Legal
Privacy policy
HIPAA Privacy Manual and Notice of Privacy Practices for Amsara Health.
Effective date: July 10, 2026 · Last updated: July 9, 2026
This notice describes how medical information about you may be used and disclosed and how you can get access to this information. Please review it carefully.
Amsara Health is a telemedicine healthcare practice focused on perimenopause, menopause-related care, hormone health, symptom management, preventive health, medication management, genetic testing where clinically appropriate, and related women’s health services.
This Privacy Manual and Notice of Privacy Practices explains how Amsara Health may collect, use, maintain, protect, and disclose your protected health information, also called “PHI,” and describes your rights under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations, commonly known as HIPAA.
Amsara Health is committed to protecting the privacy and security of your health information. We are required by law to maintain the privacy of your protected health information, provide you with this Notice, follow the terms of the Notice currently in effect, and notify you if a breach occurs involving your unsecured protected health information.
1. Who This Notice Applies To
This Notice applies to Amsara Health, its workforce members, clinicians, contractors, care coordination personnel, billing personnel, administrative personnel, technology vendors, and business associates who create, receive, maintain, or transmit protected health information on behalf of Amsara Health.
This Notice applies to information collected through Amsara Health’s telemedicine services, patient intake forms, patient portal, clinical communications, billing and payment processes, laboratory and genetic testing coordination, prescription management, customer support, website interactions where health information is collected, and other healthcare operations.
2. Protected Health Information We Collect
Amsara Health may collect information directly from you, from your authorized representative, from healthcare providers involved in your care, from laboratories, pharmacies, health plans, payment processors, technology vendors, or other sources permitted by law.
The information we collect may include:
2.1 Personal and Contact Information
We may collect your name, date of birth, address, phone number, email address, emergency contact information, preferred communication method, patient portal credentials, and other information used to identify or communicate with you.
2.2 Demographic Information
We may collect information such as age, sex assigned at birth, gender identity where relevant to care, preferred language, marital status, and other demographic information needed to provide care, comply with law, or support healthcare operations.
2.3 Clinical and Health Information
We may collect information about your medical history, current symptoms, perimenopause or menopause symptoms, menstrual history, reproductive and gynecologic history, hormone-related symptoms, sleep, mood, weight, metabolic health, medications, allergies, supplements, prior diagnoses, surgical history, family history, lifestyle information, social history, and other information relevant to your care.
2.4 Telemedicine Visit Information
We may collect clinical notes, telemedicine visit documentation, treatment plans, prescriptions, medication refill requests, care recommendations, provider communications, visit recordings only if separately disclosed and permitted, and other documentation created as part of your care.
2.5 Laboratory, Diagnostic, and Genetic Testing Information
We may collect laboratory orders, laboratory results, diagnostic test information, genetic testing information, pharmacogenomic information, specimen collection information, and related clinical interpretations when such testing is ordered or reviewed as part of your care.
Genetic testing information is treated as protected health information. Amsara Health uses genetic and pharmacogenomic information only for treatment, payment, healthcare operations, or other purposes permitted by law or authorized by you.
2.6 Prescription and Pharmacy Information
We may collect prescription history, medication instructions, refill information, pharmacy information, prior authorization information, medication adherence information, and information needed to prescribe, manage, or monitor medications.
2.7 Billing, Payment, and Insurance Information
We may collect self-pay information, payment status, credit card or payment processor information, invoices, receipts, health plan information, claim information, diagnosis and procedure codes, eligibility information, prior authorization information, and other payment-related information.
Amsara Health may provide self-pay services and may also bill commercial health plans where applicable. Amsara Health will use and disclose only the information needed for payment and healthcare operations unless a broader disclosure is permitted or required by law.
2.8 Patient Portal, Website, and Technical Information
When you use Amsara Health’s website, patient portal, telemedicine platform, or digital forms, we may collect technical information such as device information, IP address, browser type, date and time of access, pages visited, system logs, authentication records, and security audit records.
If technical or website information is connected to your healthcare, payment for healthcare, patient portal use, appointment scheduling, symptom reporting, or other identifiable health information, it may be treated as protected health information.
Amsara Health does not permit website tracking technologies, analytics tools, pixels, cookies, or similar tools to disclose protected health information to third parties unless the disclosure is permitted by HIPAA, supported by a required business associate agreement, authorized by you, or otherwise permitted by law.
