Skip to content
TEXPEPS

Last updated: February 1, 2026

TEXPEPS takes the privacy and security of your health information seriously. This page explains, in plain language, what HIPAA is, how we keep our informational pages free of health data, and how the protected health information you enter on our secure intake is safeguarded by our clinical platform.

What is HIPAA?

HIPAA is the federal Health Insurance Portability and Accountability Act. Among other things, it sets national standards for protecting protected health information (PHI) — information that identifies you and relates to your health, healthcare, or payment for healthcare. Examples of PHI include your symptoms, conditions, medications, lab results, weight or dosing details, and the fact that you are receiving a particular treatment, when tied to your identity.

HIPAA applies to “covered entities” (such as healthcare providers and pharmacies) and to their “business associates” — vendors that handle PHI on their behalf. A Business Associate Agreement (BAA) is the contract that requires such a vendor to protect PHI under HIPAA standards.

Our informational pages are intentionally PHI-free

Outside our secure intake, this website does not collect or store health information, and we keep health-data tracking off it by design. The educational and general-information pages do not ask for symptoms, conditions, medications, weight, dosing, or any other health details, and you should not enter them there.

We also keep advertising and analytics trackers that are not covered by a BAA off of any surface that could involve health information. The secure intake itself carries no non-BAA marketing pixels or trackers — that is a deliberate privacy safeguard.

Where your health information is handled

Health information is collected only when you begin our secure intake at /start. What you enter is transmitted securely and processed by Qualiphy PC, our clinical and e-prescribing platform. We require a Business Associate Agreement with any vendor before it processes protected health information on our behalf. The eligibility questionnaire, clinical review, e-prescribing, checkout, pharmacy fulfillment, and records are handled on that platform.

  • We collect PHI only on the secure intake and only to provide your care — never on our informational pages, and never for marketing.
  • We require a Business Associate Agreement with every vendor that touches PHI in the clinical workflow, including Qualiphy PC and the e-prescribing and pharmacy services it integrates, before that vendor processes any patient information.
  • Independent licensed providers and U.S.-licensed pharmacies in the network are responsible, as covered entities, for their own HIPAA obligations and may provide their own Notice of Privacy Practices.

How PHI is safeguarded

On the clinical platform, protected health information is safeguarded using administrative, technical, and physical controls consistent with HIPAA, which typically include:

  • Encryption of data in transit and at rest.
  • Access controls and authentication so only authorized people can view PHI, on a need-to-know basis.
  • Audit logging and monitoring of access to records.
  • Operation on infrastructure that maintains SOC 2 controls and undergoes independent assessment.
  • Business Associate Agreements with vendors that handle PHI, and breach-notification procedures as required by law.

Your privacy rights under HIPAA

When your health information is held by a covered entity, HIPAA gives you rights that generally include the ability to:

  • Access and obtain a copy of your health records.
  • Request a correction to information you believe is inaccurate.
  • Receive a Notice of Privacy Practices describing how your information is used and disclosed.
  • Request restrictions on certain uses and disclosures, and request confidential communications.
  • Receive an accounting of certain disclosures of your information.
  • File a complaint without retaliation if you believe your privacy rights were violated.

Requests involving health information held on the clinical platform are handled through that platform’s and the treating provider’s processes; contact us and we will help direct your request appropriately.

A note on scope

Information collected on our non-clinical pages — such as a name and email submitted through the contact form, or general analytics — is generally not PHI and is governed by our Privacy Policy rather than HIPAA. The secure intake is the one surface where we intentionally collect health information, and it is treated as PHI under the safeguards described above; the contact form is not for clinical questions.

Contact us about privacy

For questions about how your information is handled, contact us at care@texpeps.com. See also our Privacy Policy and Terms of Service.

This page is a plain-language summary for general information and is not legal advice or a Notice of Privacy Practices. It is a template that should be reviewed and adapted by qualified legal and compliance advisors, and aligned with the clinical platform’s and providers’ actual practices, before publication.

← Back to home

Start Your Consultation