Read this first — who owes this notice, and who does not
Gale Care Inc. is not the covered entity that owes you this notice, and this is not Gale's notice.
A Notice of Privacy Practices is an obligation of a covered entity — under federal health-privacy law, a health plan, a health care clearinghouse, or a health care provider who bills electronically (45 CFR 160.103; 45 CFR 164.520). Gale Care Inc. is a health-technology company and an administrative-services organization. Gale does not practice medicine. Licensed clinicians practice medicine under their own professional judgment, through clinician-owned professional entities — "the practice." The practice is the covered entity that treats you and that owes you this notice.
Gale is the practice's business associate under 45 CFR 160.103, and will work under a written business associate agreement with the practice before it handles any patient information. (No such agreement is signed today — see "Status of the Gale platform," below.)
So this document is published as a template: the notice that Gale provides to the practices it serves, which each practice adopts under its own name, customizes for its own state and services, and distributes to its own patients. Every place this template says "we," it means the practice — not Gale. Where the template describes something Gale does on the practice's behalf, it says "Gale" by name.
Nothing in this document should be read to suggest that Gale Care Inc. provides health care, or that Gale is the party responsible to a patient under 45 CFR 164.520. It is not.
Status of the Gale platform — read before relying on anything below
Gale is pre-commercial. Today the product runs on synthetic demonstration data.
There is no real patient record, no real clinical note, no real claim, and no real payment in the system. No practice has yet adopted this notice. Gale has not yet signed a business associate agreement with any practice. As to its vendors: the Google Cloud HIPAA Business Associate Addendum was signed on 13 July 2026, covering the Google services that run the database, sign-in, file storage and servers. That agreement does not cover Google's consumer AI endpoint — so the AI calls were migrated to Vertex AI, the covered version of the same model, on the same day. Transcription moved the same way — from Modal, which had no agreement, to Google Cloud Speech-to-Text, a HIPAA-covered Google service inside that same agreement. No agreement yet covers a claims clearinghouse. Those signatures are a legal precondition to real patient data reaching those vendors, and Gale's internal rules treat them as hard gates that fail closed. (Stripe needs no such agreement: a payment processor receiving only payment data is outside HIPAA under 42 U.S.C. § 1320d-8.)
This notice is published now, in draft, so that it can be reviewed before real patients are served rather than after. It describes the terms that will govern when a practice using Gale begins treating real patients.
One honest qualification, because a blanket claim would be false: while no patient data in the system is real, some real personal information of real people does flow through Gale's public surfaces today —
- an email address left to be contacted about care;
- a question typed into the public health chat;
- a phone number left to request an appointment.
Gale does not contact any of those people today. No message and no telephone call has ever been sent or placed to a real person: the scheduling-request record carries a structural never-send marker, no code reads it in order to contact anyone, and the care-finding call feature is built up to the point of dialing and stops there — it is switched off behind a legal gate. If that ever changes, a real phone call to a real office is a real-world act, and labeling the data behind it "synthetic" would not make it so. Gale's Privacy Policy and Terms of Service say the same thing, and none of the three documents may drift from it.
Those surfaces are not covered by this notice, because they are not health care and there is no covered entity involved in them. They are governed by Gale's separate Privacy Policy and Consumer Health Data Privacy Policy. The HIPAA / non-HIPAA split is real, and this notice covers only one side of it. Which side a piece of information is on depends on what the information is, not on who you are: a patient of this practice who reads a Gale health article or types a question into Gale's public chat has generated consumer health data, not protected health information, and this notice does not reach it.
THE NOTICE
Everything from this point forward is the text the practice adopts. In the adopted version, the statement immediately below must appear as the header of the document or otherwise prominently displayed, exactly as written — its wording is prescribed by 45 CFR 164.520(b)(1)(i) and may not be paraphrased, re-cased, or reworded.
THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.
Practice: TBD Effective date: TBD
The short version
The rest of this notice is long because the law requires it to be. Here is what it says.
- We never sell information about you. Not information that identifies you, and not information we have de-identified. Not to anyone, at any price.
- We never use anything we learn about your health to decide what to promote to you — not someone else's product, and not our own.
- You can read your whole record, and get a copy of it. There is one gap in our software today, and we tell you about it rather than let you find it.
- Some research runs on de-identified information from your visit, by default, and you cannot opt out. We explain exactly what is kept, what it cannot do, and the one honest limit on the word "de-identified."
- You can complain to us or to the federal government, and we will not retaliate.
- Who to call: Bill Nguyen, CEO, bill@gale.care
Who we are
We are TBD, a professional entity owned by licensed clinicians. Your clinician works for us, and makes clinical decisions using their own professional judgment.
We use software and administrative services from Gale Care Inc. to run the practice: scheduling, your medical record, video and in-person visits, an AI scribe that helps your clinician write the note from your visit, billing, and payments.
Gale is our business associate. That means Gale handles your health information for us, under a written contract we must have in place before Gale touches your record, and is bound by federal law directly — not just by that contract. Gale does not provide your care and does not decide your treatment.
This notice tells you how we may use and share your health information, and what you can do about it. In this notice, "health information" means protected health information — information about your health, your care, or payment for your care, that identifies you. Where a promise below is deliberately broader than that — where it also covers information we have de-identified — we say so in that sentence.
What we will never do
Federal law lets a practice like ours do some things we have decided not to do. We are allowed to state those self-imposed limits here, and doing so makes them binding on us: we are required to abide by the terms of the notice currently in effect (45 CFR 164.520(b)(1)(v)(B), (b)(2)(i)).
