Legal

Privacy Policy

1

Overview

DocSearch Health Solutions (“DocSearch,” “we,” “us,” or “our”) operates docsearch.com, a dual-purpose healthcare platform offering (1) telehealth treatment programs facilitated through TelegraMD and its Provider Groups, and (2) a free physician search directory. This Privacy Policy applies to all users of the Platform.

Two Categories of Information

DocSearch handles two distinct categories of information: (1) Personal Information — general data like your name, email, and payment details — governed by this Privacy Policy; and (2) Protected Health Information (PHI) — your medical and health data — governed by our HIPAA Notice of Privacy Practices and federal law. PHI receives additional protections required by HIPAA.

2

Information We Collect

2.1 Information You Provide Directly

Category

Examples

When Collected

Identity Information

Full name, date of birth, gender

Account registration, eligibility funnel

Contact Information

Email address, phone number, mailing address

Account registration, payment checkout

Health & Eligibility Information

Approximate age, treatment interest, symptom selections, eligibility responses

Treatment eligibility funnel (pre-handoff to TelegraMD)

Payment Information

Credit/debit card details, billing address (processed by third-party payment processor)

Treatment program checkout

Account Credentials

Username, password (hashed), security preferences

Account creation

Communications

Messages, support tickets, feedback, survey responses

When you contact us

Doctor Search Queries

Specialty searches, location inputs, filter preferences

When using the free Physician Search tool

2.2 Information Collected Automatically

We automatically collect device and technical data (IP address, browser type, operating system), usage data (pages visited, features used), log data (access logs, timestamps), approximate location derived from IP address, and cookie and tracking data as described in Section 7.

2.3  Information from Our Telehealth Partner, TelegraMD

DocSearch’s data relationship with TelegraMD operates on two levels, and we describe both accurately here:

First, in the normal course of operations, DocSearch receives routine transactional data from TelegraMD confirming treatment program status (such as confirmation that a consultation has been completed or that a prescription has been issued) for the limited purposes of billing reconciliation, subscription management, and patient support. This transactional data includes order status, subscription status, and payment confirmation information.

Second, DocSearch maintains authorized administrative access to TelegraMD’s affiliate dashboard systems for the four BAA-permitted purposes described in Section 6.3. Through this authorized dashboard access, DocSearch’s Compliance Officer and other specifically authorized personnel can view patient account information, order history, clinical encounter data, and other information necessary to fulfill patient support, billing reconciliation, quality assurance, and compliance monitoring functions. This dashboard access is governed by a HIPAA Business Associate Agreement and strictly limited by DocSearch’s role-based access control policy (described in Section 6.3).

DocSearch does not independently hold your full clinical medical record. Your medical records, physician notes, diagnoses, and prescriptions are held and controlled by TelegraMD’s Provider Groups as the Covered Entities responsible for your clinical care.

About Our Eligibility Funnel

Our treatment eligibility funnel asks basic questions (approximate age, symptom selections, treatment interest) before you are redirected to TelegraMD for full clinical intake. This funnel data — even though it precedes formal medical treatment — may constitute Protected Health Information when combined with your identity. We treat all funnel data with HIPAA-level protections from the moment you select a treatment category.

3

How We Collect Your Information

We collect information: directly from you when you create an account, complete our eligibility funnel, make a payment, use the doctor search, or contact our support team; automatically through cookies, web beacons, log files, and similar tracking technologies; from TelegraMD through routine transactional confirmation data and through our authorized dashboard access as described in Section 2.3; and from payment processors (transaction confirmations, partial card numbers, fraud signals).

4

How We Use Your Information

4.1  To Provide and Operate the Platform

  • Creating and managing your account
  • Processing your treatment program enrollment and payments
  • Routing you to TelegraMD for clinical evaluation and prescription services
  • Providing access to the free Physician Search directory
  • Delivering customer and technical support
  • Communicating with you about your account, orders, and treatment status
  • Sending authorized patient notifications directing you to review your TelegraMD patient dashboard

 

4.2  To Improve and Develop the Platform

  • Analyzing usage patterns to improve features and user experience
  • Conducting internal research and analytics on aggregated, de-identified data
  • Testing new features and optimizing platform performance

 

4.3  For Safety, Security, and Legal Compliance

  • Detecting and preventing fraud, abuse, and unauthorized access
  • Verifying user identity and eligibility
  • Complying with applicable laws, regulations, and legal obligations, including HIPAA, HITECH, and FIPA
  • Responding to legal requests, court orders, and government inquiries

 

4.4  For Communications

  • Sending transactional emails and confirmations
  • Sending service-related notifications
  • Sending marketing communications about DocSearch services — only with your consent or where permitted by law

5

HOW WE SHARE YOUR INFORMATION

We do not sell your personal information. We share your information only as described in this section.

