Legal
Privacy Policy.
Effective July 27, 2026
This policy covers the information Provost collects through its website, waitlist, and app. Health information created when you become a patient of the Provost Medical Group is governed instead by a separate HIPAA Notice of Privacy Practices.
This Privacy Policy describes how Congruence Corporation d/b/a Provost Health ("Provost," "we," "us," or "our") collects, uses, discloses, and safeguards information when you visit our website, join our waitlist, or use our applications and related services (collectively, the "Services"). By using the Services, you acknowledge that you have read and understand this Privacy Policy.
1. Who we are, and which document applies
Provost is a management services organization. Provost is not a health care provider, does not practice medicine, and is not a Covered Entity under HIPAA. Clinical services are provided by independently owned professional corporations — referred to here as the "Medical Group" — whose licensed physicians and clinicians exercise independent professional judgment. Provost furnishes the Medical Group with technology, administrative support, and non-clinical staffing under a management services agreement.
That distinction determines which privacy document governs your information:
- This Privacy Policy governs information Provost collects through the website, the waitlist, marketing, and the non-clinical parts of our applications.
- The Notice of Privacy Practices issued by the Medical Group governs Protected Health Information ("PHI") created or received in the course of your treatment. The Medical Group is the health care provider and is a Covered Entity under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"). Provost handles PHI only as the Medical Group's Business Associate, under a written Business Associate Agreement. Where HIPAA applies, it controls, and nothing in this Privacy Policy limits your rights under it.
- Where the Medical Group is made up of more than one professional corporation under common ownership or control — for example, a separate entity in each state where we practice — those entities may designate themselves an Affiliated Covered Entity under HIPAA. That lets one Notice of Privacy Practices, one privacy official, and one set of privacy practices cover all of them, and lets them share PHI with each other for treatment, payment, and health care operations. You may request the current list of entities from the Privacy Officer.
If you have not yet become a patient — for example, if you have only joined the waitlist — the information you have given us is generally not PHI, and this Privacy Policy governs it.
2. Information we collect
a. Information you provide
When you join the waitlist we collect your name, email address, and any message you choose to send us. If you become a patient or create an account, we may also collect your mailing address, date of birth, telephone number, payment information, insurance information, and emergency contact.
b. Information collected automatically
When you visit our website we collect technical information including IP address, browser type and version, operating system, referring URLs, pages viewed, and the dates and times of your visits. We use this for analytics, security monitoring, and performance.
c. Connected device and wearable data
If you choose to connect a wearable or health application — for example a smart ring, band, watch, continuous glucose monitor, or a platform such as Apple Health — we receive the categories of data you authorize, which may include heart rate, heart rate variability, sleep, oxygen saturation, temperature, activity, and glucose readings. We use a third-party integration provider to normalize this data.
Connecting a device is always optional, you choose which data to share, and you may disconnect a device at any time. Disconnecting stops future collection; it does not remove data already incorporated into your medical record, which is retained as a clinical record requires.
d. Health information you send us before you are a patient
Please do not send detailed health information through the website or the waitlist form. If you do, we will treat it with the same safeguards we apply to health information generally, but a secure clinical channel is the right place for it.
e. De-identified and aggregated data
We may create de-identified or aggregated datasets, de-identified in accordance with 45 C.F.R. § 164.514(b). We may use such data to improve our services and for research and quality measurement. We do not attempt to re-identify de-identified data, and we require the same of anyone we share it with.
3. How we use information
- To operate, maintain, and improve the Services
- To administer the waitlist and tell you when care is available near you
- To support the Medical Group in providing treatment, and to carry out payment and health care operations on its behalf
- To surface clinically relevant changes — such as a lab value or a device trend moving out of range — to your care team
- To verify your identity and secure your account
- To detect, investigate, and prevent security incidents, fraud, and unauthorized activity
- To comply with legal and regulatory obligations, including HIPAA and state health privacy law
- To communicate with you about your care, appointments, and administrative matters
We do not use PHI for marketing, and we do not sell personal information or PHI. We do not use your health information to train general-purpose machine learning models offered to third parties.
4. How we share information
We do not sell your personal information. We share it only as described below:
- The Medical Group and your care team, so that your clinicians can treat you.
- Service providers — including cloud hosting, communications, payment processing, laboratory and imaging partners, and the device-integration provider — who are bound by contract, and by a Business Associate Agreement where they handle PHI.
- Other treating providers, such as specialists we refer you to, consistent with HIPAA and your instructions.
- Legal compliance, where required by law, regulation, subpoena, court order, or governmental request, and to report as public health or safety law requires.