2.9 Information From Connected Devices or Apps
If you authorize Amsara Health to receive information from a wearable device, mobile application, symptom tracker, or other digital health tool, we may collect information such as sleep data, activity data, heart rate, cycle tracking information, symptom history, weight, or other health data relevant to your care.
Amsara Health will treat such information as protected health information when it is received, created, maintained, or transmitted by Amsara Health in connection with your healthcare.
3. How We Use and Disclose Your Health Information
HIPAA allows Amsara Health to use and disclose your protected health information for treatment, payment, and healthcare operations without a separate written authorization from you. We may also use and disclose your information in other limited circumstances permitted or required by law.
3.1 Treatment
We may use and disclose your health information to provide, coordinate, or manage your healthcare.
Examples include:
- A clinician reviews your intake form before a telemedicine visit.
- Amsara Health shares relevant clinical information with a laboratory to order testing.
- Amsara Health sends a prescription to your pharmacy.
- Amsara Health communicates with another healthcare provider involved in your care.
- A clinician uses your symptom history, lab results, medications, and health history to create a treatment plan.
3.2 Payment
We may use and disclose your health information to bill and collect payment for services.
Examples include:
- We may send information to a commercial health plan to support payment for covered services.
- We may provide diagnosis or procedure codes to a billing vendor or clearinghouse.
- We may process self-pay invoices, receipts, refunds, or payment questions.
- We may verify eligibility, benefits, coverage, or prior authorization requirements when applicable.
3.3 Healthcare Operations
We may use and disclose your health information to operate Amsara Health and improve the quality and safety of our services.
Examples include:
- Quality review and clinical improvement activities.
- Provider training and supervision.
- Compliance reviews and audits.
- Credentialing and peer review.
- Customer support and care coordination.
- Security monitoring and fraud prevention.
- Business planning, reporting, and practice management.
- Evaluating patient experience and service quality.
3.4 Appointment Reminders and Care Communications
We may use your information to contact you about appointments, telemedicine visits, follow-up care, refill reminders, lab testing, care plan reminders, patient portal messages, billing questions, and other service-related communications.
We may communicate with you by patient portal, phone, email, text message, mail, or other methods you provide or authorize. You may request that we contact you in a specific way or at a specific location.
3.5 Treatment Alternatives and Health-Related Benefits
We may contact you about treatment options, services, programs, or health-related benefits that may be relevant to your care.
3.6 Business Associates
Amsara Health may share protected health information with vendors or service providers who perform functions on our behalf, such as electronic health record services, telemedicine technology, billing, payment processing, laboratory coordination, secure messaging, cloud hosting, cybersecurity, legal, accounting, analytics, or administrative support.
When HIPAA requires it, Amsara Health will enter into a written business associate agreement requiring the vendor to appropriately safeguard protected health information and use or disclose it only as permitted by the agreement and applicable law.
3.7 Family Members, Caregivers, and Others Involved in Your Care
We may share relevant information with a family member, caregiver, or other person involved in your care or payment for your care if you agree, if you have the opportunity to object and do not object, or if we determine based on professional judgment that the disclosure is in your best interest.
You may tell us not to share information with certain people, and we will honor your request unless disclosure is required or permitted by law.
3.8 Required by Law
We may use or disclose your health information when required to do so by federal, state, or local law.
3.9 Public Health and Safety
We may disclose health information for public health and safety purposes, including to prevent or control disease, report adverse events, report suspected abuse, neglect, or domestic violence where required or permitted by law, prevent or reduce a serious threat to health or safety, or comply with public health reporting obligations.
3.10 Health Oversight Activities
We may disclose health information to health oversight agencies for audits, investigations, inspections, licensure, disciplinary actions, or other activities authorized by law.
3.11 Legal Proceedings and Law Enforcement
We may disclose health information in response to a court order, subpoena, discovery request, administrative request, or other lawful process when required or permitted by law. We may also disclose information to law enforcement in limited circumstances permitted by HIPAA and applicable law.
3.15 Research
Amsara Health may use or disclose health information for research only as permitted by HIPAA and applicable law. This may include use of de-identified information, limited data sets with appropriate safeguards, research approved by an Institutional Review Board or Privacy Board, or research authorized by you.
3.16 De-Identified or Aggregated Information
Amsara Health may use health information to create de-identified or aggregated information that does not identify you and cannot reasonably be used to identify you. Once information is properly de-identified under applicable law, it is no longer protected health information under HIPAA.
5. Your HIPAA Rights
You have the following rights regarding your protected health information.
