Privacy and security

Health Data & Privacy

Last updated July 15, 2026

Gabriel is a consumer health intelligence and care-navigation product, not a healthcare provider. Whether HIPAA applies to particular information depends on the service, relationship, and workflow involved. This page is not a HIPAA Notice of Privacy Practices and does not claim that every Gabriel service is governed by HIPAA.

You may choose to share health information with Gabriel, including symptoms, medications, supplements, lab results, records, and other files. We handle that information under our Privacy Policy and the controls applicable to the product you use.

Restricted access

Access to sensitive data is limited to authorized systems and people with a legitimate operational need.

Security controls

We use measures such as encryption in transit, infrastructure encryption at rest, monitoring, and least-privilege access where supported by the service.

Vendor configuration

A vendor offering HIPAA-eligible infrastructure does not by itself make every use of that infrastructure HIPAA compliant. Agreements, configuration, and operating practices also matter.

Data minimization

Share only what Gabriel needs for the task. Do not place health records, account credentials, or payment details in the public contact form or ordinary email.

Use the right channel

Keep sensitive records out of email.

Use the secure upload or signed-in product when it is available. The public contact form is for customer-service questions, not medical records. For an emergency, call 911 or your local emergency number.