Privacy Policy
Last updated: May 17, 2026 · Effective date: May 17, 2026
1. Introduction
Snapback Health Technologies LLC ("Snapback Health," "we," "us," or "our") is committed to protecting the privacy and security of your personal and health information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our patient recovery portal at snapbackhealth.com and app.snapbackhealth.com (the "Service").
We act as a Business Associate under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA") to your healthcare provider, and we are committed to the protection of Protected Health Information ("PHI") in accordance with HIPAA, the Health Information Technology for Economic and Clinical Health Act ("HITECH"), and applicable state privacy laws.
2. Information We Collect
We collect the following categories of information when you use our Service:
- Account information: First and last name, email address, encrypted password, clinic code
- Protected Health Information (PHI): Procedure type, surgery date, recovery day, pain scores, temperature, blood pressure, heart rate, wound and access site photographs, medication lists, exercise activity logs, daily checklist completion, AI Recovery Assistant chat history, and provider communications
- Contact information: Mobile phone number (only if you opt in to SMS reminders)
- Patient-Reported Outcome (PRO) survey responses: KOOS Jr., HOOS Jr., QuickDASH, PROMIS, and other clinically validated outcome assessments
- Consent records: Timestamps and details of all consents you provide, including remote therapeutic monitoring consent and SMS opt-in
- Usage data: Page views, feature usage, device type, browser type, IP address, and access timestamps, used for security, audit, and quality improvement purposes
3. How We Use Your Information
We use your information solely for the following purposes:
- Delivering your personalized recovery portal, exercise program, education content, and daily checklists
- Sending medication reminders, exercise reminders, wound photo reminders, appointment reminders, and recovery check-in notifications via email and SMS — only if you have explicitly opted in
- Sharing your recovery progress, vital signs, photographs, and outcome survey results with your authorized healthcare provider through our HIPAA-compliant provider portal
- Operating, maintaining, securing, and improving the Service
- Detecting, preventing, investigating, and responding to fraud, security incidents, or potential threats
- Analyzing de-identified and aggregated data to improve patient outcomes and service quality
- Complying with applicable legal, regulatory, and Medicare reporting requirements, including CMS PRO reporting for applicable procedures under the Comprehensive Care for Joint Replacement (CJR) and Transforming Episode Accountability Model (TEAM) programs
We do not use your information for advertising, marketing to third parties, or sale to data brokers.
4. How We Share Your Information
We do not sell your personal information or health data to any third party under any circumstance. We share your information only in the following limited circumstances:
- Your healthcare provider: Your clinic, surgeon, nurses, and authorized care team members can view your recovery data, vital sign readings, photographs, and survey results through our HIPAA-compliant provider portal. Provider access is strictly limited to patients at their own clinic through database-level Row Level Security controls.
- Business Associates (service providers): We share data with vendors who help us operate our platform. For any vendor that processes Protected Health Information (PHI) on our behalf, we maintain a signed Business Associate Agreement (BAA) as required by HIPAA. Categories of vendors we use include: cloud database and authentication providers, web hosting providers, transactional email providers, SMS messaging providers, AI service providers (with PHI sanitization applied where applicable), and security/network providers. A current list of named vendors and the status of their respective BAAs is available to clinic partners upon written request.
- Legal compliance: We may disclose information when required by law, court order, subpoena, or regulatory request, or when necessary to investigate suspected fraud, protect the rights, safety, or property of our users or others, or comply with HIPAA breach notification requirements.
- Business transfers: In the event of a merger, acquisition, or sale of all or part of our assets, your information may be transferred to the successor entity, subject to the same privacy commitments described in this Policy.
SMS Data Restriction: No mobile information, including phone numbers, opt-in data, or SMS message content, will be shared with any third parties or affiliates for marketing or promotional purposes under any circumstances. Mobile information is used solely for delivery of recovery reminders you have explicitly opted in to receive.
5. SMS / Text Message Reminders
If you choose to receive SMS reminders, you explicitly consent to receive automated text messages from Snapback Health at the mobile number you provide.
- Program name: Snapback Health Recovery Reminders
- Description: Automated medication reminders, exercise reminders, wound photo reminders, daily check-in reminders, and appointment reminders
- Message frequency: Varies based on your reminder settings — up to 6 messages per day
- Charges: Message and data rates may apply based on your mobile carrier plan
- Opt-out: Reply STOP to any text message at any time, or turn off SMS reminders in your account settings under the Reminders tab
- Help: Reply HELP to any message or email john.oshea@snapbackhealth.com
Your SMS opt-in consent is logged with timestamp in our database for audit purposes. SMS is disabled by default for all reminder types — you must affirmatively enable SMS for each reminder type you wish to receive via text message.
