Health Privacy Policy
Effective Date: 10/21/2025
Last Updated: 4/23/2026
Xport Health, Inc. (“Xport Health,” “we,” “us,” or “our”) respects the privacy of health information and other personal information. This Health Privacy Policy explains the information we collect through our websites, mobile applications, patient engagement tools, provider-facing platforms, integrations, and related services (collectively, the “Services”), how we collect it, how we use it, when we share it, and the choices available to users.
This policy is intended to describe Xport Health’s privacy practices in clear language. It does not replace any separate Notice of Privacy Practices issued by a physician, clinic, hospital, health plan, or other healthcare provider or covered entity that uses Xport Health’s Services.
By using the Services, or by providing information to us through the Services, you acknowledge that you have read and understand this policy.
1. Scope and Role of Xport Health
Xport Health provides digital health technology, patient engagement tools, remote monitoring workflows, care coordination support, analytics, and related services.
Depending on the context, Xport Health may act in different roles:
-
Service Provider / Business Associate to Healthcare Organizations. When Xport Health provides services to or on behalf of a healthcare provider, health plan, or other regulated healthcare organization, we may create, receive, maintain, or transmit protected health information (“PHI”) under a contract such as a Business Associate Agreement.
-
Direct Provider of Consumer-Facing Digital Services. In some cases, Xport Health may collect information directly from users of our mobile application, website, forms, support channels, or digital tools.
-
Independent Controller of Certain Operational Data. Xport Health may act independently with respect to certain business, administrative, security, technical, and legal compliance data.
Because our role can vary depending on the service and relationship, some privacy rights and disclosures may be handled directly by the healthcare organization with which you interact.
2. What Data We Collect
Depending on the Services used, the permissions granted, the settings selected, and the relationship involved, Xport Health may collect, receive, generate, infer, use, store, transmit, or otherwise process the following categories of information:
-
Personal identifiers and contact information, such as name, date of birth, email address, phone number, mailing address, username, password, account credentials, and similar identifiers
-
Health and health-related information, such as symptoms, diagnoses, conditions, medications, allergies, treatment information, care plans, clinical notes, laboratory information, questionnaires, assessments, surveys, patient-reported outcomes, and similar health or wellness information
-
Vital signs, biometric information, remote monitoring data, device-generated readings, wellness information, activity-related information, and other information made available through the Services
-
Provider, billing, eligibility, referral, scheduling, enrollment, insurance-related, and program participation information
-
Technical, device, log, usage, diagnostic, security, and online activity information, such as IP address, device identifiers, browser type, operating system, app version, timestamps, crash reports, cookies, SDK data, access history, and similar data
-
Communications and content submitted through the Services, including messages, support requests, prompts, uploads, attachments, free-text entries, and other information provided through forms, questionnaires, chat, or related tools
-
Information obtained from healthcare providers, care teams, health plans, pharmacies, laboratories, caregivers, authorized representatives, connected devices, electronic health records, practice management systems, health information exchanges, APIs, and other authorized integrations or sources
-
De-identified, aggregated, derived, operational, analytics, and similar information generated from or relating to the use of the Services where permitted by law
Xport Health may collect only some of these categories in a particular workflow, and the specific information collected may vary depending on the feature used, the permissions granted, the applicable legal relationship, and the user’s interactions with the Services.
3. How We Collect Information
Xport Health may collect information in multiple ways, including:
-
Directly from users, patients, caregivers, providers, customer support requests, forms, surveys, assessments, questionnaires, uploads, prompts, free-text entries, communications, and other interactions with the Services
-
Automatically through the operation of our websites, mobile applications, platforms, devices, logs, cookies, software development kits, analytics tools, security tools, application programming interfaces, and similar technologies
-
From healthcare providers, healthcare organizations, care teams, health plans, employer-sponsored programs, payers, pharmacies, laboratories, and other authorized organizations
-
From connected devices, interoperability tools, electronic health records, practice management systems, health information exchanges, operating system permissions, and other authorized third-party integrations or data sources
-
From caregivers, family members, authorized representatives, or others acting on a user’s behalf where permitted by law
-
From data generated, inferred, de-identified, aggregated, or otherwise created in connection with the operation, analysis, security, maintenance, or improvement of the Services
The method of collection depends on the feature used, the data source involved, the permissions granted, and the relationship between Xport Health, the user, and the applicable healthcare organization.
