Get Your Medical Marijuana Card Today - Fast & Easy!

Effective Date: November 5, 2025
TeleLeaf (“TeleLeaf,” “we,” “us,” or “our”) is dedicated to maintaining the privacy and integrity of your personal and protected health information (PHI). We are required by law to maintain the privacy of your health information and to provide you with this notice of our legal duties and privacy practices. This Notice of Privacy Practices and Privacy Policy (“Notice”) describes how we may use and disclose your information and your rights regarding that information. It applies to all services provided by TeleLeaf, including our telehealth platform, website, and any other interactions you have with us.
We are committed to complying with all applicable federal and state laws, including the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the Health Information Technology for Economic and Clinical Health (HITECH) Act, substance use disorder confidentiality regulations (42 CFR Part 2), the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), and the General Data Protection Regulation (GDPR).
THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.
You have the following rights regarding the PHI we maintain about you:
Right to Inspect and Copy: You have the right to inspect and obtain a copy of your health and billing records. We may charge a reasonable, cost-based fee for copies.
Right to Request Amendments: If you believe that information in your record is incorrect or incomplete, you have the right to request an amendment. We may deny your request under certain circumstances, but we will provide you with a written explanation.
Right to an Accounting of Disclosures: You have the right to receive a list of certain disclosures we have made of your PHI. This right does not apply to disclosures for treatment, payment, healthcare operations, or certain other exceptions.
Right to Request Restrictions: You have the right to request a restriction on how we use or disclose your PHI for treatment, payment, or healthcare operations. We are not required to agree to your request, but we will consider it. However, if you pay for a service or health care item out-of-pocket in full, you can ask us not to share that information for the purpose of payment or our operations with your health insurer.
Right to Request Confidential Communications: You have the right to request that we communicate with you about medical matters in a certain way or at a certain location.
Right to a Paper Copy of This Notice: You have the right to a paper copy of this notice at any time.
We may use and disclose your PHI for the following purposes:
Treatment: We will use your health information to provide you with medical treatment or services, such as consulting with physicians and other healthcare providers involved in your care.
Payment: We may use and disclose your health information to bill and collect payment from you, your health plan, or a third party.
Healthcare Operations: We may use and disclose your health information for our business operations, such as quality assessment, employee training, and compliance activities.
We may also use or disclose your PHI without your authorization for the following purposes:
As Required by Law: We will disclose your PHI when required to do so by federal, state, or local law.
Public Health Activities: We may disclose your PHI for public health activities, such as to prevent or control disease, injury, or disability.
Health Oversight Activities: We may disclose PHI to a health oversight agency for activities authorized by law, such as audits, investigations, and inspections.
Lawsuits and Disputes: If you are involved in a lawsuit or a dispute, we may disclose your PHI in response to a court or administrative order.
Law Enforcement: We may release PHI if asked to do so by a law enforcement official in response to a court order, subpoena, warrant, summons, or similar process.
We reserve the right to change this notice and our privacy practices. We will post a copy of the current notice on our website with the effective date.
If you believe your privacy rights have been violated, you may file a complaint with us by contacting us at the address below. You may also file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights.Â
Contact Information:
235 Derbigny Street, Suite 201, Gretna, LA 70053
(504) 264-3123
For individuals receiving treatment or assessment for substance use disorder (SUD), federal law (42 CFR Part 2) provides special protection for your treatment records.Â
In general, we may not say to a person outside the program that you attend the program, or disclose any information identifying you as an alcohol or drug abuser, or disclose any other protected information except with your specific written consent.
Exceptions to this rule include:
Violation of these regulations is a crime, and suspected violations may be reported to the United States Attorney in the district where the violation occurs.
If you are a resident of the EEA or UK, you have certain data protection rights under the General Data Protection Regulation (GDPR). TeleLeaf is committed to ensuring that your rights are protected. These rights include the right to access, correct, update, or request deletion of your personal information.
The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), provides California residents with specific rights regarding their personal information. While most of the health information we collect is exempt from the CCPA/CPRA because it is protected by HIPAA, other personal information we collect may be subject to these laws. You have the right to know what personal information is being collected about you, to request that we delete your personal information, and to opt-out of the sale or sharing of your personal information.
