Privacy Policy
Last updated: September 15, 2026
Health Nexus, a dba of FollowThatPatient.com (“Health Nexus,” “we,” “us”), respects your privacy. This Privacy Policy explains what information we collect, how we use and share it, how we protect it, and the choices and rights you have. It applies to health-nexus.com, our member portal, and related services (the “Services”).
1. Information we collect
- Account and identity information: name, email, date of birth, sex, phone number, shipping and billing address.
- Health information: laboratory results, biomarkers, uploaded medical records (such as imaging reports, DEXA scans, and clinician notes), intake responses, and information you share with our care team.
- Payment information: processed by Stripe, Inc. We receive limited details such as the last four digits, card brand, and subscription status. We do not store full card numbers.
- Technical information: IP address, device and browser type, pages viewed, referring pages, and approximate location derived from IP.
- Communications: emails, support requests, and messages you send us.
2. How we use information
- To provide memberships, testing, results, protocols, and clinician access;
- To create and maintain your account and Digital Health Vault;
- To process payments, renewals, refunds, and fulfillment;
- To generate personalized insights, including via automated and AI-assisted analysis;
- To secure the Services, prevent fraud, and debug problems;
- To communicate service updates and, with your consent, marketing;
- To comply with legal obligations and enforce our Terms.
We do not sell your personal information, and we do not sell or share your health information for advertising or cross-context behavioral advertising.
3. Legal bases (EEA/UK visitors)
Where GDPR applies, we process personal data on the bases of contract performance, your explicit consent (for health data), our legitimate interests in operating and securing the Services, and compliance with legal obligations.
4. How we share information
- Clinical partners: CLIA-certified laboratories, independent ordering physicians, phlebotomy providers, and clinicians involved in your care.
- Service providers: hosting, database, email, analytics, customer support, and shipping vendors, bound by contract to protect your information and use it only for us.
- Payment processing: Stripe, under its own privacy policy.
- Legal and safety: when required by law, subpoena, or to protect rights, safety, or prevent fraud.
- Business transfers: in connection with a merger, financing, acquisition, or sale of assets, subject to this Policy.
- With your direction: when you ask us to send records to a provider or third party.
5. Health information and HIPAA
Some of the information we handle is protected health information created or received in connection with clinical services. Where we act as a business associate of a covered entity, or where a covered entity relationship exists, that information is handled in accordance with HIPAA and applicable business associate agreements. Information you upload voluntarily that is not created through a covered clinical encounter is protected under this Policy and applicable state health-privacy laws, including the California Confidentiality of Medical Information Act and the Washington My Health My Data Act where applicable.
6. Security
We use encryption in transit and at rest, role-based access controls, row-level database security, audit logging, least-privilege administration, and vendor security review. No system is perfectly secure; we cannot guarantee absolute security, and you share information at your own risk. If a breach affecting your information occurs, we will notify you as required by law.
7. Retention
We keep your information for as long as your account is active and afterward as needed to meet legal, clinical recordkeeping, tax, and accounting obligations — typically at least seven years for records associated with laboratory testing. We then delete or de-identify it.
8. Your rights and choices
- Access, correct, or download a copy of your information;
- Request deletion of your account and information, subject to legal retention;
- Withdraw consent for optional processing, including AI-assisted analysis;
- Opt out of marketing email at any time via the unsubscribe link;
- Limit cookies through our cookie banner and browser settings;
- Appeal a denied request, and (California residents) exercise rights under the CCPA/CPRA, including the right not to be discriminated against for exercising them.
To exercise any right, email Support@health-nexus.com. We will verify your identity and respond within the time required by law (generally 45 days).
9. Children
The Services are not directed to anyone under 18, and we do not knowingly collect information from children. If we learn we have, we will delete it.
10. International transfers
We operate in the United States. If you access the Services from outside the U.S., your information will be transferred to and processed in the U.S. under appropriate safeguards.
11. Changes
We may update this Policy. Material changes will be posted here with a new “Last updated” date and, where required, emailed to you.
12. Contact
Health Nexus, a dba of FollowThatPatient.com
P.O. Box 4199, Malibu, CA 90264
Support@health-nexus.com