 

Recipient

What We Share

Why / Legal Basis

TelegraMD (Telehealth Partner via BAA)

Name, contact info, treatment selection, payment confirmation, eligibility funnel data

To facilitate clinical intake, physician evaluation, and prescription services. Governed by HIPAA Business Associate Agreement. See Section 6.

Provider Groups (via TelegraMD)

Patient identity and treatment information necessary for clinical consultation

TelegraMD routes information to the applicable Provider Group for your state to conduct the clinical evaluation. DocSearch does not share directly with Provider Groups.

Licensed Pharmacies (via TelegraMD Pharmacy API)

Prescription details, shipping address, patient name

TelegraMD routes fulfilled prescriptions to the dispensing pharmacy through its Pharmacy API. DocSearch does not share directly with pharmacies.

Payment Processors

Payment card details, billing address, transaction data

To process payments for treatment programs. We do not store full card numbers.

Cloud Infrastructure Providers

All data we store, subject to BAAs where PHI is involved

To host and operate our platform securely

Analytics Providers

De-identified or aggregated usage data

To understand how our platform is used. Health data is not used for analytics targeting.

Email & Communication Providers

Name, email address, communication content

To send transactional and authorized patient notifications

Customer Support Tools

Name, contact info, support ticket content

To manage and respond to support requests

Legal & Compliance

Any data required by applicable law

To comply with court orders, subpoenas, regulatory requirements, or law enforcement requests

Business Transfers

All data held at the time of the transaction

In connection with a merger, acquisition, or sale of assets. We will notify you before your data is transferred.

With Your Consent

Any data you specifically authorize

For any purpose you explicitly agree to

 

We Never Do This

DocSearch does not sell your personal information or protected health information to data brokers, advertisers, or any third party for commercial benefit. We do not permit third-party advertisers to use your health data for targeting. We do not share your medical information with your employer, insurer, or family members without your explicit written authorization.

6

TelegraMD & Our Telehealth Partnership

DocSearch partners with TelegraMD (telegramd.com) and the Provider Groups to provide the clinical and prescription components of our Treatment Programs. Understanding this relationship is important for your privacy.

6.1  The Provider Groups

All medical consultations are provided by independent licensed Provider Groups: Online Medical Care, P.C. (NJ/NY); TMD of Kansas, P.A. (KS); TMD of Texas, P.A. (TX); and TMD of CA, PC (all other states). TelegraMD is the management services organization and technology platform provider for the Provider Groups. TelegraMD does not itself practice medicine.

6.2  How the Handoff Works

  • You complete DocSearch’s eligibility funnel and payment on docsearch.com
  • Upon qualifying and completing payment, you are redirected to telegramd.com for full clinical intake
  • On TelegraMD’s platform, a licensed Provider employed by one of the Provider Groups conducts a comprehensive medical evaluation
  • The Provider — not DocSearch — makes all prescribing decisions
  • If prescribed, your medication is dispensed by an independent licensed pharmacy and shipped to you

 

6.3  TelegraMD’s Own Privacy Practices

Once you are redirected to telegramd.com, your interactions on that platform are governed by TelegraMD’s own Privacy Policy and HIPAA Notice of Privacy Practices, which are separate from this document. We encourage you to review TelegraMD’s privacy documentation at telegramd.com before submitting your medical history.

6.4  DocSearch’s Authorized Dashboard Access

DocSearch has authorized access to TelegraMD’s affiliate administration dashboards, which contain information about patients who enrolled through our platform. This access is governed by a HIPAA Business Associate Agreement between DocSearch and TelegraMD and is strictly limited to four permitted purposes:

  • Patient support and account management
  • Billing reconciliation and payment processing
  • Quality assurance and compliance monitoring
  • Responding to patient inquiries about treatment status

Through this dashboard access, DocSearch’s authorized personnel may view patient account information, order and subscription data, clinical encounter information, and other data accessible in the dashboard system. Access is governed by DocSearch’s documented Role-Based Access Control (RBAC) policy. DocSearch’s Compliance Officer is implementing role-based access controls limiting each staff member to only the data necessary for their specific authorized function. All dashboard access is logged and subject to quarterly review by the Compliance Officer.

