Technical Information

Privacy Policy

MyMediFile — operated by E³ Health Technologies, Inc
Effective Date:
 July 21, 2026

Our Commitment  to privacy

At MyMediFile, we believe your health information belongs to you.

Our mission is to help individuals organize, understand, and share their health information with healthcare providers when they choose. We believe healthcare works best when patients arrive with accurate, organized information and providers have the context they need before the visit begins.

Privacy is fundamental to that mission. We are committed to handling your information responsibly, communicating our data practices transparently, and continually improving the safeguards that protect your information.

Our Privacy Principles

Patient Control: You decide what health information you add to MyMediFile and what information you choose to share with healthcare providers.

Transparency : We strive to explain our privacy practices in clear language.

Purpose Limitation : We collect information needed to operate and improve MyMediFile. We do not collect information unrelated to providing our services.

Security : We implement reasonable administrative, technical, and organizational safeguards designed to protect information entrusted to us.

Continuous Improvement : As MyMediFile evolves, we will continue strengthening our privacy practices and update this Privacy Policy when material changes occur.

Introduction

MyMediFile is a patient-controlled health information platform operated by E³ Health Technologies, Inc. (“MyMediFile,” “we,” “us,” or “our”). We are committed to giving individuals meaningful control over the health information they choose to organize and share through the platform

MyMediFile enables patients to organize their health information and share provider-ready summaries with healthcare providers and authorized care teams before appointments. The platform is designed to complement — not replace —existing clinical workflows and electronic medical record systems.

This Privacy Policy explains what information we collect, how we use it, when we share it, and the choices available to you regarding your information. By using MyMediFile, you acknowledge that you have read and understand this Privacy Policy.

What MyMediFile Is Not

MyMediFile is a health information technology platform. MyMediFile does not deliver medical care and is not a hospital, physician practice, health insurance company, pharmacy, or emergency medical service. California law separately deems software designed to maintain medical information a “provider of health care” for medical-confidentiality purposes only; that designation is described in Section 10 and does not mean MyMediFile delivers medical care or has a treatment relationship with you.

MyMediFile does not provide medical advice, diagnose medical conditions, prescribe treatment, or replace the relationship between patients and licensed healthcare professionals. Healthcare decisions should always be made in consultation with qualified healthcare professionals.

1.  Who This Policy Covers

This Privacy Policy applies to:

  • Patients : Who create a MyMediFile account and use the platform to organize and share their health information.
  • Providers and Clinic Ttaff : Who use MyMediFile to review patient summaries and manage intake workflows..
  • Visitors : To mymedifile.org who browse our public website without creating an account.

2.  Information We Collect

2.1  Information You Provide

Patients provide:
  • Name, date of birth, gender, and contact information
  • Medical history, including conditions, medications, allergies, surgeries, and hospitalizations
  • Lab results, imaging reports, discharge summaries, and other uploaded medical documents
  • ‍Symptoms, visit notes, and health updates
  • ‍Insurance information
  • ‍Emergency contact information
Providers and clinic staff provide::
  • Name, role, specialty, and clinic or organization name
  • Work email address
  • Billing information (processed securely by Stripe)

2.2  Platform Activity Information

  • Provider-ready summaries generated from your health information
  • Changes since your last visit, automatically identified by the platform
  • Audit logs of actions taken — including who reviewed, exported, or copied a summary and when
  • Intake link activity — including when a link was sent, opened, and completed

2.3  Artificial Intelligence Features

MyMediFile uses Google Cloud Vertex AI to power the Explain Results feature. AI processing occurs only when you actively choose to use the Explain Results feature.

When you use this feature, the text of the document you select is transmitted to the AI model to generate the explanation. No other profile information, such as your age or sex at birth, is included in the request. Medical documents often contain identifying information — your name, date of birth, medical record number, or your provider’s details — and that information is transmitted as part of the document text. We do not attach your account credentials or other MyMediFile account identifiers to the request.

Our agreement with Google for Vertex AI services includes a Business Associate Agreement (BAA), which contractually requires Google to protect the privacy and security of your health information in accordance with HIPAA. Information processed by Vertex AI is not used to train Google’s general AI models and is protected under the terms of our BAA.

AI-generated explanations:
  • AI-generated explanations:
  • Are generated automatically
  • Are intended for informational purposes only
  • May contain inaccuracies or omissions
  • Do not constitute medical advice
  • Should not be relied upon for diagnosis or treatment decisions

Users should consult qualified healthcare professionals regarding any medical questions or treatment decisions.

