Privacy Policy and Notice of Privacy Practices

Last updated: July 15, 2026

This document includes the Privacy Policy for the SiggyMD application, website, and related services, followed by the HIPAA Notice of Privacy Practices for patients. Sigmind, Inc. operates the SiggyMD application and related technology services. Affiliated Siggy medical groups provide clinical care and are covered by the HIPAA Notice below.

Information We Collect and How We Collect It

We collect personal information when you provide it, when you use the Services, when clinicians create or receive information in connection with your care, and when service providers perform functions for us. The information we collect depends on the features you use.

Information You Provide

This may include your name, email address, phone number, date of birth, state of residence, time zone, account credentials, notification preferences, payment or insurance information, support communications, and other information you submit through forms or account settings.

Health, Intake, and Care Information

This may include your intake answers, chat messages, symptoms, health and medication history, treatment goals, daily check-ins, clinician communications and notes, diagnoses, prescriptions, billing and insurance records, consent records, and other information associated with your care.

Device, Usage, and Optional Media Information

We may automatically collect device and app information, IP address, time zone, usage events, diagnostic and crash information, notification tokens and preferences, and security logs. If you choose to use voice input or send feedback attachments, we also collect the audio, photos, screenshots, or video you select and the resulting text or feedback.

How We Use Information

We use personal information to operate and secure the Services; create and maintain accounts; provide intake, healthcare, and clinician review; generate and maintain medical records; process payments and insurance workflows; deliver reminders and other communications; respond to support requests; prevent fraud or misuse; comply with legal, regulatory, professional, payer, pharmacy, prescribing, accounting, security, and audit obligations; and evaluate the reliability, performance, and safety of the Services.

Artificial Intelligence Processing

With your permission, SiggyMD sends information to Amazon Web Services ("AWS") through Amazon Bedrock for artificial intelligence processing. The information sent may include what you type, intake answers, symptoms, health and medication history, prior conversation, clinician-reviewed context, and any identifying information you choose to include in free-text messages.

Amazon Bedrock uses models developed by Anthropic and OpenAI to generate responses, organize and summarize information for clinician review, support clinician-supervised intake, and flag potential safety concerns for human review. SiggyMD does not send your information directly to Anthropic or OpenAI. The AI does not make final diagnoses, prescribe medication, or make final treatment decisions; licensed clinicians make those decisions.

AWS processes this information under contractual privacy and security safeguards, including a business associate agreement and data protection terms. SiggyMD configures its Bedrock use for zero data retention, so AWS does not write prompts or responses to durable storage or share them with model providers after processing. AWS, Anthropic, and OpenAI do not use your prompts or SiggyMD responses to train their models through this Bedrock processing. Model providers do not have access to SiggyMD prompts or responses processed within Bedrock.

SiggyMD may retain relevant AI interactions as part of your care record. We may use de-identified information derived from AI interactions for internal quality assurance, safety testing, and product improvement. We do not use identifiable AI interactions to train outside AI models.

Your Permission

Before SiggyMD sends personal information to Amazon Bedrock, the app identifies the information that will be sent, identifies AWS and the models used through Bedrock, and asks you to affirmatively consent. If you do not consent, SiggyMD will not send your information to Bedrock, and AI-enabled features will remain unavailable.

When We Share Information

We may share information with affiliated medical groups and clinicians involved in your care; service providers that support hosting, authentication, AI processing, communications, notifications, billing, analytics, security, and customer support; payers, pharmacies, and other healthcare partners; and government authorities or other parties when required or permitted by law. We do not sell your health information.

We require third parties that receive personal information from us to provide the same or equal protection described in this Policy and required by applicable law. Their access is limited to the information and purposes needed to perform services for us or as otherwise legally permitted.

Data Retention

SiggyMD retains personal information for as long as reasonably necessary to provide and support the Services, maintain your account, provide healthcare services, process transactions, maintain records of care, comply with legal, regulatory, professional, payer, pharmacy, prescribing, accounting, security, and audit obligations, resolve disputes, prevent fraud or misuse, enforce our agreements, and protect the safety and integrity of our Services.

Clinical information and protected health information, including intake information, medical history, clinical communications, clinician notes, prescriptions and prescription-related records, consent records, billing records, insurance records, and other records associated with care provided through SiggyMD, may be retained as part of the medical record for at least ten (10) years after your last interaction, visit, prescription, or treatment-related encounter with SiggyMD, or longer if required or permitted by applicable federal or state law, payer requirements, pharmacy or prescribing rules, professional standards, audits, investigations, disputes, litigation holds, or other legal or regulatory obligations.

Other personal information, such as account information, support communications, device or usage information, analytics information, and marketing preferences, may be retained for shorter or longer periods depending on the type of information, the reason it was collected, user choices, operational needs, legal requirements, and our legitimate business purposes. When information is no longer needed in identifiable form, we may delete it, aggregate it, or de-identify it. Backup copies and security logs may persist for a limited period according to our normal backup, security, and disaster-recovery procedures before they are deleted or overwritten.

Data Deletion Requests

You may request deletion of your SiggyMD account and eligible personal information by emailing support@siggymd.ai with the subject line “Data Deletion Request.” Please send your request from the email address associated with your SiggyMD account or include your name, account email address, phone number, and enough information for us to verify your identity and locate your account.

After we verify your request, we will delete, deactivate, or de-identify personal information that we are not required or permitted to retain. We will aim to complete eligible deletion requests within 45 days after verification unless a longer period is permitted or required by law. We may retain certain information where necessary to comply with healthcare, medical-record, prescribing, pharmacy, billing, insurance, tax, accounting, fraud-prevention, security, audit, dispute-resolution, litigation, or other legal and regulatory obligations. If we cannot delete specific information for these reasons, we will explain the reason where required and, where appropriate, restrict or deactivate account access.


THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.

Notice of Privacy Practices (HIPAA) - For Patients

This Notice of Privacy Practices describes how "Siggy Medical Group, P.A.," "Siggy Medical Group of CA, P.C.," "Siggy Medical Group NJ P.A.," and other affiliated professional entities, each of which may operate under the brand name "Siggy MD" (collectively, "we" or "us"), each of which are members of an affiliated covered entity ("ACE"), may use and disclose your protected health information and your rights to access and control your protected health information. "Protected health information" is information about you, including demographic information, that may identify you and that relates to your past, present or future physical or mental health or condition and related health care services. We are required to abide by the terms of this Notice of Privacy Practices. We may change the terms of our notice at any time. The new notice will be effective for all protected health information that we maintain at that time. It will be available upon request and on our website.


1. Uses and Disclosures of Protected Health Information

Following are examples of the types of uses and disclosures of your protected health information that we are permitted to make. These examples are not meant to be exhaustive, but to describe the types of uses and disclosures that we may make.

Treatment

We will use and disclose your protected health information to provide, coordinate, or manage your health care and any related services. This includes the coordination of your health care with another provider. For example, we would disclose your protected health information, as necessary, to a clinician or hospital that provides care to you, such as by providing information about your assessments and prescriptions to your other treating providers. We also may make your protected health information available to third-party health care providers by making it accessible through a health information exchange ("HIE"). This means that if one of your other treating clinicians uses an HIE that we participate in, the clinician will be able to access the protected health information generated in the course of your treatment with us, subject to all required consents. We also may access your protected health information available through the HIE to provide treatment to you, subject to any required consents.

Coordinated Care With Other Providers

We may use and disclose your protected health information to coordinate your care with other health care providers, professional medical groups, and clinical partners involved in your treatment. This may include Bridge-affiliated professional entities or providers when they are involved in your care, co-treating you, supporting clinical services, or coordinating treatment, referrals, insurance-related workflows, or follow-up care. These disclosures may include information reasonably necessary for treatment, care coordination, payment, health care operations, quality assurance, documentation, and continuity of care.

Payment

Your protected health information will be used and disclosed, as needed, to obtain payment for your health care services provided by us or by another provider. This may include responses to inquiries regarding invoices for the health care services we provide. We may also disclose protected health information to providers, professional entities, billing partners, payers, and other parties involved in verifying coverage, submitting claims, processing payment, resolving billing issues, or supporting insurance-related operations for you.

Health Care Operations

We may use or disclose your protected health information in order to support our business activities, including for quality assessment, employee review, training and conducting or arranging for other business activities. We also may share your protected health information with third-party "business associates" that perform various activities for us. We will have a written contract with business associates to protect the privacy of your protected health information. We may use or disclose your protected health information, as necessary, to provide you with information about our services or other health-related benefits and services that may be of interest to you; you may contact our Privacy Officer to opt out of receiving these materials.

Affiliated Covered Entity

We, as members of an ACE, will share your protected health information with each other for treatment, payment and the health care operations of the affiliated covered entity and as permitted by HIPAA and this Notice.


Other Permitted and Required Uses and Disclosures

These situations include uses and disclosures that may be made without your authorization or opportunity to agree or object:

Required by Law

We may use or disclose your protected health information to the extent that the use or disclosure is required by law. The use or disclosure will be made in compliance with the law and will be limited to the relevant requirements of the law.

Public Health

We may disclose your protected health information for public health activities and purposes to a public health authority that is permitted by law to collect or receive the information.

Health Oversight

We may disclose protected health information to a health oversight agency for activities authorized by law, such as audits, investigations, and inspections.

Abuse or Neglect

We may disclose your protected health information if we believe that you have been a victim of abuse, neglect or domestic violence to the governmental entity or agency authorized to receive such information.

Legal Proceedings

We may disclose protected health information in the course of any judicial or administrative proceeding, in response to an order of a court or administrative tribunal.

Law Enforcement

We may also disclose protected health information, so long as applicable legal requirements are met, for law enforcement purposes.

Research

We may disclose your protected health information to researchers when their research has been approved by an institutional review board.

Workers' Compensation

We may disclose your protected health information as authorized to comply with workers' compensation laws and other similar legally-established programs.


Uses and Disclosures Based on Your Written Authorization

Other uses and disclosures of your protected health information will be made only with your written authorization, unless otherwise permitted or required by law. You may revoke any authorization in writing at any time. If you revoke your authorization, we will no longer use or disclose your protected health information for the reasons covered by your written authorization. Please understand that we are unable to take back any disclosures that you previously authorized.


2. Your Rights

Following is a statement of your rights with respect to your protected health information.

Right to Inspect and Copy

You have the right to inspect and obtain a copy of protected health information about you, including medical and billing records.

Right to Request Restriction

You may ask us not to use or disclose any part of your protected health information for the purposes of treatment, payment or health care operations.

Right to Confidential Communications

You have the right to request to receive confidential communications from us by alternative means or at an alternative location.

Right to Request Amendment

You may have the right to request an amendment of your protected health information.

Right to Accounting of Disclosures

You have the right to receive an accounting of certain disclosures we have made of your protected health information.

Right to Breach Notification

You have the right to be notified of a breach of unsecured protected health information that affects you.


3. Complaints

If you believe your privacy rights have been violated by us, you may file a complaint with our Privacy Officer via email at support@siggymd.ai. We will not retaliate against you for filing a complaint.

You may also file a complaint with the HHS Office for Civil Rights.