Privacy Policy
How Puzzle Healthcare collects, uses, and protects your information — including HIPAA-covered health data and SMS communications.
This Privacy Policy describes how Puzzle Healthcare collects, uses, and protects your information, including with respect to SMS communications and health data.
SMS Messaging
Puzzle uses SMS to coordinate care with patients on behalf of the discharging facility. Consent is obtained at enrollment. Message frequency is typically 1–2 messages per day. Reply STOP to opt out or START to opt back in. Standard message and data rates may apply.
Data Security
All patient data is encrypted in transit and at rest. Access is role-based and audited. Puzzle undergoes regular third-party security assessments and maintains HIPAA-compliant infrastructure.
HIPAA Compliance
Puzzle operates as a Business Associate under HIPAA and maintains executed BAAs with all covered-entity partners. Protected Health Information is handled in accordance with 45 CFR Parts 160 and 164.
Patient Rights
Patients have the right to access their information, request amendments, and receive an accounting of disclosures. To exercise any right, email privacy@puzzlehealthcare.com.
Data Retention and Disposal
Records are retained for the period required by law and covered-entity agreements, then securely disposed of using industry-standard methods.
Policy Updates
Material changes to this policy will be posted here with a revised effective date.