5.1 Right to Access Your Health Information
You have the right to request access to inspect or receive a copy of protected health information maintained in your designated record set. This may include medical records, billing records, and other records used to make decisions about you.
We will usually provide access within 30 days of your request. We may charge a reasonable, cost-based fee where permitted by law. In limited circumstances, we may deny access, and if we do, we will explain the reason in writing and tell you whether you have a right to have the denial reviewed.
5.2 Right to Request an Amendment
You have the right to ask us to correct health information that you believe is incorrect or incomplete.
We may deny your request in certain circumstances, such as if the information is accurate and complete, was not created by Amsara Health, is not part of the designated record set, or is not available for inspection under HIPAA. If we deny your request, we will explain the reason in writing and tell you about your right to submit a written statement of disagreement.
5.3 Right to an Accounting of Disclosures
You have the right to request a list of certain disclosures of your protected health information made by Amsara Health or our business associates during the six years before your request.
The accounting will not include all disclosures. For example, it generally will not include disclosures made for treatment, payment, or healthcare operations; disclosures made to you; disclosures made with your authorization; or other disclosures excluded by HIPAA.
We will provide one accounting in any 12-month period without charge. We may charge a reasonable, cost-based fee for additional requests within the same 12-month period.
5.4 Right to Request Restrictions
You have the right to request that we restrict certain uses or disclosures of your protected health information for treatment, payment, or healthcare operations.
We are not required to agree to most restriction requests. If we agree, we will comply with the restriction except in an emergency or as otherwise permitted by law.
If you pay for a healthcare item or service out of pocket in full, you may request that we not disclose information about that item or service to your health plan for payment or healthcare operations. We will agree to that request unless disclosure is required by law.
5.5 Right to Request Confidential Communications
You have the right to request that we contact you in a specific way or at a specific location. For example, you may ask that we contact you only through the patient portal, only by phone, or at a specific email or mailing address.
We will accommodate reasonable requests.
5.6 Right to Receive a Copy of This Notice
You have the right to receive a paper or electronic copy of this Notice at any time, even if you previously agreed to receive it electronically.
This Notice will also be available on the Amsara Health website once published.
5.7 Right to Choose a Personal Representative
You may choose someone to act on your behalf, such as a person with medical power of attorney or a legal guardian. Before we take action based on a personal representative’s request, we may verify that the person has authority to act for you.
5.8 Right to Receive Notice of a Breach
You have the right to be notified if Amsara Health discovers a breach of your unsecured protected health information, as required by HIPAA and applicable law.
5.9 Right to File a Complaint
You have the right to file a complaint if you believe your privacy rights have been violated.
You may contact Amsara Health at:
Privacy Officer
Stelle Smith
Email
privacy@thepause.ai
Address
Amsara Health
4250 N Drinkwater Blvd, Suite 300
Scottsdale, AZ 85251
You may also file a complaint with the U.S. Department of Health and Human Services, Office for Civil Rights.
Amsara Health will not retaliate against you for filing a complaint.
6. Our Privacy and Security Responsibilities
Amsara Health is required by law to:
- Maintain the privacy and security of your protected health information.
- Provide this Notice explaining our legal duties and privacy practices.
- Follow the terms of the Notice currently in effect.
- Notify you if a breach occurs involving your unsecured protected health information.
- Train workforce members on privacy and security responsibilities.
- Maintain safeguards designed to protect protected health information.
- Limit uses and disclosures to the minimum necessary when required by HIPAA.
- Maintain written agreements with business associates where required.
- Investigate potential privacy or security incidents.
- Document privacy and security policies, procedures, complaints, investigations, and breach determinations as required by law.
7. Safeguards We Use to Protect Health Information
Amsara Health maintains administrative, physical, and technical safeguards designed to protect the confidentiality, integrity, and availability of protected health information and electronic protected health information.
7.1 Administrative Safeguards
Amsara Health maintains policies and procedures addressing privacy, security, access control, workforce training, incident response, risk management, vendor oversight, business associate agreements, and sanctions for workforce members who violate privacy or security policies.
7.2 Physical Safeguards
Amsara Health uses reasonable physical safeguards to protect devices, systems, records, and workspaces used to access protected health information. This may include secure work areas, device protection, secure disposal, and controls for workforce access to systems and records.
7.3 Technical Safeguards
Amsara Health uses technical safeguards designed to protect electronic protected health information, which may include access controls, authentication, encryption, and audit logging.
