Legal

Privacy Policy and Notice of Privacy Practices

Last reviewed May 1, 2026

PRIVACY

Past Updated: August 14, 2026   ·   Effective: August 14, 2026

Welcome to Bloom360! We’re so glad you’re here.

Your health information belongs to you. This page explains, in plain English, what we collect, why we collect it, who else ever sees it, and how to tell us to stop. It’s long because the law asks us to cover a lot of ground, but nothing in it is designed to be hard to understand. If a section doesn’t make sense, email privacy@bloom360.com and a real person will walk you through it.

This Privacy Policy and Notice of Privacy Practices explains how Bloom360, Inc. (“Bloom360” or “Company”) and its affiliated professional medical entities, including Bloom360 Medical PLLC (“Practice,” and together with Bloom360, “we,” “us,” or “our”), handle your personal information, including on our website at bloom360.com and our other online or offline offerings which link to, or are otherwise subject to, this document (collectively, the “Services”). This document combines our Privacy Policy (Part One), covering how we collect, use, and protect your personal information, with our HIPAA Notice of Privacy Practices (Part Two), which describes how we use and disclose your protected health information and explains your rights under federal health privacy law. If you are a Bloom360 patient, both parts apply to you.

Contents

Part One: Privacy Policy

Section 1: What This Policy Covers

Section 2: Information We Collect

Section 3: How We Use Your Information

Section 4: When We Share Your Information

Section 5: Cookies and Tracking Technologies

Section 6: Security, Data Retention, and Children's Privacy

Section 7: Your Privacy Rights

Section 8: State-Specific Privacy Rights and Consumer Health Data

Section 9: Artificial Intelligence and Automated Tools

Section 10: Third-Party Links

Section 11: International Visitors

Section 12: Changes to This Policy

Section 13: Contact Us

Part Two: HIPAA Notice Of Privacy Practices

Section A: How We May Use and Disclose Your PHI

Section B: Authorization, Your HIPAA Rights, and Legal Duties

Section C: Complaints, Changes to This Notice, and Contact Information

PART ONE · PRIVACY POLICY

Section 1: What This Policy Covers

This Privacy Policy describes how we collect, use, disclose, and protect information when you use our Services. We’ve written it to be read, not skimmed past. If any part of it is unclear, tell us and we’ll make it clearer.

Bloom360, Inc. provides the technology platform, administrative services, and operational support for our Services. All clinical and medical services are provided by the Practice.

This Privacy Policy applies to you if you are a current or prospective member, a visitor to our website, or anyone who communicates with us through any channel. If you are a patient of the Practice, Part Two of this document (our HIPAA Notice of Privacy Practices) also applies to you and describes additional rights and protections for your protected health information.

By using our Services, you agree to the practices described in this Privacy Policy. If you do not agree, please do not access or use the Services. If something here is the reason you’re hesitating, we’d genuinely like to hear about it, so please email privacy@bloom360.com.

SECTION 2: INFORMATION WE COLLECT

We collect information in three ways: directly from you, automatically when you use our Services, and from third parties. Here is what that looks like.

2.1 Information You Provide Directly

• Account Data: name, email address, phone number, date of birth, and login credentials.

• Health and Medical Information: medical history, symptoms, diagnoses, medications, treatment preferences, and other clinical details you share with your care team.

• Payment Data: billing address, payment method details, and insurance information if applicable.

• Identity Verification: government-issued ID or other documentation required to confirm your identity.

• Communications: messages, emails, chat transcripts, and other correspondence with us or your care team, including interactions with automated care tools and AI-powered features within our Services.

• Survey Responses: feedback, questionnaires, and assessment responses you submit.

2.2 Information Collected Automatically

• Device Information: device type, operating system, browser type, and unique device identifiers.

• Usage Data: pages visited, features used, session duration, and interaction patterns.

• Location Data: general geographic location derived from your IP address.

• Cookies and Similar Technologies: as described in Section 5.

2.3 Information from Third Parties

• Healthcare Providers: records or referral information from your other providers, where permitted.

• Health Information Exchanges: clinical data shared through authorized health information networks, where we participate.

• Partners and Service Providers: information from vendors that help us deliver or improve our Services.

• Public Sources: publicly available information used to verify identity or support your care.