6.5  Two Privacy Policies Apply to You

If you enroll in a Treatment Program, your information is subject to both this Privacy Policy (for your DocSearch account and eligibility data) and TelegraMD’s Privacy Policy (for your clinical intake and medical records on the TelegraMD platform). DocSearch and TelegraMD are separately responsible for the data each entity controls.

7

Cookies & Tracking Technologies

We use cookies and similar tracking technologies to operate our Platform, remember your preferences, and understand how the Platform is used.

 

Cookie Type

Purpose

Duration

Strictly Necessary

Required for Platform operation — session management, authentication, security, payment processing. Cannot be disabled.

Session / up to 1 year

Functional

Remember your preferences, language settings, and personalization choices

Up to 1 year

Analytics

Understand how users navigate the Platform using tools like Google Analytics; data is aggregated and anonymized where possible

Up to 2 years

Marketing / Advertising

Track referral sources and measure campaign effectiveness. Health data is not used for ad targeting.

Up to 90 days

 

7.1  How to Opt Out of Advertising and Analytics Cookies

In addition to your browser’s own cookie controls, you can exercise specific opt-out rights through the following industry tools:

  • Advertising cookies: opt out through the Network Advertising Initiative (optout.networkadvertising.org) or the Digital Advertising Alliance (optout.aboutads.info)
  • Analytics cookies: install the Google Analytics Opt-out Browser Add-on (tools.google.com/dlpage/gaoptout)

 

Opting out of advertising or analytics cookies does not affect strictly necessary cookies required for the Platform to function, or your ability to use Treatment Program services.

8

Data Retention

We retain your personal information for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required by law.

 

Data Category

Retention Period

Legal Basis

Account information

Duration of account + 3 years after closure

Business records; dispute resolution

Eligibility funnel data (health-related)

6 years from date of collection

HIPAA minimum retention: 45 CFR § 164.530(j)

PHI accessed via TelegraMD dashboard

6 years from creation or last effective date, whichever is later

45 CFR § 164.530(j); Business Associate Agreement with TelegraMD

Payment & billing records

7 years

Federal and state tax and financial record requirements

Support communications

3 years from resolution

Quality assurance; dispute resolution

Analytics & usage data

Up to 2 years (aggregated/anonymized)

Platform improvement

Marketing preferences & consent records

Until you opt out + 3 years

Proof of consent

Security logs & access records

3 years minimum; 6 years for HIPAA-related access logs

HIPAA Security Rule; 45 CFR § 164.312(b)

 

9

Data Security

We implement reasonable and appropriate technical, administrative, and physical safeguards to protect your personal information from unauthorized access, disclosure, alteration, and destruction. Our security measures include:Encryption in transit (TLS 1.2 or higher / HTTPS) and encryption at rest (AES-256 or equivalent)

  • Role-based access controls limiting who can access your data to personnel with a legitimate need
  • Multi-factor authentication required for all internal systems accessing personal or health data
  • Periodic vulnerability assessments and penetration testing
  • Annual employee security and privacy training
  • Vendor management: all third-party vendors with access to personal data are contractually required to maintain appropriate security standards and, where PHI is involved, execute Business Associate Agreements

 

9.1  Breach Notification

In the event of a breach of unsecured Protected Health Information, DocSearch will provide notifications as follows: to TelegraMD within ten (10) business days of DocSearch’s discovery; to affected Florida residents and the Florida Attorney General within thirty (30) calendar days per Fla. Stat. § 501.171; and to affected individuals and HHS/OCR within sixty (60) calendar days of discovery per 45 CFR §§ 164.404–164.414. If a breach affects 500 or more residents of a single state, we will also provide notice to prominent media outlets in that state. We will notify you by email to the address on your account or by first-class mail.

9.2  FTC Health Breach Notification Rule

Separate from the HIPAA notification obligations above, certain health-related information DocSearch collects — including eligibility funnel data collected before a clinical relationship with a Provider Group is established — may also be subject to the Federal Trade Commission’s Health Breach Notification Rule (16 CFR Part 318). This rule applies to health information held by entities that are not necessarily HIPAA-covered, and requires notification to affected individuals, and in some cases the FTC and the media, following a breach of unsecured information covered by the rule. Where a breach implicates both HIPAA and the FTC Health Breach Notification Rule, DocSearch will provide notice satisfying both frameworks using the timelines described in Section 9.1.