We will never use what we learn about your health to promote anything to you.
Not our services. Not Gale's. Not anyone else's. Whether or not we are paid.
We want to be precise here, because this is a place where the law is narrower than the promise. Federal law defines "marketing" as any communication about a product or service that encourages you to purchase or use it (45 CFR 164.501). A few things are carved out of that definition — talking to you about your own treatment, coordinating your care, describing our own health-related services, and recommending other clinicians or settings of care — and those carve-outs apply only so long as no one pays us to make the communication.
We do not rely on those carve-outs. We will not use your health information to send you a promotional communication of any kind, paid or unpaid, about our services or anyone's. We do not decide who gets a message by looking at what is wrong with them. And we take no payment from any third party in exchange for communicating with you about their product or service.
The only messages we send you are about your care: your appointments, your results, your bill, and how to reach us.
We will never sell information about you.
Federal law defines a "sale" of protected health information broadly: any disclosure where we receive payment — direct or indirect, money or anything else of value — in exchange for your information (45 CFR 164.502(a)(5)(ii)(B)). That prohibition binds Gale directly as well as us.
This promise is wider than the law. It covers information that identifies you and information we have de-identified. Once information is de-identified, federal law stops protecting it, and we could lawfully sell it. We will not. We have not built a business on doing so and we will not build one.
One thing "never sold" does not cover, and we would rather say it than let you assume otherwise. If this practice is acquired, merges, or consolidates with another, or if Gale is bought by another company, patient records generally transfer to the new owner. Federal law permits that as a "health care operation" and does not call it a sale of your information (45 CFR 164.501, "Health care operations," ¶(6)(iv)). We are telling you because we think most people, reading "we never sell your information," would assume it covered this. It does not. What we commit to: if that ever happens, we will tell you before it takes effect, and the commitments in this section will bind whoever holds your record.
We will never accept payment for a recommendation.
When Gale's software suggests a clinician or a setting of care, no one has paid for that placement, and no one ever will. We do not accept, and will not accept, payment, referral fees, or any other consideration in exchange for how a clinician, facility, or service is ranked, matched, or recommended to you. No clinician can buy a higher position. There is no sponsored slot.
You should also know the part that is not a denial: Gale earns a fee when a visit happens and is billed — and the fee is larger when the visit is larger. Gale charges this practice 8% of a self-pay transaction, all-in (card processing included) — or 3.5% when the clinician brings the patient to Gale — and, on an insurance claim, a fixed billing cost of $2.50 per paid transaction plus 15% of the amount the claim pays. It is never charged to you. But that percentage means Gale earns more from a more expensive visit, and Gale earns nothing if a visit is never billed. Gale does not earn more from one clinician than another for the same transaction — the schedule is the same. That is Gale's financial interest, stated plainly, so you can weigh a recommendation yourself. Gale's Privacy Policy states the identical fee.
We will never put advertising or third-party tracking on the pages where you seek care.
Gale's web application ships with no advertising pixel and no third-party analytics package. There is no Google Analytics, no Meta pixel, no Segment, no PostHog, no advertising SDK. The application's entire third-party dependency list is five packages, none of them analytics — you can view the page source and check.
Gale maintains an automated scan (evals/pixel_gate.py) that checks the built application against a list of known tracking hosts and analytics dependencies. We will not tell you that scan blocks the build, because today it does not run automatically — it is a check a person runs. We would rather describe it accurately than claim an enforcement we have not wired.
We do measure how our own pages are used, on our own servers and nowhere else. That is described honestly under "What we measure", below. It is not advertising and it never becomes advertising.
We will never share your information for cross-context behavioral advertising, and we will never build an advertising profile of you.
There is no form that would let us do any of this.
The law provides a form we could ask you to sign to permit marketing, and another to permit a sale (45 CFR 164.508(a)(3), (a)(4)). Neither form exists in this practice. There is nothing you could sign that would let us do either.
These commitments are permanent.
Below, in "Our duties," we reserve the right to revise this notice — as every notice does. That reservation does not reach this section. We will not revise this notice to weaken or remove any commitment in "What we will never do." If we ever change them, it will be to make them stronger. Everything else in this notice we may revise.
The one limit on our limits.
We cannot promise never to disclose your information at all. Some disclosures are required by law — a court order, a mandated report of abuse, a health-oversight audit — and federal law does not let us promise those away. Neither may we limit our ability to act to prevent a serious and imminent threat to someone's safety (45 CFR 164.520(b)(2)(i); 45 CFR 164.512(j)(1)(i)). Those are described below.
Your rights
To exercise any right below, contact our Privacy Officer. We may require your request in writing.
You can see and get a copy of your record
You have the right to inspect and obtain a copy of the health information we hold about you in a designated record set — your medical record, your billing record, and any other records we use to make decisions about you (45 CFR 164.501) — for as long as we keep it (45 CFR 164.524).
- We will act on your request within 30 days. We may extend once, by no more than 30 days, if we tell you in writing why and when we will finish (45 CFR 164.524(b)(2)).
- If we hold it electronically and you ask for an electronic copy, we must give you one — in the form and format you ask for, if we can readily produce it, and otherwise in a readable electronic form we agree on with you (45 CFR 164.524(c)(2)(ii)).
- You can tell us to send a copy directly to someone else. Your request must be in writing, signed by you, and clearly identify the person and where to send it (45 CFR 164.524(c)(3)(ii)).
- We may charge a reasonable, cost-based fee covering only labor for copying, supplies, postage if you ask us to mail it, and preparing a summary if you agreed to one in advance (45 CFR 164.524(c)(4)).