SECTION 3: HOW WE USE YOUR INFORMATION

We use the information we collect for the following purposes:

• Providing Care: Delivering, coordinating, and managing your healthcare services, including through AI-powered tools and automated features that support your care team.

• Account Management: Creating and maintaining your account, processing payments, verifying your identity, and sending membership-related communications.

• Improving Services: Analyzing how our platform is used so we can improve functionality, user experience, and clinical workflows.

• Communications: Sending appointment reminders, care updates, and service announcements, and responding to your questions or requests.

• Safety and Security: Detecting and preventing fraud, unauthorized access, and other harmful activity.

• Legal Compliance: Meeting our obligations under applicable federal and state laws and regulations.

• Marketing: With your consent where required by law, sending you information about our Services. You can opt out of marketing communications at any time.

• Quality Assurance: Conducting internal audits, workforce training, and quality improvement activities.

• De-Identified Data: We may create de-identified or aggregated data sets that can no longer identify you, using methods that comply with HIPAA and applicable state law. We may use this data for research, analytics, product development, and service improvement.

SECTION 4: WHEN WE SHARE YOUR INFORMATION

We do not sell your personal information. We never have, and our business model doesn’t depend on it. You pay us a membership fee, and that’s how we make money. We share your information only in the ways described below.

(a) Service Providers: We share information with vendors, contractors, and partners who perform services on our behalf, including AI vendors that support clinical and administrative functions. Each service provider is contractually bound to use your information only as directed by us and to maintain appropriate safeguards. AI vendors are required to enter into HIPAA-compliant Business Associate Agreements where applicable.

(b) Affiliates: We share information between Bloom360, Inc. and the Practice as necessary to deliver, coordinate, and support your care and our operations.

(c) Legal Requirements: We may disclose information when required by law, regulation, legal process, or enforceable governmental request.

(d) Business Transactions: If Bloom360 is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will provide notice before your information becomes subject to a different privacy policy.

(e) With Your Consent: We may share your information for purposes not described in this Privacy Policy when you give us your consent.

(f) De-Identified Data: We may share de-identified or aggregated data that can no longer reasonably identify you.

(g) Healthcare Operations: For patients, your protected health information may be used and disclosed as described in Part Two of this document.

SMS/Text Messages: If you opt in to receive text messages from us, your opt-in data and consent will not be shared with third parties for their own marketing purposes.

SECTION 5: COOKIES AND TRACKING TECHNOLOGIES

We use cookies and similar tracking technologies to operate our website, understand how visitors interact with our pages, and support our marketing efforts. Cookies are small data files placed on your device that help us recognize your browser and remember certain information.

We organize cookies into four categories:

• Strictly Necessary: Required for core website functionality, such as security, authentication, and session management. These cookies cannot be disabled.

• Performance and Analytics: Help us understand how visitors interact with our website so we can improve performance and usability.

• Functional: Remember your preferences and settings to provide a more personalized experience.

• Marketing and Advertising: Used on our public, unauthenticated pages to measure the effectiveness of our marketing campaigns and deliver relevant information about our Services. These cookies are never placed on pages where you are logged in or providing health information.

We do not place advertising or third-party tracking technologies on any page where you are logged in, accessing your health information, or communicating with your care team.

You can manage your cookie preferences by adjusting your browser settings at any time. Disabling certain cookies may affect the functionality of our Services.

To the extent our use of marketing cookies constitutes a "sale" or "sharing" of personal information under applicable state law, you may opt out by sending a recognized opt-out preference signal such as Global Privacy Control (GPC). Where required by applicable law, we honor GPC signals.

SECTION 6: SECURITY, DATA RETENTION, AND CHILDREN'S PRIVACY

6.1 Security

We take the protection of your information seriously. We maintain administrative, technical, and physical safeguards designed to protect your personal information and protected health information from unauthorized access, use, or disclosure. These safeguards include:

• Encryption of data in transit and at rest

• Role-based access controls that limit information access to authorized personnel

• Regular security assessments and vulnerability testing

• Workforce training on privacy and security practices

• Monitoring systems designed to detect and respond to potential threats

No method of electronic transmission or storage is 100% secure. While we work hard to protect your information, we cannot guarantee absolute security.

6.2 Data Retention

We retain your personal information and health records for as long as necessary to fulfill the purposes described in this Privacy Policy and to comply with our legal obligations. Medical records are retained for a minimum of seven (7) years from the date of your last treatment, or longer where required by applicable state or federal law.

