Kōvn Health

Privacy & HIPAA

Effective: July 5, 2026 | Version ID: 2026-07-05 | Version 3.0

Kōvn Health is committed to protecting your privacy and safeguarding your Protected Health Information ("PHI") in accordance with the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), the Health Information Technology for Economic and Clinical Health Act ("HITECH Act"), the Florida Information Protection Act of 2014 ("FIPA"), and all applicable state privacy laws. This Privacy Policy applies to services provided by Kōvn Health (Tennessee professional corporation) and the technology platform operated by Apex Health and Technology, LLC (Tennessee limited liability company).

1. INFORMATION WE COLLECT

1.1 Personal Identifiable Information (PII) 1.2 Protected Health Information (PHI) 1.3 Technical Data (De-identified) CRITICAL: Technical data collected on marketing surfaces (homepage, Learn Hub) is anonymized and NEVER linked to PHI. No analytics or tracking occurs on clinical intake pages. 1.4 Payment Information Payment card information is processed through PCI-DSS Level 1 compliant third-party processors (Stripe). Kōvn Health does NOT store full credit card numbers. We retain only the last four digits for billing reference and dispute resolution.

  • Full name, date of birth, gender
  • Email address, phone number, mailing address
  • Government-issued identification (for identity verification)
  • Payment information (credit card, billing address)
  • Complete medical history and current health conditions
  • Current medications, supplements, and over-the-counter drugs
  • Known allergies and adverse drug reactions
  • Symptoms, clinical complaints, and treatment goals
  • Laboratory results (CMP, lipase, HbA1c, hormone panels)
  • Clinical notes and provider assessments
  • Prescription records and medication history
  • Telehealth session transcripts and secure messages
  • Photos (if applicable for ED or dermatological assessment)
  • IP address, browser type, device information
  • Usage analytics (anonymized, never linked to PHI)
  • Session duration and page navigation patterns

2. HOW WE USE YOUR INFORMATION

We use your information for the following purposes: 2.1 Treatment Providing, coordinating, and managing your healthcare services, including: 2.2 Payment Processing subscription fees, consultation charges, and coordinating payment with pharmacies and laboratories. 2.3 Healthcare Operations 2.4 Legal and Regulatory Compliance Complying with applicable federal and state laws, including HIPAA, FDA regulations, DEA requirements, state medical board reporting obligations, and public health mandates.

  • Clinical evaluations and treatment recommendations
  • Prescription management and pharmacy coordination
  • Laboratory test ordering and results review
  • Ongoing monitoring, dosage adjustments, and side effect management
  • Care coordination with external providers (with your authorization)
  • Quality assurance and clinical protocol improvement
  • Provider credentialing and performance review
  • Business planning and operational analytics
  • Compliance audits and regulatory reporting
  • Fraud detection and prevention

3. BUSINESS ASSOCIATE RELATIONSHIPS & DATA SHARING

3.1 IPCo/OpCo Structure & BAA Compliance CRITICAL DISCLOSURE: Kōvn Health operates under a legally compliant IPCo/OpCo structure required by corporate practice of medicine (CPOM) doctrine: Under the BAA, the MSO has access to PHI ONLY to the extent necessary to provide technology infrastructure, customer support, and administrative services on behalf of the PC. The MSO is contractually prohibited from using or disclosing PHI except as permitted by HIPAA and the BAA. 3.2 Third-Party Business Associates We share PHI with the following third-party Business Associates under HIPAA-compliant BAAs: Licensed Pharmacies and Compounding Facilities: * For prescription fulfillment and medication dispensing. Pharmacies receive only the minimum necessary information (prescription details, delivery address). Clinical Laboratories: * For processing blood work and diagnostic testing (CMP, lipase, hormone panels). Labs receive patient demographics and clinical orders. Electronic Health Record (EHR) System: * [EHR VENDOR NAME - TBD] serves as the system of record for your complete medical chart. The EHR vendor operates under a HIPAA BAA and maintains SOC 2 Type II certification. Email and Communications Platform: * Resend (email service) operates under a HIPAA BAA for delivery of appointment reminders and secure communications. No PHI appears in email subject lines. Cloud Infrastructure: * Supabase (database hosting) or AWS RDS (production alternative) - operates under HIPAA BAA with AES-256 encryption at rest and TLS 1.3 in transit. 3.3 No PHI Sharing for Marketing WE NEVER SELL YOUR PROTECTED HEALTH INFORMATION. We do not share PHI with third parties for marketing purposes. Marketing communications (if you opt in) are sent by Kōvn Health directly and are based on de-identified usage patterns, NOT your medical conditions or prescriptions.

  • Kōvn Health (PC - OpCo): A Tennessee professional corporation that is the HIPAA Covered Entity. The PC employs or contracts with licensed healthcare providers and maintains all medical records.
  • Apex Health and Technology, LLC (MSO - IPCo): A Tennessee limited liability company that operates the technology platform and provides administrative services. The MSO is a Business Associate of the PC under a formal Business Associate Agreement (BAA).

