Privacy Policy

Effective Date: August 19, 2026
Last Updated: August 19, 2026

1. Introduction

Sunkar Technologies, LLC ("we," "us," "our") operates BioMedicineHealth, a HIPAA-compliant telehealth platform. This Privacy Policy explains how we collect, use, disclose, and protect your Protected Health Information (PHI) and personal data.

2. HIPAA Compliance

We are a HIPAA-Covered Entity

We comply with the Health Insurance Portability and Accountability Act (HIPAA) Privacy and Security Rules. This means your medical information is protected by federal law.

3. Information We Collect

a) Protected Health Information (PHI)

  • Personal identifiers (name, date of birth, address, phone, email)
  • Medical history, symptoms, diagnoses, and treatment plans
  • Prescription records and pharmacy information
  • Insurance information and billing records
  • Video consultation recordings (if consent is provided)

b) Technical Information

  • IP address, browser type, device information
  • Login timestamps and activity logs
  • Cookies and analytics data (see Section 8)

4. How We Use Your Information

a) Treatment, Payment, and Healthcare Operations (HIPAA-Permitted)

  • Treatment: Provide medical consultations, prescriptions, and care coordination
  • Payment: Process billing, insurance claims, and payment disputes
  • Healthcare Operations: Quality improvement, provider credentialing, legal compliance

b) With Your Consent

  • Marketing communications (you can opt out)
  • Third-party research studies (explicit consent required)

c) As Required by Law

  • Court orders, subpoenas, or law enforcement requests
  • Public health reporting (e.g., communicable diseases)
  • Abuse, neglect, or domestic violence reporting

5. Information Sharing & Disclosure

We Share PHI Only With:

  • Healthcare Providers: Your assigned doctors, nurses, and care team members
  • Pharmacies: To fulfill prescriptions (via encrypted e-prescribing)
  • Labs & Imaging Centers: For test orders and results (with your consent)
  • Business Associates: HIPAA-compliant vendors (cloud hosting, payment processing, video platform)
  • Your Insurance: For claims processing (if you use insurance)

We Do NOT:

  • Sell your PHI to third parties
  • Use PHI for marketing without your explicit opt-in
  • Share PHI with non-HIPAA-compliant entities

6. Data Security

We use industry-standard safeguards to protect your PHI:

  • Encryption: TLS 1.3 for data in transit; AES-256 for data at rest
  • Access Controls: Role-based permissions, multi-factor authentication (MFA)
  • Audit Logs: All PHI access is logged and monitored
  • Regular Security Audits: Penetration testing and vulnerability scans
  • HIPAA Training: All staff complete annual compliance training

7. Your HIPAA Rights

You have the right to:

  • Access: Request a copy of your medical records (we respond within 30 days)
  • Amend: Request corrections to inaccurate PHI
  • Accounting of Disclosures: See where your PHI was shared (last 6 years)
  • Restrict: Request limits on how we use/share your PHI (we may deny if legally required)
  • Confidential Communications: Request we contact you via specific methods (e.g., work email only)
  • Revoke Consent: Withdraw authorization for marketing or research (does not affect past uses)
  • Breach Notification: Be notified if your PHI is compromised

To exercise your rights: Email sunkartech@gmail.com or write to us at [Your Physical Address].

8. Cookies & Analytics

We use cookies for:

  • Session management (login state)
  • Analytics (Google Analytics with IP anonymization)
  • Performance monitoring (error tracking)

Marketing Cookies: We do NOT use third-party advertising trackers on authenticated pages. You can disable cookies in your browser settings.

9. Data Retention

  • Medical Records: Retained for 7 years (or longer if state law requires)
  • Billing Records: 7 years per IRS requirements
  • Inactive Accounts: PHI anonymized or deleted after 3 years of inactivity (after notice)

10. Children's Privacy (Under 18)

Our Platform is not intended for minors under 18 without parental/guardian consent. If a minor uses our services, a parent/guardian must create the account and consent to treatment. We comply with all applicable state laws regarding minors' medical privacy.

11. State-Specific Rights

Additional privacy rights for residents of:

  • California (CCPA/CPRA): Right to know, delete, and opt out of "sales" (we do not sell PHI)
  • Virginia, Colorado, Connecticut (State Privacy Laws): Similar data access and deletion rights
  • EU/UK (GDPR): Right to data portability, erasure, and processing restrictions

To exercise state-specific rights, contact sunkartech@gmail.com.

12. Breach Notification

If a data breach affects your PHI, we will notify you within 60 days via email or mail, as required by HIPAA. We will also report breaches to the U.S. Department of Health & Human Services (HHS) and, if applicable, state regulators and media.

13. Changes to This Policy

We may update this Privacy Policy to reflect legal changes or new practices. Material changes will be posted on our Platform and sent via email. Continued use after changes constitutes acceptance.

14. Contact Us

Privacy Officer:
Sunkar Technologies, LLC
Email: sunkartech@gmail.com
Website: www.biomedicinehealth.com

File a Complaint: If you believe your privacy rights have been violated, contact us or file a complaint with the U.S. Department of Health & Human Services Office for Civil Rights (OCR):HHS Complaint Portal.

Acknowledgment: By using this Platform, you acknowledge that you have read and understood this Privacy Policy.