Privacy Policy
Document Version: 2.1
Effective Date: September 8, 2026
Last Updated: September 8, 2026
PepMed ("PepMed," "we," "our," or "us") respects your privacy and is committed to protecting the personal and health information you share with us.
This Privacy Policy explains how we collect, use, disclose, store, and safeguard information when you visit our Website, create or use a PepMed account or patient portal, communicate with us, receive communications from us, connect a wearable device or health-data service, participate in telehealth or healthcare services, purchase products or services, or otherwise interact with PepMed.
PepMed believes that privacy, transparency, and trust are fundamental to healthcare and wellness services. We are committed to handling personal information responsibly and in accordance with applicable privacy and healthcare laws.
Certain information collected or maintained in connection with healthcare services may constitute Protected Health Information ("PHI") under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA").
HIPAA Notice of Privacy Practices
If you are a PepMed patient, please review our Notice of Privacy Practices, which describes in greater detail how PHI may be used and disclosed and explains your rights regarding PHI.
Where this Privacy Policy and the Notice of Privacy Practices both apply to PHI, the Notice of Privacy Practices controls to the extent required by applicable healthcare privacy law.
Acceptance of or use of services subject to this Privacy Policy does not constitute a HIPAA authorization for uses or disclosures of PHI that otherwise require separate authorization under applicable law.
1. Purpose
The purpose of this Privacy Policy is to explain:
What information PepMed collects.
How information is collected.
Why we collect information.
How we use information.
How information may be disclosed.
How health and healthcare information is handled.
How wearable and connected health information is handled.
How communications such as email and text messages are handled.
How prescription, pharmacy, laboratory, fulfillment, payment, and delivery information may be handled.
How Website technologies, cookies, and analytics are used.
How we protect information.
How long information may be retained.
The choices and privacy rights that may be available to you.
2. Scope of This Privacy Policy
This Privacy Policy applies to interactions with PepMed, including through:
PepMed websites and webpages.
PepMed patient portals and digital services.
Account registration and patient onboarding.
Contact forms.
Email subscriptions and communications.
SMS and text-message communications.
Waitlist and service-availability registration.
Telehealth and healthcare services.
Wearable-device and health-data integrations.
Prescription and pharmacy-related services.
Laboratory services.
Supplements and wellness products.
Medication fulfillment and delivery coordination.
Payment and transaction processing.
Educational and informational content.
Other online or offline interactions with PepMed.
Visiting PepMed's public Website, reading educational content, joining a waitlist, subscribing to general updates, or submitting a general contact form does not by itself create a provider-patient relationship.
A provider-patient relationship may be established only through the applicable patient onboarding and clinical process.
3. Definitions
"PepMed," "we," "our," or "us" means PepMed and the business operating the PepMed Website and services, including authorized healthcare providers and service providers where applicable.
"Website" means PepMed's websites, webpages, content, forms, and related online properties.
"Services" means PepMed's informational, digital, healthcare, telehealth, wellness, communication, patient-portal, and related services.
"Personal Information" means information that identifies, relates to, describes, or can reasonably be linked to an identifiable individual or household, as defined by applicable law.
"Health Information" means information relating to an individual's health, wellness, fitness, physical characteristics, activity, sleep, physiological measurements, medications, treatment, or healthcare.
"Protected Health Information" or "PHI" has the meaning assigned under HIPAA and its implementing regulations.
"Wearable Data" means health, wellness, fitness, activity, sleep, physiological, or related information obtained from a wearable device, health application, connected service, or health-data platform at the user's direction.
"Patient Portal" means the digital platform through which eligible PepMed patients may access or interact with PepMed healthcare services.
"User," "you," or "your" means an individual who interacts with PepMed or uses the Services.
4. Information We Collect
The information PepMed collects depends on how you interact with us.
A. Information You Provide Directly
We may collect information such as:
First and last name.
Email address.
Telephone number.
Mailing or delivery address.
State of residence.
Date of birth or age information.
Account information.
Communication preferences.
Interests and wellness goals.
Information submitted through forms or messages.
Information submitted during patient registration or onboarding.
Information provided during healthcare interactions.
Information necessary to coordinate prescriptions, pharmacy services, laboratory services, supplements, or medication delivery.
Billing or transaction-related information.
Other information you voluntarily provide.
B. Health and Healthcare Information
If you become a PepMed patient or use healthcare services, PepMed and healthcare providers involved in your care may collect information necessary to provide care, including information regarding:
Medical history.
Current and previous health conditions.
Medications and supplements.
Allergies.
Laboratory results.
Vital signs and measurements.
Symptoms.
Diagnoses.
Treatment plans.
Prescriptions.
Healthcare-provider interactions.
Telehealth encounters.
Clinical notes.
Patient-reported outcomes.
Other information relevant to your care.
Health information that constitutes PHI is handled in accordance with applicable healthcare privacy laws and PepMed's Notice of Privacy Practices.
C. Wearable and Connected Health Data
PepMed may allow you to voluntarily connect compatible wearable devices, health applications, or health-data services to your PepMed account.
Depending on the device, service, permissions you grant, and features available, this may include integrations involving:
Apple Health and Apple HealthKit.
Google Health Connect or other compatible Google health services.
Fitbit.
Oura.
WHOOP.
Other compatible health or wearable platforms that PepMed may support.
Depending on your authorization, Wearable Data may include categories such as:
Steps and physical activity.
Exercise and workout information.
Heart rate and heart-rate trends.
Resting heart rate.
Heart-rate variability.
Sleep duration, stages, timing, and related measurements.
Respiratory measurements.
Blood oxygen or oxygen-saturation information.
Temperature-related measurements.
Weight and body measurements.
Calories or energy expenditure.
Recovery, readiness, strain, or similar scores provided by connected platforms.
Fitness and activity trends.
Other health or wellness measurements that you expressly authorize PepMed to access.
The specific information available varies by platform and by the permissions you choose to grant.
Connecting a wearable or health-data account is voluntary unless otherwise expressly disclosed for a particular PepMed service.
PepMed will request access only to data categories reasonably related to features or healthcare services we provide. You control permissions available through the applicable device or third-party platform and may be able to modify or revoke those permissions through that platform.
Revoking access may prevent PepMed from receiving new data. Information previously received may be retained where reasonably necessary to provide healthcare, maintain legally required medical or business records, comply with applicable law, or as otherwise described in this Privacy Policy or our Notice of Privacy Practices.
PepMed does not sell Wearable Data.
PepMed does not use Wearable Data obtained through Apple HealthKit, Google Health Connect, Fitbit, Oura, WHOOP, or similar health integrations for third-party advertising, targeted advertising, or data-broker purposes.
Wearable Data may be used for purposes associated with providing, supporting, personalizing, monitoring, or improving health, wellness, and healthcare services for the applicable user, as permitted by the user's authorization and applicable law.
D. Communications Information
When you communicate with PepMed or receive communications from us, we may collect and maintain information including:
Email address.
Mobile telephone number.
Communication preferences.
Date and time communications were sent or received.
Delivery status.
Opt-in and opt-out status.
Consent records.
Message metadata.
Communications between you and PepMed where appropriate.
E. Prescription and Pharmacy Information
When a licensed healthcare provider determines that a prescription is medically appropriate, information necessary to issue, transmit, process, dispense, fulfill, or coordinate a prescription may be shared with or processed by authorized healthcare technology providers, pharmacies, and related service providers.
This information may include:
Patient identifying information.
Contact information.
Prescription information.
Prescriber information.
Pharmacy information.
Medication name, strength, dosage, quantity, and instructions.
Information reasonably necessary for prescription processing and dispensing.
PepMed may use electronic-prescribing infrastructure, including Surescripts or other authorized networks, to facilitate electronic transmission of prescription information.
F. Laboratory Information