- We may deny access in limited circumstances. Some denials you have a right to have reviewed by a licensed health care professional who was not involved in the original decision (45 CFR 164.524(a)(3), (a)(4)). Psychotherapy notes are not subject to the right of access (45 CFR 164.524(a)(1)(i)).
Open notes — you get your record, not a summary of it
We do not hide your record from you. You can read your clinician's visit notes, your test results, your medications, and your diagnoses. We do not delay, obstruct, or charge you out of an unwillingness to share (21st Century Cures Act; 45 CFR Part 171).
One gap exists today, and we would rather tell you than have you discover it. The Assessment section of your clinician's visit note — their reasoning about what is going on with you — is not currently displayed in the patient portal. That is a limitation of our software, not a decision about you or your care. The law entitles you to it (45 CFR 164.524). Ask our Privacy Officer and we will give it to you. We are fixing the portal.
There are risk scores about you, and here is where you stand
Our software computes internal risk signals about you. They help your clinician, and they help improve the engine. Three things you should know.
- They exist. We are not going to pretend otherwise.
- You cannot see them in the app today. Neither can a family member: the collections that hold risk are denied to patient and family accounts by the database's security rules, and the collections a family can read have no risk field at all. That is a protection against others seeing a label about you — it is not a reason you may not have it.
- If a score is ever shown to your clinician and used in a decision about your care, it becomes part of your medical record and you have the right to ask for it (45 CFR 164.501, "Designated record set," ¶(1)(iii); 45 CFR 164.524). Write to our Privacy Officer and we will give it to you.
You can ask us to correct your record
If you think information in your record is wrong or incomplete, you can ask us to amend it (45 CFR 164.526). We may deny the request — for example, if we did not create the information, or if we determine it is accurate and complete — and if we do, we will tell you why in writing, and you may submit a statement of disagreement that we will keep with the record.
You can get a list of certain disclosures — but it is narrower than it sounds
You have the right to an accounting of disclosures of your health information that we made in the six years before your request (45 CFR 164.528). We will act within 60 days, with one possible 30-day extension. The first accounting in any 12-month period is free.
We want to set your expectation honestly, because this right disappoints people. The list will not include the disclosures we make for your treatment, for billing, or to run the practice, and it will not include anything you told us to send, or disclosures made to you. Those are the great majority of disclosures. What the list will show are the unusual ones — a court order, a public health report, a disclosure required by law.
If what you actually want to know is who looked at your chart, ask us that directly. See "Who can actually read your chart," below.
You can ask us to restrict what we share — and one restriction we must honor
You may ask us to restrict how we use or share your information for treatment, payment, or health care operations — and you may ask us to restrict what we share with a family member, friend, or anyone else involved in your care or in paying for it (45 CFR 164.522(a)(1)(i)(A)–(B)). We are not required to agree — with one exception, and it matters:
If you pay for a service out of pocket, in full, you may require us not to tell your health plan about it. We must honor that request, unless the disclosure is required by law (45 CFR 164.522(a)(1)(vi)). Tell us before or at the time of the visit.
You can ask us to contact you a different way
You may ask us to communicate with you by a different means, or at a different address — a different phone number, a different mailing address, no voicemail. We will accommodate reasonable requests, and we will not ask you why (45 CFR 164.522(b)).
You can get this notice in a form you can use
If English is not your first language, or if you need this notice in large print, braille, or another accessible format, ask us and we will provide it at no cost to you.
You can get a paper copy of this notice
Even if you agreed to receive it electronically, you may ask us for a paper copy at any time, and we will give you one (45 CFR 164.520(b)(1)(iv)(F)).
You will be told if your information is breached
If there is a breach of unsecured health information about you, we will notify you — without unreasonable delay and in no case later than 60 days after we discover it (45 CFR 164.404). Gale, as our business associate, is required to notify us of any breach it discovers, within 60 days (45 CFR 164.410).
If you cannot act for yourself
If you have a personal representative — the person legally entitled to act for you, such as a guardian, a person holding your health care power of attorney, or the executor of your estate — that person may exercise these rights on your behalf, and we may need to see documentation of their authority. (There is an important exception for adolescents; see "Minors, guardians, and confidential care," below.)
How we may use and share your health information without asking you first
Treatment
We use your health information to provide, coordinate, and manage your care.
Example: Your clinician reviews your medication list and your last visit's note before your appointment, and sends a prescription to your pharmacy. If you are referred to a specialist, we may send that specialist the relevant part of your record so they can treat you.
Example — appointment reminders and care coordination. We send you appointment reminders — a text or an email with the time, a link, and a code, and nothing about why you are coming. We may contact you about treatment alternatives, and we may recommend another clinician or a different setting of care when that is what your care needs. Federal law does not treat these as marketing (45 CFR 164.501, "Marketing," ¶(2)(ii)(A), (C)), and we take no payment from anyone to send them. They are the only kinds of message we send. (45 CFR 164.520(b)(1)(iii)(A).)
Example — the AI scribe. During a visit, your clinician may use an AI scribe that records the conversation and produces a draft note, which your clinician then edits and signs. You can say no. How it works, what it records, and where the audio goes are described exactly under "How Gale's technology handles your information" below — not in general terms.
Payment
We use and share your health information to bill and be paid for your care.
Example: We send a claim to your health plan containing your name, your diagnosis codes, and the services you received, so the plan will pay for the visit. We may check whether you are eligible for coverage before your appointment, and we may give you a Good Faith Estimate of what you will owe.
