Security & HIPAA Compliance
Your health data security is our top priority. Learn how we protect your Protected Health Information (PHI) with enterprise-grade encryption and HIPAA-aligned best practices.
Important Disclosure
Sagebrush Wellness, LLC is not a HIPAA-covered entity as defined by federal law. We are an educational wellness platform, not a healthcare provider, health plan, or healthcare clearinghouse. However, we implement HIPAA-compliant security standards and best practices to protect your health information.
AES-256 Encryption
Military-grade encryption for all stored data
Encrypted Databases
All health records, symptoms, and personal data encrypted
Secure File Storage
PDF uploads encrypted in cloud storage
TLS 1.3 Protocol
Latest encryption standard for data transmission
HTTPS Everywhere
All connections use secure HTTPS protocol
Secure API Calls
All data exchanges encrypted end-to-end
Role-Based Access
- • Users can only access their own data
- • Admin access strictly controlled
- • No shared access by default
- • Granular permission system
Strong Authentication
- • Secure password requirements
- • Email verification
- • Session management
- • Automatic logout on inactivity
Audit Logging
- • All data access logged
- • Timestamps recorded
- • User activity tracking
- • 6-year log retention
We carefully vet all third-party services and require HIPAA-compliant Business Associate Agreements (BAAs) for any vendor that processes Protected Health Information (PHI).
Supabase (Cloud Infrastructure)
Purpose: Database hosting, file storage, authentication
Compliance: SOC 2 Type II certified, HIPAA-compliant infrastructure with BAA, AES-256 encryption, automatic backups, 99.9% uptime SLA
Stripe (Payment Processing)
Purpose: Subscription billing, payment processing
Compliance: PCI DSS Level 1, HIPAA BAA available for healthcare businesses, does not store PHI (only payment data)
OpenAI (AI Analysis)
Purpose: Generating personalized health recommendations
Compliance: Enterprise tier with HIPAA BAA for PHI processing, zero data retention policy for API calls, SOC 2 Type II certified
Constant Contact (Email Marketing)
Purpose: Newsletter delivery, educational content
Compliance: HIPAA-compliant tier available with BAA, we only send educational content (no PHI in emails), users can opt-out anytime
Technical Safeguards
- Unique user identification and authentication
- Automatic logoff after 30 minutes of inactivity
- Encryption and decryption of ePHI
- Audit controls and access logs
- Integrity controls to prevent data alteration
- Transmission security with encryption
Administrative Safeguards
- Security risk assessment and management
- Privacy and security policies
- Incident response procedures
- Contingency planning and disaster recovery
- Business associate agreements with vendors
- Evaluation and updates to security measures
Right to Access
View and download all your health data at any time
Right to Amend
Request corrections to your health records
Right to Restrict
Limit how your information is used or shared
Right to Delete
Request complete deletion of your account and data
In the unlikely event of a data breach involving your Protected Health Information:
- • You will be notified within 60 days as required by HIPAA
- • Notification will include what happened, what information was affected, and steps to protect yourself
- • We will work with law enforcement and cybersecurity experts
- • Credit monitoring or identity theft protection may be offered if appropriate
- • We will report to the Department of Health and Human Services (HHS) as required
Privacy Officer: Melissa Rose
Email: privacy@sagebrushwellness.com
Security Issues: security@sagebrushwellness.com
For HIPAA compliance questions or to file a privacy complaint, contact us at the addresses above. You also have the right to file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights.
Last Updated: June 2026
© 2026 Sagebrush Wellness, LLC. All rights reserved.