Where laboratory testing is ordered or coordinated through PepMed, PepMed, healthcare providers, laboratories, and service providers may process information reasonably necessary to order, coordinate, perform, bill for, or report laboratory testing.
This may include:
Patient identifying information.
Contact information.
Provider and order information.
Test information.
Specimen information.
Laboratory results.
Payment or transaction information where applicable.
Other information reasonably necessary for laboratory services.
Clinical laboratory information that constitutes PHI is subject to applicable healthcare privacy requirements.
G. Medication Fulfillment and Delivery Information
When medication or another healthcare product is shipped to you, PepMed, a dispensing pharmacy, fulfillment provider, or delivery provider may process information necessary to fulfill and deliver the shipment.
This may include:
Your name.
Shipping address.
Telephone number or email address where necessary for delivery.
Shipment information.
Tracking information.
Delivery status.
Delivery instructions.
Signature information where applicable.
A dispensing pharmacy may use UPS Healthcare or another qualified delivery or logistics provider to deliver medication to a patient's designated address.
Only information reasonably necessary to coordinate and complete the applicable shipment should be provided to delivery and logistics providers.
H. Payment and Transaction Information
PepMed may collect payments for PepMed services and for certain healthcare-related products or services fulfilled or performed by third parties, including pharmacies, laboratories, supplement suppliers, or other service providers.
This centralized payment structure may reduce the need for patients to establish separate payment relationships or provide payment credentials to multiple parties involved in their care.
Payment and transaction information may include:
Name.
Billing information.
Transaction amount.
Transaction date and status.
Products or services purchased.
Payment-method information processed through an applicable payment processor.
Refund, credit, or dispute information.
Other information reasonably necessary to process or administer a transaction.
PepMed may use third-party payment processors to securely process transactions.
Payment processors may independently receive information necessary to process, authenticate, prevent fraud, or administer payments in accordance with their applicable role, contractual obligations, and privacy practices.
PepMed seeks to limit payment-related information shared with other parties to information reasonably necessary for the applicable transaction, administrative purpose, or legal requirement.
I. Website and Technical Information
When you use PepMed's Website or digital services, PepMed and its service providers may process technical information such as:
Browser and device information.
Operating system.
IP address.
Website and page interactions.
Referring information.
Approximate location derived from technical information.
Date and time information.
Website performance information.
Security and diagnostic information.
Cookies or similar technologies.
Please review PepMed's Cookie Policy for additional information.
5. Public Website Information and Clinical Information
PepMed distinguishes between information collected through its public-facing Website and marketing services and information collected or maintained in connection with healthcare and clinical services.
Information submitted through public Website forms, waitlists, newsletters, service-availability forms, or general informational interactions may not constitute PHI merely because it relates generally to health or wellness.
Information collected or maintained in connection with healthcare services may constitute PHI and, where applicable, is subject to HIPAA and PepMed's Notice of Privacy Practices.
PepMed seeks to maintain appropriate separation between public-facing marketing activities and systems or environments containing PHI.
PepMed does not knowingly use PHI obtained through authenticated patient-portal or clinical areas for targeted advertising or provide such PHI to advertising platforms or data brokers for their independent advertising purposes.
6. How We Use Information
PepMed may use information to:
Provide healthcare and telehealth services.
Facilitate patient registration and onboarding.
Maintain patient accounts.
Schedule and manage appointments.
Send appointment reminders.
Communicate regarding patient care or services.
Provide patient-portal functionality.
Assist healthcare providers in evaluating health and wellness information.
Display or analyze wearable and connected health information for the user.
Monitor health, wellness, activity, or treatment trends where appropriate.
Facilitate prescriptions and electronic prescribing.
Coordinate with pharmacies.
Coordinate laboratory services.
Facilitate medication fulfillment and delivery.
Process payments and administer transactions.
Coordinate payments for third-party healthcare products or services.
Send transactional email and SMS communications.
Respond to inquiries.
Provide requested educational or informational communications.
Manage marketing preferences.
Operate and improve PepMed's services.
Maintain security.
Detect fraud or misuse.
Maintain required healthcare and business records.
Comply with legal and regulatory requirements.
Establish, exercise, or defend legal rights.
We may use information for additional purposes disclosed at the time of collection or with your authorization where required.
7. SMS and Text Messaging
PepMed may use SMS or other text messaging to communicate with users and patients who provide an eligible mobile telephone number and consent to receive applicable communications.
Messages may include:
Appointment confirmations.
Appointment reminders.
Scheduling updates.
Account or service notifications.
Verification or security messages.
Prescription or pharmacy-related status notifications where appropriate.
Delivery-related notifications.
Other transactional or healthcare-service communications.
Marketing or promotional messages only where separately authorized as required by applicable law.
PepMed may use Twilio or another communications provider to facilitate text-message delivery.
By providing your mobile number and opting into an applicable PepMed text-messaging program, you authorize PepMed and its service providers to send communications described in the applicable consent disclosure.
Message frequency may vary. Message and data rates may apply.
You may opt out of applicable text messages at any time by replying STOP. You may reply HELP for assistance where supported or contact PepMed directly.
Consent to receive marketing text messages is not a condition of purchasing goods or healthcare services from PepMed.
Opting out of optional SMS communications may limit PepMed's ability to provide certain text-based reminders or notifications but will not prevent PepMed from communicating through other appropriate channels when reasonably necessary.
Wireless carriers are not liable for delayed or undelivered messages.
PepMed maintains records of messaging consent and opt-out preferences as reasonably necessary to comply with applicable law and communications requirements.
Mobile opt-in information and consent will not be sold, rented, or shared with third parties for their own marketing or promotional purposes.
8. Email Communications
PepMed may send email communications including:
Appointment confirmations and reminders.
Account and security notifications.
Patient-service communications.
Requested educational content.
PepTalk articles.
Service announcements.
Prescription, pharmacy, laboratory, or delivery-related notifications where appropriate.
Marketing communications where authorized.
PepMed may use Twilio SendGrid or another email-delivery provider to facilitate email communications.
Marketing emails will include an appropriate method to unsubscribe where required.
Unsubscribing from marketing emails does not prevent PepMed from sending transactional, healthcare, account, security, legal, or other non-marketing communications reasonably necessary to provide requested services.
Where a communication contains PHI, PepMed handles the communication in accordance with applicable healthcare privacy requirements.
9. Wearable Authorization and User Control
PepMed will access connected wearable or health-platform information only after the user completes the applicable authorization or connection process.
Depending on the platform, users may be able to:
Select specific categories of information PepMed may access.
Decline particular permissions.
Revoke previously granted permissions.
Disconnect an integration.
Request deletion of certain information, subject to applicable healthcare recordkeeping and legal requirements.
Disconnecting a wearable integration does not necessarily delete information previously incorporated into a medical record or information that PepMed is legally required or permitted to retain.
PepMed does not guarantee the accuracy, completeness, or continuous availability of information generated by third-party wearable devices or services.
Wearable information is supplemental and should not be relied upon as an emergency-monitoring system.
10. Service Providers, Business Associates, and Healthcare Partners
PepMed uses third-party organizations to operate and support its services.
Depending on how you use PepMed, these may include organizations supporting:
Healthcare technology and electronic health records.
Patient-portal infrastructure.
Telehealth services.
Cloud infrastructure and data storage.
Email delivery.
SMS and text messaging.
Patient communications.
Electronic prescribing.
Pharmacies and medication fulfillment.
Medication delivery and logistics.
Wearable-device integrations.
Laboratory services.
Supplements and wellness-product fulfillment.
