Privacy Policy

Protecting Your Health Information

Mailing Address
55 W 14th St, Helena, MT 59601, United States

1 Introduction and Commitment to Privacy

At GoTo Telemed, we recognize that your privacy is paramount. As a leading telehealth platform connecting patients with qualified medical practitioners, we understand the sensitive nature of the health information entrusted to us. Our commitment extends beyond mere compliance—we strive to set the gold standard for privacy protection in digital healthcare.

This Privacy Policy serves as your comprehensive guide to understanding how we collect, use, protect, and manage your personal and medical information. We've designed our privacy practices around core principles of transparency, security, and respect for individual rights. Whether you're a patient seeking care or a medical practitioner providing services, you can trust that your data is handled with the utmost care and in full compliance with all applicable privacy regulations.

We believe informed patients and practitioners make better decisions. This policy empowers you with knowledge about your privacy rights and our obligations, ensuring a foundation of trust in every telehealth interaction conducted through our platform.

2 Information Collection and Types of Data

GoTo Telemed collects various types of information necessary to deliver secure, effective telehealth services. Our data collection practices are designed to serve two primary purposes: facilitating quality healthcare delivery and maintaining regulatory compliance. We collect only the information needed to provide excellent care and operate our platform efficiently.

Personal Information
Name, contact details, date of birth, and demographic information essential for identification and communication
Medical Data
Complete health records, diagnoses, treatment plans, and clinical notes from consultations
Professional Credentials
Licenses, certifications, and qualifications of medical practitioners on our platform

The scope of information we collect varies depending on your role—whether you're a patient receiving care or a medical practitioner providing services. Every piece of information collected serves a specific purpose in ensuring seamless, secure healthcare delivery.

3 Patient Personal Information

When you register as a patient on GoTo Telemed, we collect essential personal information that enables us to deliver telehealth services safely and effectively. This includes your full legal name, date of birth, gender, and contact information such as email addresses, phone numbers, and residential address.

Data Protection: We also gather demographic information including preferred language, emergency contact details, and insurance information when applicable. All personal information is collected with your explicit consent during the registration process. You have the right to review and update this information at any time through your secure patient portal.

Your demographic information may also be used in aggregate form—stripped of identifying details—to improve our services and understand the communities we serve. This ensures we maintain current and accurate records for optimal care delivery.

4 Medical Practitioner Professional Information

For medical practitioners joining our platform—including Physicians, Physician Assistants (PAs), Registered Nurses (RNs), Nurse Practitioners (NPs), Dentists (DDS), Registered Dental Hygienists (RDH), and other licensed healthcare professionals—we collect comprehensive professional information to verify credentials and maintain practice standards.

1
Credential Verification
State medical licenses, DEA numbers, and board certifications
2
Professional Background
Education, training, specialties, and areas of clinical expertise
3
Practice Information
Current practice locations, affiliations, and malpractice insurance details
4
Ongoing Compliance
Continuing education records and license renewal documentation

5 Health and Medical Records

GoTo Telemed maintains detailed electronic health records (EHRs) for every patient receiving care through our platform. These records include your complete medical history, current medications, known allergies, previous diagnoses, and treatment outcomes. Our system integrates information from each consultation, creating a longitudinal health record that enables continuity of care.

Security & Confidentiality: All medical records are stored in HIPAA-compliant systems with robust security measures protecting against unauthorized access. We maintain strict audit trails documenting every instance of record access, ensuring accountability and enabling investigation of any security concerns.

Medical practitioners document clinical notes, assessment findings, treatment plans, and follow-up recommendations during and after each telehealth visit. These records are essential for coordinating care between multiple providers, tracking treatment progress, and ensuring patient safety through medication interaction checks and allergy alerts.

6 Diagnostic and Test Data

Our platform facilitates the collection and secure management of diagnostic information essential for clinical decision-making. This includes laboratory test results from blood work, urinalysis, and other clinical tests ordered by your healthcare provider, as well as diagnostic imaging data such as X-rays, CT scans, MRIs, and ultrasounds.