4. How We Use Information
Xport Health may use collected information for healthcare, care coordination, operational, administrative, technical, legal, security, quality, support, product, and compliance purposes, including to:
-
Provide, operate, host, maintain, secure, troubleshoot, support, and improve the Services
-
Create, manage, verify, authenticate, and administer accounts, profiles, access rights, permissions, settings, and user relationships
-
Receive, collect, organize, store, display, retrieve, process, analyze, summarize, transmit, exchange, and otherwise make available information through the Services
-
Support remote monitoring, chronic care management, patient engagement, care coordination, documentation support, reporting, reminders, summaries, notifications, escalations, workflows, and related functions
-
Facilitate communications among users, providers, care teams, caregivers, customer support personnel, authorized representatives, and organizations using the Services
-
Personalize the user experience, configure workflows, improve usability, maintain continuity of care, and support service functionality requested by users or healthcare organizations
-
Detect, investigate, prevent, and respond to fraud, misuse, abuse, unauthorized activity, technical issues, incidents, security events, and other harmful or unlawful activity
-
Conduct analytics, quality assurance, auditing, system monitoring, debugging, product development, training, performance measurement, financial administration, corporate governance, and other internal business operations
-
Comply with contractual, legal, regulatory, compliance, audit, billing, accounting, tax, recordkeeping, enforcement, and public health obligations
-
Protect the rights, safety, property, systems, users, providers, Xport Health, and the public
-
Create, use, and disclose de-identified or aggregated information where permitted by law
-
Carry out any other purpose disclosed at the time of collection, authorized by the user, required by a healthcare organization relationship, or otherwise permitted by law
The specific uses of information may vary depending on the Services used, the permissions granted, the data involved, and the relationship between Xport Health, the user, and any applicable healthcare organization.
5. Use of Third-Party Artificial Intelligence Services
Xport Health uses certain third-party artificial intelligence and machine-learning service providers to support limited features within the Services. Our current third-party AI provider is Google Cloud Vertex AI.
How Google Cloud Vertex AI Is Used
Xport Health may transmit selected health-related information to Google Cloud Vertex AI through secure cloud-based interfaces. Google Cloud Vertex AI processes that information on Xport Health’s behalf and returns software-generated output to Xport Health.
Xport Health may use this output to:
-
organize and summarize health information;
-
analyze health information and identify relevant patterns;
-
support alerts, reports, documentation, and care-coordination workflows;
-
present information to authorized healthcare providers for their review; and
-
support other AI-enabled features clearly disclosed within the Services.
AI-generated information is provided only to support the functionality of the Xport Health platform. It does not constitute medical advice, diagnosis, treatment, or an independent clinical decision and does not replace the professional judgment of a licensed healthcare provider.
Information That May Be Sent
Depending on the feature being used, Xport Health may send the following information to Google Cloud Vertex AI: health check-in text entered by the user; patient-reported symptoms; questionnaire responses; patient-uploaded or submitted vital signs, including blood pressure, heart rate, oxygen saturation, blood glucose, weight, and similar readings; medication notes; health updates; messages or free-text health-related entries; relevant existing medical data needed for the applicable check-in, care-coordination, documentation, or review workflow; structured or derived health data such as extracted vital readings, symptom labels, symptom severity, medication-adherence statements, and potential review flags; and limited technical or request information reasonably necessary to securely transmit, process, and return the AI-supported result.
How This Information Is Collected
Information processed by Google Cloud Vertex AI may be collected:
-
directly from the patient through forms, questionnaires, messages, symptom reports, manual entries, or uploaded information;
-
from connected health or medical devices and integrations authorized by the patient;
-
from healthcare providers, care teams, electronic health records, or other authorized healthcare sources; and
-
from information already maintained within the patient’s Xport Health profile.
Treatment of Direct Identifiers
Xport Health configures its ordinary AI-processing workflow to exclude structured direct identifiers from information submitted to Google Cloud Vertex AI. Xport Health does not intentionally send names, email addresses, phone numbers, account identifiers, patient IDs, authentication credentials, or sign in with Apple data to Google Cloud Vertex AI. However, identifying information may be transmitted if it is contained within patient-submitted free text, provider-entered content, uploaded records, attachments, messages, or other source information selected for processing. Xport Health limits information submitted for AI processing to information reasonably necessary to provide the applicable feature.
