Last Updated: January 12, 2026
HealthCareProxyMD ("we," "our," or "us") respects your privacy. This Privacy Policy explains how we collect, use, store, and protect information you provide when using our service to complete your Health Care Proxy and Living Will documents (your "Proxy Package™").
Important: We Are Not a HIPAA-Covered Entity or Business Associate. HealthCareProxyMD is NOT a HIPAA-covered entity, and we are NOT a business associate under HIPAA. Our communications are NOT HIPAA-protected. Please avoid sharing highly sensitive information you do not want transmitted via email or other communication channels we use.
Why We Are Not HIPAA-Covered: HealthCareProxyMD is a document preparation service and software tool that helps consumers create legal health planning documents. We are not HIPAA-covered because:
Our service is similar to other document preparation tools or legal form services—we help you complete forms based on your preferences, but we do not provide medical care, bill insurance, or act on behalf of healthcare providers.
Your Choice to Share. You choose what information you share with us. Sharing is voluntary and at your consent. You can stop using our service at any time.
Information You Provide. We collect information you voluntarily provide when using our service, including:
Usage Information. We do not collect anonymous usage data or use analytics services to track website visitors.
We use the information you provide solely to:
We Do Not Sell or Share Your Personal Information. HealthCareProxyMD does not sell, rent, or share your personal information for marketing purposes or with data brokers. We do not engage in cross-context behavioral advertising or share your information for advertising purposes.
We only share your information in the following limited circumstances:
We do not share your data with marketing data brokers, advertising networks, or other third parties for their own marketing or commercial purposes.
Under the General Data Protection Regulation (GDPR), we are required to inform you of the legal basis for processing your personal data. We process different categories of data under different legal bases:
1. Health Information (Special Category Data - GDPR Article 9):
2. Personal Information (Name, Email, Address, Phone):
3. Payment Information:
4. Email Communications and Document Delivery:
Your Rights Based on Legal Basis:
For more information about your rights, see "Your Rights and Choices" (Section 10) below. If you have questions about our legal basis for processing your data, please contact us at Contact@HealthCareProxyMD.com.
Primary Communication: Email. Our primary communication channel is email. We may also communicate via phone or video call using third-party providers (e.g., for your scheduled call with our doctor).
Email Is Not Guaranteed Secure. Email is not guaranteed secure, and communications are not HIPAA-protected. When you share information with us, you consent to us communicating with you via email and other channels necessary to provide our service. You should avoid sending highly sensitive information via email if you are concerned about security.
BCC Email Storage. When we send your completed Proxy Package™ documents via email, we may send a copy to our business email address using BCC (blind carbon copy) to ensure high quality results and help resolve any issues that may arise. This allows us to maintain records for customer support purposes and verify document delivery. By using our service, you consent to this BCC email storage practice.
Data Handling and Logging Practices. We take steps to protect your information during processing. We do not log your health information, form data, or document contents in our system logs or error messages. When errors occur, we return generic error messages to protect your privacy—we never expose detailed error information, stack traces, or your data in error responses. Your information is only used to provide our service and is not stored in logs or error tracking systems.
Reasonable Security Measures. While we implement reasonable security measures and rely on Google's security infrastructure (see "How We Store Your Information" below), no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security, but we take reasonable steps to protect your information.
Storage Location. Your information is stored only in our business email inbox and associated Google Workspace tools (including Gmail, Google Calendar, and Google Drive as applicable). This data is protected by Google's account security and access controls. We do not maintain a separate patient portal, electronic health record (EHR), or dedicated database.
No Separate Patient Portal or EHR. We do not use a separate patient portal or electronic health record system. All information is stored in our Google Workspace email and associated tools, protected by Google's security infrastructure and our access controls.
We retain your information until you request deletion, except where we are required to retain it for legal, accounting, or regulatory compliance purposes.
You may request deletion of your information at any time by emailing Contact@HealthCareProxyMD.com. We will process deletion requests within 30 days, subject to our legal obligations to retain certain records.
Legal and Business Obligations: We may be required to retain certain information for legal, accounting, or regulatory compliance purposes, including:
For more information about your rights and how to request deletion, see "Your Rights and Choices" (Section 10) below.
We use third-party services that may collect or process your information:
We are not responsible for the privacy practices of third-party services. We encourage you to review their privacy policies.
We do not use advertising trackers, analytics cookies, or sell your data to marketing data brokers. We may use essential cookies necessary for website functionality (such as maintaining form progress) and security cookies from Google reCAPTCHA to protect against spam and abuse. You can control cookies through your browser settings, though this may affect website functionality.
Data Portability. Your completed Proxy Package™ is delivered to you as a PDF document via email. This PDF format makes your data inherently portable—you can download, save, and share your documents anywhere you choose. You maintain full control over your Proxy Package™ documents and can access them at any time from your email or downloaded files.
How to Request Access or Deletion. You may request access to the personal information we hold about you, or request that we delete your information where feasible. To make a request, email us at Contact@HealthCareProxyMD.com with your name, email address, and the nature of your request (e.g., "I would like to access my information" or "I would like to delete my information").
We will respond to your request within a reasonable timeframe. Note that we may be unable to delete certain information if we are required to retain it for legal, accounting, or business purposes, or if deletion would prevent us from providing ongoing customer support.
Opt-Out of Communications. You may opt out of non-essential communications from us by emailing Contact@HealthCareProxyMD.com. We may still send you essential communications related to your service or account.
Non-Discrimination. We will not discriminate against you for exercising your privacy rights. We will not deny you services, charge you different prices, provide you a different level or quality of services, or suggest that you may receive different treatment for exercising your rights under this Privacy Policy or applicable law, including your rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA).
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
How to Exercise Your California Privacy Rights. To exercise any of these rights, please email us at Contact@HealthCareProxyMD.com with:
We will respond to your request within 45 days (or as otherwise required by law). We may need to verify your identity before processing your request to protect your privacy and security.
Categories of Personal Information We Collect. Under CCPA/CPRA, we collect the following categories of personal information:
We use this information solely for the purposes described in Section 3 ("How We Use Your Information") and do not sell or share it for marketing or advertising purposes.
Global Privacy Control (GPC) Signals. We do not sell or share your personal information, so Global Privacy Control (GPC) signals are not applicable to our service. Since we do not engage in sale or sharing of personal information, there is no opt-out mechanism needed. If you have questions about GPC or our data practices, please contact us at Contact@HealthCareProxyMD.com.
Our service is intended for adults (age 18 and older). We do not knowingly collect information from children under 18. If you believe we have collected information from a child under 18, please contact us immediately at Contact@HealthCareProxyMD.com.
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. Your continued use of our service after changes become effective constitutes acceptance of the updated policy.
If you have questions about this Privacy Policy or our privacy practices, please contact us at Contact@HealthCareProxyMD.com.