When your information is no longer needed, we securely delete or de-identify it using methods consistent with HIPAA standards and applicable state law.

6.3 Children's Privacy

Our Services are designed for adults aged 18 and older. We do not knowingly collect personal information from anyone under the age of 18. If we learn that we have collected information from a minor, we will promptly delete that information. If you believe a minor has provided us with personal information, please contact us at privacy@bloom360.com.

SECTION 7: YOUR PRIVACY RIGHTS

We respect your right to control your personal information. Depending on where you live, applicable state and federal laws may provide you with the following rights:

• Right to Know and Access: You may request confirmation of whether we process your personal information and obtain a copy of the specific data we hold about you.

• Right to Correct: You may request that we correct inaccurate personal information we maintain about you.

• Right to Delete: You may request deletion of your personal information, subject to certain legal exceptions (for example, where retention is required for medical records or legal compliance).

• Right to Opt Out of Sale or Sharing: You may opt out of the sale or sharing of your personal information. We do not sell your personal information; however, this right is available to you under applicable law.

• Right to Limit Use of Sensitive Information: You may request that we limit our use of sensitive personal information to what is necessary to provide the Services.

• Right to Data Portability: Where required by applicable state law, you may request a portable copy of your personal information in a commonly used, machine-readable format.

• Right to Non-Discrimination: We will not discriminate against you for exercising any of your privacy rights.

The rights in this section apply to personal information that is not protected health information ("PHI"). Your rights regarding PHI are described in Part Two of this document and are governed by HIPAA.

We will respond to your request within 45 days of receipt. If we need additional time, we will notify you of the extension and the reason for it.

You may designate an authorized agent to submit a request on your behalf. We may require verification of your identity and confirmation that the agent is authorized to act for you before processing the request.

To exercise any of these rights, contact us at privacy@bloom360.com.

If we deny your request, you may appeal by emailing us with the subject line "Privacy Rights Appeal." We will respond to your appeal within the timeframe required by applicable law.

SECTION 8: STATE-SPECIFIC PRIVACY RIGHTS AND CONSUMER HEALTH DATA

8.1 California. If you are a California resident, you have rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA). The rights described in Section 7 apply to you. In the preceding 12 months, we have not sold personal information as defined under the CCPA. To the extent our use of certain cookies constitutes "sharing" for cross-context behavioral advertising, you may opt out through a recognized opt-out preference signal.

8.2 Virginia, Colorado, Connecticut, Oregon, Texas, Montana, Minnesota, Delaware, Iowa, Indiana, Tennessee, New Hampshire, New Jersey, Nebraska, Kentucky, Maryland, and Other States with Comprehensive Privacy Laws. If you reside in a state with a comprehensive privacy law, you may have the right to access, correct, and delete your personal information, obtain a portable copy, and opt out of targeted advertising, profiling, or the sale of personal information. To exercise these rights, contact us as described in Section 7. As privacy laws continue to evolve across the country, we are committed to honoring the rights provided by your state's laws. If your state provides privacy rights not listed here, please contact us and we will work with you.

8.3 Consumer Health Data (Washington, Nevada, Connecticut, and Other Applicable States). If you reside in a state with a consumer health data privacy law, additional protections apply to certain health-related information collected through our Services. Consumer health data is personal information linked or reasonably linkable to you that identifies your past, present, or future physical or mental health status, including information about health conditions, diagnoses, treatments, medications, and related activities, as well as information that could reveal your attempt to seek healthcare services. Consumer Health Data Privacy Notice — bloom360.com/consumer-health-data

How we handle consumer health data:

• We collect consumer health data only as necessary to provide our Services and as described in this Privacy Policy.

• We share consumer health data only as needed to deliver your care, support our operations, or with your consent.

• We do not sell consumer health data.

• Our service providers that process consumer health data are contractually bound to use it only as directed by us and to maintain appropriate safeguards.

Your consumer health data rights: You have the right to confirm whether we are collecting, sharing, or selling your consumer health data; access your consumer health data; request deletion; withdraw consent from our collection and sharing of your consumer health data; and receive a list of third parties with whom we have shared your consumer health data. We will respond to consumer health data requests within 45 days.