User Permission
Before Xport Health sends personal or health-related information to Google Cloud Vertex AI, Xport Health will present an in-app disclosure that:
-
identifies Google Cloud Vertex AI as the recipient;
-
describes the categories of information that may be sent;
-
explains the purposes for which the information will be processed; and
-
requests the user’s affirmative permission to proceed.
Xport Health will not transmit the user’s personal or health-related information to Google Cloud Vertex AI through the applicable AI-enabled feature unless the user has provided the required permission.
A user who declines permission will not have information transmitted to Google Cloud Vertex AI. Certain AI-dependent features may be unavailable, but declining AI processing will not prevent the user from accessing other platform functions that do not require such processing.
Users may withdraw permission for future AI processing through the privacy or consent controls available within their account or by contacting Xport Health at care@xporthealth.com. Withdrawal of permission will stop future transmissions to Google Cloud Vertex AI but will not reverse processing that occurred before permission was withdrawn or require deletion of information that Xport Health or an authorized healthcare organization must retain under applicable law or contractual obligations.
Third-Party Privacy and Security Protections
Xport Health requires Google Cloud and any other third party that receives personal or health-related information from Xport Health to maintain privacy, confidentiality, and security protections that provide the same or equal protection required by this Privacy Policy, applicable law, and Xport Health’s contractual obligations.
Such providers may process information only as necessary to perform contracted services on behalf of Xport Health or as otherwise permitted by applicable law. Xport Health does not authorize Google Cloud Vertex AI to use identifiable patient information for advertising, data brokerage, or unrelated marketing purposes.
Where protected health information is involved, Xport Health uses applicable Google Cloud services subject to appropriate contractual protections, including a Business Associate Agreement where required.
Google Cloud states that customer data submitted to managed Vertex AI models is not used to train or fine-tune AI or machine-learning models without the customer’s prior permission or instruction.
Retention and Deletion
Information maintained by Xport Health, including AI-supported outputs retained within a patient profile or platform record, is subject to the retention and deletion provisions described elsewhere in this Privacy Policy.
Processing or temporary retention by Google Cloud is governed by Xport Health’s Google Cloud configuration, applicable contractual terms, security requirements, and legal obligations. Xport Health seeks to limit the information submitted and retained for AI processing to what is reasonably necessary to provide and secure the applicable feature.
Users may request access, correction, deletion, or withdrawal of consent as described in the Individual Rights and Choices section of this Privacy Policy.
6. How We Share Information
We may share information in the following circumstances:
A. With Healthcare Organizations and Care Teams
We may share information with healthcare providers, care teams, health plans, and authorized healthcare organizations in connection with providing the Services and supporting care, operations, coordination, and related permitted activities.
B. With Service Providers and Contractors
We may share information with vendors, contractors, consultants, service providers, infrastructure providers, cloud providers, communications providers, analytics providers, security providers, interoperability providers, AI-enabled service providers, customer support providers, and other third parties that perform services on our behalf or support the Services. These parties may access information only as reasonably necessary to perform services for Xport Health or support the requested functionality and are required to protect the information they receive using privacy, confidentiality, and security protections that are the same as or substantially similar to those required by applicable law, our contracts, and our internal security standards, as applicable.
C. With Third Parties Supporting Features and Integrations
We may share information with third parties that support specific features, integrations, workflows, automations, analytics, AI-enabled tools, communications, connected devices, interoperability functions, customer support functions, or other components of the Services. Where required by law, platform requirements, contract, or the nature of the feature, we will provide additional notice, obtain consent, or provide user choice before transmitting information in connection with such features.
D. With Your Direction or Consent
We may share information when you direct us to do so, consent to the disclosure, or authorize an integration or connection.
E. For Legal, Regulatory, and Safety Reasons
We may disclose information as required or permitted by law, regulation, subpoena, court order, governmental request, public health obligation, or similar legal process, or when we believe disclosure is necessary to protect health, safety, rights, property, or the security of the Services.
F. Business Transfers
We may disclose information in connection with a merger, acquisition, financing, restructuring, asset sale, bankruptcy, or other corporate transaction, subject to applicable confidentiality and legal requirements.
G. De-Identified and Aggregated Information
We may use and disclose information that has been de-identified or aggregated so that it does not reasonably identify an individual, as permitted by law.
7. HIPAA and Protected Health Information
When Xport Health handles protected health information on behalf of a healthcare provider, health plan, or other HIPAA covered entity, our use and disclosure of that PHI is governed by applicable law and our contract with that covered entity, including any Business Associate Agreement.