Payment processing.
Website hosting.
Analytics.
Security.
Customer support.
Other business or healthcare operations.
Current or anticipated providers may include Twilio for text messaging, Twilio SendGrid for email delivery, Surescripts for electronic-prescribing connectivity, dispensing pharmacies, laboratories, supplement suppliers, and UPS Healthcare or other delivery providers used in connection with fulfillment.
PepMed may also receive information at your direction from Apple Health/HealthKit, Google Health Connect, Fitbit, Oura, WHOOP, and other connected health services.
These organizations process information according to their respective roles, contractual obligations, authorizations, applicable privacy laws, and healthcare privacy requirements.
Where required by HIPAA, appropriate Business Associate Agreements or other legally required privacy arrangements are maintained with organizations that create, receive, maintain, or transmit PHI on behalf of an applicable covered entity.
Not every third party interacting with PepMed is necessarily a HIPAA business associate; the applicable legal relationship depends on the party's role and the information involved.
11. How We Disclose Information
PepMed does not sell PHI.
PepMed does not sell Personal Information or health information for monetary consideration as part of its ordinary business practices.
Subject to applicable law, information may be disclosed:
To healthcare providers involved in your care.
To service providers acting on our behalf.
To electronic-prescribing networks.
To pharmacies for prescription processing, dispensing, and fulfillment.
To fulfillment and logistics providers for delivery.
To connected health platforms at your direction.
To laboratories and other healthcare organizations involved in services you request.
To supplement or wellness-product suppliers involved in fulfilling your purchases.
To payment processors where reasonably necessary.
To professional advisers where appropriate and legally permitted.
When required or permitted by law.
To protect PepMed, patients, users, or others where legally permitted.
In connection with an authorized corporate transaction, subject to applicable privacy and healthcare laws.
At your direction or with your consent or authorization.
As otherwise permitted by applicable law.
PepMed does not disclose PHI or Wearable Data to advertising platforms, data brokers, or other third parties for their independent targeted-advertising purposes without authorization where authorization is required by law.
Any disclosure of PHI in connection with a merger, acquisition, restructuring, financing, sale, or other corporate transaction remains subject to HIPAA and other applicable privacy requirements. Nothing in this Privacy Policy authorizes the unrestricted sale or transfer of PHI as an ordinary commercial asset.
12. Marketing and Advertising
PepMed may use contact information and marketing preferences to provide promotional or educational communications where permitted by law and consistent with applicable consent requirements.
PepMed does not sell PHI.
PepMed does not disclose PHI to third parties for their independent advertising or marketing purposes except pursuant to a valid authorization where such authorization is required by law.
PepMed does not use Wearable Data obtained through connected health integrations for third-party targeted advertising or data-broker purposes.
Communications concerning treatment, healthcare services, account activity, products or services involved in your care, or other communications permitted under applicable healthcare law are not necessarily considered marketing under HIPAA.
Where HIPAA or another law requires authorization for a marketing use or disclosure of PHI, PepMed will obtain the required authorization.
Declining optional marketing communications will not affect your ability to obtain healthcare through PepMed.
13. Cookies, Analytics, and Similar Technologies
PepMed and technology providers supporting our public Website may use cookies, local storage, analytics tools, and similar technologies for purposes including:
Essential Website functionality.
Authentication.
Security.
Remembering preferences.
Website performance.
Understanding Website interactions.
Analytics.
Diagnosing technical issues.
Where required by law, appropriate consent will be obtained for non-essential technologies.
PepMed does not knowingly configure advertising or analytics technologies to collect PHI from authenticated patient-portal or clinical areas for targeted-advertising purposes.
PepMed does not knowingly use PHI or Wearable Data for targeted advertising through cookies, pixels, analytics tools, or similar technologies.
Where information transmitted through an online tracking technology constitutes PHI, PepMed will handle such information in accordance with applicable HIPAA requirements.
Additional information is available in PepMed's Cookie Policy.
14. Data Security
PepMed maintains reasonable administrative, technical, physical, and organizational safeguards designed to protect Personal Information and health information against unauthorized access, acquisition, loss, misuse, alteration, or disclosure.
Where appropriate, safeguards may include:
Encryption.
Access controls.
Authentication.
Monitoring and logging.
Secure communications.
Security testing.
Vendor and contractual safeguards.
Policies and procedures designed to protect sensitive information.
Where HIPAA applies, PepMed and applicable covered entities or business associates maintain safeguards required by applicable healthcare privacy and security requirements.
No electronic system, storage system, network, transmission method, or security measure can be guaranteed to be completely secure, and PepMed cannot guarantee absolute security.
If a breach of unsecured PHI occurs, affected individuals will be notified when and as required by applicable law.
15. Data Retention
PepMed retains information for as long as reasonably necessary for the purposes for which it was collected and as required or permitted by law.
Retention periods may depend on:
The type of information.
Healthcare and medical-record retention requirements.
The duration of the patient relationship.
Legal and regulatory requirements.
Prescription and pharmacy requirements.
Laboratory requirements.
Payment and transaction requirements.
Security requirements.
Business recordkeeping obligations.
Consent and opt-out records.
Whether a wearable integration remains connected.
Legal claims or disputes.
When information is no longer reasonably necessary, PepMed may delete, de-identify, anonymize, or otherwise appropriately dispose of it, subject to applicable healthcare, legal, regulatory, and recordkeeping requirements.
A request to delete Personal Information does not necessarily require deletion of information that PepMed or a healthcare provider is legally required or permitted to retain, including information incorporated into an applicable medical record.
16. Your Choices and Privacy Rights
Depending on applicable law and the type of information involved, you may have rights to:
Request access to Personal Information.
Request correction.
Request deletion.
Obtain certain information in portable form.
Withdraw consent where applicable.
Opt out of marketing.
Manage SMS preferences.
Disconnect wearable integrations.
Modify wearable permissions through the applicable provider.
Request information regarding certain disclosures or processing.
Appeal certain privacy decisions where applicable law provides that right.
Different and additional rights may apply to PHI under HIPAA.
These may include rights concerning access, amendment, confidential communications, restrictions, certain disclosures, copies of privacy notices, and complaints.
Please review PepMed's Notice of Privacy Practices for a description of rights applicable to PHI.
Privacy requests concerning PHI may be directed to the PepMed Privacy Officer at privacy@pepmed.net.
17. Family Members, Caregivers, and Personal Representatives
Where permitted by applicable law, you may identify a family member, spouse, caregiver, close friend, or other person whom you would like involved in your care or payment for your care.
PepMed and healthcare providers may disclose information to such persons based on your direction, authorization, agreement, circumstances indicating that you do not object, professional judgment, or other authority permitted by applicable law.
Where a person is legally authorized to act as your personal representative, PepMed may verify that person's identity and authority before allowing that person to exercise applicable rights on your behalf.
Disclosures of PHI to family members, caregivers, or personal representatives are subject to HIPAA and other applicable laws as described more fully in PepMed's Notice of Privacy Practices.
18. Marketing Preferences
You may unsubscribe from marketing emails using the unsubscribe link provided in applicable emails.
You may opt out of applicable SMS messages by replying STOP.
PepMed may retain limited information necessary to record and honor opt-out preferences.
Marketing preferences do not prevent PepMed from sending communications that are reasonably necessary for healthcare, transactions, security, legal notices, or services you have requested.
Consent to receive promotional email or SMS communications is not a condition of receiving healthcare through PepMed where prohibited by applicable law.
19. Children's Privacy
PepMed's Website and healthcare services are intended for adults unless PepMed expressly states otherwise.
PepMed does not knowingly collect Personal Information from children under 18 through its general marketing, waitlist, or healthcare-registration services except where specifically permitted and appropriately authorized under applicable law.