Laboratory Results
Blood tests, cultures, pathology reports, and other lab findings integrated directly into your health record
Imaging Studies
Digital medical images with radiologist interpretations and annotations accessible during consultations
Clinical Assessments
Standardized assessment tools, screening questionnaires, and telemedicine-adapted examination findings

7 Billing and Payment Information

We collect comprehensive insurance details to facilitate claims processing and verify coverage for telehealth services. This includes your insurance carrier name, policy numbers, group numbers, and subscriber information. For patients with multiple insurance policies, we maintain records of primary and secondary coverage and coordination of benefits information.

Payment Security: For direct payment transactions, we securely process credit card information and bank account details through PCI-compliant payment processors. We do not store complete credit card numbers on our servers—instead, we use tokenization to protect your financial information. Your billing address, payment history, and financial assistance arrangements are maintained in secure systems separate from your medical records.

8 Usage and Device Information

We automatically collect information about the devices you use to access our platform and how you interact with our services. This technical information helps us optimize platform performance, ensure compatibility across different devices, and improve user experience.

Device Identifiers
Device type, operating system, unique device identifiers, and mobile network information
Browser & Network
Browser type and version, IP address, internet service provider information
Platform Usage Analytics
Pages visited, features used, time spent on sections, and click patterns

9 Communication Records

GoTo Telemed records and stores various forms of communication between patients and medical practitioners to ensure quality care, maintain accurate medical records, and protect both parties. Video consultations may be recorded with your explicit consent, providing an audio-visual record of the clinical encounter.

1
Pre-Visit Messages
Scheduling communications and intake questionnaires
2
Consultation Records
Video recordings and real-time chat during visits
3
Follow-Up Communications
Post-visit instructions and secure messaging
4
Care Coordination
Communications between providers about your care

10 Consent and Authorization Forms

Before receiving telehealth services through GoTo Telemed, patients and practitioners complete various consent and authorization documents. These legally binding forms establish the foundation for our professional relationship and define how your information may be used and shared.

Patient Consents
Telehealth services agreement, treatment consent forms, technology use acknowledgment, financial responsibility agreement
HIPAA Authorizations
Notice of Privacy Practices acknowledgment, information sharing authorizations, release of information forms
Practitioner Agreements
Platform terms of service, HIPAA Business Associate Agreement, professional conduct policies

Your consent is never assumed—we obtain explicit authorization before using your information for purposes beyond direct treatment, payment, or healthcare operations. You maintain the right to revoke certain authorizations at any time through your secure portal.

11 HIPAA Compliance Standards

The Health Insurance Portability and Accountability Act (HIPAA) establishes national standards for protecting sensitive patient health information. As a covered entity under HIPAA, GoTo Telemed adheres strictly to all Privacy Rule and Security Rule requirements governing Protected Health Information (PHI).

Privacy Rule Compliance
We implement stringent controls over PHI use and disclosure, ensuring information is shared only for permitted purposes or with your explicit authorization
Security Rule Standards
Our technical, physical, and administrative safeguards protect electronic PHI from unauthorized access, modification, or destruction
Breach Notification
We've established procedures to identify, investigate, and report any unauthorized PHI disclosure within strict timelines

Our workforce receives regular HIPAA training covering privacy principles, security practices, and individual responsibilities. Compliance is a core value that shapes every decision we make about protecting your health information.

12 Data Security and Encryption

Protecting your sensitive health information requires multiple layers of sophisticated security technology. GoTo Telemed employs industry-leading encryption protocols to safeguard data throughout its lifecycle—during transmission, while in use, and when stored in our databases.

Data in Transit
TLS 1.3 encryption for all network communications
Data at Rest
AES-256 encryption for stored data and backups
Data in Use
Secure enclaves and memory encryption during processing

All data transmitted between your device and our servers uses Transport Layer Security (TLS) 1.3 encryption. When you participate in a video consultation, the audio and video streams are encrypted end-to-end, ensuring your conversation remains private.

13 Access Controls and Authentication

Every user accessing GoTo Telemed must authenticate their identity using multiple factors before gaining platform access. Beyond traditional passwords, we require a second verification method—such as a code sent to your mobile device or biometric authentication.

