DocSearch Health Solutions (“DocSearch,” “we,” “us,” or “our”) operates docsearch.com, a dual-purpose healthcare platform offering (1) telehealth treatment programs facilitated through TelegraMD and its Provider Groups, and (2) a free physician search directory. This Privacy Policy applies to all users of the Platform.
Two Categories of Information DocSearch handles two distinct categories of information: (1) Personal Information — general data like your name, email, and payment details — governed by this Privacy Policy; and (2) Protected Health Information (PHI) — your medical and health data — governed by our HIPAA Notice of Privacy Practices and federal law. PHI receives additional protections required by HIPAA. |
2.1 Information You Provide Directly
Category | Examples | When Collected |
Identity Information | Full name, date of birth, gender | Account registration, eligibility funnel |
Contact Information | Email address, phone number, mailing address | Account registration, payment checkout |
Health & Eligibility Information | Approximate age, treatment interest, symptom selections, eligibility responses | Treatment eligibility funnel (pre-handoff to TelegraMD) |
Payment Information | Credit/debit card details, billing address (processed by third-party payment processor) | Treatment program checkout |
Account Credentials | Username, password (hashed), security preferences | Account creation |
Communications | Messages, support tickets, feedback, survey responses | When you contact us |
Doctor Search Queries | Specialty searches, location inputs, filter preferences | When using the free Physician Search tool |
2.2 Information Collected Automatically
We automatically collect device and technical data (IP address, browser type, operating system), usage data (pages visited, features used), log data (access logs, timestamps), approximate location derived from IP address, and cookie and tracking data as described in Section 7.
2.3 Information from Our Telehealth Partner, TelegraMD
DocSearch’s data relationship with TelegraMD operates on two levels, and we describe both accurately here:
First, in the normal course of operations, DocSearch receives routine transactional data from TelegraMD confirming treatment program status (such as confirmation that a consultation has been completed or that a prescription has been issued) for the limited purposes of billing reconciliation, subscription management, and patient support. This transactional data includes order status, subscription status, and payment confirmation information.
Second, DocSearch maintains authorized administrative access to TelegraMD’s affiliate dashboard systems for the four BAA-permitted purposes described in Section 6.3. Through this authorized dashboard access, DocSearch’s Compliance Officer and other specifically authorized personnel can view patient account information, order history, clinical encounter data, and other information necessary to fulfill patient support, billing reconciliation, quality assurance, and compliance monitoring functions. This dashboard access is governed by a HIPAA Business Associate Agreement and strictly limited by DocSearch’s role-based access control policy (described in Section 6.3).
DocSearch does not independently hold your full clinical medical record. Your medical records, physician notes, diagnoses, and prescriptions are held and controlled by TelegraMD’s Provider Groups as the Covered Entities responsible for your clinical care.
About Our Eligibility Funnel Our treatment eligibility funnel asks basic questions (approximate age, symptom selections, treatment interest) before you are redirected to TelegraMD for full clinical intake. This funnel data — even though it precedes formal medical treatment — may constitute Protected Health Information when combined with your identity. We treat all funnel data with HIPAA-level protections from the moment you select a treatment category. |
We collect information: directly from you when you create an account, complete our eligibility funnel, make a payment, use the doctor search, or contact our support team; automatically through cookies, web beacons, log files, and similar tracking technologies; from TelegraMD through routine transactional confirmation data and through our authorized dashboard access as described in Section 2.3; and from payment processors (transaction confirmations, partial card numbers, fraud signals).
4.1 To Provide and Operate the Platform
4.2 To Improve and Develop the Platform
4.3 For Safety, Security, and Legal Compliance
4.4 For Communications
We do not sell your personal information. We share your information only as described in this section.
