This Privacy Notice describes how Tiger Medical, PLLC ("Tiger Medical," "we," "us," or "our") collects, uses, discloses, and safeguards information about you when you receive telehealth services from our providers through a third-party telehealth technology platform (the "Platform"). Please review it carefully.
Effective Date: August 8, 2026
Applicable Law and Our Voluntary HIPAA-Aligned Standards
Tiger Medical is a cash-pay telehealth medical group that does not bill health insurance and does not conduct the electronic standard transactions that would technically classify it as a "covered entity" under the Health Insurance Portability and Accountability Act ("HIPAA"). Accordingly, HIPAA does not directly govern Tiger Medical's clinical services, and this Notice is not a HIPAA Notice of Privacy Practices. Nevertheless, Tiger Medical voluntarily maintains privacy and security practices consistent with HIPAA standards for all patients, and complies with the privacy, telehealth, confidentiality-of-medical-information, consumer-privacy, and health-data laws of every state in which it treats patients (collectively, the "Privacy Laws"). These state Privacy Laws include, among others, the California Confidentiality of Medical Information Act ("CMIA") and the California Consumer Privacy Rights Act ("CPRA"); the Washington My Health My Data Act; the Texas Medical Records Privacy Act (HB 300); the Nevada, Colorado, Connecticut, and Virginia consumer privacy acts; and the medical-confidentiality and telehealth statutes of every other state in which Tiger Medical treats patients. Where a state Privacy Law provides you with a right or protection greater than what is described in this Notice, that state law will control for your care.
Our Commitment to Your Privacy
Tiger Medical treats your health information as confidential. We restrict access to your information to Tiger Medical providers and personnel who need it to deliver your care, and we contractually require our third-party Platform Operator and other vendors to maintain administrative, technical, and physical safeguards to protect it. We have implemented safeguards modeled on the HIPAA Privacy and Security Rules, including workforce training, access controls, encryption of electronic information at rest and in transit, audit logging, and an incident response program.
How We Use and Disclose Your Information
We may use and disclose information about you for the following purposes:
Treatment: We use your information to provide, coordinate, and manage your healthcare, including asynchronous and synchronous telehealth consultations, prescribing, laboratory review, and consultation with other treating providers or pharmacies.
Operations: We use your information to operate our medical practice, including quality assessment, provider oversight, compliance, credentialing, training, and business management. We also share information with the Platform Operator to the extent necessary for it to provide the technology, management, administrative, customer service, technology support, and fulfillment services that support our delivery of care to you.
Additional permitted or required uses and disclosures include:
- To your pharmacy or laboratory partners as necessary to fulfill prescriptions or process ordered testing;
- As required or permitted by state or federal law, including in response to a valid court order, subpoena, or lawful government request;
- For public health activities, such as reporting adverse drug events or communicable diseases;
- To report suspected abuse, neglect, or domestic violence, where required or permitted by law;
- For health-oversight activities, such as audits or investigations by government agencies;
- To avert a serious and imminent threat to health or safety; and
- For any other purpose only with your written authorization, which you may revoke at any time except to the extent we have already relied on it.
We do not sell your health information. We do not share your health information for cross-context behavioral advertising. We do not use or disclose your information for marketing without your prior written authorization. For California residents, these commitments include the CMIA prohibition on the unauthorized use or disclosure of medical information and the CPRA's sensitive-personal-information limits. For Washington residents, these commitments include the My Health My Data Act's requirements for consumer health data. Similar protections apply under the state privacy laws of other states in which we treat patients.
Your Rights Regarding Your Information
Subject to the Privacy Laws of the state in which you receive care, you have the following rights with respect to information Tiger Medical maintains about you. These rights are modeled on the HIPAA Privacy Rule and are extended to all our patients, whether or not HIPAA technically applies:
- Right to Access and Copy: You may inspect and obtain a copy of your medical records within a reasonable time after your written request, and in any event within the timeframe required by the Privacy Laws of your state (generally 15 days in California under CMIA, or 30 days as a HIPAA-modeled default).
- Right to Request Amendment: You may request that we amend information you believe is incorrect or incomplete. We may decline the request under certain circumstances permitted by law, and we will provide you with a written explanation.
- Right to Request Restrictions: You may request that we restrict certain uses or disclosures of your information. We are not required to agree to every requested restriction.
- Right to Request Confidential Communications: You may request that we communicate with you by alternative means or at an alternative contact point.
- Right to a Paper or Electronic Copy of this Notice: You may request a copy of this Notice at any time.