Washington residents may file complaints with the Washington State Attorney General at www.atg.wa.gov/file-complaint. For all consumer health data requests, contact us at privacy@bloom360.com.

Section 9: Artificial Intelligence and Automated Tools

We use artificial intelligence and automated tools to support and improve the care we deliver. This section explains what these tools do and how we protect your information when they are involved.

9.1 How We Use AI

Our AI-powered tools may assist with:

• Clinical documentation and note preparation

• Care plan recommendations and health risk assessments

• Patient-facing features such as automated care assistants, chat-based tools, and interactive health assessments within the Services

• Administrative workflows and operational efficiency

AI-powered tools, including any automated or interactive features within our Services, operate under the oversight of your care team. They support clinical decision-making but do not independently make medical decisions. All clinical decisions are made by licensed healthcare professionals within the Practice.

9.2 How We Protect Your Information in AI Systems

All AI vendors and partners that create, receive, maintain, or transmit your protected health information are required to enter into HIPAA-compliant Business Associate Agreements and adhere to our data security and privacy standards. AI vendors that do not handle protected health information are bound by confidentiality and data security commitments.

Our AI vendors are contractually required to limit retention of your health information to the minimum necessary to provide the Services and to delete or de-identify it in accordance with their Business Associate Agreement obligations.

Your health information is not used by our AI vendors to train, improve, or develop general-purpose AI models available to third parties.

If you have questions about how AI is used in your care, contact us at privacy@bloom360.com.

Section 10: Third-Party Links

Our Services may contain links to websites, applications, or services operated by third parties. We are not responsible for the privacy practices, content, or security of any third-party site or service. We encourage you to review the privacy policy of any site you visit before providing your information.

Section 11: International Visitors

Our Services are designed for use within the United States and are governed by U.S. federal and state law. If you access our Services from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States. By using our Services, you consent to the transfer of your information to the United States.

Section 12: Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. If we make material changes, we will provide advance notice by posting the updated policy on our website and, where appropriate, notifying you by email. The "Last Updated" date at the top of this document will always reflect the most recent revision. Your continued use of the Services after the effective date of any changes constitutes your acceptance of the updated Privacy Policy.

Section 13: Contact Us

If you have questions about this Privacy Policy, want to exercise any of your privacy rights, or would like to get in touch, we are here to help. A real person reads this inbox.

• Email: privacy@bloom360.com

• Phone: (833) 348-3044

• Mail: Bloom360, Inc., Attn: Privacy Officer, 4444 2nd Ave Ste 30674, Detroit, MI 48201

PART TWO · HIPAA NOTICE OF PRIVACY PRACTICES

Section A: How We May Use and Disclose Your PHI

The section below is our formal HIPAA notice. Federal law dictates much of this language, so it reads more legal than the rest of this document. The short version: we protect your medical information, we share it only for treatment, payment, healthcare operations, or when the law requires it, and you have real, enforceable rights over it.

THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.

This Notice of Privacy Practices ("Notice") applies to Bloom360 Medical PLLC and its affiliated professional entities (the "Practice"), along with their workforce members and business associates who create, receive, maintain, or transmit your protected health information ("PHI") in connection with the healthcare services we provide. Bloom360, Inc. supports the Practice by providing technology, administrative, and operational services and serves as a business associate of the Practice under a Business Associate Agreement.

PHI is individually identifiable health information, whether oral, written, or electronic, that relates to your past, present, or future physical or mental health, the provision of healthcare to you, or payment for that care.

The Practice may use and disclose your PHI in the following ways without your written authorization:

• Treatment: To provide, coordinate, and manage your healthcare. For example, your physician may share your care plan with a wellness coach on your care team so they can relay physician-approved recommendations to you. We may also use your PHI to contact you with appointment reminders, information about treatment alternatives, or other health-related benefits and services that may be of interest to you.

• Payment: To bill and collect payment for the services you receive.

• Healthcare Operations: For quality assessment, training, compliance activities, audits, and other internal operations that support the care we deliver.

• Required by Law: When federal, state, or local law requires disclosure.

• Public Health Activities: To public health authorities for purposes such as preventing or controlling disease, injury, or disability.

• Health Oversight Activities: To health oversight agencies for audits, investigations, inspections, and licensure activities authorized by law.

• Abuse, Neglect, or Domestic Violence: To appropriate authorities when we reasonably believe you are a victim of abuse, neglect, or domestic violence, as permitted or required by law.