2.4  Information Collected Automatically

  • Log data including IP address, browser type, and pages visited
  • Device information
  • Session activity within the platform

MyMediFile does not currently use third-party analytics tools. Platform usage data is derived from our own internal systems.

2.5  Cookies and Similar Technologies

MyMediFile uses cookies and similar technologies necessary for authentication, account security, maintaining user sessions, and supporting core platform functionality.

These technologies are not currently used for third-party advertising or behavioral tracking. Users may configure their browser settings to manage cookies. However, disabling essential cookies may prevent portions of the MyMediFile platform from functioning properly.

2.6  Information from Provider Enquiries

When a healthcare provider or clinic staff member submits an enquiry through our Contact page, we collect: name, work email, role, specialty, clinic or organization name, number of providers, approximate monthly patient volume, a description of their current intake workflow, and any information provided in the optional free-text field. This information is used to evaluate and respond to pilot and partnership enquiries and is retained for 24 months from the date of submission, after which it is deleted.

3.  How We Use Your Information

We collect, use, and retain only the information reasonably necessary to operate, secure, improve, and provide the MyMediFile platform and the services requested by our users.

We use your information to:
  • Provide and operate the MyMediFile platform
  • Generate provider-ready summaries from your health information
  • Send intake links, account notifications, security notifications, and other service-related communications
  • Enable providers and clinical staff to review your health summary before visits
  • Process provider billing through Stripe
  • Maintain audit logs and records of platform activity
  • Improve platform functionality and reliability
  • Communicate with you about your account, updates, and support
  • ‍Comply with legal obligations, including responding to lawful requests from government authorities

We do not use your health information for advertising purposes. We do not sell your health information to third parties. We do not share your health information with advertisers.

 4.  How We Share Your Information

4.1   With Your Care Team

When you use MyMediFile through a clinic, your provider-ready summary is shared with the clinical staff at that clinic.

You control what information is included in your shared health summary. Healthcare providers receive only the information you choose to share through MyMediFile or that is otherwise made available as described in this Privacy Policy. A provider’s previous access to your information does not automatically provide ongoing access to future updates unless you choose to share additional information or another lawful basis for access applies.

4.2  With Service Providers

We work with trusted third-party service providers to operate the platform. These providers process your data only as directed by us and are bound by confidentiality obligations.

Current service providers:
Provider
• Supabase
• Supabase
• AWS Textract
• Google’s Gemini AI services
• Resend
• Stripe
• AWS
• Calendly
Purpose
Authentication and database storage
File storage
Document OCR — text extraction from uploaded files
AI-powered Explain Results feature
Transactional email — intake links, notifications
Provider billing and payment processing
Platform hosting and infrastructure
Demo scheduling for provider inquiries
Data Involved
Account credentials, health records
Uploaded medical documents
Uploaded medical documents
Selected document content, which may include identifiers printed on the document
Email address, notification content
Provider payment information
All platform data
Name, email, scheduling preferences

4.3  Legal Requirements

We may disclose your information if required by law, court order, or government authority, or if we believe disclosure is necessary to protect the rights, property, or safety of MyMediFile, our users, or others.

4.4  Business Transfers

If MyMediFile is acquired, merged, or sold, your information may be transferred as part of that transaction. Where required by applicable law, we will provide notice before any material changes affecting the handling of your personal information become effective.

5.  Health Information & HIPAA

MyMediFile is designed to help individuals securely organize and share health information. We use cloud infrastructure and security practices intended to help protect sensitive information stored within the platform

The Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) is a federal law that governs the privacy and security of Protected Health Information (“PHI”). MyMediFile’s role under HIPAA depends on how the platform is used.

When you use the platform for personal use:

When you create an account and upload your own health information for personal storage and management, MyMediFile is not acting as a “Business Associate” under HIPAA. That information is not PHI governed by HIPAA, because you are the one creating, storing, and controlling it. Instead, it is protected by other laws, including the Federal Trade Commission Act and the FTC’s Health Breach Notification Rule, as well as applicable state laws.