- Right to Notification of a Security Incident: You will be notified in the event of a security incident involving your information, in accordance with the Privacy Laws applicable to your care and, where applicable, the Federal Trade Commission's Health Breach Notification Rule.
- Right to Withdraw Consent: You may withdraw any consent you have given for a specific use or disclosure of your information, except to the extent we have already acted in reliance on that consent.
Additional state-specific rights:
- California residents have additional rights under the CPRA, including the right to know what personal information we have collected, the right to delete personal information (subject to medical-record retention exceptions), the right to correct inaccurate personal information, the right to limit the use of sensitive personal information, and the right not to be discriminated against for exercising these rights.
- Washington residents have rights under the My Health My Data Act to access, delete, and withdraw consent for the collection and sharing of consumer health data.
- Residents of Colorado, Connecticut, Nevada, Virginia, and other states with comprehensive privacy laws have similar rights under those statutes.
To exercise any of these rights, please contact us using the information below. We do not require verification beyond what is reasonably necessary to confirm you are the person entitled to make the request.
How to Exercise Your Rights or File a Complaint
To exercise any of the rights described above, or to ask a question or file a complaint about our privacy practices, please contact Tiger Medical at:
Tiger Medical, PLLCc/o Northwest Registered Agent LLC7901 4th St N, Ste 300St. Petersburg, FL 33702Email: notices@lion.mdPhone: (561) 652-5360You may also file a privacy complaint with the medical licensing board, attorney general, or consumer-protection authority of the state in which you receive care. California residents may contact the California Attorney General or California Privacy Protection Agency. Washington residents may contact the Washington State Attorney General. We will not retaliate against you for filing a complaint or exercising any right described in this Notice.
Account Security
Your Platform account — including registration, login, password management, and other account administration features — is provided and maintained by the Platform Operator, not by Tiger Medical. You are responsible for maintaining the confidentiality of your account credentials. If you believe your account has been accessed without your permission, notify the Platform Operator immediately through the Platform's support channel, and also notify Tiger Medical using the contact information above.
The Third-Party Platform
Tiger Medical delivers care through the Platform, which is separately owned, operated, and maintained by an independent third-party company (the "Platform Operator"), including its servers, software, network infrastructure, and security architecture. The Platform Operator represents that it maintains a HIPAA-aligned security program and has completed an independent SOC 2 examination of its security controls. Under a written Master Services Agreement, Tiger Medical and the Platform Operator have agreed that neither party is acting as a HIPAA "covered entity" or "business associate," and there is no HIPAA Business Associate Agreement in place between them. Instead, the Master Services Agreement requires the Platform Operator to comply with written privacy and security policies protecting all patient information, to implement administrative, technical, and physical safeguards, to notify Tiger Medical of security incidents affecting patient information, and to maintain cyber-liability and data-security insurance. The Platform Operator's own website terms of use and privacy policy are separate from this Notice and govern the Platform Operator's technology services rather than Tiger Medical's clinical services. We encourage you to review the Platform Operator's own privacy policy and terms of service for information about how it collects, stores, transmits, and secures information as part of its services.
Security Incidents and Notification
In the event of a security incident involving your information, Tiger Medical will provide you with the notice required under the Privacy Laws applicable to your care and, where applicable, the Federal Trade Commission's Health Breach Notification Rule. The Platform Operator is contractually required to notify Tiger Medical of any security incident affecting information on the Platform without unreasonable delay, and maintains cyber-liability and data-security insurance coverage. You may also receive notice directly from the Platform Operator or from another affected client of the Platform Operator; receiving multiple notices does not necessarily mean multiple incidents have occurred.
Record Retention
Tiger Medical retains your medical records for the longest period required by the Privacy Laws of the states in which we treat patients, which is generally the longer of seven (7) years after your last visit or the retention period required by your state's medical-records statute (for example, California requires retention for at least seven years from the date of the last encounter for adults, and longer for minors). We may retain information for longer periods where required by applicable state or federal law, by pending legal or regulatory proceedings, or as reasonably necessary for our compliance, insurance, or defense obligations.
Changes to This Notice
We reserve the right to change the terms of this Notice at any time and to make the revised Notice effective for all information we maintain. Material changes will be communicated to you through the Platform or by email, and the current version will be made available through the Platform or upon request.
This document is a template Privacy Notice intended for a cash-pay telehealth medical group that is not a HIPAA "covered entity" but voluntarily maintains HIPAA-aligned privacy and security practices while complying with applicable state privacy, telehealth, and consumer-privacy laws. It should be reviewed by qualified legal/compliance counsel to confirm completeness and accuracy for your specific practice, third-party vendors, and each state's requirements before use.