10

Your Privacy Rights

Depending on your location and applicable law, you have the following rights regarding your personal information. To exercise any of these rights, contact us at info@docsearch.com with the subject line “Privacy Rights Request.” We will respond within 30 days.

 

Right

Description

Right to Know & Access

Request a copy of the personal information we hold about you and information about how we use it.

Right to Correct

Request correction of inaccurate or incomplete personal information.

Right to Delete

Request deletion of your personal information, subject to legal retention obligations and ongoing treatment relationships.

Right to Opt Out of Marketing

Opt out of marketing communications at any time by clicking “Unsubscribe” in any marketing email or contacting us.

Right to Portability

Receive your personal information in a structured, machine-readable format where technically feasible.

Right to Restrict Processing

Ask us to limit how we use your personal information in certain circumstances.

Note on PHI Requests

For requests relating to your Protected Health Information and clinical records, see our HIPAA Notice of Privacy Practices. For clinical records held by TelegraMD’s Provider Groups, please contact TelegraMD directly at telegramd.com.

11

Florida residents — florida information protection act (FIPA)

Florida Residents: Additional Rights Under FIPA

If you are a Florida resident, the Florida Information Protection Act (Fla. Stat. § 501.171) provides you with specific rights and protections regarding your personal information held by Florida entities such as DocSearch.

11.1  FIPA Coverage

Florida’s Information Protection Act defines “personal information” to include your name in combination with any of the following: Social Security number; driver’s license number or identification card number; financial account numbers with security codes or passwords; medical history or treatment information; health insurance information; online account credentials (username and password); and geolocation data. DocSearch collects several of these categories.

11.2  FIPA Breach Notification Rights

In the event of a breach of security involving your unencrypted personal information under FIPA, DocSearch will notify affected Florida residents and the Florida Attorney General within thirty (30) calendar days of DocSearch’s determination that a breach has occurred. Notice will be provided to you by email or first-class mail.

11.3  Exercising Your Rights

Florida residents may submit privacy requests to DocSearch at info@docsearch.com with the subject line “Florida Privacy Request.” We will respond within 30 days. For requests relating to medical and health information protected by HIPAA, please also see our HIPAA Notice of Privacy Practices.

12

California residents — CCPA / CPRA

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), including the right to know, right to delete, right to correct, right to opt out of sale or sharing (we do not sell or share personal information for cross-context behavioral advertising), right to limit use of sensitive personal information, and right to non-discrimination. Submit California rights requests to info@docsearch.com with the subject line “California Privacy Request.” We will respond within 45 days (extendable by an additional 45 days with notice). Note: PHI collected in connection with healthcare treatment is generally exempt from the CCPA. For health data, see our HIPAA Notice of Privacy Practices.

13

Other state privacy laws — comprehensive and consumer health data statutes

Beyond Florida and California, a growing number of states have enacted their own comprehensive consumer privacy laws, several of which include provisions specific to health-related data that may apply to information DocSearch collects even where HIPAA does not, such as eligibility funnel responses collected before a clinical relationship with a Provider Group begins.

13.1  Washington and Nevada Consumer Health Data Laws

Washington’s My Health My Data Act and a parallel Nevada statute (SB 370) regulate “consumer health data” broadly, independent of HIPAA coverage. If you are a Washington or Nevada resident, DocSearch will honor applicable rights under these statutes with respect to consumer health data we collect, including rights to access, delete, and withdraw consent for the collection or sharing of such data. Washington’s law includes a private right of action; DocSearch takes its obligations under this statute seriously given TelegraMD’s own domicile in Washington. To exercise these rights, contact info@docsearch.com with the subject line “Washington/Nevada Health Data Request.”

13.2  Other State Comprehensive Privacy Laws

DocSearch also honors applicable consumer privacy rights — including rights to access, correct, delete, and opt out of certain processing — for residents of other states with comprehensive privacy statutes, including but not limited to Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and Montana. The specific rights available and response timelines vary by state. To exercise rights under any applicable state privacy law not otherwise addressed in this Privacy Policy, contact info@docsearch.com with the subject line “State Privacy Request” and identify your state of residence.

