Privacy Policy
Last Updated: April 14, 2026
HIPAA-Compliant Platform. iScript.care is committed to the privacy and security of your health information. All protected health information (PHI) is handled in accordance with HIPAA. Our
Notice of Privacy Practices is a separate document governing PHI in connection with healthcare services.
I. Introduction
PLEASE READ THIS PRIVACY POLICY CAREFULLY BEFORE USING OUR SERVICES OR WEBSITE.
IMPORTANT NOTE: Our Notice of Privacy Practices is a separate document that governs how protected health information ("PHI") about you may be used and disclosed in connection with healthcare services in accordance with HIPAA.
This Privacy Policy describes how iScript.care (Cantobiz, Inc.), a Delaware corporation ("we", "us", "our"), collects and uses personal data about you through our website (iscript.care), and through email, text, and other electronic communications. iScript.care respects your privacy and is committed to protecting it through compliance with this policy.
This Privacy Policy describes our practices for collecting, using, maintaining, protecting, and disclosing your information. Use of the Platform is governed by this Privacy Policy and our Terms of Service. By accessing or using the Platform, you acknowledge that you have read, understood, and agreed to be legally bound by this Privacy Policy. If any term is unacceptable to you, please do not use the Platform.
II. Information We Collect
We collect several types of information from and about users, including:
Personal Identifiers: Name, mailing address, email address, telephone number, date of birth, gender, occupation, and account information.
Health Information (PHI): Clinical history, conditions, medications, biometric readings (blood pressure, glucose, weight, SpO₂), and information exchanged through the Platform.
Technical Data: IP address, browser type, device identifiers, usage details, and information collected through cookies and tracking technologies.
Payment Information: Billing information processed through secure third-party payment processors. We do not store full credit card details.
Communications: Records and copies of your correspondence, including support inquiries.
We collect information directly from you when you provide it, automatically as you navigate the Platform, and from third parties (physicians, pharmacies, device vendors) under signed Business Associate Agreements.
III. How We Use Your Information
We use the information we collect to:
• Provide, operate, and improve our telehealth, RPM, and CCM services
• Facilitate clinical assessments, care coordination, and physician-patient interactions
• Process billing and reimbursement documentation
• Comply with applicable laws, regulations, and HIPAA requirements
• Send administrative communications, including service updates and policy changes
• Detect, prevent, and respond to fraud, security incidents, and harmful activities
• Analyze usage patterns to improve platform functionality and user experience
• Contact you about your account, care programs, and health services
IV. HIPAA & Protected Health Information
iScript.care is committed to compliance with HIPAA and applicable state health privacy laws. PHI collected through our RPM, CCM, and telehealth services is subject to our Notice of Privacy Practices, provided separately at enrollment.
Your PHI may be used or disclosed for:
• Treatment (clinical care coordination, physician review)
• Healthcare operations (billing documentation, quality improvement)
• Payment processing (claim generation and reimbursement)
• As required by law (regulatory compliance, court orders)
We do not sell PHI to third parties. We do not use PHI for marketing without your explicit authorization.
V. Sharing of Information
We may share your information with:
Healthcare Providers: Referring or treating physicians and practice groups receive clinical data and billing documentation.
Independent Licensed Physicians: For telehealth consultations, intake information is shared with the licensed clinician conducting your assessment.
Partner Pharmacies: For prescription fulfillment, relevant clinical information may be shared with our pharmacy network partners.
Technology Vendors: Third-party service providers operating under signed HIPAA Business Associate Agreements (BAAs).
Legal Authorities: When required by applicable law, regulation, or court order.
We do not sell your personal information or PHI to third parties for marketing or commercial purposes.
VI. Cookies and Tracking Technologies
Our website uses cookies and similar technologies to maintain session state, analyze website traffic, track marketing campaign performance, and improve user experience. We use payment processors including Stripe, which use session cookies to detect and prevent fraud. You may configure your browser to refuse cookies; however, some features may not function properly without them. Our sites respond to Global Privacy Control (GPC) signals.
VII. Data Security
We implement industry-standard security measures including:
• HIPAA-compliant encryption in transit (TLS 1.3) and at rest (AES-256)
• Secure, access-controlled servers and infrastructure
• Role-based access controls limiting data to authorized personnel
• Regular security audits and vulnerability assessments
• Incident response procedures for potential breaches
No method of internet transmission is 100% secure. We cannot guarantee absolute security, but we are committed to protecting your information with the highest reasonable standards.
VIII. Your Rights and Choices
Depending on your location and applicable law, you may have the right to:
• Access: Request a copy of the personal information we hold about you
• Correction: Request correction of inaccurate or incomplete information
• Deletion: Request deletion of your personal information, subject to clinical retention requirements
• Opt-Out: Opt out of non-essential communications and marketing
• Data Portability: Request your data in a portable format
• HIPAA Rights: Access, amend, and receive an accounting of disclosures of your PHI
California residents have additional rights described in our California Privacy Statement. To exercise any rights, contact us at privacy@iscript.care or (408) 796-1258.
IX. Third-Party Links
Our website may contain links to third-party websites. This Privacy Policy does not apply to those sites. We encourage you to review the privacy policies of any third-party sites you visit. We are not responsible for the privacy practices or content of third-party websites.
X. Children's Privacy
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected information from a child under 18, we will take steps to delete that information promptly.
XI. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy with a new "Last Updated" date. Your continued use of our services after such changes constitutes acceptance of the updated policy.
XII. Contact Us
For questions, concerns, or requests regarding this Privacy Policy:
iScript.care (Cantobiz, Inc.)
Email: privacy@iscript.care
Phone: (408) 796-1258
For HIPAA-specific requests, please reference your Notice of Privacy Practices or contact our Privacy Officer directly.