If PepMed learns that information has been collected from a person under 18 in a manner inconsistent with applicable requirements, PepMed will take reasonable steps to appropriately handle or delete the information, subject to applicable legal and healthcare recordkeeping obligations.
20. State Privacy Rights and Sensitive Information
Residents of certain U.S. states may have additional privacy rights.
Depending on applicable law, these may include rights to:
Confirm whether Personal Information is processed.
Access Personal Information.
Correct inaccuracies.
Request deletion.
Obtain portable copies.
Opt out of certain targeted advertising, sale, or profiling.
Appeal certain privacy-request decisions.
Healthcare information, PHI, and other sensitive information may be subject to different or additional protections, exemptions, or requirements under state and federal law.
Certain categories of health information may receive additional protection under applicable laws, potentially including information relating to:
Substance use disorder treatment.
Mental or behavioral health.
HIV/AIDS or communicable diseases.
Genetic information.
Reproductive or sexual health.
Minors.
Other specially protected health information.
Where applicable law provides protections greater than those provided by this Privacy Policy or HIPAA, PepMed will comply with the applicable legal requirements.
21. Third-Party Platforms and Services
PepMed may integrate with or facilitate access to third-party services.
Your relationship with Apple, Google, Fitbit, Oura, WHOOP, pharmacies, laboratories, supplement suppliers, payment providers, delivery companies, and other third parties may also be governed by those organizations' privacy policies and terms.
PepMed does not control the privacy practices of third-party services when you interact directly with them.
Authorization of a third-party health integration allows PepMed to receive information made available within the scope of permissions you grant and the applicable integration.
PepMed's use of information received from connected platforms remains subject to PepMed's applicable privacy obligations, authorizations, and this Privacy Policy.
22. Research
PepMed does not currently operate a program that uses identifiable patient PHI for clinical research.
If PepMed participates in research in the future, PHI will be used or disclosed for research only in accordance with applicable law, including obtaining patient authorization or appropriate approval where required.
Use of PepMed's Website, acceptance of this Privacy Policy, creation of an account, or establishment of care does not constitute consent to participate in research.
23. Healthcare Information and HIPAA
Certain information handled in connection with PepMed healthcare services may constitute PHI.
Where HIPAA applies, PHI may be used and disclosed for purposes including:
Treatment.
Payment.
Healthcare operations.
Public-health activities.
Health oversight.
Other purposes permitted or required by law.
The specific HIPAA rights and permitted uses and disclosures applicable to PHI are described in PepMed's Notice of Privacy Practices.
This Privacy Policy is not intended to replace the Notice of Privacy Practices.
If this Privacy Policy and the Notice of Privacy Practices address the same PHI, the Notice of Privacy Practices controls to the extent required by applicable law.
Acceptance of this Privacy Policy does not constitute authorization for a use or disclosure of PHI for which HIPAA or another applicable law requires separate authorization.
24. Changes to This Privacy Policy
PepMed may update this Privacy Policy to reflect changes in:
Healthcare services.
Technology.
Connected devices and wearable integrations.
Communications.
Service providers.
Pharmacy, laboratory, or fulfillment operations.
Payment processing.
Legal requirements.
Information practices.
Business operations.
When updated, PepMed will revise the Last Updated date and, where appropriate, the document version.
Minor clarifications, compliance updates, or changes that do not materially alter the nature or scope of PepMed's information practices may result in an incremental version change.
Material changes to the nature or scope of PepMed's services or information practices may result in a major version change.
Where required by applicable law, PepMed may provide additional notice or obtain consent or authorization before material changes become effective.
25. Contact Us
If you have questions regarding this Privacy Policy, PepMed's privacy practices, or wish to exercise an applicable privacy right, please contact:
PepMed Privacy Officer
Email: privacy@pepmed.net
Website: PepMed.net
For questions or requests concerning PHI or your HIPAA privacy rights, please also review PepMed's Notice of Privacy Practices.
PepMed will not retaliate against a patient for exercising a privacy right or filing a privacy complaint as protected by applicable law.
Privacy Policy
Document Version: 2.1
Effective Date: September 8, 2026
Last Updated: September 8, 2026
PepMed ("PepMed," "we," "our," or "us") respects your privacy and is committed to protecting the personal and health information you share with us.
This Privacy Policy explains how we collect, use, disclose, store, and safeguard information when you visit our Website, create or use a PepMed account or patient portal, communicate with us, receive communications from us, connect a wearable device or health-data service, participate in telehealth or healthcare services, purchase products or services, or otherwise interact with PepMed.
PepMed believes that privacy, transparency, and trust are fundamental to healthcare and wellness services. We are committed to handling personal information responsibly and in accordance with applicable privacy and healthcare laws.
Certain information collected or maintained in connection with healthcare services may constitute Protected Health Information ("PHI") under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA").
HIPAA Notice of Privacy Practices
If you are a PepMed patient, please review our Notice of Privacy Practices, which describes in greater detail how PHI may be used and disclosed and explains your rights regarding PHI.
Where this Privacy Policy and the Notice of Privacy Practices both apply to PHI, the Notice of Privacy Practices controls to the extent required by applicable healthcare privacy law.
Acceptance of or use of services subject to this Privacy Policy does not constitute a HIPAA authorization for uses or disclosures of PHI that otherwise require separate authorization under applicable law.
1. Purpose
The purpose of this Privacy Policy is to explain:
What information PepMed collects.
How information is collected.
Why we collect information.
How we use information.
How information may be disclosed.
How health and healthcare information is handled.
How wearable and connected health information is handled.
How communications such as email and text messages are handled.
How prescription, pharmacy, laboratory, fulfillment, payment, and delivery information may be handled.
How Website technologies, cookies, and analytics are used.
How we protect information.
How long information may be retained.
The choices and privacy rights that may be available to you.
2. Scope of This Privacy Policy
This Privacy Policy applies to interactions with PepMed, including through:
PepMed websites and webpages.
PepMed patient portals and digital services.
Account registration and patient onboarding.
Contact forms.
Email subscriptions and communications.
SMS and text-message communications.
Waitlist and service-availability registration.
Telehealth and healthcare services.
Wearable-device and health-data integrations.
Prescription and pharmacy-related services.
Laboratory services.
Supplements and wellness products.
Medication fulfillment and delivery coordination.
Payment and transaction processing.
Educational and informational content.
Other online or offline interactions with PepMed.
Visiting PepMed's public Website, reading educational content, joining a waitlist, subscribing to general updates, or submitting a general contact form does not by itself create a provider-patient relationship.
A provider-patient relationship may be established only through the applicable patient onboarding and clinical process.
3. Definitions
"PepMed," "we," "our," or "us" means PepMed and the business operating the PepMed Website and services, including authorized healthcare providers and service providers where applicable.
"Website" means PepMed's websites, webpages, content, forms, and related online properties.
"Services" means PepMed's informational, digital, healthcare, telehealth, wellness, communication, patient-portal, and related services.
"Personal Information" means information that identifies, relates to, describes, or can reasonably be linked to an identifiable individual or household, as defined by applicable law.
"Health Information" means information relating to an individual's health, wellness, fitness, physical characteristics, activity, sleep, physiological measurements, medications, treatment, or healthcare.
"Protected Health Information" or "PHI" has the meaning assigned under HIPAA and its implementing regulations.
"Wearable Data" means health, wellness, fitness, activity, sleep, physiological, or related information obtained from a wearable device, health application, connected service, or health-data platform at the user's direction.
"Patient Portal" means the digital platform through which eligible PepMed patients may access or interact with PepMed healthcare services.
"User," "you," or "your" means an individual who interacts with PepMed or uses the Services.
4. Information We Collect
The information PepMed collects depends on how you interact with us.
A. Information You Provide Directly
We may collect information such as:
First and last name.
Email address.
Telephone number.
Mailing or delivery address.
State of residence.
Date of birth or age information.