Health care operations
"Health care operations" is a broad category in federal law, and it is the widest permission we have. We would rather name it than let it do quiet work. It covers running a medical practice: assessing quality, reviewing clinicians' performance, training staff, auditing our billing, our legal and business work, and fraud and compliance activity (45 CFR 164.501).
Example: A clinician supervisor reviews a sample of visit notes for quality. We look at how long patients wait for an appointment. We train our staff.
The limits we place on ourselves here, because this is where companies usually are not exact:
- We do not use "health care operations" to contact you with promotional communications about treatment alternatives, our own services, or anyone else's — even though the definition would permit some of that (45 CFR 164.501, ¶(1)–(2)). See "What we will never do."
- We do not use your health information for business planning, business development, or fundraising (45 CFR 164.501, ¶(5), ¶(6)(v); 45 CFR 164.514(f)).
- We do not use information that identifies you to build products or train models under this heading. We do use de-identified signals derived from visits — including yours — to improve Gale's software. That is described under Research, below, where the rules are stricter and where we tell you exactly what is kept. We are pointing at it rather than hiding it under "operations," which is where this use is usually hidden.
Business associates
We share your health information with Gale Care Inc. and, through Gale, with the vendors that run the platform's infrastructure. Each must be bound by a written business associate agreement that limits what they may do with it and requires them to safeguard it. They are listed by name later in this notice, with the honest status of each agreement.
To people involved in your care
Unless you tell us not to, we may share information relevant to your care with a family member, friend, or other person you involve in your care or in payment for it, and we may use it to notify someone of your location or condition (45 CFR 164.510). You can ask us to restrict this — see "Your rights," above.
Other ways we may use or share your health information without your permission
Federal law permits or requires each of the following, under conditions the law sets out (45 CFR 164.512). Where a stricter law applies — including 42 CFR Part 2 for substance use disorder records, or a stricter state law — we follow the stricter law.
| Purpose | What it means | Citation |
|---|---|---|
| Required by law | When a federal, state, or local law requires the disclosure, we make it — limited to what the law requires. | 45 CFR 164.512(a) |
| Public health | Reporting disease, injury, births and deaths; reporting a reaction to a medication or a problem with a product; notifying someone who may have been exposed to a disease. | 45 CFR 164.512(b) |
| Abuse, neglect, or domestic violence | Reporting to a government authority authorized to receive such reports, as the law requires or permits. | 45 CFR 164.512(c) |
| Health oversight | Audits, investigations, inspections, and licensure actions by agencies that oversee the health care system. | 45 CFR 164.512(d) |
| Judicial and administrative proceedings | In response to a court or administrative order; or to a subpoena or discovery request, only if the required assurances about notifying you or protecting the information are satisfied. | 45 CFR 164.512(e) |
| Law enforcement | In the limited circumstances the rule allows — for example, in response to a court order or grand jury subpoena, to identify or locate a suspect, or about a crime on our premises. | 45 CFR 164.512(f) |
| Decedents | To a coroner or medical examiner to identify a deceased person or determine cause of death, and to funeral directors as necessary. | 45 CFR 164.512(g) |
| Organ and tissue donation | To organ procurement organizations, for donation and transplantation. | 45 CFR 164.512(h) |
| Research | Only as described in the Research section below. | 45 CFR 164.512(i) |
| To prevent a serious threat to health or safety | When we believe in good faith that a disclosure is necessary to prevent or lessen a serious and imminent threat to you or to someone else, to a person able to prevent the threat. | 45 CFR 164.512(j) |
| Military, veterans, and national security | For activities of the armed forces, for security clearances, and for authorized national-security and intelligence activities. | 45 CFR 164.512(k) |
| Correctional institutions | If you are an inmate, to the institution, in the circumstances the rule allows. | 45 CFR 164.512(k)(5) |
| Workers' compensation | As authorized by and necessary to comply with workers' compensation laws. | 45 CFR 164.512(l) |
We apply the minimum necessary standard to these uses and disclosures: we limit what we use, disclose, and request to the least information needed to accomplish the purpose (45 CFR 164.502(b)). This standard binds Gale directly as well.
Redisclosure. Once we disclose your information to someone who is not a health care provider, health plan, or business associate — a court, an employer's workers' compensation carrier, a law enforcement agency — that recipient may be permitted to share it further, and it may no longer be protected by the federal privacy rule (45 CFR 164.520(b)(1)(ii)(H)).
Our commitment on reproductive and gender-affirming care. We will not disclose information about lawful reproductive health care or gender-affirming care that you sought, obtained, or that we provided, for the purpose of investigating or bringing a proceeding against you, or against the person who provided or helped you get that care — except where a law we cannot lawfully refuse compels us. If we receive such a request, we will resist it to the extent the law permits.
Uses and disclosures that require your written permission
Some uses require your written authorization — a specific, separate document you sign (45 CFR 164.508).
Psychotherapy notes
If your clinician keeps psychotherapy notes — notes analyzing the contents of a private counseling conversation, kept separate from the rest of your medical record — we will not use or disclose them without your written authorization, except in the narrow circumstances the law allows (45 CFR 164.508(a)(2)).
Marketing, and the sale of your information
Both require your written authorization under federal law (45 CFR 164.508(a)(3), (a)(4)). We do neither, we will never ask you to authorize either, and no such form exists in this practice. See "What we will never do," above.
Everything else
Any other use or disclosure of your health information not described in this notice will be made only with your written authorization, and you may revoke that authorization at any time, in writing, except to the extent we have already acted in reliance on it (45 CFR 164.508(b)(5)).
Research
We conduct research — to make care better, and to improve the tools your clinician uses. This section applies to every patient, so we have given it its own place rather than filing it under a heading about permission.
