DOCSEARCH HEALTH SOLUTIONS LLC

Notice of Privacy Practices

THIS NOTICE DESCRIBES HOW HEALTH INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.

This Notice of Privacy Practices (“Notice”) describes how DocSearch Health Solutions LLC (“DocSearch,” “we,” “us,” or “our”) may use and disclose your Protected Health Information (PHI) in connection with our role as a Business Associate of TelegraMD’s Provider Groups, and how you can access this information. It also describes your rights and our obligations regarding your PHI.

DocSearch’s Role — Business Associate, Not Covered Entity

DocSearch is a Business Associate of the Provider Groups under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and its implementing regulations, as amended by the HITECH Act. DocSearch operates as a non-clinical facilitator — it does not practice medicine, employ the physicians who treat you, or hold your complete clinical medical record. Your clinical records, physician notes, diagnoses, and prescriptions are held and controlled by the Provider Groups as the Covered Entities responsible for your clinical care:

• Online Medical Care, P.C.  —  New Jersey & New York

• TMD of Kansas, P.A.  —  Kansas

• TMD of Texas, P.A.  —  Texas

•  TMD of CA, PC  —  All other states

For questions about your clinical records or to exercise HIPAA patient rights regarding records held by the Provider Groups, contact TelegraMD at telegramd.com. This Notice governs the PHI that DocSearch itself accesses and handles as a Business Associate.

1

PHI THAT DOCEARCH ACCESSES AND HANDLES

As a Business Associate, DocSearch accesses patient PHI through two channels: (1) routine transactional data received from TelegraMD confirming treatment program status for billing reconciliation and support; and (2) authorized administrative dashboard access to TelegraMD’s affiliate administration systems for the four BAA-permitted purposes described below. DocSearch’s access to PHI through the TelegraMD affiliate-admin dashboard and Command Center (Beta) dashboard may include patient identity information, contact information, order and prescription history, clinical encounter records, laboratory order and result information, and subscription and payment data.

DocSearch’s access to PHI is governed by a HIPAA Business Associate Agreement with TelegraMD and by DocSearch’s internal Role-Based Access Control (RBAC) policy, which limits each authorized personnel member’s access to the minimum PHI necessary for their specific function (the HIPAA Minimum-Necessary Standard, 45 CFR § 164.514(d)).

2

HOW DOCSEARCH MAY USE AND DISCLOSE YOUR PHI

As a Business Associate, DocSearch may use and disclose your PHI only as permitted by our Business Associate Agreement with TelegraMD and as described in this Notice. The following describes how we may use and disclose PHI:

Permitted Uses and Disclosures Without Your Authorization

DocSearch may use or disclose your PHI without your written authorization for the following purposes:

Purpose

Description

Example

Patient Support

Accessing PHI necessary to respond to your inquiries about your treatment program, order status, subscription, or account

Reviewing your order history to respond to a question about your prescription shipment status

Billing Reconciliation

Using PHI necessary to verify that payments have been correctly allocated to Provider Groups, the Pharmacy, and DocSearch

Confirming that a consultation fee has been correctly processed and attributed to the applicable Provider Group

Quality Assurance

Using PHI to monitor and improve the quality of DocSearch’s facilitation services

Reviewing dashboard access logs to confirm that the correct notification message was sent to a patient with a pending lab order

Compliance Monitoring

Using PHI as necessary to monitor DocSearch’s compliance with HIPAA, the Business Associate Agreement, and applicable law

Reviewing patient records involved in a privacy complaint to investigate and respond appropriately

Healthcare Operations

Supporting treatment coordination, TelegraMD system operations, and the provision of telehealth services by the Provider Groups

Communicating with TelegraMD about service operations that affect patient care access

Required by Law

Disclosing PHI as required by applicable federal, state, or local law

Responding to a valid court order, subpoena, or law enforcement request that compels disclosure

Public Health Activities

Reporting as required to public health authorities to prevent or control disease, injury, or disability

Reporting to the CDC or FDA as required by applicable public health law

HHS/OCR Oversight

Making PHI available to the U.S. Department of Health and Human Services Office for Civil Rights for purposes of determining compliance with HIPAA

Providing records in response to an HHS/OCR compliance review or investigation

Uses and Disclosures That Require Your Written Authorization

Other than as described above or as otherwise required by law, DocSearch will not use or disclose your PHI without your written authorization. Uses and disclosures that require your authorization include: marketing communications that are not otherwise permitted by HIPAA; the sale of your PHI; and most uses of psychotherapy notes. You may revoke any authorization you give us at any time in writing, except to the extent that DocSearch has already acted in reliance on the authorization.

3

YOUR RIGHTS REGARDING YOUR PHI

You have the following rights regarding the PHI that DocSearch holds and accesses in its role as Business Associate. To exercise any of these rights, contact DocSearch’s Privacy Officer at info@docsearch.com with the subject line “HIPAA Privacy Rights Request.”