We take special care to protect your privacy in the context of our telehealth services. This includes:
We have implemented administrative, physical, and technical safeguards to protect your PHI from unauthorized access, use, or disclosure. These safeguards include employee training, facility security, and technical measures such as encryption and access controls.
In the unlikely event of a breach of your unsecured PHI, we will notify you and the Department of Health and Human Services as required by the HITECH Act.
We will make reasonable efforts to use, disclose, and request only the minimum amount of PHI needed to accomplish the intended purpose of the use, disclosure, or request.
We enter into Business Associate Agreements (BAAs) with third-party vendors who perform services on our behalf and have access to your PHI.Â
These agreements require our business associates to:
Our business associates may include video conferencing platforms, electronic health record vendors, billing and payment processors, cloud storage providers, email and messaging services, and other technology service providers.
We collect several types of information from and about users of our services, including:
Protected Health Information (PHI): This includes information that identifies you and relates to your past, present, or future physical or mental health condition, the provision of healthcare to you, or payment for healthcare. Examples include your name, address, date of birth, Social Security number, medical history, diagnoses, treatment information, and billing information.
Personal Information: This includes information that identifies you but is not health-related, such as your email address, phone number, and payment information.
Technical Information: We automatically collect certain information when you use our website and services, including your IP address, browser type, operating system, access times, and the pages you have viewed.
Usage Information: We collect information about how you use our services, such as the features you use, the pages you visit, and the actions you take.
In addition to the uses described in the Notice of Privacy Practices section above, we may use your information for the following purposes:
We do not sell your personal information or PHI. We may share your information in the following circumstances:
With Your Consent: We may share your information with third parties when you give us your consent to do so.
For Treatment, Payment, and Healthcare Operations: As described in the Notice of Privacy Practices section, we may share your PHI with healthcare providers, health plans, and other entities for treatment, payment, and healthcare operations purposes.
With Business Associates: We may share your information with vendors and service providers who perform services on our behalf, such as hosting, data analysis, payment processing, and customer service. These business associates are required to protect your information and use it only for the purposes for which we disclose it to them.
For Legal Reasons: We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court or government agency).
To Protect Rights and Safety: We may disclose your information when we believe it is necessary to investigate, prevent, or take action regarding illegal activities, suspected fraud, situations involving potential threats to the safety of any person, violations of our Terms of Service, or as evidence in litigation in which we are involved.
Business Transfers: If TeleLeaf is involved in a merger, acquisition, or sale of all or a portion of its assets, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our website of any change in ownership or uses of your information.
We retain your PHI for as long as necessary to provide you with our services and as required by law. In general, we retain medical records for a minimum of seven years from the date of the last service, or longer if required by state law. We retain other personal information for as long as necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements.
We have implemented appropriate technical and organizational security measures designed to protect the security of any personal information and PHI we process. However, despite our safeguards and efforts to secure your information, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure. We cannot guarantee that unauthorized third parties will never be able to defeat our security measures or use your information for improper purposes.
Our security measures include:
Administrative Safeguards:
Physical Safeguards:
Technical Safeguards:
As described in the Notice of Privacy Practices section, you have specific rights under HIPAA regarding your PHI:
Right to Access Medical Records: You have the right to inspect and obtain a copy of your medical records and billing records that we maintain. To request access, please submit a written request to our Privacy Officer. We will respond to your request within 30 days. We may charge a reasonable, cost-based fee for providing copies.
Right to Request Amendments: If you believe that information in your medical record is incorrect or incomplete, you have the right to request that we amend the information. To request an amendment, please submit a written request to our Privacy Officer that includes the reason for your request. We may deny your request if the information was not created by us, is not part of the records we maintain, is not available for inspection, or is accurate and complete.
Right to an Accounting of Disclosures: You have the right to request an accounting of certain disclosures of your PHI that we have made in the six years prior to your request (or a shorter period if you prefer). To request an accounting, please submit a written request to our Privacy Officer. The first accounting you request within a 12-month period will be free. For additional accountings, we may charge you for the costs of providing the list.