Research we do without asking you — on de-identified information
By default, research runs on de-identified information, and you cannot opt out. We would rather say that plainly than let you assume otherwise.
After your visit, the platform retains one small record — a signal. It contains:
- the area of care (for example, behavioral health);
- the kind of intervention and a coarse band describing what happened;
- a broad age range — under-18, 18–25, 26–39, 40–64, or 65 and older where it is computed from your record, and on some paths simply "adult" or "12–14". Every age above 89 sits inside a single top band, and no value is ever narrower than the de-identification rule allows;
- a broad geographic region — a multi-state U.S. Census division. Never your state, your city, or your ZIP code.
It carries no name, no patient identifier, no encounter identifier, and no date of any kind.
And there is no key. The signal is written and then deliberately orphaned: its identifier is not stored on the visit record, and no part of Gale's software hands it out. Nothing turns a signal back into a visit.
That sentence became true on 13 July 2026. Before that date Gale did keep such a link, and an earlier draft of this notice disclosed it as an unresolved defect. It was removed rather than explained away, and an automated test now fails Gale's build if any record is found holding a signal identifier beside a patient identifier.
The method the practice asserts is Safe Harbor (45 CFR 164.514(b)(2)) — all eighteen identifier categories removed, no dates, no geography finer than a State, no free-text narrative, and every age over 89 inside a single top band. Gale's Privacy Policy and Terms of Service assert the same method. Safe Harbor also requires that no re-identification code be held (45 CFR 164.514(c)); with the link above removed, that condition is met.
What that means for you. Once information is de-identified, the law stops treating it as yours. It is no longer "protected health information," the rules in this notice no longer apply to it, and we may keep it and study it indefinitely without asking you (45 CFR 164.502(d)(2)). That is a real transfer, and we are not going to describe it in language that hides its size. A covered entity may direct its business associate to perform the de-identification (45 CFR 164.502(d)(1)).
And you should know who benefits. Gale Care Inc. is a for-profit company, and the tools this research improves are tools Gale sells. Better care and Gale's commercial interest point the same way here. We would rather you knew that than discovered it.
Research that requires your signature — on information that identifies you
Research on information that still identifies you almost always requires your signature — and there are three narrow exceptions, which we list rather than bury.
We do not use your information for research, and Gale does not train any model on it. If that ever changed, we would first have to obtain a separate, written HIPAA Authorization from you (45 CFR 164.508) — and signing it could never be made a condition of your care. No such authorization exists, none is published, and nobody has been asked to sign one.
- is its own document, signed on its own — never bundled into your booking flow, your treatment consent, or your financial agreement;
- you may revoke it at any time, in writing. When you do, we stop using your identifiable information for research from that point forward. We cannot undo analyses already completed, or pull your contribution back out of data that was already de-identified — that is the honest limit the law recognizes (45 CFR 164.508(b)(5)(i)) — but nothing new happens after you withdraw;
- is never a condition of receiving care. You do not have to sign it. Your care will be exactly the same either way. Federal law requires the authorization form itself to say this (45 CFR 164.508(c)(2)(ii)(A)), and we are repeating it here.
The three exceptions. Federal law permits identifiable information to be used for research without your signature in three narrow situations, and we would rather you knew about them now than found out later (45 CFR 164.512(i)(1)):
- when an independent ethics committee — a board of clinicians, researchers, and community members that reviews studies, which federal law calls an Institutional Review Board, or a Privacy Board — reviews the study and approves a waiver, finding that it poses no more than minimal privacy risk and could not practicably be done otherwise (45 CFR 164.512(i)(1)(i), (i)(2)(ii));
- for a researcher's preparation of a research protocol, where no information leaves the practice (45 CFR 164.512(i)(1)(ii));
- for research about people who have died (45 CFR 164.512(i)(1)(iii)).
Our commitment: we do not currently conduct research under an IRB or Privacy Board waiver of authorization. If we ever intend to, we will revise this notice first.
A note about a different form you may have seen
If you asked us to send a summary of your visit to a clinician you named, you signed a clinical summary share authorization. That form covers one disclosure, to one clinician you chose, and it expires shortly after your appointment. It does not authorize research. Research on identifiable information requires the separate authorization described above.
Substance use disorder records — 42 CFR Part 2
Records of substance use disorder treatment from a federally-assisted "part 2 program" — a substance use treatment program that receives federal support, which most do — get extra protection under 42 CFR Part 2, which is stricter than HIPAA. Where Part 2 applies, it wins.
The most important differences:
- Records, or testimony relaying their content, may not be used or disclosed in any civil, criminal, administrative, or legislative proceeding against you unless you gave specific written consent, or a court entered an order after you (or the record holder) got notice and an opportunity to be heard. A court order authorizing disclosure must also be accompanied by a subpoena or other legal mandate compelling disclosure. A subpoena alone is never enough. (42 CFR 2.13; 45 CFR 164.520(b)(1)(iii)(D).)
- Most disclosures require your written consent, including for treatment, payment, and health care operations — though you may give a single consent covering all future treatment, payment, and operations uses, valid until you revoke it in writing (42 CFR 2.31, 2.33).
- Minors: if state law lets a minor consent to substance use disorder treatment on their own, only the minor may consent to a disclosure — including a disclosure to a parent, and including a disclosure made to obtain payment (42 CFR 2.14).
- Part 2 programs must give their own patient notice, with its own required header text, different from the one at the top of this notice (42 CFR 2.22).
