Apply for your Card Today!
Image
Featured In and Trusted By

Effective Date: November 5, 2025

Our Commitment to Your Privacy

TeleLeaf (“TeleLeaf,” “we,” “us,” or “our”) is dedicated to maintaining the privacy and integrity of your personal and protected health information (PHI). We are required by law to maintain the privacy of your health information and to provide you with this notice of our legal duties and privacy practices. This Notice of Privacy Practices and Privacy Policy (“Notice”) describes how we may use and disclose your information and your rights regarding that information. It applies to all services provided by TeleLeaf, including our telehealth platform, website, and any other interactions you have with us.

We are committed to complying with all applicable federal and state laws, including the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the Health Information Technology for Economic and Clinical Health (HITECH) Act, substance use disorder confidentiality regulations (42 CFR Part 2), the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), and the General Data Protection Regulation (GDPR).

Notice of Privacy Practices (NPP)

THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.

Your Health Information Rights

You have the following rights regarding the PHI we maintain about you:

Right to Inspect and Copy: You have the right to inspect and obtain a copy of your health and billing records. We may charge a reasonable, cost-based fee for copies.

Right to Request Amendments: If you believe that information in your record is incorrect or incomplete, you have the right to request an amendment. We may deny your request under certain circumstances, but we will provide you with a written explanation.

Right to an Accounting of Disclosures: You have the right to receive a list of certain disclosures we have made of your PHI. This right does not apply to disclosures for treatment, payment, healthcare operations, or certain other exceptions.

Right to Request Restrictions: You have the right to request a restriction on how we use or disclose your PHI for treatment, payment, or healthcare operations. We are not required to agree to your request, but we will consider it. However, if you pay for a service or health care item out-of-pocket in full, you can ask us not to share that information for the purpose of payment or our operations with your health insurer.

Right to Request Confidential Communications: You have the right to request that we communicate with you about medical matters in a certain way or at a certain location.

Right to a Paper Copy of This Notice: You have the right to a paper copy of this notice at any time.

Our Uses and Disclosures of Your Health Information

We may use and disclose your PHI for the following purposes:

Treatment: We will use your health information to provide you with medical treatment or services, such as consulting with physicians and other healthcare providers involved in your care.

Payment: We may use and disclose your health information to bill and collect payment from you, your health plan, or a third party.

Healthcare Operations: We may use and disclose your health information for our business operations, such as quality assessment, employee training, and compliance activities.

We may also use or disclose your PHI without your authorization for the following purposes:

As Required by Law: We will disclose your PHI when required to do so by federal, state, or local law.

Public Health Activities: We may disclose your PHI for public health activities, such as to prevent or control disease, injury, or disability.

Health Oversight Activities: We may disclose PHI to a health oversight agency for activities authorized by law, such as audits, investigations, and inspections.

Lawsuits and Disputes: If you are involved in a lawsuit or a dispute, we may disclose your PHI in response to a court or administrative order.

Law Enforcement: We may release PHI if asked to do so by a law enforcement official in response to a court order, subpoena, warrant, summons, or similar process.

Our Responsibilities

  • We are required by law to maintain the privacy and security of your protected health information.
  • We will let you know promptly if a breach occurs that may have compromised the privacy or security of your information.
  • We must follow the duties and privacy practices described in this notice and give you a copy of it.
  • We will not use or share your information other than as described here unless you tell us we can in writing. If you tell us we can, you may change your mind at any time. Let us know in writing if you change your mind.

Changes to This Notice

We reserve the right to change this notice and our privacy practices. We will post a copy of the current notice on our website with the effective date.

Complaints

If you believe your privacy rights have been violated, you may file a complaint with us by contacting us at the address below. You may also file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights. 

Contact Information:

235 Derbigny Street, Suite 201, Gretna, LA 70053

(504) 264-3123

Confidentiality of Substance Use Disorder Patient Records (42 CFR Part 2)

For individuals receiving treatment or assessment for substance use disorder (SUD), federal law (42 CFR Part 2) provides special protection for your treatment records. 

In general, we may not say to a person outside the program that you attend the program, or disclose any information identifying you as an alcohol or drug abuser, or disclose any other protected information except with your specific written consent.

Exceptions to this rule include:

  • Medical emergencies.
  • Scientific research.
  • Audits and evaluations.
  • If there is a court order.

Violation of these regulations is a crime, and suspected violations may be reported to the United States Attorney in the district where the violation occurs.

Consumer Privacy Laws (GDPR, CCPA/CPRA)

For Residents of the European Economic Area (EEA) and United Kingdom (UK)

If you are a resident of the EEA or UK, you have certain data protection rights under the General Data Protection Regulation (GDPR). TeleLeaf is committed to ensuring that your rights are protected. These rights include the right to access, correct, update, or request deletion of your personal information.