7.4 Minimum Necessary Standard
When HIPAA requires the minimum necessary standard, Amsara Health makes reasonable efforts to use, disclose, and request only the minimum amount of protected health information necessary to accomplish the intended purpose.
The minimum necessary standard does not apply to all situations, such as disclosures to healthcare providers for treatment, disclosures to you, disclosures made with your authorization, or disclosures required by law.
7.5 Workforce Training and Sanctions
Amsara Health trains workforce members who may access protected health information on HIPAA, privacy, security, confidentiality, and appropriate use of systems.
Workforce members who violate Amsara Health privacy or security policies may be subject to corrective action, up to and including termination of access, termination of employment or contract, and reporting to authorities where required.
8. Telemedicine Privacy Practices
Amsara Health provides care through telemedicine. Telemedicine visits may involve video, audio, secure messaging, electronic intake forms, patient portal communications, electronic prescribing, laboratory orders, and electronic health record documentation.
Amsara Health expects patients to participate in telemedicine visits from a private location whenever possible. You are responsible for choosing a location where you are comfortable discussing your health information.
Amsara Health uses telemedicine and communication systems intended to support privacy and security. However, no electronic communication method can be guaranteed to be completely secure. If you choose to communicate with Amsara Health through email, text message, or other non-portal communication methods, there may be additional privacy risks. You may request confidential communication methods at any time.
10. Email, Text Messaging, and Patient Portal Communications
Amsara Health may use email, text messages, mail, or patient portal messages to communicate with you about appointments, administrative matters, billing, care coordination, and other healthcare-related matters.
Whenever feasible, Amsara Health encourages use of the patient portal for sensitive clinical information.
If you request communication through a specific method, we will accommodate reasonable requests. You may change your communication preferences by contacting Amsara Health.
11. Breach Response and Notification
A breach is generally an acquisition, access, use, or disclosure of unsecured protected health information in a manner not permitted by HIPAA that compromises the security or privacy of the information.
If Amsara Health discovers a potential breach, we will take steps to:
- Identify and contain the incident.
- Investigate what happened.
- Determine what information was involved.
- Determine which individuals were affected.
- Assess the probability that protected health information was compromised.
- Mitigate potential harm.
- Take corrective action to reduce the risk of future incidents.
- Provide required notices to affected individuals, the U.S. Department of Health and Human Services, and, where required, the media or other authorities.
If a breach of unsecured protected health information occurs, Amsara Health will notify affected individuals without unreasonable delay and no later than 60 days after discovery, unless a shorter time period is required by applicable law.
The notice will include, to the extent possible:
- A brief description of what happened.
- The date of the breach and the date it was discovered, if known.
- The types of information involved.
- Steps you should take to protect yourself from potential harm.
- What Amsara Health is doing to investigate, mitigate harm, and prevent future breaches.
- Contact information for questions.
If a breach affects 500 or more residents of a state or jurisdiction, Amsara Health will provide notice to prominent media outlets serving that state or jurisdiction when required by HIPAA.
Amsara Health will notify the U.S. Department of Health and Human Services as required by HIPAA. For breaches involving 500 or more individuals, notice will be made without unreasonable delay and no later than 60 days after discovery. For breaches involving fewer than 500 individuals, Amsara Health may report such breaches annually as permitted by HIPAA, unless applicable law requires earlier reporting.
If a breach occurs at or by a business associate, Amsara Health requires the business associate to notify Amsara Health as required by HIPAA and the applicable business associate agreement.
12. Restrictions on Marketing and Sale of Information
Amsara Health does not sell protected health information without your written authorization when HIPAA requires authorization.
Amsara Health does not use protected health information for third-party advertising or marketing in a manner that would violate HIPAA.
Amsara Health may communicate with you about health-related services, treatment options, care reminders, or services provided by Amsara Health where permitted by HIPAA.
13. Fundraising
Amsara Health does not currently use protected health information for fundraising. If Amsara Health conducts fundraising in the future, we will do so only as permitted by law and will provide a clear opportunity to opt out of future fundraising communications.
14. Personal Representatives
Amsara Health will comply with applicable federal and state laws regarding minors, parents, guardians, and personal representatives.
In some circumstances, a parent, guardian, or personal representative may have the right to access or control a patient’s health information. In other circumstances, applicable law may limit access to certain information. Amsara Health will evaluate these requests based on applicable law and the facts of the situation.
15. State Law and Other Privacy Laws
HIPAA provides federal privacy and security protections for protected health information. In some cases, state privacy laws or other federal laws may provide additional protections or impose additional requirements.