1
Identity Verification
Confirm your identity through knowledge-based authentication during registration
2
Strong Passwords
Create complex passwords meeting length, character variety, and uniqueness standards
3
Second Factor
Verify access attempts using a separate device or biometric confirmation
4
Session Management
Automatic logout after inactivity periods and secure session token handling

Our role-based access control system ensures users can only access data and features necessary for their specific role. A billing administrator cannot view clinical notes, while a nurse practitioner cannot access billing information beyond what's needed for treatment authorization.

14 Data Storage and Infrastructure

GoTo Telemed's technical infrastructure is built on enterprise-grade cloud services maintained in secure, geographically distributed data centers. These facilities feature 24/7 physical security, environmental controls, redundant power systems, and sophisticated fire suppression—all designed to ensure your data remains available and protected.

Redundant Backups
Automated daily backups stored in multiple geographic locations ensure data recovery capability
High Availability
Load-balanced server architecture and failover systems maintain platform availability with 99.9% uptime target
Data Integrity
Checksums, version control, and audit logging ensure data accuracy and detect unauthorized modifications
Disaster Recovery
Comprehensive disaster recovery plans enable rapid service restoration following major incidents

All data storage locations are within the United States, subject to U.S. privacy laws and healthcare regulations. We maintain detailed documentation of data flows, storage locations, and system architectures to support security audits and regulatory compliance reviews.

15 Third-Party Service Providers

Delivering comprehensive telehealth services requires collaboration with carefully selected third-party vendors and service providers. GoTo Telemed works only with partners who demonstrate strong security practices and willingness to comply with HIPAA requirements through Business Associate Agreements.

Technology Partners
Cloud hosting providers, video conferencing technology, electronic health record systems, data backup and recovery services
Business Operations
Payment processors, insurance verification services, identity verification providers, communication platforms

Each third-party provider operates under strict contractual obligations limiting how they may access, use, and disclose your information. We regularly review vendor compliance through audits, security assessments, and performance evaluations. We maintain a current list of all third-party processors with access to patient data, available upon request to regulatory authorities.

16 Data Sharing Restrictions

Your medical information belongs to you, and GoTo Telemed takes seriously our responsibility to share it only when appropriate and authorized. Our default position is always to restrict sharing unless there's a clear legal basis or your explicit consent.

Treatment Purposes
We share information with healthcare providers directly involved in your care, including specialists, laboratories, and pharmacies
Payment Activities
Insurance companies and billing services receive minimum necessary information to process claims and payments
Healthcare Operations
Quality improvement, training, compliance activities, and business management occur with limited, monitored access
No Sales of Data: We do not sell, rent, or trade your health information for marketing purposes. Research use of de-identified data occurs only after rigorous review and approval by privacy officials.

17 Patient Rights and Data Access

As a patient using GoTo Telemed services, you possess important legal rights regarding your personal health information. We are committed not only to respecting these rights but to making them easy to exercise.

1
Right to Access
Request and receive copies of your medical records within 30 days of your request
2
Right to Amend
Request corrections to information you believe is inaccurate or incomplete
3
Right to Accounting
Receive a list of disclosures we've made of your information outside routine purposes
4
Right to Restrict
Request limits on how we use or share your information with appropriate limitations
5
Right to Confidential Communications
Request communications through alternative means if regular contact could endanger you

You can exercise these rights by submitting requests through your secure patient portal or by contacting our privacy office. In most cases, there is no charge for accessing your records.

18 Practitioner Data Access Restrictions

Medical practitioners on the GoTo Telemed platform operate under the principle that governs all healthcare: access patient information only when directly relevant to providing treatment. Our system enforces strict limitations ensuring practitioners can view records only for patients under their active care.

Emergency Access: Emergency break-glass procedures allow practitioners to access patient information in urgent situations even without established relationships, but these accesses trigger immediate security reviews and require documented justification.
Access Only for Treatment
Practitioners can access only patient records for individuals under their direct care
Security Monitoring
Our audit systems flag inappropriate access attempts for investigation
Session Security
Practitioners must log out after each session and never share login credentials
Incident Reporting
Suspected security incidents or privacy breaches must be reported immediately

19 Data Retention Policies

GoTo Telemed maintains your health information for specific periods determined by medical best practices, legal requirements, and regulatory standards. Our retention schedules balance the need to preserve records for continuity of care and legal protection against privacy principles favoring limited data retention.

