Privacy policy
Last updated August 10, 2026
We hold your health records so you can read and use them. We do not sell your information, we do not use it for advertising, and we do not use it to train artificial intelligence models. When you choose to send your records to an outside AI assistant, we tell you plainly what that means before you do it.
This policy explains how Market Me LLC, operating MyWholeFile MD, handles information. It is written to follow the structure of the Model Privacy Notice published by the Office of the National Coordinator for Health Information Technology, so that it can be compared against other health applications.
Our relationship to your clinician
MyWholeFile MD is provided through your clinician’s practice. The practice is a covered entity under the Health Insurance Portability and Accountability Act, and we act as its Business Associate. We handle your protected health information on the practice’s behalf and under a written Business Associate Agreement that requires us to safeguard it, limits what we may do with it, and obligates us to report any breach.
Your practice’s own Notice of Privacy Practices governs your relationship with them. This policy describes what we do with the copy of your information that we hold.
What information we collect
Health information from your clinicians. When you authorize a connection, we retrieve the categories of record that practice publishes, which may include medications, allergies and intolerances, conditions and problem lists, laboratory results, vital signs, immunizations, procedures, encounters and visits, care team members, clinical notes and visit summaries, and information about the organizations and clinicians who created those records.
Provenance information. For every clinical item we retain its origin: the source organization, the clinician or author where available, the encounter, the clinical date, the version and last update recorded by the source system, when we retrieved it, and whether it was entered by a clinician, reported by a patient, or derived.
Account information. Your name, email address, authentication factors, and the practice through which you enrolled.
Information you add. Documents you upload, notes you write, and information you provide about how you are feeling.
Operational records. Access logs, audit records of every read of your health information, error diagnostics, and security telemetry.
What we do not collect. We do not collect your patient portal passwords. We do not request insurance coverage records or records about your family members. We do not place advertising or session-replay trackers in the application.
Where the information comes from
- Your clinicians’ electronic health record systems, retrieved through standards-based interfaces after you authorize access
- You, directly
- Your practice, when it enrolls you
How we use it
- To assemble and present your health record to you
- To answer your questions about your own record, and to supply the record to an AI assistant you have connected
- To operate, secure, debug, and support the service
- To meet our legal and contractual obligations
We do not use your health information to develop or improve products for anyone other than you and your practice, and we do not analyze it to build profiles or generate insights for third parties.
What we never do
- We never sell your health information. Not to advertisers, data brokers, insurers, employers, pharmaceutical companies, or researchers, and not in any transaction where health data is exchanged for money or other valuable consideration.
- We never use your health information for advertising or to target you, and we do not permit any third party to do so through us.
- We never use your health information to train artificial intelligence models, ours or anyone else’s.
- We never write to your medical record. Our access is read-only.
What we share, and with whom
With your practice. We act on its behalf, and it may access information about your use of the service as permitted by our agreement with it.
With an AI assistant you connect. Only when you instruct us to, and only the categories you approve. This is the most consequential sharing decision available to you, and it has its own disclosure page explaining the legal mechanism and its consequences.
With service providers. Vendors that host and operate the service on our behalf, each bound by a written agreement and, where they handle protected health information, by a Business Associate Agreement. Each is named on our subprocessor page.
When the law requires it. In response to a valid legal demand, and only to the extent required. Where we are permitted to tell you, we will.
In a business transfer. If the service is acquired, your information may transfer. Any acquirer would be bound by commitments no less protective than these, and the prohibition on selling health information survives.
Your choices and rights
- Access and export. Obtain a complete, readable copy of everything we hold at any time.
- Deletion. Delete individual connections, your health data, or your entire account.
- Revocation. Disconnect any practice or any AI assistant immediately, without contacting support.
- Correction. We cannot amend your medical record, because we hold a copy rather than the original. You have a right to request an amendment from the practice that created the entry, and corrections flow through to us on the next sync.
See export and deletion for how to exercise these. As a Business Associate, some requests may need to be directed through your practice, and we will tell you when that applies and help you make the request.
How we protect it
Encryption in transit and at rest, additional encryption of credentials with per-record keys, database-enforced isolation between practices and between patients, tamper-evident audit logging of every access, least-privilege access for our own staff, and no third-party scripts anywhere that health information is handled. Our security page describes the design in more detail.
No system is perfectly secure. If your information is involved in a breach, we will notify your practice and you as required by the HIPAA Breach Notification Rule and applicable state law.
How long we keep it
We keep your health information while your account is active. When you delete your health data or your account, we remove it from active systems promptly and from encrypted backups within 90 days as those backups age out. Audit logs recording who accessed health information are retained for six years as HIPAA requires, and are not deleted on request, because their purpose is to record access that has already happened.
Children
The service is not offered directly to anyone under 18. Where a practice enables access for a minor patient, it is arranged through the practice with the legally authorized representative.
Changes to this policy
If we make a material change to how we handle health information, we will notify you before it takes effect. We will never make a retroactive change that reduces protection for information already collected without your explicit consent.
Contact
Privacy questions and requests: privacy@mywholefilemd.com. General support: support@mywholefilemd.com.
MyWholeFile MD is operated by Market Me LLC, Redondo Beach, CA, United States. A full mailing address is available on request for legal notices.