Recipient | What We Share | Why / Legal Basis |
TelegraMD (Telehealth Partner via BAA) | Name, contact info, treatment selection, payment confirmation, eligibility funnel data | To facilitate clinical intake, physician evaluation, and prescription services. Governed by HIPAA Business Associate Agreement. See Section 6. |
Provider Groups (via TelegraMD) | Patient identity and treatment information necessary for clinical consultation | TelegraMD routes information to the applicable Provider Group for your state to conduct the clinical evaluation. DocSearch does not share directly with Provider Groups. |
Licensed Pharmacies (via TelegraMD Pharmacy API) | Prescription details, shipping address, patient name | TelegraMD routes fulfilled prescriptions to the dispensing pharmacy through its Pharmacy API. DocSearch does not share directly with pharmacies. |
Payment Processors | Payment card details, billing address, transaction data | To process payments for treatment programs. We do not store full card numbers. |
Cloud Infrastructure Providers | All data we store, subject to BAAs where PHI is involved | To host and operate our platform securely |
Analytics Providers | De-identified or aggregated usage data | To understand how our platform is used. Health data is not used for analytics targeting. |
Email & Communication Providers | Name, email address, communication content | To send transactional and authorized patient notifications |
Customer Support Tools | Name, contact info, support ticket content | To manage and respond to support requests |
Legal & Compliance | Any data required by applicable law | To comply with court orders, subpoenas, regulatory requirements, or law enforcement requests |
Business Transfers | All data held at the time of the transaction | In connection with a merger, acquisition, or sale of assets. We will notify you before your data is transferred. |
With Your Consent | Any data you specifically authorize | For any purpose you explicitly agree to |
We Never Do This DocSearch does not sell your personal information or protected health information to data brokers, advertisers, or any third party for commercial benefit. We do not permit third-party advertisers to use your health data for targeting. We do not share your medical information with your employer, insurer, or family members without your explicit written authorization. |
DocSearch partners with TelegraMD (telegramd.com) and the Provider Groups to provide the clinical and prescription components of our Treatment Programs. Understanding this relationship is important for your privacy.
6.1 The Provider Groups
All medical consultations are provided by independent licensed Provider Groups: Online Medical Care, P.C. (NJ/NY); TMD of Kansas, P.A. (KS); TMD of Texas, P.A. (TX); and TMD of CA, PC (all other states). TelegraMD is the management services organization and technology platform provider for the Provider Groups. TelegraMD does not itself practice medicine.
6.2 How the Handoff Works
6.3 TelegraMD’s Own Privacy Practices
Once you are redirected to telegramd.com, your interactions on that platform are governed by TelegraMD’s own Privacy Policy and HIPAA Notice of Privacy Practices, which are separate from this document. We encourage you to review TelegraMD’s privacy documentation at telegramd.com before submitting your medical history.
6.4 DocSearch’s Authorized Dashboard Access
DocSearch has authorized access to TelegraMD’s affiliate administration dashboards, which contain information about patients who enrolled through our platform. This access is governed by a HIPAA Business Associate Agreement between DocSearch and TelegraMD and is strictly limited to four permitted purposes:
Through this dashboard access, DocSearch’s authorized personnel may view patient account information, order and subscription data, clinical encounter information, and other data accessible in the dashboard system. Access is governed by DocSearch’s documented Role-Based Access Control (RBAC) policy. DocSearch’s Compliance Officer is implementing role-based access controls limiting each staff member to only the data necessary for their specific authorized function. All dashboard access is logged and subject to quarterly review by the Compliance Officer.
6.5 Two Privacy Policies Apply to You
If you enroll in a Treatment Program, your information is subject to both this Privacy Policy (for your DocSearch account and eligibility data) and TelegraMD’s Privacy Policy (for your clinical intake and medical records on the TelegraMD platform). DocSearch and TelegraMD are separately responsible for the data each entity controls. |
We use cookies and similar tracking technologies to operate our Platform, remember your preferences, and understand how the Platform is used.
Cookie Type | Purpose | Duration |
Strictly Necessary | Required for Platform operation — session management, authentication, security, payment processing. Cannot be disabled. | Session / up to 1 year |
Functional | Remember your preferences, language settings, and personalization choices | Up to 1 year |
Analytics | Understand how users navigate the Platform using tools like Google Analytics; data is aggregated and anonymized where possible | Up to 2 years |
Marketing / Advertising | Track referral sources and measure campaign effectiveness. Health data is not used for ad targeting. | Up to 90 days |
7.1 How to Opt Out of Advertising and Analytics Cookies
In addition to your browser’s own cookie controls, you can exercise specific opt-out rights through the following industry tools:
Opting out of advertising or analytics cookies does not affect strictly necessary cookies required for the Platform to function, or your ability to use Treatment Program services.
We retain your personal information for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required by law.
Data Category | Retention Period | Legal Basis |
Account information | Duration of account + 3 years after closure | Business records; dispute resolution |
Eligibility funnel data (health-related) | 6 years from date of collection | HIPAA minimum retention: 45 CFR § 164.530(j) |
PHI accessed via TelegraMD dashboard | 6 years from creation or last effective date, whichever is later | 45 CFR § 164.530(j); Business Associate Agreement with TelegraMD |
Payment & billing records | 7 years | Federal and state tax and financial record requirements |
Support communications | 3 years from resolution | Quality assurance; dispute resolution |
Analytics & usage data | Up to 2 years (aggregated/anonymized) | Platform improvement |
Marketing preferences & consent records | Until you opt out + 3 years | Proof of consent |
Security logs & access records | 3 years minimum; 6 years for HIPAA-related access logs | HIPAA Security Rule; 45 CFR § 164.312(b) |
We implement reasonable and appropriate technical, administrative, and physical safeguards to protect your personal information from unauthorized access, disclosure, alteration, and destruction. Our security measures include:Encryption in transit (TLS 1.2 or higher / HTTPS) and encryption at rest (AES-256 or equivalent)
9.1 Breach Notification
In the event of a breach of unsecured Protected Health Information, DocSearch will provide notifications as follows: to TelegraMD within ten (10) business days of DocSearch’s discovery; to affected Florida residents and the Florida Attorney General within thirty (30) calendar days per Fla. Stat. § 501.171; and to affected individuals and HHS/OCR within sixty (60) calendar days of discovery per 45 CFR §§ 164.404–164.414. If a breach affects 500 or more residents of a single state, we will also provide notice to prominent media outlets in that state. We will notify you by email to the address on your account or by first-class mail.