Amsara Health will comply with applicable federal and state privacy laws. If another law provides greater privacy protection than HIPAA and applies to Amsara Health, we will follow the more protective law where required.
16. Changes to This Notice
Amsara Health may change the terms of this Notice at any time. The revised Notice may apply to all protected health information we maintain, including information created or received before the Notice was revised.
If we make a material change to this Notice, we will post the revised Notice on our website and make it available upon request. The revised Notice will include an updated effective date.
17. How to Exercise Your Rights
To exercise your privacy rights, ask questions, request a copy of this Notice, request access to your medical records, request an amendment, request confidential communications, request restrictions, or file a privacy complaint, contact:
Privacy Officer
Stelle Smith
Email
privacy@thepause.ai
Address
Amsara Health
4250 N Drinkwater Blvd, Suite 300
Scottsdale, AZ 85251
Amsara Health may require requests to be submitted in writing and may verify your identity before responding.
18. Questions or Complaints
If you believe your privacy rights have been violated, you may file a complaint with Amsara Health or with the U.S. Department of Health and Human Services, Office for Civil Rights.
Amsara Health will not retaliate against you for filing a complaint, participating in an investigation, or exercising your rights under HIPAA.
19. Acknowledgment of Receipt
Amsara Health may ask you to acknowledge that you received this Notice. Your acknowledgment does not mean that you agree to any special use or disclosure of your information. If you do not sign or submit an acknowledgment, Amsara Health may still provide treatment and will document that acknowledgment was not obtained.
State-Specific Privacy Requirements
Arizona Privacy Requirements
Arizona is Amsara Health’s initial launch state. Amsara Health will treat Arizona medical records, payment records, telemedicine records, laboratory records, prescription records, patient portal information, and related healthcare information as confidential and protected.
Under Arizona law, medical records and payment records are generally privileged and confidential. Amsara Health will not disclose Arizona patient medical records or payment records except as permitted by HIPAA, Arizona law, other applicable federal or state law, or a valid written authorization signed by the patient or the patient’s authorized health care decision maker.
Arizona patients, or their authorized health care decision makers, may request access to or copies of their medical records and payment records. Amsara Health will respond to such requests in accordance with HIPAA and applicable Arizona law. Amsara Health may deny access only in limited circumstances permitted by law, such as when a qualified health professional determines that access is reasonably likely to endanger the life or physical safety of the patient or another person, or when another legally recognized basis for denial applies. If Amsara Health denies access, Amsara Health will provide a written explanation as required by law.
Amsara Health may disclose Arizona patient information without written authorization where permitted by law, including for treatment, payment, healthcare operations, continuity of care, clinical laboratory purposes, quality assurance, peer review, utilization review, legal compliance, health oversight, third-party payment, contracted services, or other purposes authorized by HIPAA or Arizona law.
Amsara Health may charge reasonable fees for copies of medical records where permitted by law. Amsara Health will not charge for records when Arizona law prohibits charging, including certain records provided to another healthcare provider for continuity of care or to the patient for the demonstrated purpose of obtaining healthcare.
Arizona Breach Notification
If Amsara Health identifies a potential privacy or security incident involving Arizona patient information, Amsara Health will investigate the incident promptly and determine whether notification is required under HIPAA, Arizona law, or another applicable law.
For protected health information governed by HIPAA, Amsara Health will follow HIPAA breach notification requirements. If Arizona’s data breach law applies to information that is not governed exclusively by HIPAA, Amsara Health will provide notices required by Arizona law. Arizona law may require notice to affected individuals within 45 days after determining that a qualifying security system breach occurred. If a breach requires notice to more than 1,000 Arizona individuals, additional notice may be required to the Arizona Attorney General, the Arizona Department of Homeland Security, and the three largest nationwide consumer reporting agencies.
Arizona’s breach notification law may apply to certain unencrypted and unredacted computerized personal information, including health insurance identification numbers, medical or mental health treatment or diagnosis information, certain financial information, login credentials, government identifiers, and biometric data.
How Amsara Health Applies Multiple Laws
When more than one privacy or breach notification law applies to the same information, Amsara Health will follow the requirement that provides greater protection to the patient or imposes the stricter obligation on Amsara Health. For example, if Arizona law requires breach notification sooner than HIPAA, Amsara Health will follow the shorter timeline. Where Amsara Health uses a vendor to create, receive, maintain, or transmit protected health information, Amsara Health will require appropriate contractual safeguards, including a business associate agreement where HIPAA requires one.