Legal & compliance11 documents

Consumer Health Data Privacy Policy

Last updated 28 July 2026

This Consumer Health Data Privacy Policy (“Policy”) supplements the trellOS Privacy Policy and applies only to Consumer Health Data that trellOS collects, uses, or discloses outside of its role as a HIPAA Business Associate.

This Policy is intended to comply with the Washington My Health My Data Act (RCW 19.373), Nevada Senate Bill 370, and other applicable consumer health privacy laws.

This Policy does notapply to Protected Health Information (“PHI”) that trellOS creates, receives, maintains, or transmits on behalf of healthcare providers. Where trellOS processes PHI on behalf of a Covered Entity, trellOS functions as a Business Associate pursuant to the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), as amended by the Health Information Technology for Economic and Clinical Health Act (“HITECH Act”), including the HIPAA Privacy Rule, HIPAA Security Rule, and HIPAA Breach Notification Rule (45 C.F.R. Parts 160 and 164). Such information is governed by applicable Business Associate Agreements and the applicable healthcare provider’s Notice of Privacy Practices, not this Policy. See HIPAA and Your Health Records.

Questions about anything on this page? compliance@trellos.org