14

International users

DocSearch’s Platform and Treatment Programs are designed for and offered to residents of the United States. If you access the Platform from outside the United States, including from the European Economic Area (EEA), United Kingdom, or Switzerland, the following applies.

14.1  Legal Basis for Processing (EEA/UK Users)

Where required by the General Data Protection Regulation (GDPR) or the UK GDPR, DocSearch processes your personal information based on one or more of the following legal bases: performance of a contract with you; our legitimate business interests in operating and improving the Platform; compliance with a legal obligation; or your consent, which you may withdraw at any time.

14.2  International Data Transfers

If you access the Platform from outside the United States, your information will be transferred to and processed in the United States, which may not have data protection laws equivalent to those in your jurisdiction. By using the Platform, you consent to this transfer and processing.

14.3  EEA/UK Rights

If GDPR or UK GDPR applies to you, you have rights to access, rectify, erase, restrict, or object to processing of your personal information, and to data portability, in addition to the rights described in Section 10. You also have the right to lodge a complaint with your local data protection authority. To exercise these rights, contact info@docsearch.com with the subject line “GDPR Request.”

15

Children’s privacy

Our Platform is intended for adults aged 18 and older. We do not knowingly collect personal information from individuals under 18. If we discover that we have inadvertently collected information from a minor, we will delete it promptly. Contact us at info@docsearch.com if you believe we may have collected information from a minor.

16

Third-party links and services

Our Platform may contain links to third-party websites, services, and applications, including pharmacy portals and healthcare provider websites accessible through our Physician Search. This Privacy Policy does not apply to those third-party services. We are not responsible for the privacy practices of any third-party website or service.

 

TelegraMD Is Not Covered by This General Disclaimer

TelegraMD (telegramd.com) is DocSearch’s designated telehealth partner governed by a HIPAA Business Associate Agreement, as described in Section 6. The general third-party disclaimer above does not apply to data shared with TelegraMD pursuant to that BAA relationship. However, once you are on telegramd.com, TelegraMD’s own privacy policy and HIPAA Notice govern your experience on that platform. We encourage you to review TelegraMD’s privacy documentation at telegramd.com.

17

Use of artificial intelligence tools

DocSearch offers two AI-powered informational tools on docsearch.com: AI Skin Analysis and SmartConsult™ Plastic Surgery Visualization. Both are educational and informational utilities only. They do not diagnose medical conditions, prescribe treatment, provide medical advice, or establish a physician-patient relationship.

17.1  AI Engine

DocSearch’s AI tools are powered by Anthropic’s Claude foundation model, accessed through the Anthropic commercial API. Anthropic does not use API inputs or outputs to train, fine-tune, or improve its AI models. API logs are retained by Anthropic for a maximum of 30 days per Anthropic’s commercial terms.

17.2  What We Collect and Do Not Store

When you use an AI tool, we process your uploaded image and text inputs in real time. Images are not retained or stored by DocSearch after the analysis is returned. DocSearch does not link AI tool inputs to your account or transmit them to physicians. Any copies you make of your results leave DocSearch’s custody and become your own records.

17.3  If You Request a Consultation After AI Tool Use

If you elect to request a physician consultation after using an AI tool, only your name, email address, phone number, and geographic area are transmitted to initiate the consultation. The image you submitted, the AI-generated analysis, and any specific condition information entered into the tool are not transmitted to the physician. Any clinical evaluation begins fresh between you and the physician.

18

Changes to this privacy policy

We may update this Privacy Policy from time to time. When we make changes, we will update the “Effective Date,” post the revised policy on docsearch.com/privacy, and for material changes, notify registered users by email at least 14 days before the changes take effect. Your continued use of the Platform after the effective date constitutes acceptance of the revised Privacy Policy.

19

Contact us

Privacy Contact  —  DocSearch Health Solutions LLC

8135 N Orange Blossom Trail  •  Orlando, FL 32810  •  United States

Email: info@docsearch.com  (for general privacy requests)

Phone: +1 (407) 974-6808

HIPAA Privacy Officer: info@docsearch.com  (subject line: “HIPAA Privacy Request”)

 

Effective Date: July 20, 2026  │  Version 2.0  │  Supersedes all prior versions.

© 2026 DocSearch Health Solutions LLC. All rights reserved.