For Residents of California

The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), provides California residents with specific rights regarding their personal information. While most of the health information we collect is exempt from the CCPA/CPRA because it is protected by HIPAA, other personal information we collect may be subject to these laws. You have the right to know what personal information is being collected about you, to request that we delete your personal information, and to opt-out of the sale or sharing of your personal information.

Telehealth Platform Privacy

We take special care to protect your privacy in the context of our telehealth services. This includes:

  • Secure Communications: We use secure, encrypted video conferencing and messaging to protect your communications with our providers.
  • Access Controls: We have strict access controls in place to ensure that only authorized individuals can access your health information.
  • Business Associate Agreements: We have Business Associate Agreements (BAAs) in place with all of our vendors who have access to your PHI, requiring them to protect your information to the same extent we do.

Security Safeguards

We have implemented administrative, physical, and technical safeguards to protect your PHI from unauthorized access, use, or disclosure. These safeguards include employee training, facility security, and technical measures such as encryption and access controls.

Breach Notification

In the unlikely event of a breach of your unsecured PHI, we will notify you and the Department of Health and Human Services as required by the HITECH Act.

Minimum Necessary Standard

We will make reasonable efforts to use, disclose, and request only the minimum amount of PHI needed to accomplish the intended purpose of the use, disclosure, or request.

Business Associate Agreements

We enter into Business Associate Agreements (BAAs) with third-party vendors who perform services on our behalf and have access to your PHI. 

These agreements require our business associates to:

  • Use and disclose your PHI only as permitted by the agreement and as required by law.
  • Implement appropriate safeguards to prevent unauthorized use or disclosure of your PHI.
  • Report to us any security incidents or breaches of unsecured PHI.
  • Ensure that any subcontractors they engage also agree to the same restrictions and conditions.
  • Make PHI available to you for inspection and copying.
  • Make PHI available for amendment and incorporate any amendments as directed.
  • Make available the information required to provide an accounting of disclosures.
  • Return or destroy all PHI at the termination of the agreement, if feasible.

Our business associates may include video conferencing platforms, electronic health record vendors, billing and payment processors, cloud storage providers, email and messaging services, and other technology service providers.

Information We Collect

We collect several types of information from and about users of our services, including:

Protected Health Information (PHI): This includes information that identifies you and relates to your past, present, or future physical or mental health condition, the provision of healthcare to you, or payment for healthcare. Examples include your name, address, date of birth, Social Security number, medical history, diagnoses, treatment information, and billing information.

Personal Information: This includes information that identifies you but is not health-related, such as your email address, phone number, and payment information.

Technical Information: We automatically collect certain information when you use our website and services, including your IP address, browser type, operating system, access times, and the pages you have viewed.

Usage Information: We collect information about how you use our services, such as the features you use, the pages you visit, and the actions you take.

How We Use Your Information

In addition to the uses described in the Notice of Privacy Practices section above, we may use your information for the following purposes:

  • To provide, maintain, and improve our services.
  • To process your transactions and send you related information, including confirmations and invoices.
  • To send you technical notices, updates, security alerts, and support and administrative messages.
  • To respond to your comments, questions, and requests and provide customer service.
  • To communicate with you about products, services, offers, promotions, and events offered by TeleLeaf and others, and provide news and information we think will be of interest to you (subject to your communication preferences).
  • To monitor and analyze trends, usage, and activities in connection with our services.
  • To detect, investigate, and prevent fraudulent transactions and other illegal activities and protect the rights and property of TeleLeaf and others.
  • To comply with legal obligations.

How We Share Your Information

We do not sell your personal information or PHI. We may share your information in the following circumstances:

With Your Consent: We may share your information with third parties when you give us your consent to do so.

For Treatment, Payment, and Healthcare Operations: As described in the Notice of Privacy Practices section, we may share your PHI with healthcare providers, health plans, and other entities for treatment, payment, and healthcare operations purposes.

With Business Associates: We may share your information with vendors and service providers who perform services on our behalf, such as hosting, data analysis, payment processing, and customer service. These business associates are required to protect your information and use it only for the purposes for which we disclose it to them.

For Legal Reasons: We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court or government agency).

To Protect Rights and Safety: We may disclose your information when we believe it is necessary to investigate, prevent, or take action regarding illegal activities, suspected fraud, situations involving potential threats to the safety of any person, violations of our Terms of Service, or as evidence in litigation in which we are involved.

Business Transfers: If TeleLeaf is involved in a merger, acquisition, or sale of all or a portion of its assets, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our website of any change in ownership or uses of your information.

