Legal
HIPAA notice
Last updated: June 8, 2026
This notice explains, at a high level, how protected health information (PHI) is handled in connection with the Wellstaq platform, and the role each party plays. It is provided for transparency to prospective partners. It is not the Notice of Privacy Practices that patients receive from their treating providers.
This website does not collect PHI
Wellstaq.com is a business-to-business marketing site. It collects business contact information from prospective partners (see our Privacy Policy). It does not collect, request or store patient protected health information, and it is not a patient portal.
Who handles patient PHI
Patient care, evaluation and prescribing are performed by an independent, board-certified provider network licensed in all 50 states. That network and its providers act as the covered entities (or their business associates) responsible for patient PHI.
PHI is processed on HIPAA-compliant systems, and the parties that handle PHI do so under Business Associate Agreements (BAAs) where required by HIPAA. Wellstaq provides technology and brand infrastructure and structures its access to PHI to be consistent with these obligations.
The partner's role
A Wellstaq partner is the brand and marketing layer. The partner does not make clinical decisions, does not prescribe, and does not need access to patient PHI to run their branded program. This keeps clinical liability and PHI handling with the licensed network, not the partner.
Patient rights
Patients receive a Notice of Privacy Practices from their treating providers describing how their PHI is used and disclosed and the rights they have — including the rights to access and obtain a copy of their records, request corrections, request restrictions, receive an accounting of certain disclosures, and file a complaint.
Patients exercise these rights through their treating provider or the clinical network, as described in the notice they receive. A complaint will not result in retaliation.
Security and breach notification
The parties that handle PHI maintain administrative, technical and physical safeguards designed to protect it, as required by the HIPAA Security Rule. In the event of a breach of unsecured PHI, notification is provided by the responsible covered entity or business associate in accordance with the HIPAA Breach Notification Rule and applicable state law.
Educational diagnostics note
Where offered, the genetic pathway report is educational and wellness-oriented. It does not diagnose, prescribe, or determine which products anyone should use; it maps variants to pathways as a roadmap to discuss with a licensed provider. Licensed providers make all clinical decisions.
Changes to this notice
We may update this notice from time to time. The "Last updated" date above reflects the latest version.
Contact us
For questions about how PHI is handled across the platform, contact [privacy@wellstaq.com]. If you are a patient with a request about your own records, please contact your treating provider or the clinical network identified in the Notice of Privacy Practices you received.