4. DISCLOSURES WITHOUT YOUR AUTHORIZATION

HIPAA permits us to disclose PHI without your authorization in the following circumstances: 4.1 As Required by Law When disclosure is mandated by federal or state law, court orders, or administrative subpoenas. 4.2 Public Health Activities 4.3 Health Oversight Activities Disclosures to state medical boards, DEA, or federal agencies conducting audits, investigations, or licensure proceedings. 4.4 Judicial and Administrative Proceedings In response to lawful court orders, subpoenas, or administrative tribunal orders. We will notify you unless prohibited by law. 4.5 Law Enforcement When required by law, such as reporting gunshot wounds, suspected abuse or neglect, or in response to valid warrants. 4.6 Serious Threats to Health or Safety To avert a serious and imminent threat to your health or safety, or the health and safety of others, consistent with applicable professional standards.

  • Mandatory disease reporting to state health departments
  • FDA adverse event reporting (MedWatch) for serious drug reactions
  • Vaccine injury reporting (if applicable)

5. YOUR RIGHTS UNDER HIPAA

5.1 Right to Access Your Medical Records You have the right to inspect and obtain copies of your PHI maintained in our electronic health record system. We will provide access within 30 days of your written request. We may charge a reasonable, cost-based fee for copying and mailing records. 5.2 Right to Request Amendment You may request corrections to your medical records if you believe they are incorrect or incomplete. We may deny your request if the information was not created by us, is not part of our records, or is accurate and complete. If denied, you may submit a statement of disagreement. 5.3 Right to an Accounting of Disclosures You may request a list of certain disclosures we have made of your PHI within the past 6 years. This does NOT include disclosures for treatment, payment, healthcare operations, or disclosures you authorized. 5.4 Right to Request Restrictions You may request that we limit how we use or disclose your PHI. We are not required to agree to your request unless you ask us not to disclose information to your health plan for payment purposes regarding services you paid for out-of-pocket in full. 5.5 Right to Confidential Communications You may request that we communicate with you in a specific way (e.g., via email instead of phone) or at a specific location. We will accommodate reasonable requests. 5.6 Right to a Paper Copy of This Notice You may request a printed copy of this Privacy Policy at any time, even if you previously agreed to receive it electronically. 5.7 Right to File a Complaint If you believe your privacy rights have been violated, you may file a complaint with: YOU WILL NOT BE RETALIATED AGAINST FOR FILING A COMPLAINT.

  • Kōvn Health Privacy Officer at privacy@kovnhealth.com
  • U.S. Department of Health and Human Services (HHS) Office for Civil Rights: www.hhs.gov/hipaa/filing-a-complaint

6. STATE-SPECIFIC PRIVACY REQUIREMENTS

6.1 Florida Information Protection Act (FIPA) Compliance For patients located in Florida, we comply with the Florida Information Protection Act of 2014 (Fla. Stat. 501.171): Breach Notification Timeline: * In the event of a data breach affecting Florida residents, we will provide notice WITHOUT UNREASONABLE DELAY and in no case later than 30 days after determination of the breach (stricter than HITECH's 60-day federal requirement). Notice Content: * Breach notifications will include: (1) date of breach, (2) description of PHI involved, (3) actions taken to protect affected individuals, (4) contact information for questions. 6.2 Tennessee Privacy Law Compliance Tennessee does not currently have a comprehensive state privacy law beyond HIPAA. We comply with Tennessee medical record confidentiality requirements under Tenn. Code Ann. 68-11-304. 6.3 Future State Expansion As Kōvn Health expands to additional states, we will update this Privacy Policy to reflect state-specific privacy requirements and will notify affected users of material changes.

7. HIPAA SECURITY MEASURES

We implement comprehensive technical, physical, and administrative safeguards: 7.1 Technical Safeguards 7.2 Administrative Safeguards 7.3 Physical Safeguards

  • AES-256 encryption for data at rest
  • TLS 1.3 encryption for data in transit
  • Multi-factor authentication (MFA) for provider access
  • Role-based access controls (RBAC) - providers see only assigned patients
  • Comprehensive audit logging of all PHI access
  • Automatic session timeout after 15 minutes of inactivity
  • HIPAA training for all workforce members
  • Annual security risk assessments
  • Incident response plan with 24-hour breach detection
  • Business Associate Agreements with all third-party vendors
  • HIPAA-compliant cloud hosting with SOC 2 Type II certification
  • Geographically redundant backups with encryption
  • Secure workstation policies for workforce members

8. DATA RETENTION

Medical records and clinical intake data are retained for a minimum of seven (7) years from the date of last service in accordance with: After the retention period, medical records may be securely destroyed in accordance with NIST Special Publication 800-88 (media sanitization guidelines). Audit logs are retained for 6 years to comply with HIPAA's accounting of disclosures requirements.

  • HIPAA regulations (45 CFR 164.316(b)(2)(i))
  • Florida medical record retention requirements
  • Tennessee medical record retention requirements

9. PRIVACY OFFICER CONTACT INFORMATION

For privacy-related questions, requests, or complaints: Privacy Officer: [NAME - TO BE DESIGNATED] Email: privacy@kovnhealth.com Phone: [CLINIC PHONE - REQUIRED] Address: [PHYSICAL ADDRESS - REQUIRED] To file a complaint with the U.S. Department of Health and Human Services: Website: www.hhs.gov/hipaa/filing-a-complaint Phone: 1-877-696-6775

Privacy Officer Contact: privacy@Kovn.health | 888.Kōvn.US
To file a complaint with HHS: www.hhs.gov/hipaa/filing-a-complaint