Skip to content

Trust center

HIPAA & Health Information

How Concierge Lab separates its public marketing website from protected clinical workflows.

Last updated August 27, 2026 · Draft for review before public launch

01

What HIPAA covers

HIPAA applies to covered entities and business associates as defined by federal law. Whether a particular organization or activity is regulated depends on its role and the information involved; a privacy policy alone does not make a service HIPAA compliant.

02

Public website boundary

This unauthenticated marketing website is not the patient portal. Its forms are limited to basic contact and organization information and explicitly instruct visitors not to submit medical details.

03

Protected platform boundary

Health assessment, identity verification, ordering, results, clinical communication, and other protected workflows are intended for a separate authenticated platform with role-based access, audit logging, encryption, approved vendors, and appropriate agreements.

04

Service providers and BAAs

When a vendor creates, receives, maintains, or transmits protected health information on behalf of a regulated entity, the parties must evaluate business-associate status and execute an appropriate Business Associate Agreement when required.

05

Tracking technologies

No third-party analytics is enabled by this codebase. Tracking on authenticated healthcare pages requires specific legal, privacy, security, vendor, and data-flow review before use. Cookie consent alone is not a HIPAA authorization.

06

Learn more

Authoritative information is available from the U.S. Department of Health and Human Services Office for Civil Rights. This page is operational information, not legal advice or a Notice of Privacy Practices.

Visit HHS health-information privacy resources