IMPORTANT: For rights relating to your clinical medical records, physician notes, diagnoses, and prescriptions held by TelegraMD’s Provider Groups, you must contact TelegraMD directly at telegramd.com. DocSearch can only fulfill rights requests for PHI that DocSearch itself controls as a Business Associate.

Your Right

Description

Timeline

Right to Access 45 CFR § 164.524

Request access to PHI about you that DocSearch holds in a designated record set. You may receive a copy in paper or electronic form. DocSearch may charge a reasonable cost-based fee for copies.

DocSearch must respond within 30 days (extendable by 30 days with notice). Provider Group records: contact TelegraMD.

Right to Amend 45 CFR § 164.526

Request amendment of PHI in DocSearch’s designated record set if you believe the information is incorrect or incomplete. DocSearch may deny the request under specific circumstances and must explain any denial.

DocSearch must respond within 60 days (extendable by 30 days with notice).

Right to Accounting of Disclosures 45 CFR § 164.528

Request an accounting of disclosures of your PHI that DocSearch has made for purposes other than treatment, payment, and healthcare operations during the prior six years.

DocSearch must respond within 60 days. First accounting per 12-month period is free; subsequent accountings carry a reasonable fee.

Right to Request Restrictions 45 CFR § 164.522(a)

Request that DocSearch restrict certain uses or disclosures of your PHI. DocSearch is not required to agree to all restriction requests, but must agree to requests restricting disclosure to a health plan where you have paid for the service in full out of pocket and the service is not otherwise required to be disclosed.

DocSearch will respond to restriction requests within 30 days.

Right to Confidential Communications 45 CFR § 164.522(b)

Request that DocSearch communicate with you about your PHI through alternative means or at an alternative location. DocSearch will accommodate reasonable requests.

DocSearch will respond within 30 days.

Right to Electronic Access 21st Century Cures Act

Request access to your electronic PHI (ePHI) in electronic form. Under the HITECH Act and the 21st Century Cures Act’s information-blocking provisions, DocSearch will not unreasonably delay or interfere with your access to ePHI we hold. If you have an account on our platform, you may view certain health information, intake questionnaire responses, and treatment history directly through your account dashboard.

DocSearch will provide electronic access without unreasonable delay, consistent with 45 CFR § 171 information-blocking standards.

Right to a Copy of This Notice 45 CFR § 164.520(c)

Request and receive a paper copy of this Notice at any time, even if you have agreed to receive it electronically.

Available at any time upon request at info@docsearch.com.

Right to Notification of Breach 45 CFR § 164.404

Receive written notification if DocSearch discovers a breach of your unsecured PHI. DocSearch will notify you within 60 days of discovery. If you are a Florida resident, you will also receive notice under FIPA within 30 days.

60 days from DocSearch’s discovery (HIPAA). 30 days (FIPA, Florida residents). 10 business days from DocSearch’s discovery (TelegraMD notification, per BAA).

4

DOCEARCH’S DUTIES

DocSearch is required by law to:

Maintain the privacy of your PHI

– Provide you with notice of our legal duties and privacy practices with respect to PHI

– Notify you following a breach of your unsecured PHI

– Abide by the terms of the Notice currently in effect

– Not use or disclose your PHI other than as described in this Notice or as otherwise required or permitted by law

DocSearch reserves the right to change the terms of this Notice and to make the new Notice provisions effective for all PHI that we maintain, including PHI created or received prior to the change. We will post the revised Notice on our website at docsearch.com/privacy and will provide a copy upon request.

5

MINIMUM NECESSARY AND ACCESS CONTROLS

When using or disclosing PHI, DocSearch applies the HIPAA Minimum Necessary Standard (45 CFR § 164.514(d)). DocSearch makes reasonable efforts to limit PHI access to only the minimum amount necessary to accomplish the intended BAA-permitted purpose.

DocSearch implements Role-Based Access Controls (RBAC) governing which personnel may access which PHI through TelegraMD’s administrative dashboards:

– Level 01 — Compliance Officer, CEO, and CSO: Full dashboard access for all four BAA-permitted purposes.

– Level 02 — CFO (in addition to Level 01 holders): Access to financial and billing modules only. No access to clinical records.

– Level 03 — Message Board Manager: Access to patient name, telephone number, and email address only, for the sole purpose of sending authorized patient notifications directing patients to review their TelegraMD patient dashboard.

All dashboard access is logged. DocSearch’s Compliance Officer reviews access logs quarterly and conducts an annual RBAC authorization review.