Right to Request Restrictions: You have the right to request a restriction on the PHI we use or disclose about you for treatment, payment, or healthcare operations. You also have the right to request a limit on the PHI we disclose about you to someone who is involved in your care or the payment for your care. To request a restriction, please submit a written request to our Privacy Officer. We are not required to agree to your request unless you are asking us to restrict disclosures to a health plan for payment or healthcare operations purposes and the information pertains solely to a healthcare item or service for which you have paid us in full.
Right to Request Confidential Communications: You have the right to request that we communicate with you about medical matters in a certain way or at a certain location. For example, you can ask that we only contact you at work or by mail. To request confidential communications, please submit a written request to our Privacy Officer. We will accommodate all reasonable requests.
Right to a Paper Copy of This Notice: You have the right to a paper copy of this notice. You may ask us to give you a copy of this notice at any time by contacting our Privacy Officer.
Right to Notification of a Breach: You have the right to be notified in the event of a breach of your unsecured PHI.
If you are a California resident, you have specific rights regarding your personal information under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA). Please note that most of the health information we collect is exempt from the CCPA/CPRA because it is protected health information under HIPAA. However, other personal information we collect may be subject to these laws.
Categories of Personal Information We Collect:
Your Rights:
To exercise any of these rights, please contact us at (504) 264-3123. We will verify your identity before processing your request.
If you are a resident of the European Economic Area (EEA) or the United Kingdom (UK), you have certain data protection rights under the General Data Protection Regulation (GDPR).
Legal Basis for Processing:
We process your personal data on the following legal bases:
Your Rights:
To exercise any of these rights, please contact us.Â
If we transfer your personal data outside of the EEA or UK, we will ensure that it is protected in a manner consistent with how your personal data will be protected by us in the EEA or UK. This may include using standard contractual clauses approved by the European Commission or ensuring that the recipient is certified under an approved certification mechanism.
We use cookies and similar tracking technologies to track activity on our website and hold certain information. Cookies are files with a small amount of data which may include an anonymous unique identifier. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our website.
We use the following types of cookies:
We use third-party service providers such as Google Analytics, Google Tag Manager, and other analytics tools to monitor and analyze the use of our services. For more information about how Google uses data when you use our website, please visit: https://policies.google.com/privacyÂ
You can opt-out of Google Analytics by installing the Google Analytics opt-out browser add-on available at: https://tools.google.com/dlpage/gaoptoutÂ
Our website may contain links to other websites that are not operated by us. If you click on a third-party link, you will be directed to that third party’s site. We strongly advise you to review the privacy policy of every site you visit. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.
Our services are not intended for individuals under the age of 18. We do not knowingly collect personally identifiable information from anyone under the age of 18. If you are a parent or guardian and you are aware that your child has provided us with personal information, please contact us. If we become aware that we have collected personal information from children without verification of parental consent, we take steps to remove that information from our servers.
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the “Effective Date” at the top of this Privacy Policy. We will also notify you via email or through a prominent notice on our website prior to the change becoming effective. You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
If you have any questions about this Privacy Policy or our privacy practices, please contact us:
235 Derbigny Street, Suite 201, Gretna, LA 70053
Phone: (504) 264-3123
For HIPAA-related inquiries or to exercise your HIPAA rights:
Contact our Privacy Officer at the address above.
For CCPA/CPRA-related inquiries (California residents):
Contact us (504) 264-3123.
For GDPR-related inquiries (EEA and UK residents):
Contact us (504) 264-3123.
To file a complaint with regulatory authorities:
HIPAA Complaints: U.S. Department of Health and Human Services, Office for Civil Rights
Website: https://www.hhs.gov/hipaa/filing-a-complaint/index.htmlÂ
GDPR Complaints: Your local supervisory authority in the EEA or UK
CCPA/CPRA Complaints: California Privacy Protection Agency
  Website: https://cppa.ca.govÂ
By using our services, you acknowledge that you have received and reviewed this Notice of Privacy Practices and Privacy Policy. If you have any questions or need clarification, please contact our Privacy Officer before using our services.
—
Last Updated: November 5, 2025
© 2025 TeleLeaf Inc. All rights reserved.