Privacy Policy

Last updated: June 2026

1. Introduction

RETA MD, operated by Reta MD Holdings LLC ("we," "us," or "our"), is committed to protecting the privacy and security of your personal and health information. This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you visit our website (retamd.com), use our telehealth services, or interact with us in any way. This policy complies with the Health Insurance Portability and Accountability Act (HIPAA), applicable state privacy laws, and other relevant federal regulations. We encourage you to read this policy carefully. If you do not agree with the terms, please discontinue use of our services.

2. Information We Collect

We collect the following categories of information: Personal Information: • Full name, date of birth, gender • Email address, phone number, mailing address • Payment and billing information (credit card, HSA/FSA details) • Government-issued identification (when required for identity verification) Protected Health Information (PHI): • Medical history, current medications, allergies • Health questionnaire responses • Consultation notes and treatment plans • Prescription information • Lab results and diagnostic information • Photographs (if submitted for clinical evaluation) Technical Information: • IP address, browser type, device information • Cookies, usage data, and analytics • Pages visited and interaction patterns

3. How We Use Your Information

We use your information for the following purposes: • Treatment: To provide telehealth consultations, prescribe medications, and deliver clinical care • Payment: To process payments, verify insurance or HSA/FSA eligibility, and manage billing • Healthcare Operations: To improve our services, conduct quality assurance, train staff, and comply with legal obligations • Communication: To send appointment reminders, treatment updates, and respond to your inquiries • Legal Compliance: To comply with federal and state laws, regulations, and legal processes • Safety: To report adverse events, prevent fraud, and protect the health and safety of our patients and the public We do NOT sell your personal or health information to third parties. We do NOT use your health information for marketing purposes without your explicit written consent.

4. How We Share Your Information

We may disclose your information in the following circumstances: • Healthcare Providers: With physicians, pharmacies, and clinical staff involved in your care • Pharmacy Partners: With our licensed compounding pharmacies to fulfill prescriptions • Payment Processors: With third-party payment processors to complete transactions • Legal Requirements: When required by law, court order, subpoena, or government investigation • Public Health: For public health activities, such as reporting adverse events to the FDA • Business Associates: With HIPAA-compliant vendors who perform services on our behalf (all bound by Business Associate Agreements) • Emergency: To prevent or lessen a serious and imminent threat to your health or safety All third parties with access to PHI are required to maintain HIPAA compliance and enter into Business Associate Agreements (BAAs) with us.

5. Your Rights Under HIPAA

As a patient, you have the following rights regarding your health information: • Right to Access: You may request copies of your medical records and health information. • Right to Amend: You may request corrections to inaccurate or incomplete health information. • Right to Restrict: You may request restrictions on how we use or disclose your information. • Right to Confidential Communications: You may request that we communicate with you through specific channels. • Right to an Accounting of Disclosures: You may request a list of certain disclosures we have made of your health information. • Right to a Copy of This Policy: You may request a paper or electronic copy of this Privacy Policy at any time. • Right to File a Complaint: You may file a complaint with us or with the U.S. Department of Health and Human Services if you believe your privacy rights have been violated. To exercise any of these rights, contact our Privacy Officer at privacy@retamd.com.

6. Data Security

We implement administrative, technical, and physical safeguards to protect your information, including: • SSL/TLS encryption on all pages and data transmissions • HIPAA-compliant data storage with encrypted databases • Access controls limiting employee access to PHI on a need-to-know basis • Regular security audits and vulnerability assessments • HIPAA-compliant video and communication technology for telehealth consultations • Business Associate Agreements (BAAs) with all vendors handling PHI • Employee training on HIPAA compliance and data security While we take reasonable measures to protect your information, no method of electronic transmission or storage is 100% secure.

7. Cookies & Tracking Technologies

We use cookies and similar technologies to improve your experience on our website: • Essential Cookies: Required for site functionality (login, form submission) • Analytics Cookies: Help us understand how visitors use our site (e.g., Google Analytics) • Marketing Cookies: Used for advertising purposes (only with your consent) You can manage cookie preferences through your browser settings. Disabling certain cookies may affect site functionality. We do NOT use cookies to collect Protected Health Information. We do NOT use remarketing lists tied to sensitive health behaviors.

8. State-Specific Privacy Rights

Depending on your state of residence, you may have additional privacy rights: California (CCPA/CPRA): California residents have the right to know what personal information is collected, request deletion, opt out of the sale of personal information, and not be discriminated against for exercising privacy rights. Washington (My Health My Data Act): Washington residents have rights regarding consumer health data, including the right to access, delete, and withdraw consent for the collection and sharing of health data. Other States: We comply with all applicable state privacy laws. Contact us for information about rights specific to your state. To exercise state-specific rights, contact privacy@retamd.com.

9. Children's Privacy

RETA MD services are intended for adults 18 years of age and older. We do not knowingly collect personal information from children under 18. If we learn that we have collected information from a child under 18, we will take steps to delete it promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated effective date. We encourage you to review this policy periodically. Material changes will be communicated via email or prominent notice on our website. Continued use of our services after changes constitutes acceptance of the updated policy.

11. Contact Our Privacy Officer

If you have questions about this Privacy Policy or wish to exercise your rights, contact us: Privacy Officer RETA MD, Reta MD Holdings LLC 9201 W Sunset Blvd, Suite 912 Los Angeles, CA 90069 Email: privacy@retamd.com To file a complaint with the U.S. Department of Health and Human Services: https://www.hhs.gov/hipaa/filing-a-complaint/index.html