How Abeó Health, LLC collects, uses, discloses, and protects personal information about clients, families, caregivers, website visitors, and app users. Harmonizes HIPAA, CCPA / CPRA, and California-specific privacy rules. DRAFT — counsel review required before publication.
This Privacy Policy harmonizes HIPAA, CCPA / CPRA, and California-specific privacy rules with the actual data handling Abeó will perform. California-licensed counsel must finalize before publication on abeo.health.
This Privacy Policy describes how Abeó Health, LLC ("Abeó," "we," "us") collects, uses, discloses, and protects personal information about:
• Clients receiving home care services
• Family members and authorized representatives
• Caregivers and Abeó employees
• Website visitors to abeo.health
• Mobile app users of Abeó Care, Abeó Connect, Abeó Dispatch, or future Abeó applications
For Protected Health Information (PHI) about clients, our HIPAA Notice of Privacy Practices (provided in the Client Services Package at intake) governs in addition to this Privacy Policy.
• Information from children under 13 (we do not target services to minors)
• Sensitive demographic information beyond what's voluntarily disclosed for cultural-competency or care-planning purposes
• Aggregate, de-identified analysis of service quality, caregiver retention, family satisfaction
• Internal training and quality improvement
• Operational metrics for ourselves and (with explicit consent) for hospital partners and managed care plans
When the abeoOS platform launches (Phase 4 milestone), aggregated and de-identified outcomes data may be used for:
• Public-health research and publication (with appropriate institutional review)
• Hospital and managed-care plan partnership reporting
• Population health analytics for policymakers and community partners
• (With explicit, separate, written consent) third-party data partnerships such as research collaborations with universities or clinical partners
(from marketing/marketing-plan-6-phase.md cross-phase principle 6)
• All client and caregiver data is aggregated and de-identified before any external publication
• No individual story is shared without that individual's explicit written consent
• Annual privacy audits by independent counsel
• Brittany Solomon's personal commitment: community trust is the moat. Data without consent is not data — it is extraction.
We share personal information only as described in this Privacy Policy:
The caregiver(s) assigned to a client need access to information relevant to their care — care plan details, dietary requirements, mobility status, emergency contacts, home access. They do not access information unrelated to their assignment.
Family members designated by the client (and authorized in writing) may access care-plan summaries, schedule information, and coordinate communications via the Family app.
With client consent (or as legally permitted), we may share information with the client's physicians, hospitals, or other healthcare providers to coordinate care.
With client consent, we may share discharge-relevant information with referring hospitals (e.g., MemorialCare Saddleback) for care continuity.
We share information with vendors who help us operate, including:
• mythOS Infrastructure (StarHub Studios PBC) — our technology platform; bound by HIPAA Business Associate Agreement
• Uber Health (when Phase 2 Abeó Transport launches) — for ambulatory ride coordination; HIPAA-enabled platform
• Background-check vendors — Checkr, Sterling, or similar; for caregiver clearance
• Payroll and HR systems — for caregiver employment administration
• Communications providers — Twilio, RingCentral, etc.; HIPAA Business Associate Agreement required
• Banking and payment processors
All third-party service providers handling PHI sign HIPAA Business Associate Agreements obligating them to protect the information.
We share information with CDSS, state health authorities, and law enforcement as required by law.
We are Mandated Reporters of suspected elder, dependent adult, or child abuse. We will report suspected abuse to Adult Protective Services (APS), Child Protective Services (CPS), or law enforcement as legally required, even without consent.
In a sale, merger, or other business transaction involving Abeó, client information may be disclosed to potential acquirers under confidentiality agreements. Final transfer of records to the acquirer is subject to client notification and consent where required by law.
We do not sell personal information for monetary consideration. Period.
California residents have the right to:
• Know what personal information we collect, how we use it, and who we share it with
• Access a copy of personal information we hold about them
• Delete personal information (subject to legal retention requirements such as CDSS Health & Safety Code §1796.20)
• Correct inaccurate personal information
• Opt-out of sharing personal information for cross-context behavioral advertising (we do not engage in this)
• Limit use of sensitive personal information (e.g., health information used only for care-related purposes)
• Non-discrimination for exercising these rights
Clients have specific rights under HIPAA, detailed in our HIPAA Notice of Privacy Practices, including:
• Right to access PHI
• Right to amend PHI
• Right to request restrictions on disclosures
• Right to an accounting of certain disclosures
• Right to receive notification of a breach
Contact our Compliance & Quality Assurance Officer:
• Email: privacy@abeo.health (TBD)
• Phone: (949) 987-4605
• Mail: Abeó Health, LLC — Privacy Office, 28100 Cabot Rd. Suite 232, Laguna Niguel, CA 92677
We will respond to verifiable requests within 45 days (extendable to 90 days for complex requests).
You can control cookies through your browser settings. Disabling strictly necessary cookies may impair site functionality.
We honor browser Do Not Track signals.
We implement administrative, physical, and technical safeguards consistent with HIPAA Security Rule requirements, including:
• Encryption of data at rest and in transit
• Role-based access controls (caregivers see only their assignments; coordinators see only their assigned clients)
• Multi-factor authentication for staff
• Annual security training for all employees
• Annual penetration testing and security audits (Phase 3+ when budget supports)
• Incident response plan and breach notification procedures
• Client records (PHI): Retained for at least 7 years from last service date, per California Health & Safety Code §1796.20 and HIPAA. Some records (e.g., minors) retained longer.
• Employee records: Retained per employment law (typically 7+ years post-employment)
• Website analytics: Aggregated; individual-level retained 24 months max
• Marketing communications: Retained while you consent to receive them; deleted upon opt-out
All client PHI is stored on infrastructure located in the United States. We do not transfer PHI outside the U.S. without explicit consent and HIPAA-compliant safeguards.
Our services are designed for adults (18+). We do not knowingly collect personal information from children under 13. If a parent or guardian believes we have inadvertently collected such information, please contact us at privacy@abeo.health (TBD) for prompt deletion.
Our mobile apps may request the following permissions:
• Location (Caregiver app): for visit verification and EVV compliance
• Notifications (all apps): for shift reminders, family updates, schedule changes
• Camera (optional): for caregiver-uploaded photos of completed tasks (with client consent)
Our apps store some information locally on your device for offline access. Sensitive data is encrypted at rest.
Our apps may use third-party SDKs for functionality (e.g., maps, payment processing). These SDKs are listed in the app's Settings > Privacy section.
The Abeó services are designed for residents of the United States. If you access our services from outside the U.S., be aware that your information will be transferred to and processed in the U.S., where data protection laws may differ from those in your jurisdiction.
We may update this Privacy Policy from time to time. Material changes will be communicated to active clients via email and posted on abeo.health with at least 30 days' notice. Continued use of services after the effective date constitutes acceptance.
Privacy Officer / Compliance & QA Officer
Abeó Health, LLC
28100 Cabot Rd. Suite 232, Laguna Niguel, CA 92677
Phone: (949) 987-4605
Email: privacy@abeo.health (TBD)
For complaints to a regulator:
• California Attorney General's Office (CCPA/CPRA): https://oag.ca.gov/privacy
• U.S. Department of Health and Human Services Office for Civil Rights (HIPAA): 1-800-368-1019
Source documents: marketing/cdss-application/client-services-package.pdf (HIPAA Notice of Privacy Practices), marketing/cdss-application/B3-personnel-policies.pdf (employee privacy), marketing/marketing-plan-6-phase.md cross-phase principle 6 (consent-first data practices).