When your healthcare provider uses the platform:

If your healthcare provider (a “Covered Entity” under HIPAA) uses our platform to manage or share information with you, or if we onboard a clinic or other healthcare organization, MyMediFile is acting as a “Business Associate” to that provider. In that capacity we are required by law to have a Business Associate Agreement (BAA) in place with the provider, and we must protect the privacy and security of your PHI in accordance with HIPAA

6.  Data Storage & Security

MyMediFile currently utilizes Amazon Web Services (AWS) infrastructure to store and process platform data. The following protections are in place:

  • Encryption in transit using TLS
  • Encryption at rest for stored files and records
  • Role-based access controls
  • Authentication safeguards
  • Security monitoring
  • Routine infrastructure updates where appropriate
  • Audit logging of all significant platform actions

Users are responsible for maintaining the confidentiality of their account credentials and should promptly notify MyMediFile if they believe their account has been accessed without authorization.

Our specific notification obligations depend on the type of data involved:

For non-HIPAA health information : If a breach involves health information you manage for personal use, we will notify you and the Federal Trade Commission (FTC) in accordance with the FTC’s Health Breach Notification Rule. That rule requires notice without unreasonable delay and in no case later than 60 calendar days after discovery of a breach. For breaches affecting 500 or more individuals, we will also notify the media

For PHI governed by HIPAA :  If a breach involves PHI that we manage on behalf of your healthcare provider, we will notify the provider in accordance with our Business Associate Agreement and HIPAA. Your provider is then responsible for notifying you.

For California residents : If a breach involves personal information of California residents — including medical information or other data elements covered by California Civil Code § 1798.82 — we will notify affected California residents within 30 calendar days of discovery, as required by California law, except where delay is permitted to accommodate the legitimate needs of law enforcement or as necessary to determine the scope of the breach and restore the integrity of our systems. For breaches affecting more than 500 California residents, we will also
electronically submit a sample copy of the breach notification to the California Attorney General within 15 calendar days of notifying affected residents.

7.  Data Retention

We retain your health information for as long as your account is active or as needed to provide the services you have requested. When you delete your account, we delete or de-identify your personal and health information, except where we are required to retain certain information to comply with law, resolve disputes, enforce our agreements, or maintain the security and integrity of the platform

Deletion occurs in two stages:

Active system deletion : Your account and associated data are deleted from our active production systems within 30 days of your request.

We may retain anonymized or aggregated data indefinitely for research and service improvement purposes

Legal retention exceptions

To meet our legal and compliance obligations, we must retain certain records for longer than the 30-day and 90-day schedules described above. Specifically, the authorization you provide for the “Explain Results” feature is retained to comply with our obligations under state and federal law, including 45 CFR § 164.530(j) and the California Confidentiality of Medical Information Act (CMIA).

This authorization record is retained for a minimum of six (6) years from the date it was created or the date it was last in effect, whichever is later. The retained record includes only a version identifier corresponding to the authorization text you agreed to, your user ID, and a timestamp of your authorization. It does not include your medical documents or other health information, which are deleted according to the schedule described above.

8.  Your Rights & Choices

You have the right to:
  • Access : Your health information stored in MyMediFile at any time through your account
  • Update or Correct : Your information at any time
  • Delete : Your account and request deletion of your data
  • Download : Available copies of your health information through features made available within the MyMediFile platform
  • Control : What information is shared with your clinic
  • Withdraw Consent : For AI-powered features at any time

Depending on your location and applicable law, you may also have additional privacy rights.

To exercise any of these rights, contact us at privacy@mymedifile.org.

9.  California Privacy Rights

If you are a California resident, you have additional rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), and protections under the California Confidentiality of Medical Information Act (CMIA).

Sensitive personal information

The health information you provide to MyMediFile — including medical history, conditions, medications, and lab and imaging results — is treated as sensitive personal information under California law. We use this information only to provide the services you request and for the purposes described in this Privacy Policy. We do not use it to infer characteristics about you, and we do not use or disclose it beyond what is necessary to operate the platform.

Your California rights

Subject to certain exceptions, you have the right to:

  • Know and access the personal information we have collected about you Correct inaccurate personal information
  • Delete your personal information
  • Limit our use and disclosure of your sensitive personal informatio
  • Opt out of the sale or sharing of your personal information
  • Not receive discriminatory treatment for exercising any of these rights

10.  Categories of personal information collected

We collect the following categories of personal information:

Category
A.  Identifiers
B.  Personal information categories listed in the California   Customer Records statute
C.  Protected classification characteristics under California or federal law
D.  Internet or other similar network activity
E.  Professional or employment-related information
F.  Sensitive personal information
Examples
Name, email address, IP addre
Name, contact information, payment information
Age, date of birth, sex at birth (optional, provided through profile settings)
IP address, browser user agent, session and interaction data within our platform
Role, specialty, clinic or organization name, number of providers, approximate monthly patient volume, intake workflow description
Health information, account login credentials

We do not sell or share your personal information

MyMediFile does not sell your personal information, and does not share it for cross-context behavioral advertising, as those terms are defined under California law.