Account information.
Communication preferences.
Interests and wellness goals.
Information submitted through forms or messages.
Information submitted during patient registration or onboarding.
Information provided during healthcare interactions.
Information necessary to coordinate prescriptions, pharmacy services, laboratory services, supplements, or medication delivery.
Billing or transaction-related information.
Other information you voluntarily provide.
B. Health and Healthcare Information
If you become a PepMed patient or use healthcare services, PepMed and healthcare providers involved in your care may collect information necessary to provide care, including information regarding:
Medical history.
Current and previous health conditions.
Medications and supplements.
Allergies.
Laboratory results.
Vital signs and measurements.
Symptoms.
Diagnoses.
Treatment plans.
Prescriptions.
Healthcare-provider interactions.
Telehealth encounters.
Clinical notes.
Patient-reported outcomes.
Other information relevant to your care.
Health information that constitutes PHI is handled in accordance with applicable healthcare privacy laws and PepMed's Notice of Privacy Practices.
C. Wearable and Connected Health Data
PepMed may allow you to voluntarily connect compatible wearable devices, health applications, or health-data services to your PepMed account.
Depending on the device, service, permissions you grant, and features available, this may include integrations involving:
Apple Health and Apple HealthKit.
Google Health Connect or other compatible Google health services.
Fitbit.
Oura.
WHOOP.
Other compatible health or wearable platforms that PepMed may support.
Depending on your authorization, Wearable Data may include categories such as:
Steps and physical activity.
Exercise and workout information.
Heart rate and heart-rate trends.
Resting heart rate.
Heart-rate variability.
Sleep duration, stages, timing, and related measurements.
Respiratory measurements.
Blood oxygen or oxygen-saturation information.
Temperature-related measurements.
Weight and body measurements.
Calories or energy expenditure.
Recovery, readiness, strain, or similar scores provided by connected platforms.
Fitness and activity trends.
Other health or wellness measurements that you expressly authorize PepMed to access.
The specific information available varies by platform and by the permissions you choose to grant.
Connecting a wearable or health-data account is voluntary unless otherwise expressly disclosed for a particular PepMed service.
PepMed will request access only to data categories reasonably related to features or healthcare services we provide. You control permissions available through the applicable device or third-party platform and may be able to modify or revoke those permissions through that platform.
Revoking access may prevent PepMed from receiving new data. Information previously received may be retained where reasonably necessary to provide healthcare, maintain legally required medical or business records, comply with applicable law, or as otherwise described in this Privacy Policy or our Notice of Privacy Practices.
PepMed does not sell Wearable Data.
PepMed does not use Wearable Data obtained through Apple HealthKit, Google Health Connect, Fitbit, Oura, WHOOP, or similar health integrations for third-party advertising, targeted advertising, or data-broker purposes.
Wearable Data may be used for purposes associated with providing, supporting, personalizing, monitoring, or improving health, wellness, and healthcare services for the applicable user, as permitted by the user's authorization and applicable law.
D. Communications Information
When you communicate with PepMed or receive communications from us, we may collect and maintain information including:
Email address.
Mobile telephone number.
Communication preferences.
Date and time communications were sent or received.
Delivery status.
Opt-in and opt-out status.
Consent records.
Message metadata.
Communications between you and PepMed where appropriate.
E. Prescription and Pharmacy Information
When a licensed healthcare provider determines that a prescription is medically appropriate, information necessary to issue, transmit, process, dispense, fulfill, or coordinate a prescription may be shared with or processed by authorized healthcare technology providers, pharmacies, and related service providers.
This information may include:
Patient identifying information.
Contact information.
Prescription information.
Prescriber information.
Pharmacy information.
Medication name, strength, dosage, quantity, and instructions.
Information reasonably necessary for prescription processing and dispensing.
PepMed may use electronic-prescribing infrastructure, including Surescripts or other authorized networks, to facilitate electronic transmission of prescription information.
F. Laboratory Information
Where laboratory testing is ordered or coordinated through PepMed, PepMed, healthcare providers, laboratories, and service providers may process information reasonably necessary to order, coordinate, perform, bill for, or report laboratory testing.
This may include:
Patient identifying information.
Contact information.
Provider and order information.
Test information.
Specimen information.
Laboratory results.
Payment or transaction information where applicable.
Other information reasonably necessary for laboratory services.
Clinical laboratory information that constitutes PHI is subject to applicable healthcare privacy requirements.
G. Medication Fulfillment and Delivery Information
When medication or another healthcare product is shipped to you, PepMed, a dispensing pharmacy, fulfillment provider, or delivery provider may process information necessary to fulfill and deliver the shipment.
This may include:
Your name.
Shipping address.
Telephone number or email address where necessary for delivery.
Shipment information.
Tracking information.
Delivery status.
Delivery instructions.
Signature information where applicable.
A dispensing pharmacy may use UPS Healthcare or another qualified delivery or logistics provider to deliver medication to a patient's designated address.
Only information reasonably necessary to coordinate and complete the applicable shipment should be provided to delivery and logistics providers.
H. Payment and Transaction Information
PepMed may collect payments for PepMed services and for certain healthcare-related products or services fulfilled or performed by third parties, including pharmacies, laboratories, supplement suppliers, or other service providers.
This centralized payment structure may reduce the need for patients to establish separate payment relationships or provide payment credentials to multiple parties involved in their care.
Payment and transaction information may include:
Name.
Billing information.
Transaction amount.
Transaction date and status.
Products or services purchased.
Payment-method information processed through an applicable payment processor.
Refund, credit, or dispute information.
Other information reasonably necessary to process or administer a transaction.
PepMed may use third-party payment processors to securely process transactions.
Payment processors may independently receive information necessary to process, authenticate, prevent fraud, or administer payments in accordance with their applicable role, contractual obligations, and privacy practices.
PepMed seeks to limit payment-related information shared with other parties to information reasonably necessary for the applicable transaction, administrative purpose, or legal requirement.
I. Website and Technical Information
When you use PepMed's Website or digital services, PepMed and its service providers may process technical information such as:
Browser and device information.
Operating system.
IP address.
Website and page interactions.
Referring information.
Approximate location derived from technical information.
Date and time information.
Website performance information.
Security and diagnostic information.
Cookies or similar technologies.
Please review PepMed's Cookie Policy for additional information.
5. Public Website Information and Clinical Information
PepMed distinguishes between information collected through its public-facing Website and marketing services and information collected or maintained in connection with healthcare and clinical services.
Information submitted through public Website forms, waitlists, newsletters, service-availability forms, or general informational interactions may not constitute PHI merely because it relates generally to health or wellness.
Information collected or maintained in connection with healthcare services may constitute PHI and, where applicable, is subject to HIPAA and PepMed's Notice of Privacy Practices.
PepMed seeks to maintain appropriate separation between public-facing marketing activities and systems or environments containing PHI.
PepMed does not knowingly use PHI obtained through authenticated patient-portal or clinical areas for targeted advertising or provide such PHI to advertising platforms or data brokers for their independent advertising purposes.
6. How We Use Information
PepMed may use information to:
Provide healthcare and telehealth services.
Facilitate patient registration and onboarding.
Maintain patient accounts.
Schedule and manage appointments.
Send appointment reminders.
Communicate regarding patient care or services.
Provide patient-portal functionality.
Assist healthcare providers in evaluating health and wellness information.
Display or analyze wearable and connected health information for the user.
Monitor health, wellness, activity, or treatment trends where appropriate.
Facilitate prescriptions and electronic prescribing.
Coordinate with pharmacies.
Coordinate laboratory services.
Facilitate medication fulfillment and delivery.
Process payments and administer transactions.
Coordinate payments for third-party healthcare products or services.