9.2 FTC Health Breach Notification Rule
Separate from the HIPAA notification obligations above, certain health-related information DocSearch collects — including eligibility funnel data collected before a clinical relationship with a Provider Group is established — may also be subject to the Federal Trade Commission’s Health Breach Notification Rule (16 CFR Part 318). This rule applies to health information held by entities that are not necessarily HIPAA-covered, and requires notification to affected individuals, and in some cases the FTC and the media, following a breach of unsecured information covered by the rule. Where a breach implicates both HIPAA and the FTC Health Breach Notification Rule, DocSearch will provide notice satisfying both frameworks using the timelines described in Section 9.1.
Depending on your location and applicable law, you have the following rights regarding your personal information. To exercise any of these rights, contact us at info@docsearch.com with the subject line “Privacy Rights Request.” We will respond within 30 days.
Right | Description |
Right to Know & Access | Request a copy of the personal information we hold about you and information about how we use it. |
Right to Correct | Request correction of inaccurate or incomplete personal information. |
Right to Delete | Request deletion of your personal information, subject to legal retention obligations and ongoing treatment relationships. |
Right to Opt Out of Marketing | Opt out of marketing communications at any time by clicking “Unsubscribe” in any marketing email or contacting us. |
Right to Portability | Receive your personal information in a structured, machine-readable format where technically feasible. |
Right to Restrict Processing | Ask us to limit how we use your personal information in certain circumstances. |
Note on PHI Requests | For requests relating to your Protected Health Information and clinical records, see our HIPAA Notice of Privacy Practices. For clinical records held by TelegraMD’s Provider Groups, please contact TelegraMD directly at telegramd.com. |
Florida Residents: Additional Rights Under FIPA If you are a Florida resident, the Florida Information Protection Act (Fla. Stat. § 501.171) provides you with specific rights and protections regarding your personal information held by Florida entities such as DocSearch. |
11.1 FIPA Coverage
Florida’s Information Protection Act defines “personal information” to include your name in combination with any of the following: Social Security number; driver’s license number or identification card number; financial account numbers with security codes or passwords; medical history or treatment information; health insurance information; online account credentials (username and password); and geolocation data. DocSearch collects several of these categories.
11.2 FIPA Breach Notification Rights
In the event of a breach of security involving your unencrypted personal information under FIPA, DocSearch will notify affected Florida residents and the Florida Attorney General within thirty (30) calendar days of DocSearch’s determination that a breach has occurred. Notice will be provided to you by email or first-class mail.
11.3 Exercising Your Rights
Florida residents may submit privacy requests to DocSearch at info@docsearch.com with the subject line “Florida Privacy Request.” We will respond within 30 days. For requests relating to medical and health information protected by HIPAA, please also see our HIPAA Notice of Privacy Practices.
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), including the right to know, right to delete, right to correct, right to opt out of sale or sharing (we do not sell or share personal information for cross-context behavioral advertising), right to limit use of sensitive personal information, and right to non-discrimination. Submit California rights requests to info@docsearch.com with the subject line “California Privacy Request.” We will respond within 45 days (extendable by an additional 45 days with notice). Note: PHI collected in connection with healthcare treatment is generally exempt from the CCPA. For health data, see our HIPAA Notice of Privacy Practices.
Beyond Florida and California, a growing number of states have enacted their own comprehensive consumer privacy laws, several of which include provisions specific to health-related data that may apply to information DocSearch collects even where HIPAA does not, such as eligibility funnel responses collected before a clinical relationship with a Provider Group begins.