1
Active Patient Records
Complete medical records for patients with visits in the past 7 years are maintained in active systems
2
Inactive Patient Records
Records for patients without recent visits move to secure archive storage after 7 years
3
Pediatric Records
Minor patients' records are retained until age of majority plus 7 years
4
Legal Hold Records
Records subject to litigation or investigations are preserved until legal matters conclude

You may request continued retention of your records beyond standard periods by contacting us in writing, and we will accommodate such requests when operationally feasible.

20 Deletion and Data Destruction

When health information reaches the end of its retention period or when you request deletion of your data, GoTo Telemed follows rigorous procedures to ensure complete and irreversible destruction. We employ methods that make information technically infeasible to recover, meeting standards established by NIST and HIPAA guidelines.

Digital Data
Electronic records undergo cryptographic erasure where encryption keys are destroyed
Cloud-based Deletion
Coordination with infrastructure providers ensures all copies including backups are completely removed
Deletion Requests
Personal data deletion requests are processed within 60 days of verification
Note: Deletion may prevent us from providing future services since we won't have necessary medical history to ensure safe care. Some information may be preserved in de-identified form for research or quality improvement purposes.

21 Breach Notification Procedures

Despite our best efforts to prevent security incidents, we recognize that no system is completely immune to breaches. GoTo Telemed has established comprehensive procedures to detect, investigate, contain, and report any unauthorized access to or disclosure of protected health information.

1
Detection & Assessment
Security monitoring systems and employee reports trigger immediate investigation
2
Containment & Remediation
We act quickly to stop unauthorized access and secure affected systems
3
Notification Process
All affected individuals receive direct notification within 60 days
4
Post-Incident Review
Thorough analysis identifying lessons learned and implementing improvements

22 Business Associate Agreements

HIPAA regulations require that any third party accessing protected health information on behalf of a covered entity must sign a Business Associate Agreement (BAA). GoTo Telemed executes comprehensive BAAs with every vendor, contractor, or service provider who may encounter PHI in the course of working with us.

1
Permitted Uses
BAAs strictly define how business associates may use PHI, limiting activities to necessary services
2
Disclosure Restrictions
Business associates cannot share information with other parties without specific authorization
3
Security Requirements
Associates must implement appropriate safeguards comparable to our own standards
4
Breach Reporting
Business associates must notify us within 24 hours of discovering security incidents
5
Audit Rights
We retain the right to audit business associates' compliance with BAA terms

23 State Privacy Law Compliance

While HIPAA establishes baseline federal privacy protections, many states have enacted additional privacy laws providing even stronger safeguards. GoTo Telemed complies with privacy requirements in all 50 states where we operate, ensuring your information receives the maximum protection afforded by applicable state law.

California CCPA/CPRA
California residents enjoy enhanced rights including access, deletion, and opt-out rights beyond HIPAA
State Privacy Laws
Virginia, Colorado, Connecticut, and other states have enacted comprehensive privacy laws creating similar rights
Health-Specific Laws
Some states have additional protections for HIV/AIDS records, mental health records, and other sensitive data

We maintain state-specific procedures ensuring compliance with these additional protections, applying them consistently to avoid confusion and provide maximum privacy regardless of location.

24 International Data Transfers

GoTo Telemed primarily serves patients and practitioners within the United States, and we store all patient health information on servers located within U.S. borders. However, when any international data transfer occurs, we implement safeguards ensuring your information receives privacy protections equivalent to U.S. standards.

EU Adequacy
We rely on EU-U.S. Data Privacy Framework or Standard Contractual Clauses for EU transfers
Data Localization
Vendors must maintain primary data storage within the United States
Encryption in Transit
Any data crossing international borders is encrypted both in transit and at rest
Recommendation: We recommend avoiding access to sensitive medical information over public Wi-Fi networks in countries with weak privacy protections.

25 Cookies and Tracking Technologies

GoTo Telemed uses cookies and similar tracking technologies to deliver functionality, improve user experience, and analyze platform performance. We are transparent about what tracking occurs and provide options to control certain types of data collection.