Data Retention

We retain your PHI for as long as necessary to provide you with our services and as required by law. In general, we retain medical records for a minimum of seven years from the date of the last service, or longer if required by state law. We retain other personal information for as long as necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements.

Data Security

We have implemented appropriate technical and organizational security measures designed to protect the security of any personal information and PHI we process. However, despite our safeguards and efforts to secure your information, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure. We cannot guarantee that unauthorized third parties will never be able to defeat our security measures or use your information for improper purposes.

Our security measures include:

Administrative Safeguards:

  • Security management process with risk analysis and risk management.
  • Assigned security responsibility with a designated security official.
  • Workforce security with authorization and supervision procedures.
  • Information access management with access authorization and establishment.
  • Security awareness and training programs for all workforce members.
  • Security incident procedures for response and reporting.
  • Contingency planning including data backup, disaster recovery, and emergency mode operations.
  • Evaluation of security measures on a regular basis.

Physical Safeguards:

  • Facility access controls with procedures to limit physical access to our systems.
  • Workstation use policies that specify proper functions and physical attributes.
  • Workstation security with physical safeguards for workstations that access PHI.
  • Device and media controls for the receipt, removal, disposal, and re-use of electronic media.

Technical Safeguards:

  • Access controls including unique user identification, emergency access procedures, automatic logoff, and encryption.
  • Audit controls to record and examine activity in systems that contain PHI.
  • Integrity controls to protect PHI from improper alteration or destruction.
  • Transmission security with encryption and integrity controls for PHI transmitted over electronic networks.

Patient Rights Under HIPAA

As described in the Notice of Privacy Practices section, you have specific rights under HIPAA regarding your PHI:

Right to Access Medical Records: You have the right to inspect and obtain a copy of your medical records and billing records that we maintain. To request access, please submit a written request to our Privacy Officer. We will respond to your request within 30 days. We may charge a reasonable, cost-based fee for providing copies.

Right to Request Amendments: If you believe that information in your medical record is incorrect or incomplete, you have the right to request that we amend the information. To request an amendment, please submit a written request to our Privacy Officer that includes the reason for your request. We may deny your request if the information was not created by us, is not part of the records we maintain, is not available for inspection, or is accurate and complete.

Right to an Accounting of Disclosures: You have the right to request an accounting of certain disclosures of your PHI that we have made in the six years prior to your request (or a shorter period if you prefer). To request an accounting, please submit a written request to our Privacy Officer. The first accounting you request within a 12-month period will be free. For additional accountings, we may charge you for the costs of providing the list.

Right to Request Restrictions: You have the right to request a restriction on the PHI we use or disclose about you for treatment, payment, or healthcare operations. You also have the right to request a limit on the PHI we disclose about you to someone who is involved in your care or the payment for your care. To request a restriction, please submit a written request to our Privacy Officer. We are not required to agree to your request unless you are asking us to restrict disclosures to a health plan for payment or healthcare operations purposes and the information pertains solely to a healthcare item or service for which you have paid us in full.

Right to Request Confidential Communications: You have the right to request that we communicate with you about medical matters in a certain way or at a certain location. For example, you can ask that we only contact you at work or by mail. To request confidential communications, please submit a written request to our Privacy Officer. We will accommodate all reasonable requests.

Right to a Paper Copy of This Notice: You have the right to a paper copy of this notice. You may ask us to give you a copy of this notice at any time by contacting our Privacy Officer.

Right to Notification of a Breach: You have the right to be notified in the event of a breach of your unsecured PHI.

California Residents: Your CCPA/CPRA Rights

If you are a California resident, you have specific rights regarding your personal information under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA). Please note that most of the health information we collect is exempt from the CCPA/CPRA because it is protected health information under HIPAA. However, other personal information we collect may be subject to these laws.

Categories of Personal Information We Collect:

  • Identifiers (e.g., name, email address, phone number, IP address)
  • Commercial information (e.g., products or services purchased)
  • Internet or other electronic network activity information (e.g., browsing history, search history)
  • Geolocation data
  • Professional or employment-related information
  • Inferences drawn from other personal information

Your Rights:

  • Right to Know: You have the right to request that we disclose what personal information we collect, use, disclose, and sell about you.
  • Right to Delete: You have the right to request that we delete personal information we have collected from you, subject to certain exceptions.
  • Right to Correct: You have the right to request that we correct inaccurate personal information we maintain about you.
  • Right to Opt-Out: You have the right to opt-out of the sale or sharing of your personal information. We do not sell or share your personal information.
  • Right to Limit Use of Sensitive Personal Information: You have the right to limit our use of your sensitive personal information to certain purposes. We only use sensitive personal information for permitted purposes.
  • Right to Non-Discrimination: You have the right not to receive discriminatory treatment for exercising your CCPA/CPRA rights.

