THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED, AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.
1. Our Commitment to Your Privacy
Universal Health Charts is a patient-controlled personal health record platform. Unlike a hospital or clinic, we are not your healthcare provider — you are the owner and custodian of the health information you store with us. We are committed to protecting your protected health information (“PHI”) and to being transparent about how it is safeguarded, used, and disclosed consistent with the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) and applicable state law.
2. Patient-Controlled Records
Universal Health Charts is designed around the principle that you control your own medical record. You decide:
What health information to enter, upload, or import into your account
Which family members or care team members can view specific records
What information is included in your Emergency Access profile and QR code
When to export a full copy of your data or permanently delete your account
We do not sell your health information, and we do not use it for marketing or advertising purposes.
3. How We Protect Your Information
We apply administrative, physical, and technical safeguards designed to meet HIPAA's Security Rule, including:
Field-level encryption of sensitive health data at rest, in addition to encryption of the underlying database and backups
Encryption in transit (TLS/HTTPS) for all traffic between your device and our servers
Role-based access controls that limit who can view PHI, with every access recorded in an immutable audit log
Step-up (re-authentication) requirements before high-risk actions such as exporting or deleting your full record
Multi-factor authentication (MFA) for account sign-in and session controls including automatic sign-out after periods of inactivity
Continuous monitoring for unauthorized access attempts and breach-notification procedures consistent with HIPAA's Breach Notification Rule
4. How Your Information May Be Used and Disclosed
We may use or disclose your PHI to:
Provide the core service — storing, organizing, and displaying your health records back to you and the people you authorize
Enable emergency access you configure, so first responders or care providers can view designated information when you are unable to communicate or provide consent
Share records with family members, caregivers, or care providers you explicitly invite or designate
Operate, maintain, and improve the security and reliability of the platform
Comply with a valid legal or regulatory obligation, such as a court order or law enforcement request
We do not disclose your PHI to third parties for their own marketing purposes, and we will never sell your health information.
5. Emergency Access Disclosures
If you enable Emergency Access, designated information (such as allergies, medications, conditions, and emergency contacts) may be made available to healthcare providers or other authorized individuals when they reasonably determine you are unable to communicate or provide consent. This disclosure is governed by the separate Emergency Access Authorization you accept during sign-up, and you may update your emergency access settings at any time.
6. Your Rights
You have the right to:
Access and review the health information in your account at any time
Request an electronic export of your full record (a step-up password confirmation is required)
Correct or update information you have entered
Control who can view your records, including revoking sharing access
View a log of active sign-in sessions and sign out of other devices
Request permanent deletion of your account and associated records (a step-up password confirmation is required)
7. Data Retention and Deletion
We retain your information for as long as your account is active or as needed to provide the service. When you delete your account, we permanently remove your profile and health records from active systems, subject to any residual copies in encrypted backups that are purged on a routine rotation schedule and any retention required by law.
8. Breach Notification
If we discover a breach of unsecured PHI, we will notify affected individuals, and where required, regulators and the media, in accordance with the HIPAA Breach Notification Rule and applicable state law.
9. Changes to This Notice
We may update this Notice of Privacy Practices from time to time to reflect changes in our practices or applicable law. The “Last updated” date above reflects the most recent revision, and material changes will be communicated to you in-app or by email.
10. Contact Us / Filing a Complaint
If you have questions about this notice, believe your privacy rights have been violated, or want to exercise any of the rights described above, contact us:
Company: Universal Health Charts
Email: support@universalhealthcharts.com
Mailing address: For written correspondence, please contact us by email to obtain our current mailing address.
You may also file a complaint with the U.S. Department of Health and Human Services, Office for Civil Rights. We will not retaliate against you for filing a complaint.