Send transactional email and SMS communications.
Respond to inquiries.
Provide requested educational or informational communications.
Manage marketing preferences.
Operate and improve PepMed's services.
Maintain security.
Detect fraud or misuse.
Maintain required healthcare and business records.
Comply with legal and regulatory requirements.
Establish, exercise, or defend legal rights.
We may use information for additional purposes disclosed at the time of collection or with your authorization where required.
7. SMS and Text Messaging
PepMed may use SMS or other text messaging to communicate with users and patients who provide an eligible mobile telephone number and consent to receive applicable communications.
Messages may include:
Appointment confirmations.
Appointment reminders.
Scheduling updates.
Account or service notifications.
Verification or security messages.
Prescription or pharmacy-related status notifications where appropriate.
Delivery-related notifications.
Other transactional or healthcare-service communications.
Marketing or promotional messages only where separately authorized as required by applicable law.
PepMed may use Twilio or another communications provider to facilitate text-message delivery.
By providing your mobile number and opting into an applicable PepMed text-messaging program, you authorize PepMed and its service providers to send communications described in the applicable consent disclosure.
Message frequency may vary. Message and data rates may apply.
You may opt out of applicable text messages at any time by replying STOP. You may reply HELP for assistance where supported or contact PepMed directly.
Consent to receive marketing text messages is not a condition of purchasing goods or healthcare services from PepMed.
Opting out of optional SMS communications may limit PepMed's ability to provide certain text-based reminders or notifications but will not prevent PepMed from communicating through other appropriate channels when reasonably necessary.
Wireless carriers are not liable for delayed or undelivered messages.
PepMed maintains records of messaging consent and opt-out preferences as reasonably necessary to comply with applicable law and communications requirements.
Mobile opt-in information and consent will not be sold, rented, or shared with third parties for their own marketing or promotional purposes.
8. Email Communications
PepMed may send email communications including:
Appointment confirmations and reminders.
Account and security notifications.
Patient-service communications.
Requested educational content.
PepTalk articles.
Service announcements.
Prescription, pharmacy, laboratory, or delivery-related notifications where appropriate.
Marketing communications where authorized.
PepMed may use Twilio SendGrid or another email-delivery provider to facilitate email communications.
Marketing emails will include an appropriate method to unsubscribe where required.
Unsubscribing from marketing emails does not prevent PepMed from sending transactional, healthcare, account, security, legal, or other non-marketing communications reasonably necessary to provide requested services.
Where a communication contains PHI, PepMed handles the communication in accordance with applicable healthcare privacy requirements.
9. Wearable Authorization and User Control
PepMed will access connected wearable or health-platform information only after the user completes the applicable authorization or connection process.
Depending on the platform, users may be able to:
Select specific categories of information PepMed may access.
Decline particular permissions.
Revoke previously granted permissions.
Disconnect an integration.
Request deletion of certain information, subject to applicable healthcare recordkeeping and legal requirements.
Disconnecting a wearable integration does not necessarily delete information previously incorporated into a medical record or information that PepMed is legally required or permitted to retain.
PepMed does not guarantee the accuracy, completeness, or continuous availability of information generated by third-party wearable devices or services.
Wearable information is supplemental and should not be relied upon as an emergency-monitoring system.
10. Service Providers, Business Associates, and Healthcare Partners
PepMed uses third-party organizations to operate and support its services.
Depending on how you use PepMed, these may include organizations supporting:
Healthcare technology and electronic health records.
Patient-portal infrastructure.
Telehealth services.
Cloud infrastructure and data storage.
Email delivery.
SMS and text messaging.
Patient communications.
Electronic prescribing.
Pharmacies and medication fulfillment.
Medication delivery and logistics.
Wearable-device integrations.
Laboratory services.
Supplements and wellness-product fulfillment.
Payment processing.
Website hosting.
Analytics.
Security.
Customer support.
Other business or healthcare operations.
Current or anticipated providers may include Twilio for text messaging, Twilio SendGrid for email delivery, Surescripts for electronic-prescribing connectivity, dispensing pharmacies, laboratories, supplement suppliers, and UPS Healthcare or other delivery providers used in connection with fulfillment.
PepMed may also receive information at your direction from Apple Health/HealthKit, Google Health Connect, Fitbit, Oura, WHOOP, and other connected health services.
These organizations process information according to their respective roles, contractual obligations, authorizations, applicable privacy laws, and healthcare privacy requirements.
Where required by HIPAA, appropriate Business Associate Agreements or other legally required privacy arrangements are maintained with organizations that create, receive, maintain, or transmit PHI on behalf of an applicable covered entity.
Not every third party interacting with PepMed is necessarily a HIPAA business associate; the applicable legal relationship depends on the party's role and the information involved.
11. How We Disclose Information
PepMed does not sell PHI.
PepMed does not sell Personal Information or health information for monetary consideration as part of its ordinary business practices.
Subject to applicable law, information may be disclosed:
To healthcare providers involved in your care.
To service providers acting on our behalf.
To electronic-prescribing networks.
To pharmacies for prescription processing, dispensing, and fulfillment.
To fulfillment and logistics providers for delivery.
To connected health platforms at your direction.
To laboratories and other healthcare organizations involved in services you request.
To supplement or wellness-product suppliers involved in fulfilling your purchases.
To payment processors where reasonably necessary.
To professional advisers where appropriate and legally permitted.
When required or permitted by law.
To protect PepMed, patients, users, or others where legally permitted.
In connection with an authorized corporate transaction, subject to applicable privacy and healthcare laws.
At your direction or with your consent or authorization.
As otherwise permitted by applicable law.
PepMed does not disclose PHI or Wearable Data to advertising platforms, data brokers, or other third parties for their independent targeted-advertising purposes without authorization where authorization is required by law.
Any disclosure of PHI in connection with a merger, acquisition, restructuring, financing, sale, or other corporate transaction remains subject to HIPAA and other applicable privacy requirements. Nothing in this Privacy Policy authorizes the unrestricted sale or transfer of PHI as an ordinary commercial asset.
12. Marketing and Advertising
PepMed may use contact information and marketing preferences to provide promotional or educational communications where permitted by law and consistent with applicable consent requirements.
PepMed does not sell PHI.
PepMed does not disclose PHI to third parties for their independent advertising or marketing purposes except pursuant to a valid authorization where such authorization is required by law.
PepMed does not use Wearable Data obtained through connected health integrations for third-party targeted advertising or data-broker purposes.
Communications concerning treatment, healthcare services, account activity, products or services involved in your care, or other communications permitted under applicable healthcare law are not necessarily considered marketing under HIPAA.
Where HIPAA or another law requires authorization for a marketing use or disclosure of PHI, PepMed will obtain the required authorization.
Declining optional marketing communications will not affect your ability to obtain healthcare through PepMed.
13. Cookies, Analytics, and Similar Technologies
PepMed and technology providers supporting our public Website may use cookies, local storage, analytics tools, and similar technologies for purposes including:
Essential Website functionality.
Authentication.
Security.
Remembering preferences.
Website performance.
Understanding Website interactions.
Analytics.
Diagnosing technical issues.
Where required by law, appropriate consent will be obtained for non-essential technologies.
PepMed does not knowingly configure advertising or analytics technologies to collect PHI from authenticated patient-portal or clinical areas for targeted-advertising purposes.
PepMed does not knowingly use PHI or Wearable Data for targeted advertising through cookies, pixels, analytics tools, or similar technologies.
Where information transmitted through an online tracking technology constitutes PHI, PepMed will handle such information in accordance with applicable HIPAA requirements.
Additional information is available in PepMed's Cookie Policy.
14. Data Security
