Notice of Privacy Practices

HIPAA Notice · Effective April 2026

This notice describes how medical information about you may be used and disclosed and how you can get access to this information. Please review it carefully.

1. Who We Are

AvataCore LLC (“AvataCore”) is a telehealth company that helps you access GLP-1 weight-management programs and related health services. We work with a network of licensed clinicians through our clinical partner, OpenLoop Health, to provide your care.

We are required by law to protect the privacy of your health information, follow the terms of this notice, and notify you if there is a breach of your unsecured health information.

2. What Is Protected Health Information (PHI)?

“Protected Health Information” or “PHI” is information about you — including your name, contact details, health conditions, medications, lab results, and payment details — that can identify you and relates to your health or the healthcare services you receive. This notice applies to all health information we hold about you.

3. How We Use and Share Your Health Information

For Your Treatment

We use your health information to provide, coordinate, and manage your care. This includes sharing information with the licensed providers in the OpenLoop Health network who evaluate and treat you, sending your prescription to a pharmacy to fill your GLP-1 medication, and coordinating follow-up care or referrals when needed.

For Payment

We use and share your health information to process payments and billing, including processing telehealth service payments and verifying insurance eligibility if applicable.

For Our Healthcare Operations

We use and share your health information to run our business and improve your care, including quality improvement, care coordination, staff training, audits, compliance reviews, and business operations.

4. Other Ways We May Use or Share Your Information

We may use or share your health information without your permission in these additional circumstances:

  • As required by law — to comply with federal, state, or local laws
  • Public health — to report diseases, injuries, or medication reactions to public-health authorities
  • Safety — to prevent a serious and imminent threat to your health or safety, or the health or safety of others
  • Government oversight — for audits, investigations, and inspections by government agencies that oversee healthcare
  • Legal proceedings — in response to a court order or other lawful process
  • Law enforcement — under specific legal circumstances
  • Organ donation — to facilitate organ or tissue donation if relevant
  • Workers’ compensation — as authorized by workers’ compensation laws
  • Research — for certain research studies with required privacy protections

5. Uses That Require Your Written Permission

For anything not listed above, we will ask for your written authorization before using or sharing your health information. This includes:

  • Marketing — we will not use your health information for marketing communications without your written permission
  • Sale of your information — we do not sell your health information. Ever.
  • Most research uses not covered by a privacy waiver

You may revoke your authorization at any time by writing to us at [email protected]. We will honor your revocation going forward, but cannot undo any uses or disclosures already made based on your prior permission.

6. Your Rights

You have the following rights regarding your health information. To exercise any of these rights, contact us at [email protected].

Right to See and Get a Copy of Your Records

You can ask to see or get a copy of your health records. We will respond within 30 days. A reasonable fee may apply for paper copies.

Right to Correct Your Records

If information is wrong or incomplete, ask us to correct it. We will respond within 60 days and may decline in limited circumstances.

Right to Request Limits on Uses and Disclosures

You may ask us to limit certain uses. We are not always required to agree, but we must honor requests to withhold information from a health plan when you paid for the service entirely out of pocket.

Right to Request Confidential Communications

You may ask us to contact you in a specific way or at a specific location. We will make reasonable efforts to honor your request.

Right to an Accounting of Disclosures

You may request a list of certain disclosures we made in the past six years. Treatment, payment, and operations disclosures, and disclosures you authorized, are not included.

Right to a Paper Copy

You may request a paper copy of this notice at any time.

Right to Be Notified of a Breach

If there is a breach of your unsecured health information, we will notify you as required by law.

7. Our Responsibilities

We are required by law to:

  • Maintain the privacy of your health information
  • Provide you with this notice of our legal duties and privacy practices
  • Follow the terms of this notice
  • Notify you if a breach of your unsecured health information occurs

We reserve the right to change this notice. If we make a material change, we will post the new notice on our website. The new notice will apply to all health information we hold, including information created before the change.

8. How to File a Complaint

If you believe your privacy rights have been violated, you may file a complaint with us or with the federal government. We will not retaliate against you for filing a complaint.

File a complaint with AvataCore:

Email: [email protected](subject line: “Privacy Complaint”)

File a complaint with the U.S. Department of Health and Human Services:

Office for Civil Rights
200 Independence Avenue, S.W.
Washington, D.C. 20201
Hotline: 1-800-368-1019
Website: hhs.gov/ocr/privacy/hipaa/complaints

9. About Our Clinical Partner

AvataCore works with OpenLoop Health to provide clinical telehealth services. OpenLoop Health is our Business Associate and operates under a signed Business Associate Agreement requiring them to protect your health information in accordance with HIPAA.

10. Contact Us

If you have questions about this notice or your privacy rights, contact our Privacy Officer:

Garet Frank
HIPAA Privacy Officer & Security Officer
AvataCore, LLC
6501 Arlington Expressway, B105 #7295
Jacksonville, FL 32211
Email: [email protected]
Website: avatacore.com

Effective Date: April 2026 · Version: 1.0