Last Updated: 10-07-2025
This Privacy Policy covers both our healthcare platform services and our general business operations, ensuring comprehensive protection for all personal information we collect and process.
Xealth recognizes the importance of the privacy and confidentiality of your personal information, including protected health information (“PHI”).
PHI Privacy Policy
What We Do
Xealth provides a digital health platform (the “Xealth Platform”) that enables healthcare providers and care team members (“Health Systems”) to provide patients with digital content, apps, or services that can help manage health. The Xealth Platform connects digital healthcare solutions partners (“Partners”) with patients to increase patient education, engagement, and improve outcomes.
Protected Health Information (PHI)
What is PHI? PHI includes all “individually identifiable health information” that is transmitted or maintained in any form or medium by a covered entity. This includes any information that can be used to identify an individual and that was created, used, or disclosed in the course of providing healthcare services such as diagnosis or treatment.
How PHI Differs from Other Personal Information: While personally identifiable information (PII) can be used to distinguish or trace an individual’s identity, PHI specifically relates to health information. The PHI shared on the Xealth Platform may include certain data metrics that do not directly identify you as an individual, such as gender, weight, and age.
How We Use Your Information
For Healthcare Services: When a physician or care team member selects a Partner for a patient, Xealth provides the minimum amount of PHI required for the Partner to deliver their services. We temporarily store data necessary to ensure successful data transfer.
For Business Purposes: We use non-PHI personal information to manage our business relationships, improve our services, communicate with clients and prospects, and comply with legal obligations.
Legal Framework: Xealth functions as a HIPAA Business Associate of its health system clients, facilitating the transfer of information between health systems and third-party applications that clinicians may use for permissible purposes under HIPAA.
Data Retention
The type of data we store and retention periods are governed by:
- Business Associate Agreements with health system clients
- HIPAA requirements (minimum 6 years for HIPAA-related documents)
- Applicable state and federal laws
- Business necessity and legal obligations
How We Protect Your Information
We implement comprehensive security measures including:
Technical Safeguards:
- Encryption of all stored and transmitted data
- Secure network connections in accordance with industry standards
- Authentication and access controls
- Regular security assessments
Administrative Safeguards:
- Staff training on security procedures
- Clearance procedures and workforce supervision
- Security incident response procedures
- Emergency access and contingency planning
Physical Safeguards:
- Secure facilities and equipment
- Appropriate storage, backup, and disposal procedures