PepMed maintains reasonable administrative, technical, physical, and organizational safeguards designed to protect Personal Information and health information against unauthorized access, acquisition, loss, misuse, alteration, or disclosure.
Where appropriate, safeguards may include:
Encryption.
Access controls.
Authentication.
Monitoring and logging.
Secure communications.
Security testing.
Vendor and contractual safeguards.
Policies and procedures designed to protect sensitive information.
Where HIPAA applies, PepMed and applicable covered entities or business associates maintain safeguards required by applicable healthcare privacy and security requirements.
No electronic system, storage system, network, transmission method, or security measure can be guaranteed to be completely secure, and PepMed cannot guarantee absolute security.
If a breach of unsecured PHI occurs, affected individuals will be notified when and as required by applicable law.
15. Data Retention
PepMed retains information for as long as reasonably necessary for the purposes for which it was collected and as required or permitted by law.
Retention periods may depend on:
The type of information.
Healthcare and medical-record retention requirements.
The duration of the patient relationship.
Legal and regulatory requirements.
Prescription and pharmacy requirements.
Laboratory requirements.
Payment and transaction requirements.
Security requirements.
Business recordkeeping obligations.
Consent and opt-out records.
Whether a wearable integration remains connected.
Legal claims or disputes.
When information is no longer reasonably necessary, PepMed may delete, de-identify, anonymize, or otherwise appropriately dispose of it, subject to applicable healthcare, legal, regulatory, and recordkeeping requirements.
A request to delete Personal Information does not necessarily require deletion of information that PepMed or a healthcare provider is legally required or permitted to retain, including information incorporated into an applicable medical record.
16. Your Choices and Privacy Rights
Depending on applicable law and the type of information involved, you may have rights to:
Request access to Personal Information.
Request correction.
Request deletion.
Obtain certain information in portable form.
Withdraw consent where applicable.
Opt out of marketing.
Manage SMS preferences.
Disconnect wearable integrations.
Modify wearable permissions through the applicable provider.
Request information regarding certain disclosures or processing.
Appeal certain privacy decisions where applicable law provides that right.
Different and additional rights may apply to PHI under HIPAA.
These may include rights concerning access, amendment, confidential communications, restrictions, certain disclosures, copies of privacy notices, and complaints.
Please review PepMed's Notice of Privacy Practices for a description of rights applicable to PHI.
Privacy requests concerning PHI may be directed to the PepMed Privacy Officer at privacy@pepmed.net.
17. Family Members, Caregivers, and Personal Representatives
Where permitted by applicable law, you may identify a family member, spouse, caregiver, close friend, or other person whom you would like involved in your care or payment for your care.
PepMed and healthcare providers may disclose information to such persons based on your direction, authorization, agreement, circumstances indicating that you do not object, professional judgment, or other authority permitted by applicable law.
Where a person is legally authorized to act as your personal representative, PepMed may verify that person's identity and authority before allowing that person to exercise applicable rights on your behalf.
Disclosures of PHI to family members, caregivers, or personal representatives are subject to HIPAA and other applicable laws as described more fully in PepMed's Notice of Privacy Practices.
18. Marketing Preferences
You may unsubscribe from marketing emails using the unsubscribe link provided in applicable emails.
You may opt out of applicable SMS messages by replying STOP.
PepMed may retain limited information necessary to record and honor opt-out preferences.
Marketing preferences do not prevent PepMed from sending communications that are reasonably necessary for healthcare, transactions, security, legal notices, or services you have requested.
Consent to receive promotional email or SMS communications is not a condition of receiving healthcare through PepMed where prohibited by applicable law.
19. Children's Privacy
PepMed's Website and healthcare services are intended for adults unless PepMed expressly states otherwise.
PepMed does not knowingly collect Personal Information from children under 18 through its general marketing, waitlist, or healthcare-registration services except where specifically permitted and appropriately authorized under applicable law.
If PepMed learns that information has been collected from a person under 18 in a manner inconsistent with applicable requirements, PepMed will take reasonable steps to appropriately handle or delete the information, subject to applicable legal and healthcare recordkeeping obligations.
20. State Privacy Rights and Sensitive Information
Residents of certain U.S. states may have additional privacy rights.
Depending on applicable law, these may include rights to:
Confirm whether Personal Information is processed.
Access Personal Information.
Correct inaccuracies.
Request deletion.
Obtain portable copies.
Opt out of certain targeted advertising, sale, or profiling.
Appeal certain privacy-request decisions.
Healthcare information, PHI, and other sensitive information may be subject to different or additional protections, exemptions, or requirements under state and federal law.
Certain categories of health information may receive additional protection under applicable laws, potentially including information relating to:
Substance use disorder treatment.
Mental or behavioral health.
HIV/AIDS or communicable diseases.
Genetic information.
Reproductive or sexual health.
Minors.
Other specially protected health information.
Where applicable law provides protections greater than those provided by this Privacy Policy or HIPAA, PepMed will comply with the applicable legal requirements.
21. Third-Party Platforms and Services
PepMed may integrate with or facilitate access to third-party services.
Your relationship with Apple, Google, Fitbit, Oura, WHOOP, pharmacies, laboratories, supplement suppliers, payment providers, delivery companies, and other third parties may also be governed by those organizations' privacy policies and terms.
PepMed does not control the privacy practices of third-party services when you interact directly with them.
Authorization of a third-party health integration allows PepMed to receive information made available within the scope of permissions you grant and the applicable integration.
PepMed's use of information received from connected platforms remains subject to PepMed's applicable privacy obligations, authorizations, and this Privacy Policy.
22. Research
PepMed does not currently operate a program that uses identifiable patient PHI for clinical research.
If PepMed participates in research in the future, PHI will be used or disclosed for research only in accordance with applicable law, including obtaining patient authorization or appropriate approval where required.
Use of PepMed's Website, acceptance of this Privacy Policy, creation of an account, or establishment of care does not constitute consent to participate in research.
23. Healthcare Information and HIPAA
Certain information handled in connection with PepMed healthcare services may constitute PHI.
Where HIPAA applies, PHI may be used and disclosed for purposes including:
Treatment.
Payment.
Healthcare operations.
Public-health activities.
Health oversight.
Other purposes permitted or required by law.
The specific HIPAA rights and permitted uses and disclosures applicable to PHI are described in PepMed's Notice of Privacy Practices.
This Privacy Policy is not intended to replace the Notice of Privacy Practices.
If this Privacy Policy and the Notice of Privacy Practices address the same PHI, the Notice of Privacy Practices controls to the extent required by applicable law.
Acceptance of this Privacy Policy does not constitute authorization for a use or disclosure of PHI for which HIPAA or another applicable law requires separate authorization.
24. Changes to This Privacy Policy
PepMed may update this Privacy Policy to reflect changes in:
Healthcare services.
Technology.
Connected devices and wearable integrations.
Communications.
Service providers.
Pharmacy, laboratory, or fulfillment operations.
Payment processing.
Legal requirements.
Information practices.
Business operations.
When updated, PepMed will revise the Last Updated date and, where appropriate, the document version.
Minor clarifications, compliance updates, or changes that do not materially alter the nature or scope of PepMed's information practices may result in an incremental version change.
Material changes to the nature or scope of PepMed's services or information practices may result in a major version change.
Where required by applicable law, PepMed may provide additional notice or obtain consent or authorization before material changes become effective.
25. Contact Us
If you have questions regarding this Privacy Policy, PepMed's privacy practices, or wish to exercise an applicable privacy right, please contact:
PepMed Privacy Officer
Email: privacy@pepmed.net
Website: PepMed.net
For questions or requests concerning PHI or your HIPAA privacy rights, please also review PepMed's Notice of Privacy Practices.
PepMed will not retaliate against a patient for exercising a privacy right or filing a privacy complaint as protected by applicable law.
Access. Trust. Convenience.
A new era of Physician guided care.
_________
PepMed connects you with licensed physicians and personalized care - anytime, anywhere.
Social Media launching soon!