In those circumstances:
-
The healthcare provider or other covered entity is generally responsible for issuing its own Notice of Privacy Practices
-
Patient rights requests relating to PHI may need to be directed to the relevant provider, plan, or other covered entity
-
Xport Health may assist the covered entity in responding to such requests when required by law or contract
If you are a patient receiving care from a provider that uses Xport Health, please review that provider’s Notice of Privacy Practices for additional information about how your PHI may be used and disclosed.
8. Consumer Health Data and Non-HIPAA Data
Not all health-related information is regulated by HIPAA. In some circumstances, Xport Health may collect or process health-related information that falls outside HIPAA but is still protected by other federal or state privacy, consumer protection, or breach notification laws.
Xport Health does not sell personal health data in exchange for money. Xport Health does not share consumer health data for cross-context behavioral advertising or other uses prohibited by applicable law.
9. Data Retention
We retain information for as long as reasonably necessary to:
-
Provide the Services
-
Fulfill the purposes described in this policy
-
Comply with contractual, legal, regulatory, accounting, tax, audit, billing, and recordkeeping obligations
-
Resolve disputes and enforce agreements
-
Maintain security, backup, disaster recovery, and business continuity processes
Retention periods may vary based on the type of information, the Services involved, applicable law, and contractual requirements.
10. Security Measures
We maintain administrative, technical, and physical safeguards designed to protect information from unauthorized access, use, disclosure, alteration, or destruction. These measures may include access controls, authentication procedures, encryption where appropriate, logging, monitoring, workforce training, incident response procedures, vendor oversight, and other security controls.
No system or method of transmission or storage is completely secure, and we cannot guarantee absolute security.
11. Breach and Incident Response
If Xport Health becomes aware of a security incident or unauthorized disclosure involving information we maintain, we will investigate, take appropriate containment and remediation steps, and provide notice where required by applicable law, regulation, or contract.
Where Xport Health acts on behalf of a HIPAA covered entity, notification obligations may be governed by our contract and applicable breach notification requirements.
12. Individual Rights and Choices
Depending on applicable law and the nature of the relationship, individuals may have rights regarding their information, including the right to:
-
Access certain information
-
Request correction or amendment of certain information
-
Request deletion of certain information, subject to legal exceptions
-
Request restrictions on certain processing or disclosures
-
Request a copy of information in a portable format where applicable
-
Withdraw consent where processing is based on consent
-
Opt out of certain non-essential communications
-
Lodge a complaint with Xport Health or with an applicable regulator
These rights are not absolute and may be limited by law, patient safety considerations, contractual obligations, technical feasibility, and record retention requirements.
If Xport Health acts as a service provider or business associate for your healthcare provider or health plan, we may direct your request to that organization, which may be the appropriate party to respond.
13. Cookies, Analytics, and Similar Technologies
Our websites and applications may use cookies, software development kits, pixels, local storage, and similar technologies to:
-
Operate and secure the Services
-
Remember preferences and settings
-
Measure performance and functionality
-
Analyze usage trends
-
Improve user experience
Where required by law, we will provide additional notice, obtain consent, or offer choices regarding certain optional technologies.
14. Third-Party Services and Links
The Services may contain links to third-party websites, tools, integrations, or services that are not controlled by Xport Health. This policy does not apply to the privacy practices of those third parties. We encourage users to review the privacy policies of any third-party service they use.
15. Children’s Privacy
Xport Health does not knowingly collect personal information directly from children except as permitted by law and as necessary to provide Services in connection with healthcare, caregiver-authorized use, or services arranged through a healthcare organization or authorized adult.
16. Cross-Border Processing
If information is processed or accessed outside the jurisdiction in which it was collected, it may be subject to the laws of those jurisdictions. Xport Health will take reasonable steps to ensure appropriate protections consistent with applicable law.
17. Changes to This Policy
We may update this policy from time to time. When we do, we will revise the “Last Updated” date above and take additional steps where required by law. Material changes may be communicated through the Services, by email, by posting an updated policy, or by other appropriate means.
18. Contact Information
If you have questions about this policy or wish to submit a privacy request, please contact:
Xport Health, Inc.
Attn: Privacy Officer
3723 Greenville Avenue
Dallas, TX, 75206
If your concern relates to care provided by a physician, clinic, hospital, or health plan using Xport Health’s Services, you may also need to contact that organization directly.