Privacy Policy

Last Updated: November 26, 2025

1. Introduction

This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you use our Base Modul platform ("Service"). This policy complies with the Health Insurance Portability and Accountability Act (HIPAA) and other applicable privacy laws.

2. HIPAA Notice of Privacy Practices

2.1 Protected Health Information (PHI)

We are committed to protecting your Protected Health Information (PHI). This includes:

  • Medical records and health history

  • Treatment information

  • Billing and payment information

  • Appointment details

  • Communications with Base Modul providers

  • Any individually identifiable health information

2.2 Your HIPAA Rights

You have the right to:

  • Access and review your PHI

  • Request corrections to your PHI

  • Receive an accounting of PHI disclosures

  • Request restrictions on PHI use and disclosure

  • Request confidential communications

  • Receive a paper copy of this Privacy Policy

  • File a complaint if you believe your privacy rights have been violated

3. Information We Collect

3.1 Personal Information

  • Name and contact information (email, phone, address)

  • Date of birth and age

  • Government-issued identification numbers

  • Emergency contact information

  • Profile photos (optional)

3.2 Health Information

  • Medical history and conditions

  • Treatment and diagnosis information

  • Medications and allergies

  • Lab results and medical reports

  • Insurance information

  • Base Modul provider information

3.3 Technical Information

  • IP address and device information

  • Browser type and version

  • Login times and session data

  • Pages visited and actions taken

  • Cookies and similar tracking technologies

3.4 Communication Data

  • Messages sent through the platform

  • Email communications

  • Support ticket information

  • Feedback and survey responses

4. How We Use Your Information

4.1 Treatment

  • Coordinating and managing your Base Modul

  • Facilitating communication with Base Modul providers

  • Maintaining medical records

  • Scheduling appointments

4.2 Payment

  • Processing billing and claims

  • Verifying insurance coverage

  • Collection activities

  • Payment processing

4.3 Base Modul Operations

  • Quality assessment and improvement

  • Staff training and competency evaluation

  • Business planning and management

  • Customer service and support

4.4 Required by Law

  • Compliance with legal obligations

  • Public health reporting

  • Law enforcement requests

  • Court orders and legal proceedings

4.5 Platform Operations

  • Providing and improving the Service

  • Authentication and security

  • Technical support

  • System maintenance and updates

  • Fraud prevention and security monitoring

5. How We Share Your Information

5.1 With Your Consent

We will not share your PHI without your written authorization except as described in this policy.

5.2 Base Modul Providers

  • Sharing with your treating physicians and Base Modul team

  • Referrals to specialists

  • Care coordination

5.3 Business Associates

We may share PHI with third-party service providers who:

  • Sign HIPAA Business Associate Agreements

  • Provide services on our behalf (hosting, data storage, analytics)

  • Are contractually obligated to protect your information

5.4 Legal Requirements

We may disclose information when required by law:

  • Court orders and subpoenas

  • Law enforcement investigations

  • Public health authorities

  • Regulatory agencies

  • Workers' compensation programs

5.5 Emergency Situations

  • To prevent serious threats to health or safety

  • To emergency responders

  • To disaster relief organizations

6. Data Security Measures

6.1 Technical Safeguards

  • Encryption: All data is encrypted in transit (HTTPS/TLS) and at rest

  • Access Controls: Role-based access with multi-factor authentication

  • Audit Logs: Comprehensive logging of all PHI access

  • Secure Infrastructure: SOC 2 compliant hosting and data centers

  • Regular Security Audits: Penetration testing and vulnerability assessments

6.2 Administrative Safeguards

  • Security Training: Regular staff training on HIPAA and security

  • Background Checks: Screening of personnel with PHI access

  • Incident Response: Documented breach notification procedures

  • Risk Assessments: Regular security risk analysis

6.3 Physical Safeguards

  • Facility Security: Secure data center access controls

  • Device Controls: Encrypted devices and secure disposal

  • Workstation Security: Protected access to systems

7. Data Retention

7.1 Retention Periods

  • Medical records: Maintained as required by law (typically 7+ years)

  • Audit logs: Retained for 6 years minimum (HIPAA requirement)

  • Account information: Retained while account is active plus legal requirements

  • Communication records: Retained per legal and operational needs

7.2 Deletion Requests

  • You may request account deletion at any time

  • Some data must be retained for legal compliance

  • Deletion is completed within 30 days where legally permissible

  • Backups may retain data for up to 90 days

8. Your Privacy Choices

8.1 Access and Correction

  • Request access to your PHI

  • Request corrections to inaccurate information

  • Download a copy of your data

  • Response within 30 days of request

8.2 Communication Preferences

  • Opt-out of marketing communications

  • Choose how we contact you

  • Set notification preferences

8.3 Account Controls

  • Enable/disable two-factor authentication

  • Manage team access and permissions

  • Control profile visibility

  • Delete your account

9. Cookies and Tracking

9.1 Essential Cookies

  • Required for authentication and security

  • Session management

  • Cannot be disabled

9.2 Functional Cookies

  • Remember your preferences

  • Improve user experience

  • Can be managed in browser settings

9.3 Analytics

  • We use analytics to improve the Service

  • Data is aggregated and anonymized

  • No PHI is included in analytics

10. Children's Privacy

  • This Service is not intended for users under 18

  • We do not knowingly collect information from minors

  • Parental consent required for users under 18

11. Breach Notification

11.1 Our Commitment

In the event of a data breach involving your PHI:

  • We will investigate promptly

  • Affected individuals will be notified within 60 days

  • Authorities will be notified as required by law

  • We will provide information about the breach and remediation steps

11.2 Reporting Breaches

If you suspect unauthorized access to your account:

  • Change your password immediately

  • Contact us at security@fakeeh.Base Modul

  • Enable two-factor authentication if not already active

12. International Data Transfers

  • Data may be transferred to countries outside your jurisdiction

  • We ensure adequate safeguards are in place

  • Transfers comply with applicable privacy laws

13. Third-Party Links

  • Our Service may contain links to third-party websites

  • We are not responsible for their privacy practices

  • Review their privacy policies before providing information

14. Changes to This Privacy Policy

  • We may update this Privacy Policy periodically

  • Changes will be posted with updated date

  • Material changes will be notified via email

  • Continued use constitutes acceptance of changes

15. State-Specific Rights

15.1 California Residents (CCPA/CPRA)

  • Right to know what personal information is collected

  • Right to delete personal information

  • Right to opt-out of sale (we do not sell your information)

  • Right to non-discrimination

15.2 European Residents (GDPR)

  • Right to access and data portability

  • Right to rectification and erasure

  • Right to restrict processing

  • Right to object to processing

  • Right to lodge a complaint with supervisory authority

16. Contact Information

16.1 Privacy Officer

For privacy-related questions or to exercise your rights:

  • Email: privacy@fakeeh.Base Modul

  • Phone: [Privacy Officer Phone]

  • Address: [Privacy Officer Address]

16.2 Security Team

For security concerns:

16.3 HIPAA Complaints

To file a HIPAA complaint:

  • Contact our Privacy Officer (above)

  • File with the U.S. Department of Health and Human Services

17. Effective Date

This Privacy Policy is effective as of November 26, 2025, and will remain in effect except with respect to any changes in its provisions in the future, which will be in effect immediately after being posted on this page.

18. Consent

By using our Service, you consent to our Privacy Policy and agree to its terms. If you do not agree with this policy, please do not use our Service.


We are committed to protecting your privacy and the security of your health information. If you have questions or concerns, please contact us.