Essential Cookies
Necessary for core platform functionality—maintaining login sessions, security features, and site operations
Analytics Cookies
Understanding how users interact with our platform to improve experience and identify difficulties
Preference Cookies
Remember your choices about optional features for more convenient cross-session experience
No Advertising: We do NOT use advertising cookies or sell information to third-party advertisers. Our platform does not display third-party advertisements, eliminating privacy concerns associated with ad-tracking networks.

26 Marketing and Communications Preferences

GoTo Telemed respects your communication preferences and provides clear options for managing how we contact you. While some communications are necessary for service delivery, other messages are optional, and you can choose whether to receive them.

Transactional Messages
Appointment confirmations, test results, and security alerts cannot be disabled—they're essential
Service Updates
Platform changes, maintenance schedules, and policy updates help you use services effectively
Educational Content
Health tips, wellness articles, and telehealth guidance are completely optional
Promotional Offers
Discounts and special programs are entirely optional and require explicit consent

You can modify your communication preferences anytime through your account settings or by using unsubscribe links in emails. We honor opt-out requests immediately, processing them within 10 business days.

27 Privacy Policy Updates and Changes

Privacy laws, technology capabilities, and healthcare practices evolve over time, requiring periodic updates to this Privacy Policy. GoTo Telemed commits to maintaining current, accurate privacy documentation reflecting our actual data practices.

1
Review and Revision
Our privacy and legal teams conduct quarterly reviews assessing changes in law and business practices
2
Notification Process
For significant changes, we provide direct notice via email at least 30 days before changes take effect
3
Consent Requirements
Material changes requiring new uses of data trigger consent requirements before applying to you
4
Policy Accessibility
Current and previous versions are maintained with clear version numbers and effective dates

28 Compliance with Regulatory Audits

As a healthcare organization handling protected health information, GoTo Telemed is subject to oversight by multiple regulatory agencies. We maintain transparent, cooperative relationships with regulators and welcome audits as opportunities to demonstrate our commitment to privacy protection.

Federal Oversight
HHS Office for Civil Rights, Federal Trade Commission, Drug Enforcement Administration, Office of the Inspector General
State Agencies
State medical boards, state attorneys general, health departments, insurance regulators
Accreditation Bodies
HITRUST Alliance, URAC, SOC 2 auditors, ISO auditors

During audits, we provide requested documentation including policies, security assessments, breach logs, and training records. Our staff cooperates fully with investigators. Following audits, we implement corrective action plans addressing identified deficiencies.

29 Contact for Privacy Concerns

GoTo Telemed is committed to addressing your privacy questions, concerns, and complaints promptly and thoroughly. We've established multiple channels for privacy communication, ensuring you can reach us through your preferred method.

Privacy Office
Email: privacy@gototelemed.com | Phone: (660) 628-1660 ext. 102
Security Incidents
Email: security@gototelemed.com | 24/7 Hotline: (660) 628-1660 ext. 911
General Inquiries
Email: info@gototelemed.com | Phone: (660) 628-1660

We acknowledge all privacy inquiries within 2 business days and provide substantive responses within 10 business days for most issues. If you're not satisfied with our response, you have the right to escalate to external authorities including the HHS Office for Civil Rights or your state attorney general.

30 Policy Effective Date and Version Control

Transparency and accountability require clear documentation of when privacy practices take effect and how they've evolved over time. This section provides critical information about this Privacy Policy's current status and historical versions.

Current Version
Version 1.0 - Initial release of comprehensive Privacy Policy
Policy Year
2024 - Year this privacy framework was established and implemented
Total Sections
30 sections - Comprehensive coverage of all privacy aspects
Effective Date
January 1, 2025
Acceptance of Terms: This Privacy Policy becomes effective on January 1, 2025 and supersedes any previous privacy notices. Continued use of GoTo Telemed services after this date constitutes acceptance of these privacy practices and agreement to be bound by these terms.

For questions about this policy, previous versions, or how changes may affect you, please contact our Privacy Office at privacy@gototelemed.com or call (660) 628-1660. We're here to help you understand your privacy rights and our obligations.

Document Information: Privacy Policy Version 1.0 | Effective Date: January 1, 2025 | Last Reviewed: December 2024 | Next Review: March 2025