6

BREACH NOTIFICATION

In the event DocSearch discovers a breach of your unsecured PHI, DocSearch will provide notifications as follows:

Notification Recipient

Timeline

Legal Authority

TelegraMD (our Business Associate)

Within 10 business days of DocSearch’s discovery

Exhibit A § 2(m) of the TelegraMD Subcontractor BAA — the controlling and most stringent deadline

Affected Florida Residents

Within 30 calendar days of DocSearch’s determination that a breach has occurred

Fla. Stat. § 501.171 (Florida Information Protection Act)

Florida Attorney General

Within 30 calendar days if 500 or more Florida residents are affected

Fla. Stat. § 501.171(3)(b)

Affected Individuals (all states)

Within 60 calendar days of DocSearch’s discovery

45 CFR § 164.404

HHS / Office for Civil Rights

Within 60 days of discovery (500+ individuals) or annually in the first 60 days of the following calendar year (fewer than 500 individuals)

45 CFR § 164.408

Media Outlets

Without unreasonable delay and within 60 days of discovery, if 500 or more residents of a single state are affected

45 CFR § 164.406

FTC (where applicable)

In accordance with the FTC Health Breach Notification Rule, for information not otherwise covered by HIPAA (e.g., certain pre-treatment eligibility data)

16 CFR Part 318

7

HOW TO FILE A COMPLAINT

If you believe your privacy rights have been violated, you may file a complaint with DocSearch or directly with the U.S. Department of Health and Human Services Office for Civil Rights (HHS/OCR). We will not retaliate against you for filing a complaint.

 

Contact

Information

DocSearch Privacy Officer (For complaints about DocSearch’s practices)

Email: info@docsearch.com Subject line: “HIPAA Privacy Complaint” Mailing Address: DocSearch Health Solutions LLC, 8135 N Orange Blossom Trail, Orlando, FL 32810 Phone: +1 (407) 974-6808

HHS Office for Civil Rights (For complaints to the federal regulator)

Online: hhs.gov/ocr/privacy/hipaa/complaints Phone: 1-800-368-1019 (toll-free) TTY: 1-800-537-7697 Mail: 200 Independence Avenue, S.W., Washington, D.C. 20201 HHS/OCR enforces HIPAA privacy and security rules nationwide.

 

NON-RETALIATION

DocSearch will not require you to waive your right to file a complaint with HHS/OCR as a condition of receiving services, nor will we retaliate against you for filing a complaint or exercising any right described in this Notice. Retaliation in any form is prohibited by HIPAA and DocSearch’s internal policy.

8

FOR YOUR CLINICAL RECORDS: CONTACT TELEGRAMD

Your Clinical Medical Records Are Held by the Provider Groups via TelegraMD

DocSearch is a Business Associate — not your treating provider. Your physician notes, diagnoses, treatment plans, prescriptions, and laboratory results are held by TelegraMD’s Provider Groups as the Covered Entities responsible for your clinical care. If you wish to exercise HIPAA rights (such as access, amendment, or accounting of disclosures) regarding your clinical medical records, please contact TelegraMD directly:

• Website: telegramd.com

• Provider Groups: Online Medical Care, P.C. (NJ/NY) • TMD of Kansas, P.A. (KS) • TMD of Texas, P.A. (TX) • TMD of CA, PC (all other states)\

DocSearch will assist in facilitating communication with TelegraMD where appropriate. Contact us at info@docsearch.com.

9

EFFECTIVE DATE, CONTACT, AND CHANGES TO THIS NOTICE

Effective Date

This Notice is effective July 20, 2026, and replaces the prior Notice of Privacy Practices (effective April 1, 2026). Revisions to this Notice were made to: (1) accurately describe DocSearch’s Business Associate status, correcting the original Notice’s Covered Entity/Business Associate characterization; (2) reflect PHI accessible through both the affiliate-admin.telegramd.com dashboard and the TelegraMD Command Center (Beta) dashboard; (3) add the breach notification timeline table, including the FTC Health Breach Notification Rule; (4) update access control descriptions to reflect DocSearch’s Role-Based Access Control policy; (5) add Florida FIPA protections; and (6) restore an explicit reference to the 21st Century Cures Act’s information-blocking provisions and add a corresponding Right to Electronic Access.

How We Will Notify You of Changes

If we make material changes to this Notice, we will update the Effective Date and post the revised Notice on our website at docsearch.com/privacy. For changes that materially affect your rights or our uses and disclosures of your PHI, we will also provide direct notice by email or first-class mail. We will maintain the current version of this Notice on our website and will provide a paper copy upon request.

Privacy Officer Contact

DocSearch Compliance Officer

DocSearch Health Solutions LLC 8135 N Orange Blossom Trail  •  Orlando, FL 32810  •  United States

Email: info@docsearch.com  (subject: “HIPAA Privacy Notice”)

Phone: +1 (407) 974-6808  •  Monday–Friday, 9:00 a.m.–6:00 p.m. ET

Effective Date: July 20, 2026  │  Version 2.0  │  Pursuant to 45 CFR § 164.520 and 21st Century Cures Act § 3022

© 2026 DocSearch Health Solutions LLC. All rights reserved.