Effective Date: March 1, 2026
Last Updated: March 17, 2026
GLP3 Weight Loss (“GLP3,” “we,” “us,” or “our”) is committed to protecting the privacy and security of your personal and health information. This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you use our website (glp3weightloss.com) and telehealth medical weight loss services.
By using our services, you acknowledge that you have read and understood this Privacy Policy.
1. Information We Collect
1.1 Personal Information
We collect information you provide directly, including:
- Full name, date of birth, and gender
- Mailing address, email address, and phone number
- Government-issued identification (for identity verification when required)
1.2 Protected Health Information (PHI)
To provide medical care, we collect:
- Medical history, current medications, and allergies
- Vital signs, weight, BMI, and lab results
- Physician notes, treatment plans, and prescriptions
- Information related to your weight loss program participation
1.3 Financial Information
- Payment card details (processed and stored by PCI-DSS compliant third-party processors — GLP3 does not store full card numbers)
- Insurance information for coverage verification and billing
- HSA/FSA account details when used for payment
1.4 Technical Information
We automatically collect when you visit our website:
- IP address, browser type, and operating system
- Pages visited, time spent, and referring URLs
- Device identifiers and screen resolution
- Cookie data (see Section 6)
2. How We Use Your Information
We use your information to:
- Provide medical care: Physician evaluations, prescriptions, treatment planning, and ongoing monitoring
- Communicate with you: Appointment reminders, treatment updates, care team messaging, and refill coordination
- Process payments: Program fee billing, insurance claims, and HSA/FSA transactions
- Coordinate with pharmacies: Transmit prescriptions and facilitate medication fulfillment
- Improve our services: Analyze anonymized, aggregated data to improve patient experience and clinical outcomes
- Comply with legal obligations: Meet regulatory, reporting, and legal requirements
3. How We Share Your Information
We share your information only in the following circumstances:
3.1 For Treatment
With pharmacies to fill prescriptions, with laboratories for ordered tests, and with specialists if referred — using only the minimum necessary information.
3.2 For Payment
With insurance companies for coverage verification, prior authorization, and claims processing. With payment processors for program fee collection.
3.3 As Required by Law
In response to valid court orders, subpoenas, or regulatory inquiries. For mandatory public health reporting. For fraud prevention as required by federal and state law.
3.4 With Your Consent
When you explicitly authorize disclosure to a specific party (e.g., sending records to another healthcare provider).
3.5 Business Associates
With third-party service providers who perform services on our behalf (telehealth platform, electronic health records, email systems). All business associates are bound by HIPAA Business Associate Agreements (BAAs).
We do not sell your personal or health information. We do not share your health data with advertisers or marketing platforms.
4. HIPAA Compliance
GLP3 is a covered entity under the Health Insurance Portability and Accountability Act of 1996 (HIPAA). We maintain administrative, technical, and physical safeguards including:
- AES-256 encryption for data in transit and at rest
- Role-based access controls limiting PHI access to authorized personnel
- Regular security assessments and vulnerability testing
- HIPAA-compliant telehealth platforms for all physician consultations
- Workforce training on privacy and security protocols
- Business Associate Agreements with all third-party vendors handling PHI
5. Your Rights Under HIPAA
You have the right to:
- Access: Obtain copies of your medical records
- Amendment: Request corrections to inaccurate records
- Accounting of Disclosures: Receive a log of who your health information has been shared with
- Restriction Requests: Ask us to limit certain disclosures (we will accommodate where feasible)
- Confidential Communications: Request that we contact you through specific channels
- Breach Notification: Be notified if a breach of your unsecured PHI occurs
To exercise these rights, contact us using the information in Section 9.
6. Cookies and Tracking
6.1 Essential Cookies
Required for website functionality — session management, security, and basic features. Cannot be disabled.
6.2 Analytics Cookies
We use anonymized analytics (e.g., Google Analytics with IP anonymization enabled) to understand website usage patterns. This data cannot be linked to individual patients or health information.
6.3 Marketing Cookies
We may use marketing cookies for general advertising purposes. These cookies never contain health information and are not used to retarget individuals based on their medical status.
You can manage cookie preferences through your browser settings.
7. Data Retention
We retain medical records in accordance with applicable state and federal law (typically 7-10 years from the last date of service, longer for certain records). Financial records are retained as required by tax and business regulations. Website analytics data is retained in anonymized form indefinitely.
When records reach the end of their retention period, they are securely destroyed using methods appropriate to the data format.
8. State-Specific Rights
Depending on your state of residence, you may have additional privacy rights under state law (e.g., the California Consumer Privacy Act, Virginia Consumer Data Protection Act, or others). Where state law provides greater protection than HIPAA, we comply with both.
9. Contact Information
For privacy-related questions, HIPAA rights requests, or to report a privacy concern:
- Online: Contact Form
- Email: privacy@glp3weightloss.com
We will respond to all privacy-related requests within 30 days as required by HIPAA.
10. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices, technology, or legal requirements. The “Last Updated” date at the top of this page indicates when the most recent changes were made. Continued use of our services after changes constitutes acceptance of the updated policy.