Minors, guardians, and confidential care
If you are a parent or guardian, you generally have the same rights over your child's health information that your child would have. There is an important exception, and it is deliberate.
In every state, there are categories of care a minor may consent to on their own — the categories vary by state, but commonly include mental health care, care related to sexual and reproductive health, care after a sexual assault, and substance use disorder treatment. Where a minor lawfully consents to care alone, the minor — not the parent — controls that part of the record, and a parent is generally not the person legally entitled to act for the minor on it (the law calls that a "personal representative") — 45 CFR 164.502(g)(3); state law governs the details.
Two halves of the same protection, and both matter:
- The young person keeps full access to their own record — all of it. The protection restricts what a parent or guardian can see through the portal. It never restricts what the young person themselves can see about their own care.
- A guardian keeps access to everything that is not protected. Over-blocking and under-blocking are both failures.
How that separation is maintained today, honestly. Where a minor lawfully consents to care alone, we maintain the separation by our staff, under a written policy. Our software does not yet enforce it automatically, and we are not going to describe an automatic protection we have not built. Withholding information to protect an individual's privacy, consistent with a written, consistently-applied policy, is a recognized exception to the federal information-blocking rule (45 CFR 171.202) — but it requires the policy to exist in advance, which is why we say "policy" and not "software."
State law
State law may give you more protection than federal law, and where it does, we follow state law. Many states impose stricter rules on mental health records, HIV/AIDS information, genetic information, reproductive and sexual health information, and records of care a minor consented to alone. Some states require your written consent for disclosures that federal law would permit without it.
Our duties
- We are required by law to maintain the privacy and security of your health information, to give you this notice of our legal duties and privacy practices, and to notify you following a breach of unsecured health information (45 CFR 164.520(b)(1)(v)(A)).
- We are required to abide by the terms of the notice currently in effect (45 CFR 164.520(b)(1)(v)(B)). That includes every self-imposed limit above.
- We will not use or share your information in ways not described here without your written permission, and you may revoke that permission.
- We are required to enter into a written business associate agreement with Gale and with every vendor that handles your health information for us, and to obtain the same assurances from their subcontractors (45 CFR 164.502(e), 164.504(e)).
We reserve the right to change this notice. We may change our privacy practices and make the new notice apply to health information we already have as well as to information we receive in the future (45 CFR 164.520(b)(1)(v)(C)). If we make a material change, we will not put it into effect before the effective date of the revised notice. We will post the revised notice, make it available at our office if we have one, and give you a copy at your next visit or on request.
One limit on that right, and it is binding: we will not revise this notice to weaken or remove any commitment in "What we will never do." Not selling information about you, not using it to promote anything to you, not taking payment for a recommendation, and not putting advertising or third-party trackers on the pages where you seek care are permanent. If we ever change them, it will be to make them stronger.
Complaints
If you think your privacy rights have been violated, tell us. Contact our Privacy Officer. We will investigate.
You may also complain directly to the federal government, and you do not have to complain to us first. File with the U.S. Department of Health and Human Services, Office for Civil Rights:
- Online: https://ocrportal.hhs.gov/ocr/cp/complaint_frontpage.jsf
- By mail: Centralized Case Management Operations, U.S. Department of Health and Human Services, Office for Civil Rights, 200 Independence Avenue SW, Room 509F, HHH Building, Washington, D.C. 20201
- By email: OCRComplaint@hhs.gov
- By phone: (800) 368-1019 · TDD: (800) 537-7697
A complaint must generally be filed within 180 days of when you knew the act happened.
We will not retaliate against you for filing a complaint. Not in your care, not in your billing, not in any way. (45 CFR 164.520(b)(1)(vi); 45 CFR 164.530(g).)
How Gale's technology handles your information
This section is not required by 45 CFR 164.520. We include it because you cannot judge a privacy promise you cannot see, and because a notice that describes an architecture the software does not have is a false statement. Everything below is what the code actually does.
The AI scribe — and where the audio actually goes
Your clinician may use an ambient AI scribe. It records the conversation and drafts the note, which your clinician then edits and signs. We say "records," not "listens," because that is what it does.
You can say no. Tell your clinician you do not want the scribe used, and it will not be used. Your care will be exactly the same, and we will not ask you why.
If it is used, your voice is recorded. A recording of your voice is itself an identifier under federal law — it can identify you the way a fingerprint can (45 CFR 164.514(b)(2)(i)(P)). That is why what happens to the audio matters, and why we describe it exactly rather than in general terms.
What happens to the audio depends on how the visit is conducted, and we will not blur the difference.
- If your clinician is using the Gale iPhone app: the audio is turned into text on the phone itself, and the note is drafted on the phone itself. The audio never leaves the device. No transcript and no cloud model are involved, and there is nothing to restore, because your name never leaves the device in the first place.
- If your clinician is using Gale in a web browser: the audio is sent to Google's Speech-to-Text service to be turned into text. That audio is not de-identified first — it contains whatever was spoken, including names. Gale does not store the audio: it is passed through in memory and is not written to Gale's storage. That service is covered by the Google Cloud HIPAA Business Associate Addendum signed 13 July 2026, and Gale is not enrolled in its data-logging program, so the audio is not retained to improve Google's products. (This path used Modal, which had no agreement, until 13 July 2026; Modal is retired.)
- Then, on the web only: once the transcript comes back, identifiers are stripped from it on your clinician's own computer before the text is sent to the model that drafts the note. The map that restores your name for your clinician stays on that computer and is never transmitted. The de-identified signal the platform retains carries no map and no key — subject to the one honest limit described under Research, above.
How well does the stripping work? We measure it, and we will tell you the number.