COMING SOON
The PepMED mobile app.
Access consultations, health insights and more - all from your phone.



Stay tuned for launch updates.
PepTalk Updates
New articles, platform news and launch announcements


Virtual Care
Connect with licensed providers from wherever you are.


Treatment Access
Treatment options prescribed by licensed healthcare providers.


See Your Progress
Appointments, delivery tracking and health trends in one place.
© 2026 PepMed. All rights reserved
Access. Trust. Convenience.
A new era of Physician guided care.
_________
PepMed connects you with licensed physicians and personalized care - anytime, anywhere.
Social Media launching soon!
COMING SOON




The PepMED mobile app.
Access consultations, health insights and more - all from your phone.


PepTalk Updates
New articles, platform news and launch announcements


Virtual Care
Connect with licensed providers from wherever you are.


Treatment Access
Treatment options prescribed by licensed healthcare providers.


See Your Progress
Appointments, delivery tracking and health trends in one place.
© 2026 PepMed. All rights reserved
COMING SOON




The PepMED mobile app.
Access consultations, health insights and more - all from your phone.


PepTalk Updates
New articles, platform news and launch announcements


Virtual Care
Connect with licensed providers from wherever you are.


Treatment Access
Treatment options prescribed by licensed healthcare providers.


See Your Progress
Appointments, delivery tracking and health trends in one place.
© 2026 PepMed. All rights reserved