- Business transfers, in a merger, acquisition, or sale of assets. We will give notice before your information becomes subject to a different privacy policy, and medical records will transfer only as permitted by law.
- With your authorization, for anything else. Where HIPAA requires a written authorization, we will obtain one, and you may revoke it.
5. Artificial intelligence and human review
Provost uses artificial intelligence to read your record, draft responses, summarize results, and flag changes that deserve attention. This is central to how the Services work, so we want to be plain about it.
- A licensed clinician reviews AI output before it is used to make a clinical decision about you. AI does not diagnose you, prescribe for you, or independently direct your care.
- AI-generated content is grounded in your own record and in clinical references. It can still be wrong, and it is not a substitute for the judgment of your physician.
- We do not make decisions producing legal or similarly significant effects about you through automated processing alone.
- Where state or federal law gives you the right to know that AI was involved in a communication or a clinical recommendation, we will tell you.
6. Your choices and rights
If you are a patient, HIPAA gives you rights over your PHI — including the rights to inspect and obtain a copy of your record, to request an amendment, to receive an accounting of certain disclosures, to request restrictions and confidential communications, and to be notified of a breach. Those rights are described in the Medical Group's Notice of Privacy Practices and are not limited by this policy.
For information governed by this Privacy Policy, you may request access, correction, deletion, a portable copy, or restriction of processing by writing to privacy@provosthealth.com. We will not discriminate against you for exercising these rights.
California
Under the California Consumer Privacy Act, as amended, California residents may request disclosure of the categories and specific pieces of personal information we have collected, the purposes for collection, and the categories of recipients; may request deletion or correction; and may limit the use of sensitive personal information. We do not sell or share personal information for cross-context behavioral advertising. Medical information governed by HIPAA and the California Confidentiality of Medical Information Act is exempt from the CCPA and is handled under those statutes instead.
Washington and Nevada consumer health data
The Washington My Health My Data Act and Nevada Senate Bill 370 regulate "consumer health data" that falls outside HIPAA — which, for us, principally means connected-device data and information collected before you become a patient. We collect that data to provide the Services you have asked for, we obtain your consent before collecting it, and we obtain a separate signed authorization before any sale of it. We do not sell consumer health data. Washington and Nevada residents may request access to and deletion of consumer health data, and may withdraw consent, at privacy@provosthealth.com. We do not use a geofence around any facility providing health care services.
Other states
Residents of states with comprehensive privacy statutes — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and Montana, among others — have rights of access, correction, deletion, portability, and opt-out of targeted advertising, sale, and certain profiling. We treat health data as sensitive data requiring opt-in consent. You may appeal a denial of a request by replying to our response.
7. Communications and text messages
With your consent we may contact you by email, telephone, and SMS about your care, your appointments, and your place on the waitlist. Message and data rates may apply. You can stop marketing messages at any time by replying STOP or using the unsubscribe link.We may still send you non-marketing messages about your treatment, your account, and security, because those are not promotional.
Ordinary email and SMS are not fully secure. We use them for administrative purposes and use a secure channel for clinical detail.
8. Security
We maintain administrative, technical, and physical safeguards designed to protect information, including encryption in transit and at rest, role-based access controls, audit logging, workforce training, and regular security assessments, consistent with the HIPAA Security Rule (45 C.F.R. Part 164, Subpart C). No method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security.
9. Retention
We retain information only as long as necessary for the purposes described here or as law requires. Medical records are retained for the period required by the law of the state in which care was provided, which is typically a minimum of six to ten years for adults and longer for minors. Waitlist information is retained until you ask us to delete it or until it is no longer needed. Deleting your account does not delete a medical record we are legally required to keep.
10. Children
Our website and waitlist are intended for adults. We do not knowingly collect personal information from children under 13 through the website, and will delete it promptly if we learn we have.
The Medical Group may provide pediatric care. Where it does, a parent or legal guardian establishes care and provides consent, and the health information of a minor patient is handled under HIPAA and applicable state law — including state laws that give adolescents independent control over certain categories of their own health information.
11. Third-party links
Our website may link to third-party sites and services. We are not responsible for their privacy practices, and we encourage you to read their policies.
12. Changes to this policy
We may update this Privacy Policy to reflect changes in our practices, technology, or legal obligations. When we make material changes we will update the effective date above and, where required, provide additional notice. Your continued use of the Services after a change constitutes acceptance of the revised policy.
13. Contact us
Questions about this policy or our data practices:
Congruence Corporation d/b/a Provost Health
Attn: Privacy Officer
New York, NY
Email: privacy@provosthealth.com
You may also complain to the U.S. Department of Health and Human Services, Office for Civil Rights. We will not retaliate against you for filing a complaint.