Gale tests the identifier-stripping engine against a benchmark of labeled clinical transcripts before every release. It must catch every direct identifier — every name, Social Security number, record number, phone number, email address, address, and date — with no misses, or the release is blocked. Across all eighteen categories of identifier that federal law names, it must catch at least 95%.
That is a high bar, and it is not the same as a guarantee. No automated system is perfect. The benchmark is built from synthetic transcripts rather than real ones, and a real conversation may not resemble it. We would rather tell you that than imply a certainty we cannot prove. This engine runs on the web path. On iPhone, the note never leaves the device, so there is nothing to strip — and the phone's simpler identifier filter is not covered by that benchmark.
Video visits
Telehealth video and audio run peer-to-peer — directly between your device and your clinician's. Gale does not use a video-conferencing vendor, and the picture and sound of your visit do not pass through a Gale server or a video vendor's server.
Two things you should still know:
- To find each other across the internet, the two devices exchange network addresses (IP addresses) — and that exchange is coordinated through our database provider (Google/Firebase), so your IP address is written there. Both devices also contact a public Google STUN server to discover those addresses, so Google learns that a connection is being set up and from where. Google never sees the content of your visit.
- If a direct connection cannot be made because of your network, a relay server (TURN) would be needed to carry the picture and sound — and a relay does see the (encrypted) stream. No relay is configured today; the capability is switched off (
claudia-backend/app/rtcconfig.pyreturns public STUN only unless relay credentials are set). We will name the relay operator in this notice and in the vendor table below, and sign a business associate agreement with it, before we ever turn it on. We are not going to say "there is no vendor" and then quietly add one.
Payments
Your payment card and the amount you owe go to Stripe.
No clinical detail can reach Stripe — not a diagnosis, not a procedure code, not a date of service. Stripe receives only an amount, a currency, and an opaque identifier. This is enforced by a single chokepoint in the code that every payment must pass through, in test and in production alike: it rejects any payload containing anything but the permitted fields, and it rejects any value shaped like a date, a Social Security number, a diagnosis code, or a procedure code. A description field cannot even be represented in a form the payment system will accept. An automated test confirms no code path goes around it — that test is not yet wired into the deploy pipeline, so we describe it as a test and not as a build gate.
Your invoice — which we hold, not Stripe — says "Visit" and a date. It does not say why you came. The invoice lives in our records. It is never sent to Stripe.
Messages and calls
Messages. Text messages and emails we send you carry logistics only — your name, a link, a code. Never a diagnosis, a score, or a risk band. The system that sends them fails closed: if a person is not confirmed reachable and consented, nothing is sent.
Calls. No call has ever been placed through Gale, and none is placed today — the feature is built up to the point of dialing and stops there, behind a legal gate. If it is ever switched on, the audio of the call would pass through our telephony provider (Twilio) to connect it, the way any phone call passes through a carrier, and Gale would not record it (recordingOn: False is fixed in the code). Twilio would not merely be a logistics rail, and we are not going to describe it as one. Gale's Terms of Service and Consumer Health Data Privacy Policy describe the same switched-off feature.
What we measure
Gale counts how its own pages are used, so it knows whether people find care. We would rather tell you this exists than let you find it.
When you view a health article, start a search, or start or complete a screener, Gale's own server records a small event: which page, which screener, and which site referred you — joined only by a random code that lives in your browser tab and is destroyed when you close it.
That event carries no name, no email, no account identifier, and none of your words. The server discards those fields even if they were sent by mistake. Nothing goes to any third party, and none of it is ever used for advertising. This is measurement, not surveillance.
What you can choose to share
If you read health articles on Gale, the list of what you read is stored on your device, in your browser. It is not sent anywhere automatically, and it is never sent to anyone but your clinician.
Before a visit, you may choose to turn on a toggle that shares the topics you have been reading with your clinician, so they know what is on your mind. If you leave that toggle off, the list never leaves your device. You can clear it at any time.
Cookies
Gale sets no advertising cookie and no third-party tracking cookie. On the pages where you seek care, Gale sets no cookie at all.
(The one cookie Gale uses anywhere is a first-party token on the pages where clinicians apply to join, so Gale knows which colleague referred them. It is deleted when they sign up, and it never appears on a patient page.)
Signing in stores a session in your browser's own storage, on your device, so you stay signed in. It is not a tracking cookie and it is not shared with anyone.
Who can actually read your chart
Your clinician and the practice staff involved in your care and your billing can read your record.
Gale employees can technically access the systems that hold it — someone has to be able to fix the software. We are not going to write a comforting sentence here that our access controls do not actually earn.
The vendors that handle your information — and the honest status of each agreement
Federal law requires us to have a written business associate agreement with each vendor that handles your health information (45 CFR 164.502(e), 164.504(e)). One has been signed: the Google Cloud HIPAA Business Associate Addendum of 13 July 2026, which reaches the services on Google's HIPAA-eligible Covered Products list — the database, sign-in, file storage, the servers this runs on, the AI model on Vertex AI, and transcription. The rest are not signed, and most of those vendors are switched off for that reason. Each unsigned agreement is a hard precondition to real patient information reaching that vendor. The table gives the status one vendor at a time, because there is no single answer.
