers

    With trusted third-party vendors who assist us in operating our business (e.g., IT services, billing, analytics), subject to contractual obligations and, where applicable, Business Associate Agreements.

    Healthcare Providers

    With other healthcare providers involved in your treatment or care coordination, as permitted by HIPAA.

    Insurance & Payment

    With health plans and insurers for payment and coverage purposes.

    Legal Requirements

    When required by law, regulation, legal process, or governmental request, including public health reporting obligations.

    With Your Consent

    In any other circumstance where you provide your explicit consent for us to share your information.

    5. Cookies & Tracking Technologies

    Our website uses cookies and similar technologies to enhance your experience and analyze site usage. These technologies do not collect PHI.

    Essential Cookies

    Required for the website to function properly, including session management and security features. These cannot be disabled.

    Analytics Cookies

    Help us understand how visitors interact with our website by collecting anonymous usage data. We use tools such as Google Analytics, which collects data in aggregate form.

    Functional Cookies

    Remember your preferences (such as language or display settings) to provide a personalized experience.

    You can control cookies through your browser settings. For more details, please see our Cookie Policy.

    6. Your Privacy Rights

    Under HIPAA and applicable state laws, you have the following rights regarding your information:

    Right to Access

    You have the right to inspect and obtain a copy of your PHI maintained by us, subject to certain exceptions.

    Right to Amend

    You may request that we amend your PHI if you believe it is inaccurate or incomplete.

    Right to an Accounting of Disclosures

    You may request a list of certain disclosures we have made of your PHI (excluding those for treatment, payment, or healthcare operations).

    Right to Request Restrictions

    You may request restrictions on certain uses and disclosures of your PHI. While we are not required to agree to all requests, we must comply with requests to restrict disclosures to a health plan for services you have paid for in full out of pocket.

    Right to Confidential Communications

    You may request that we communicate with you about health matters using a specific method or at a certain location.

    Right to File a Complaint

    If you believe your privacy rights have been violated, you may file a complaint with us or with the U.S. Department of Health and Human Services. We will not retaliate against you for filing a complaint.

    Right to Opt Out

    You may opt out of marketing communications at any time by using the unsubscribe link in our emails or contacting us directly.

    To exercise any of these rights, please contact us at info@kurehealth.io.

    7. California Privacy Rights (CCPA/CPRA)

    If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):

    • Right to Know: You may request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purpose for collecting it, and the categories of third parties with whom we share it.
    • Right to Delete: You may request deletion of your personal information, subject to certain exceptions.
    • Right to Correct: You may request correction of inaccurate personal information.
    • Right to Opt Out of Sale/Sharing: We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising purposes.
    • Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights.
    • Right to Limit Use of Sensitive Personal Information: You may request that we limit the use and disclosure of your sensitive personal information.

    Note: Medical information governed by HIPAA, the Confidentiality of Medical Information Act (CMIA), or collected as part of a clinical trial is exempt from certain CCPA requirements. However, we extend the spirit of these protections to all personal information we handle.

    8. Data Security

    We implement administrative, technical, and physical safeguards designed to protect your personal information and PHI, including:

    Encryption

    Data encrypted in transit (TLS/SSL) and at rest using industry-standard encryption protocols.

    Access Controls

    Role-based access controls ensuring only authorized personnel can access sensitive information.

    Audit Trails

    Comprehensive logging and monitoring of access to PHI and sensitive systems.

    Staff Training

    Regular HIPAA privacy and security training for all workforce members.

    Incident Response

    Documented breach response and notification procedures in compliance with HIPAA and state laws.

    Vendor Management

    Business Associate Agreements and security assessments for all vendors handling PHI.

    While we strive to protect your information, no method of transmission over the internet or electronic storage is 100% secure. We encourage you to take steps to protect your own information, such as using strong passwords and keeping your login credentials confidential.

    9. Data Retention

    We retain your personal information and PHI for as long as necessary to fulfill the purposes described in this Policy, comply with legal obligations, resolve disputes, and enforce our agreements. Specific retention periods include:

    • Medical Records: Retained in accordance with applicable federal and state medical record retention laws (typically a minimum of 6–10 years from the last date of service, or longer for minors).
    • HIPAA Documentation: Policies, procedures, and compliance documentation retained for a minimum of 6 years as required by HIPAA.
    • Website Data: Analytics and cookie data retained for up to 26 months unless you request earlier deletion.
    • Marketing Data: Retained until you unsubscribe or request deletion.

    10. Children's Privacy

    Our website is not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13 through our website without verified parental consent, in compliance with the Children's Online Privacy Protection Act (COPPA).

    When providing healthcare services to minors, we handle their health information in accordance with HIPAA, applicable state minor consent laws, and parental access rules. If you believe we have inadvertently collected information from a child under 13 through our website, please contact us immediately at info@kurehealth.io.

    11. Third-Party Links & Services

    Our website may contain links to third-party websites, services, or applications that are not operated by Kure Health. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party service before providing your information. This includes social media platforms such as LinkedIn and Instagram where Kure Health maintains a presence.

    12. Telehealth & Digital Health Services

    If we offer telehealth or digital health services, the following applies:

    • Telehealth sessions are conducted using HIPAA-compliant platforms with end-to-end encryption.
    • We comply with applicable state telehealth laws, including informed consent requirements.
    • Recordings of telehealth sessions, if any, are treated as part of your medical record and protected accordingly.
    • Digital health tools and patient portals use secure authentication and access controls.

    13. State-Specific Disclosures

    In addition to federal laws, we comply with state-specific health privacy laws where applicable, including but not limited to:

    Florida

    Florida's health information privacy laws, the Florida Information Protection Act (FIPA), and data breach notification requirements under Florida Statute §501.171.

    California

    The Confidentiality of Medical Information Act (CMIA), CCPA/CPRA, and California's data breach notification law (Civil Code §1798.82).

    Other States

    We comply with applicable state health privacy and data protection laws in every state where we provide services, including emerging comprehensive privacy laws in states such as Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), and others.

    14. Updates to This Policy

    We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or regulatory guidance. When we make material changes, we will update the "Last Updated" date at the top of this Policy and, where required by law, provide you with additional notice. We encourage you to review this Policy periodically. Your continued use of our website or services after any changes indicates your acceptance of the updated Policy.

    15. Contact Us

    If you have questions about this Privacy Policy, wish to exercise your privacy rights, or need to report a privacy concern, please contact us:

    Kure Health Inc.

    Attn: Privacy Officer

    621 S Spring Street, Downtown Los Angeles, CA 90014

    Email: info@kurehealth.io

    To file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights, visit hhs.gov/hipaa/filing-a-complaint.

    Cookie Preferences

    We use cookies to improve your experience and analyze site traffic. Learn about our cookie policy