HIPAA Notice of Privacy Practices

Last updated: February 2026

Our Commitment to Your Privacy

This Notice of Privacy Practices describes how Gabriel Health Platform ("Gabriel") may use and disclose your Protected Health Information (PHI) and your rights regarding your health information. We are required by law to:

  • Maintain the privacy of your Protected Health Information
  • Provide you with this Notice of our legal duties and privacy practices
  • Follow the terms of the Notice currently in effect
  • Notify you if we are unable to agree to a requested restriction
  • Notify you in the event of a breach of your unsecured PHI

What is Protected Health Information (PHI)?

PHI is any individually identifiable health information that we collect, store, or transmit. This includes:

  • Diagnostic data (Bio-Well scans, HeartMath results, NRT protocols)
  • Lab results and medical history you upload
  • Symptoms, medications, and treatment notes
  • Communications between you and your practitioners
  • Billing and payment information related to health services
  • Any other health-related information linked to your identity

How We Use and Disclose PHI

For Treatment

We may use and disclose your PHI to facilitate your healthcare. For example, we share your diagnostic results with practitioners you authorize to view your records. We may also use your data to generate AI-powered health insights for you and your care team.

For Payment

We may use and disclose your PHI to process payments for services provided through the Platform, verify insurance coverage, and manage billing activities.

For Healthcare Operations

We may use and disclose your PHI for our internal operations, including quality improvement, training, auditing, and compliance activities. For example, we may review de-identified data to improve our AI algorithms.

Business Associates

We work with third-party vendors (cloud hosting, payment processors, analytics providers) who may have access to your PHI. These vendors are HIPAA-compliant and sign Business Associate Agreements (BAAs) requiring them to protect your information.

As Required by Law

We may disclose your PHI when required by federal, state, or local law, such as to public health authorities, law enforcement, or in response to a court order.

Other Uses

We may use or disclose your PHI in the following situations:

  • To avert a serious threat to health or safety
  • For public health activities (e.g., disease reporting)
  • For health oversight activities (audits, inspections)
  • In response to judicial or administrative proceedings
  • For law enforcement purposes (e.g., reporting crimes)
  • To coroners, medical examiners, or funeral directors
  • For organ or tissue donation purposes
  • For workers' compensation claims

Uses Requiring Your Authorization

We will obtain your written authorization before using or disclosing your PHI for:

  • Marketing purposes
  • Sale of your PHI
  • Research (unless the data is de-identified)
  • Psychotherapy notes (if applicable)

You may revoke your authorization at any time by contacting us in writing. Revocation does not affect disclosures already made based on your prior authorization.

Your Rights

Under HIPAA, you have the following rights regarding your PHI:

Right to Access

You may request access to and copies of your PHI. We will respond within 30 days and provide the information in the format you request (if readily available). We may charge a reasonable fee for copies.

Right to Amend

If you believe your PHI is incorrect or incomplete, you may request an amendment. We will respond within 60 days. We may deny your request if the information was not created by us, is not part of your record, or is accurate and complete.

Right to an Accounting of Disclosures

You may request a list of certain disclosures we have made of your PHI in the past six years. This does not include disclosures made for treatment, payment, or healthcare operations.

Right to Request Restrictions

You may request restrictions on how we use or disclose your PHI. We are not required to agree to your request, except in certain cases where you pay out-of-pocket in full for a service and request we not disclose that information to your health plan.

Right to Confidential Communications

You may request that we communicate with you in a specific way or at a specific location (e.g., via email instead of phone, or at a different address). We will accommodate reasonable requests.

Right to a Paper Copy of This Notice

You may request a paper copy of this Notice at any time by contacting us.

Right to Be Notified of a Breach

You have the right to be notified if we discover a breach of your unsecured PHI.

How to Exercise Your Rights

To exercise any of the rights described above, please submit a written request to:

Gabriel Health Platform
HIPAA Privacy Officer
Email: hipaa@askgabriel.com
Subject: HIPAA Rights Request

Breach Notification

In the event of a breach of your unsecured PHI, we will notify you without unreasonable delay and no later than 60 days after discovery. We will provide information about what happened, what information was involved, and what steps we are taking to mitigate harm.

Changes to This Notice

We reserve the right to revise this Notice at any time. The revised Notice will apply to all PHI we maintain. We will post the current Notice on our website and make it available upon request.

Complaints

If you believe your privacy rights have been violated, you may file a complaint with:

Gabriel Health Platform
HIPAA Privacy Officer
Email: hipaa@askgabriel.com

You may also file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights:

Office for Civil Rights
U.S. Department of Health and Human Services
200 Independence Avenue, S.W.
Washington, D.C. 20201
Phone: 1-877-696-6775
Website: www.hhs.gov/ocr/privacy

You will not be retaliated against for filing a complaint.

Contact Us

For questions about this Notice or your privacy rights, contact:

Gabriel Health Platform
HIPAA Privacy Officer
Email: hipaa@askgabriel.com
General inquiries: hello@askgabriel.com