A complete description of our SMS reminder program, including a visual demonstration of the opt-in flow, is available at snapbackhealth.com/sms-opt-in.
6. Data Security
We implement comprehensive administrative, physical, and technical safeguards to protect your health information in accordance with HIPAA Security Rule requirements:
- Encryption in transit: All data transmitted between your device and our servers is encrypted using TLS 1.2 or higher (HTTPS)
- Encryption at rest: All data stored in our database is encrypted at rest using AES-256 encryption
- Access controls: Row Level Security policies enforce that each patient can only access their own records, and each healthcare provider can only access patients at their own clinic
- Authentication: All accounts require a unique email and password meeting minimum complexity requirements
- Audit logging: All access to patient health information is logged with user identity, timestamp, action, and resource accessed, for security monitoring and regulatory compliance
- Vendor management: Business Associate Agreements are executed with all third-party vendors who handle PHI
- Personnel: Authorized personnel (currently the founder) with access to PHI are subject to confidentiality obligations and ongoing security training
- Breach response: We maintain a documented incident response procedure and will notify affected individuals and the U.S. Department of Health and Human Services within HIPAA-mandated timeframes in the event of a breach
- Regular reviews: Security policies, access controls, and vendor BAAs are reviewed annually and after any material change to our services or vendor relationships
While we implement industry-standard safeguards, no method of electronic transmission or storage is one hundred percent secure. We cannot guarantee absolute security and encourage you to use strong, unique passwords and notify us immediately of any suspected unauthorized access.
7. Data Retention
We retain your health information for as long as your account is active or as required by applicable law. Specifically:
- Active patient records are retained for the duration of the patient-provider relationship and ongoing care
- Following account termination, records may be retained for a minimum of six (6) years as required by HIPAA, and longer if required by applicable state law
- Consent records and audit logs are retained for a minimum of six (6) years for compliance and regulatory purposes
- De-identified, aggregated data may be retained indefinitely for research and service improvement purposes
You may request deletion of your account and personal identifiers by contacting us at john.oshea@snapbackhealth.com, subject to the legal retention requirements above.
8. Your Rights Under HIPAA and Applicable Law
You have the following rights regarding your health information:
- Right to access: Receive a copy of your health information in electronic or paper format
- Right to amend: Request corrections to your health information that you believe is inaccurate
- Right to restrict: Request restrictions on how your information is used or shared
- Right to accounting of disclosures: Receive a list of disclosures of your health information made by us in the prior six years
- Right to confidential communications: Request that we communicate with you in a specific way or at a specific location
- Right to file a complaint: File a complaint with us or with the U.S. Department of Health and Human Services Office for Civil Rights if you believe your privacy rights have been violated. You will not be retaliated against for filing a complaint.
To exercise any of these rights, contact us at john.oshea@snapbackhealth.com. We will respond within thirty days as required by HIPAA.
9. Minor Patients
We recognize that patients of all ages may require post-surgical care. Minor patients (under 18) may use our platform only when their healthcare provider has invited them and a parent or legal guardian has provided consent on their behalf. For patients under 13, a parent or guardian must create and manage the account and provide consent under the Children's Online Privacy Protection Act. For patients aged 13 to 17, a parent or guardian must provide consent before the patient uses the Service. Healthcare providers are responsible for obtaining appropriate parental or guardian consent before inviting minor patients to the platform.
10. International Users
The Service is intended for use by patients of healthcare providers located in the United States. We do not market the Service to individuals outside the United States. If you access the Service from outside the United States, you do so at your own risk and acknowledge that your information will be processed in the United States in accordance with U.S. law.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, applicable law, or industry standards. We will notify you of material changes by email to your registered address or through a prominent notice in the patient portal at least thirty days before changes take effect. Your continued use of the Service after the effective date of changes constitutes your acceptance of the updated Policy.
12. California Residents — Additional Rights
If you are a California resident, you have additional rights under the California Consumer Privacy Act and California Confidentiality of Medical Information Act. These include the right to know what categories of personal information we collect, the right to delete personal information (subject to HIPAA retention requirements), and the right to opt out of the sale or sharing of personal information. We do not sell or share personal information for cross-context behavioral advertising. To exercise these rights, contact us at john.oshea@snapbackhealth.com.
13. Contact Us
If you have questions about this Privacy Policy, our privacy practices, or how we handle your health information, or to exercise any of your rights, please contact our Privacy Officer:
- Email: john.oshea@snapbackhealth.com
- Website: snapbackhealth.com
- Mailing address: Snapback Health Technologies LLC, 210 West Cedar Avenue, Flagstaff, Arizona 86001, United States
You may also file a HIPAA complaint with the U.S. Department of Health and Human Services Office for Civil Rights at https://www.hhs.gov/hipaa/filing-a-complaint/index.html.