• Decedents: To coroners, medical examiners, or funeral directors as necessary to carry out their duties.

• Research: For approved research purposes, subject to applicable safeguards and oversight.

• Serious Threats to Health or Safety: To prevent or lessen a serious and imminent threat to your health or safety or that of another person or the public.

• Workers' Compensation: As authorized by workers' compensation or similar programs.

• Business Associates: To third parties that perform services on our behalf, provided they enter into a Business Associate Agreement requiring them to safeguard your PHI.

Certain health records may receive additional protections under federal or state law. Where applicable, we apply those protections in accordance with the law. These may include records of substance use disorder treatment received from a program covered by 42 C.F.R. Part 2, mental health records, HIV-related information, and genetic information, which may require your specific written consent before we disclose them.

Section B: Authorization, Your HIPAA Rights, and Legal Duties

When Your Authorization Is Required

The Practice will obtain your written authorization before using or disclosing your PHI for purposes other than those described in Section A. The following uses and disclosures require your written authorization:

• Use or disclosure of psychotherapy notes, where applicable

• Use of your PHI for marketing purposes where the Practice receives financial remuneration from a third party in connection with the communication

• Any sale of your PHI

You may revoke your authorization at any time by submitting a written request to our Privacy Officer. Revocation will not affect any uses or disclosures made in reliance on your authorization before we received your revocation.

Your HIPAA Rights

Under federal law, you have the following rights with respect to your PHI:

• Right to Access: You may request a copy of your PHI. We will respond within 30 days of your request, with one 30-day extension if needed. A reasonable, cost-based fee may apply.

• Right to Amendment: You may ask us to correct PHI you believe is inaccurate or incomplete. We may deny the request in certain circumstances and will explain the reason in writing.

• Right to an Accounting of Disclosures: You may request a list of certain disclosures of your PHI made by the Practice during the six years prior to your request.

• Right to Request Restrictions: You may ask us to limit how we use or disclose your PHI. We are required to agree to your restriction if the disclosure is to a health plan for payment or healthcare operations and the PHI relates to a service for which you have paid out of pocket in full.

• Right to Confidential Communications: You may request that we communicate with you at a specific phone number, email address, or mailing address.

• Right to a Paper Copy: You may request a paper copy of this Notice at any time.

• Right to Breach Notification: You will be notified if a breach of your unsecured PHI occurs, as required by law.

Our Legal Duties

The Practice is required by law to maintain the privacy of your PHI, provide you with this Notice of our legal duties and privacy practices, and abide by the terms of the Notice currently in effect.

To exercise any of these rights, contact our Privacy Officer at privacy@bloom360.com, call us at (833) 348-3044, or write to Bloom360, Inc., Attn: Privacy Officer, 4444 2nd Ave Ste 30674, Detroit, MI 48201.

Section C: Complaints, Changes to This Notice, and Contact Information

If you believe your privacy rights have been violated, you have the right to file a complaint. You will not be penalized, retaliated against, or denied care for filing a complaint.

Filing a Complaint with Bloom360: You may contact our Privacy Officer directly:

• Email: privacy@bloom360.com

• Phone: (833) 348-3044

• Mail: Bloom360, Inc., Attn: Privacy Officer, 4444 2nd Ave Ste 30674, Detroit, MI 48201

Filing a Complaint with the U.S. Department of Health and Human Services: You may also file a complaint with the Office for Civil Rights (OCR):

• U.S. Department of Health and Human Services, Office for Civil Rights, 200 Independence Avenue, S.W., Washington, D.C. 20201

• Phone: 1-877-696-6775

• Website: www.hhs.gov/ocr/privacy/hipaa/complaints

Changes to This Notice: The Practice reserves the right to change this Notice at any time. Any revised Notice will apply to PHI we already hold as well as PHI we create or receive after the change. When we make a material change, we will post the updated Notice on our website at bloom360.com/privacy with a new effective date. You may request a copy of the current Notice at any time by contacting us.

Contact Information: If you have any questions about this Notice or would like to exercise any of your HIPAA rights, please reach out:

• Email: privacy@bloom360.com

• Phone: (833) 348-3044

• Mail: Bloom360, Inc., Attn: Privacy Officer, 4444 2nd Ave Ste 30674, Detroit, MI 4820