Confidentiality of Medical Information Act (CMIA)

Under California law, the Confidentiality of Medical Information Act (CMIA) protects the confidentiality of medical information. Because MyMediFile offers software designed to maintain medical information and make it available to individuals and their healthcare providers, MyMediFile is deemed a “provider of health care” under CMIA (Cal. Civ. Code § 56.06(b)) and is subject to CMIA’s confidentiality requirements. This designation under California law is distinct from MyMediFile’s status under federal HIPAA, which depends on whether MyMediFile is acting as a business associate to a covered provider in a given workflow.

We will not disclose your medical information to any third party without your authorization, except as permitted or required by law. We are committed to maintaining the confidentiality of your medical information consistent with CMIA’s requirements.

The MyMediFile platform currently operates solely as a patient-controlled tool. When we onboard healthcare providers and clinics in the future, additional CMIA requirements may apply, including obligations related to sensitive services information (such as reproductive health or gender-affirming care) under Cal. Civ. Code § 56.06(c). At that time, we will work with our provider customers to implement appropriate access controls and information segregation capabilities for sensitive services as required by CMIA.

How to exercise your rights

Submit a request to privacy@mymedifile.org. We will verify your identity before acting on requests to know, delete, or correct. You may use an authorized agent to submit a request on your behalf; we may require the agent to demonstrate authority to act for you. We will respond within 45 days, which may be extended where permitted by California law. We will not discriminate against you for exercising your rights.

11.  Children’s Privacy

MyMediFile does not offer accounts to individuals under 18. A parent or legal guardian may use their own MyMediFile account to organize and manage the health information of a minor in their care. By doing so, the account holder represents that they are the minor’s parent or legal guardian and have the legal authority to access, manage, and share that information.

We do not knowingly allow individuals under 18 to create their own accounts. We collect date of birth at registration to enforce this requirement. If you believe a minor has created an account without appropriate guardian oversight, contact us at privacy@mymedifile.org and we will take appropriate steps to address it.

California minors: Consistent with the CPRA, we do not “sell” or “share” the personal information of any user, including those we know to be under 16 years of age.

12.  Analytics and Tracking

MyMediFile does not currently use third-party analytics tools such as Google Analytics,

PostHog, or similar services. We do not track your activity across other websites. Platform usage data is derived from our own internal systems only.

If MyMediFile introduces third-party analytics in the future, this Privacy Policy will be updated before those services are implemented.

13.  International Users

MyMediFile is operated from the United States, and our services are hosted in the United State

If you access the platform from outside the United States, you understand that your information may be transferred to, stored, and processed in the United States, where privacy laws may differ from those in your country of residence.

By using MyMediFile, you consent to these transfers where permitted by applicable law.

14.  Third-Party Links

Our website may contain links to third-party websites. We are not responsible for the privacy practices of those websites and encourage you to review their privacy policies independently.

15.  Governing Law

Any dispute arising from or related to this Privacy Policy or our privacy practices will be governed by and construed in accordance with the laws of the State of California, without regard to its conflict of law principles.

16.  Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a notice on the platform. Your continued use of MyMediFile following the effective date of an updated Privacy Policy constitutes acknowledgment of the revised policy to the extent permitted by applicable law.

17.  Contact Us

If you have questions about this Privacy Policy or how we handle your data, contact us at:

•  MyMediFile, operated by E³ Health Technologies, Inc.

•  Privacy inquiries :  privacy@mymedifile.org

•  General support :  support@mymedifile.org

•  Legal & Terms :  legal@mymedifile.org

• Website : https://www.mymedifile.org

We encourage users to contact us with any questions about this Privacy Policy or our privacy practices before using the platform.

Closing Statement

Thank you for trusting MyMediFile with your health information.

We recognize the responsibility that comes with helping individuals organize and share sensitive medical information, and we are committed to continually earning that trust through transparency, security, and responsible stewardship of your data.