| Vendor | What it handles | Business associate agreement |
|---|---|---|
| Gale Care Inc. | The platform: record, scheduling, scribe, billing | Not signed. |
| Google Cloud / Firebase | The database, sign-in, and file storage — everything. Also the signaling channel for video visits, so your IP address is written there | ✅ Signed 13 July 2026 (Google Cloud HIPAA Business Associate Addendum), covering Google's HIPAA-eligible services, which is what this runs on |
| Google (Gemini on Vertex AI) | Text sent to the AI model: note drafting, chart assistance, document summaries | ✅ Covered by the Google Cloud HIPAA Business Associate Addendum signed 13 July 2026. Gale previously used Google's consumer AI endpoint, which that agreement does not cover; it was migrated to Vertex AI — the HIPAA-eligible version of the same model — on the same day |
| Google Cloud Speech-to-Text | Visit audio from web visits, for transcription | ✅ Covered by the Google Cloud BAA signed 13 July 2026 (replaced Modal) |
| Stripe | Payment amounts and opaque identifiers only — no clinical detail | Not required. A payment processor that receives only payment data is outside HIPAA (42 U.S.C. § 1320d-8, the payment-processing exemption); Stripe is not a business associate and does not sign these agreements. The exemption holds because no clinical detail can reach it — see “Payment” above |
| Twilio | Phone numbers; text-message logistics (a name, a link, a code); and, if the call feature is ever switched on, the live audio of the call. No call is placed and no message is sent today. Calls are not recorded | Not signed |
| Mailgun | Email addresses and logistics bodies | Not signed |
| Claims clearinghouse | Claims sent to your health plan | Not signed. Not in use — claims are currently simulated |
| TURN relay (video) | Nothing today — the relay is switched off. If it is ever turned on, it would carry the encrypted picture and sound of your visit | Not applicable — not in use. |
| Vercel | Web hosting — request logs, including your IP address and the page you asked for. On a health site, the page you asked for can itself be sensitive. These logs are never used to build a profile of you and are never used for advertising | Not signed. |
| Google Cloud Run | API hosting — request logs for the servers the app talks to | ✅ Covered by the Google Cloud BAA signed 13 July 2026 (Cloud Run is on Google's HIPAA-eligible Covered Products list) |
Gale operates other services that are not part of your care and are not covered by this notice — a public health-article library, screening tools, a care-finding service that can call a clinic on a person's behalf before they are anyone's patient, and the Gale Care consumer app, which a person uses on their own account with no clinician and no practice involved. Anything you make for yourself in that app — including a plan you build from research papers you chose — is your own material, not the practice's medical record, and this notice does not govern it (Gale's Constitution records that as ruling PC-2). Those services use additional vendors, including OpenAI, and are described in Gale's Privacy Policy and Consumer Health Data Privacy Policy, not here.
How long we keep your information
We keep your medical record for at least six years, as federal law requires (45 CFR 164.530(j)), and longer where the law of your state requires it — for a child's record, often until some years after they reach adulthood. Signed authorizations, and each version of this notice, are kept for six years as well (45 CFR 164.316(b)(2)).
A treatment record is not deleted on request. Federal law gives you no right to erase it and state law requires us to keep it, so the deletion right you have over other kinds of data does not reach your chart. The non-medical information you give Gale's public surfaces — a chat message, a waitlist email, a callback request — is kept on a shorter, fixed schedule and then deleted automatically; that is described in Gale's Privacy Policy and Consumer Health Data Privacy Policy, not here, because it is not part of your medical record.
Contact
Privacy Officer: Bill Nguyen, CEO Telephone: TBD Email: bill@gale.care Address: TBD
Effective date of this notice: TBD
For the practice adopting this template — a checklist
- Delete the scaffolding. Before you distribute this notice to a patient, delete this checklist and the "Read this first" and "Status of the Gale platform" preambles. They are drafting apparatus, not patient-facing text. The body of the notice is written to stand alone and to be true standing alone — no sentence in it describes a control the software does not have. Do not "fix" the body by moving a gap back into a counsel block.
- Replace every remaining placeholder token. A notice with a blank contact or a blank effective date is not compliant.
- Add the state supplement for every state in which you treat patients (45 CFR 164.520(b)(1)(ii)(C); 45 CFR 160.202).
- Answer the Part 2 question. If you provide substance use disorder treatment, you need the additional notice required by 42 CFR 2.22, with its own header.
- Answer the fundraising question (45 CFR 164.520(b)(1)(iii)(A)).
- Work through the open items in the review memo with your counsel. Several of them describe software that does not yet do what a practice would need it to do. They are build items, not drafting items. The ones marked BLOCKING must be closed before a real patient is seen.
- Distribute it. As a provider with a direct treatment relationship you must give this notice no later than the date of first service, including a service delivered electronically; make a good-faith effort to get a written acknowledgment of receipt, and document the effort if you do not get one; post it prominently at any physical site; and prominently post it on your web site (45 CFR 164.520(c)(2), (c)(3)).
- Version it and keep the old ones. Retain copies of every notice you issue, and every acknowledgment, for six years (45 CFR 164.520(e); 164.530(j)).
- Do not change a practice first and update the notice later. A material change may not take effect before the effective date of the notice that reflects it (45 CFR 164.520(b)(3)).
Related documents — Gale's, not the practice's
These are published by Gale Care Inc. They govern Gale's software and Gale's own consumer surfaces. They are not this notice, and they do not replace it.**
- Privacy Policy — Gale's. Covers the consumer surfaces (chat, screeners, searches, signups) that this notice does not reach, and describes what Gale's software does with a patient's record on the practice's behalf.
- Consumer Health Data Privacy Policy — the standalone Washington My Health My Data policy. Protected health information is exempt from it (RCW 19.373.100); it governs the other half.
- Terms of Service — the patient's agreement with Gale for the software. It is not a consent to treatment and not a notice of privacy practices; only the practice can give either.