To exercise any of these rights, please contact us at  (504) 264-3123. We will verify your identity before processing your request.

European Residents Your GDPR Rights

If you are a resident of the European Economic Area (EEA) or the United Kingdom (UK), you have certain data protection rights under the General Data Protection Regulation (GDPR).

Legal Basis for Processing:

We process your personal data on the following legal bases:

  • Consent: You have given us explicit consent to process your personal data for specific purposes.
  • Contract: Processing is necessary for the performance of a contract with you.
  • Legal Obligation: Processing is necessary for compliance with a legal obligation.
  • Vital Interests: Processing is necessary to protect your vital interests or those of another person.
  • Public Interest: Processing is necessary for the performance of a task carried out in the public interest.
  • Legitimate Interests: Processing is necessary for our legitimate interests or those of a third party, except where such interests are overridden by your data protection rights.

Your Rights:

  • Right to Access: You have the right to request access to your personal data.
  • Right to Rectification: You have the right to request that we correct inaccurate personal data.
  • Right to Erasure: You have the right to request that we delete your personal data under certain circumstances.
  • Right to Restrict Processing: You have the right to request that we restrict the processing of your personal data under certain circumstances.
  • Right to Data Portability: You have the right to receive your personal data in a structured, commonly used, and machine-readable format.
  • Right to Object: You have the right to object to our processing of your personal data under certain circumstances.
  • Right to Withdraw Consent: You have the right to withdraw your consent at any time where we are relying on consent to process your personal data.
  • Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority.

To exercise any of these rights, please contact us. 

Data Transfers

If we transfer your personal data outside of the EEA or UK, we will ensure that it is protected in a manner consistent with how your personal data will be protected by us in the EEA or UK. This may include using standard contractual clauses approved by the European Commission or ensuring that the recipient is certified under an approved certification mechanism.

Cookies and Tracking Technologies

We use cookies and similar tracking technologies to track activity on our website and hold certain information. Cookies are files with a small amount of data which may include an anonymous unique identifier. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our website.

We use the following types of cookies:

  • Essential Cookies: These cookies are necessary for the website to function properly.
  • Analytics Cookies: These cookies help us understand how visitors interact with our website by collecting and reporting information anonymously.
  • Functionality Cookies: These cookies enable the website to provide enhanced functionality and personalization.
  • Advertising Cookies: These cookies may be set through our site by our advertising partners to build a profile of your interests.

We use third-party service providers such as Google Analytics, Google Tag Manager, and other analytics tools to monitor and analyze the use of our services. For more information about how Google uses data when you use our website, please visit: https://policies.google.com/privacy 

You can opt-out of Google Analytics by installing the Google Analytics opt-out browser add-on available at: https://tools.google.com/dlpage/gaoptout 

Third-Party Links

Our website may contain links to other websites that are not operated by us. If you click on a third-party link, you will be directed to that third party’s site. We strongly advise you to review the privacy policy of every site you visit. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.

Children’s Privacy

Our services are not intended for individuals under the age of 18. We do not knowingly collect personally identifiable information from anyone under the age of 18. If you are a parent or guardian and you are aware that your child has provided us with personal information, please contact us. If we become aware that we have collected personal information from children without verification of parental consent, we take steps to remove that information from our servers.

Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the “Effective Date” at the top of this Privacy Policy. We will also notify you via email or through a prominent notice on our website prior to the change becoming effective. You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.

Contact Us

If you have any questions about this Privacy Policy or our privacy practices, please contact us:

235 Derbigny Street, Suite 201, Gretna, LA 70053

Phone: (504) 264-3123

For HIPAA-related inquiries or to exercise your HIPAA rights:

Contact our Privacy Officer at the address above.

For CCPA/CPRA-related inquiries (California residents):

Contact us (504) 264-3123.

For GDPR-related inquiries (EEA and UK residents):

Contact us (504) 264-3123.

To file a complaint with regulatory authorities:

HIPAA Complaints: U.S. Department of Health and Human Services, Office for Civil Rights

Website: https://www.hhs.gov/hipaa/filing-a-complaint/index.html 

GDPR Complaints: Your local supervisory authority in the EEA or UK

CCPA/CPRA Complaints: California Privacy Protection Agency

  Website: https://cppa.ca.gov 

Acknowledgment of Receipt

By using our services, you acknowledge that you have received and reviewed this Notice of Privacy Practices and Privacy Policy. If you have any questions or need clarification, please contact our Privacy Officer before using our services.

Last Updated: November 5, 2025

© 2025 TeleLeaf Inc. All rights reserved.