13.1 Washington and Nevada Consumer Health Data Laws
Washington’s My Health My Data Act and a parallel Nevada statute (SB 370) regulate “consumer health data” broadly, independent of HIPAA coverage. If you are a Washington or Nevada resident, DocSearch will honor applicable rights under these statutes with respect to consumer health data we collect, including rights to access, delete, and withdraw consent for the collection or sharing of such data. Washington’s law includes a private right of action; DocSearch takes its obligations under this statute seriously given TelegraMD’s own domicile in Washington. To exercise these rights, contact info@docsearch.com with the subject line “Washington/Nevada Health Data Request.” |
13.2 Other State Comprehensive Privacy Laws
DocSearch also honors applicable consumer privacy rights — including rights to access, correct, delete, and opt out of certain processing — for residents of other states with comprehensive privacy statutes, including but not limited to Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and Montana. The specific rights available and response timelines vary by state. To exercise rights under any applicable state privacy law not otherwise addressed in this Privacy Policy, contact info@docsearch.com with the subject line “State Privacy Request” and identify your state of residence.
DocSearch’s Platform and Treatment Programs are designed for and offered to residents of the United States. If you access the Platform from outside the United States, including from the European Economic Area (EEA), United Kingdom, or Switzerland, the following applies.
14.1 Legal Basis for Processing (EEA/UK Users)
Where required by the General Data Protection Regulation (GDPR) or the UK GDPR, DocSearch processes your personal information based on one or more of the following legal bases: performance of a contract with you; our legitimate business interests in operating and improving the Platform; compliance with a legal obligation; or your consent, which you may withdraw at any time.
14.2 International Data Transfers
If you access the Platform from outside the United States, your information will be transferred to and processed in the United States, which may not have data protection laws equivalent to those in your jurisdiction. By using the Platform, you consent to this transfer and processing.
14.3 EEA/UK Rights
If GDPR or UK GDPR applies to you, you have rights to access, rectify, erase, restrict, or object to processing of your personal information, and to data portability, in addition to the rights described in Section 10. You also have the right to lodge a complaint with your local data protection authority. To exercise these rights, contact info@docsearch.com with the subject line “GDPR Request.”
Our Platform is intended for adults aged 18 and older. We do not knowingly collect personal information from individuals under 18. If we discover that we have inadvertently collected information from a minor, we will delete it promptly. Contact us at info@docsearch.com if you believe we may have collected information from a minor.
Our Platform may contain links to third-party websites, services, and applications, including pharmacy portals and healthcare provider websites accessible through our Physician Search. This Privacy Policy does not apply to those third-party services. We are not responsible for the privacy practices of any third-party website or service.
TelegraMD Is Not Covered by This General Disclaimer TelegraMD (telegramd.com) is DocSearch’s designated telehealth partner governed by a HIPAA Business Associate Agreement, as described in Section 6. The general third-party disclaimer above does not apply to data shared with TelegraMD pursuant to that BAA relationship. However, once you are on telegramd.com, TelegraMD’s own privacy policy and HIPAA Notice govern your experience on that platform. We encourage you to review TelegraMD’s privacy documentation at telegramd.com. |
DocSearch offers two AI-powered informational tools on docsearch.com: AI Skin Analysis and SmartConsult™ Plastic Surgery Visualization. Both are educational and informational utilities only. They do not diagnose medical conditions, prescribe treatment, provide medical advice, or establish a physician-patient relationship.
17.1 AI Engine
DocSearch’s AI tools are powered by Anthropic’s Claude foundation model, accessed through the Anthropic commercial API. Anthropic does not use API inputs or outputs to train, fine-tune, or improve its AI models. API logs are retained by Anthropic for a maximum of 30 days per Anthropic’s commercial terms.
17.2 What We Collect and Do Not Store
When you use an AI tool, we process your uploaded image and text inputs in real time. Images are not retained or stored by DocSearch after the analysis is returned. DocSearch does not link AI tool inputs to your account or transmit them to physicians. Any copies you make of your results leave DocSearch’s custody and become your own records.
17.3 If You Request a Consultation After AI Tool Use
If you elect to request a physician consultation after using an AI tool, only your name, email address, phone number, and geographic area are transmitted to initiate the consultation. The image you submitted, the AI-generated analysis, and any specific condition information entered into the tool are not transmitted to the physician. Any clinical evaluation begins fresh between you and the physician.
We may update this Privacy Policy from time to time. When we make changes, we will update the “Effective Date,” post the revised policy on docsearch.com/privacy, and for material changes, notify registered users by email at least 14 days before the changes take effect. Your continued use of the Platform after the effective date constitutes acceptance of the revised Privacy Policy.
Privacy Contact — DocSearch Health Solutions LLC 8135 N Orange Blossom Trail • Orlando, FL 32810 • United States Email: info@docsearch.com (for general privacy requests) Phone: +1 (407) 974-6808 HIPAA Privacy Officer: info@docsearch.com (subject line: “HIPAA Privacy Request”) |
Effective Date: July 20, 2026 │ Version 2.0 │ Supersedes all prior versions. © 2026 DocSearch Health Solutions LLC. All rights reserved. |