Atlas HLTH
ATLAS HLTH
Privacy Policy

Privacy Policy

Effective Date: January 1, 2025  ·  DAPP Inc. d/b/a Atlas HLTH

HIPAA-Aligned Platform

Atlas HLTH is built to HIPAA Security Rule standards. Your protected health information (PHI) is handled with the highest standards of security and confidentiality.

1. Introduction

DAPP Inc. d/b/a Atlas HLTH ("Company," "we," "us," or "our") is committed to protecting the privacy and security of your personal and health information. This Privacy Policy describes how we collect, use, disclose, and safeguard information when you use the Atlas HLTH platform (the "Service").

This policy applies to all users of the Service, including patients, clinicians, and administrative users. For patients, this policy supplements our Notice of Privacy Practices (NPP), which describes your rights under HIPAA.

2. Information We Collect

2.1 Patient Information

When you use the patient portal or are referred through the platform, we may collect:

  • Name, date of birth, and contact information
  • Referral and care coordination records
  • Clinical assessment data (ATLAS TRIAGE results, PHQ-9, GAD-7 scores)
  • Consent records (HIPAA NPP acknowledgment, 42 CFR Part 2 consent)
  • Satisfaction survey responses

2.2 Clinician and Staff Information

For clinicians and administrative users, we collect:

  • Name, email address, and professional credentials
  • Account activity and audit logs
  • Provider network information and scheduling data

2.3 Technical Information

We automatically collect certain technical information, including:

  • IP address and device information
  • Browser type and operating system
  • Pages visited and actions taken within the Service
  • Session timestamps and duration

3. How We Use Your Information

We use collected information to:

  • Facilitate behavioral health referrals and care coordination
  • Conduct clinical assessments and generate triage recommendations
  • Communicate with patients and care teams about referral status
  • Maintain audit logs for HIPAA compliance and security monitoring
  • Improve the accuracy and effectiveness of our routing algorithms
  • Send appointment reminders and care coordination notifications
  • Comply with applicable legal and regulatory requirements

We do not sell your personal or health information to third parties.

4. How We Share Your Information

4.1 With Your Care Team

We share your health information with the behavioral health providers to whom you are referred, and with your referring clinician or organization, for treatment and care coordination purposes.

4.2 Business Associates

We may share information with third-party service providers (Business Associates) who assist us in operating the Service, such as cloud infrastructure providers and communication services. All Business Associates are required to maintain the confidentiality and security of PHI under signed Business Associate Agreements (BAAs).

4.3 Legal Requirements

We may disclose information when required by law, court order, or government regulation, or when we believe disclosure is necessary to protect the rights, property, or safety of the Company, our users, or the public.

4.4 Substance Use Disorder Records

Records related to substance use disorder treatment are subject to additional protections under 42 CFR Part 2 and will not be disclosed without your explicit written consent, except as required by law.

5. Data Security

We implement industry-standard security measures to protect your information, including:

  • 256-bit TLS encryption for all data in transit
  • Encryption at rest for all stored PHI
  • Role-based access controls and multi-factor authentication
  • Comprehensive audit logging of all PHI access events
  • Regular security assessments and penetration testing
  • Incident response procedures compliant with HIPAA Breach Notification Rule

6. Data Retention

We retain patient health information for a minimum of 7 years from the date of last service, or longer as required by applicable state law. Audit logs are retained for a minimum of 6 years. You may request deletion of your non-PHI account data by contacting us at [email protected].

7. Your Rights Under HIPAA

As a patient, you have the right to:

  • Access: Request a copy of your health records
  • Amendment: Request corrections to inaccurate information
  • Accounting of Disclosures: Request a list of disclosures of your PHI
  • Restriction: Request restrictions on certain uses and disclosures
  • Confidential Communications: Request that we communicate with you through alternative means
  • Complaint: File a complaint with the U.S. Department of Health and Human Services

To exercise these rights, contact our Privacy Officer at [email protected].

8. Cookies and Tracking

The Service uses session cookies for authentication and localStorage for user preferences (including consent acknowledgment). We do not use third-party advertising cookies or tracking pixels. You may disable cookies in your browser settings, but this may affect the functionality of the Service.

9. Children's Privacy

The Service is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13 without verifiable parental consent. If you believe we have collected information from a child under 13, please contact us immediately at [email protected].

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify users of material changes by updating the effective date and, where appropriate, through in-app notifications. Your continued use of the Service after changes become effective constitutes your acceptance of the revised policy.

11. Contact Us

For privacy-related questions, requests, or complaints:

DAPP Inc. d/b/a Atlas HLTH

Privacy Officer

850 University Drive, Oxford, MS 38655

Email: [email protected]

To file a complaint with HHS: hhs.gov/hipaa/filing-a-complaint

HIPAA-Aligned
256-bit Encryption
SOC 2 Type II In Progress
42 CFR Part 2

© 2026 DAPP Inc. d/b/a Atlas HLTH. All rights reserved.