PRIVACY POLICY
Effective Date: August 10, 2026 · Version 2.2
INTRODUCTION
Black Forest Management Services LLC (“BFMS,” “we,” “us,” or “our”), a Delaware limited liability company, respects your privacy and is committed to protecting your personal information. This Privacy Policy explains what information we collect, how we use it, with whom we share it (and notably with whom we do NOT share it), and your rights.
“Black Forest MD” is the consumer-facing brand under which BFMS and affiliated physician-owned professional medical entities — including Black Forest Medical, P.A. and Black Forest MD of Florida, PLLC (each, the “Practice”) — operate the telehealth platform at blackforestmd.com (the “Site”). The Practice treating you is the entity licensed in the state where you are located. Each Practice is a HIPAA Covered Entity. BFMS performs only non-clinical functions on the Practice’s behalf and acts as a HIPAA Business Associate of the Practice pursuant to a Business Associate Agreement.
This Privacy Policy applies to information collected through the Site, our telehealth platform, and any related communications. Protected Health Information (“PHI”) is additionally governed by our HIPAA Notice of Privacy Practices, which controls in case of any conflict on a matter governed by HIPAA.
1. INFORMATION WE COLLECT
1.1 Information You Provide Directly
- Account information: Name, email, phone, mailing address, date of birth, state of residence
- Payment information: Credit card / payment method (processed by Stripe; we do not store full card numbers)
- Health information (PHI): Medical history, symptoms, medications, allergies, lab results, treatment goals, visit notes (captured by your clinician)
- Identity verification information: Government-issued photo identification, selfie image (where required), date of birth, address — collected through our identity verification vendor
- Communications: Messages between you and our team or your clinician
- Marketing communications opt-ins: Email or SMS marketing preferences where you have separately opted in
1.2 Information Collected Automatically
- Device and usage data on marketing pages: Browser type, IP address (general geolocation only), pages viewed, referral source, time on site, device identifiers
- Cookies on marketing pages: Used for site functionality and marketing analytics (see Section 5)
- HIPAA-eligible analytics on patient/PHI pages: Limited to operational metrics; no third-party advertising tracking
- Server logs: Standard request and error logs maintained for security and debugging
1.3 Information from Third Parties
- Identity verification vendor — verification confirmation and any related signals
- Payment processor (Stripe) — confirmation of payment, not card details
- Compounding pharmacy — confirmation that your prescription has been compounded, dispensed, and shipped (we do not receive pharmacy-collected PHI beyond what is required to coordinate your care)
- Shipping carriers — tracking and delivery status of medication shipments sent by the dispensing pharmacy
- Marketing partners — aggregated, de-identified campaign performance data only
2. HOW WE USE YOUR INFORMATION
We use your information to:
- Provide and operate the telehealth platform
- Connect you with a licensed clinician of the Practice
- Verify your identity and physical location for telehealth prescribing
- Process payments and manage subscriptions
- Communicate with you about your account, treatment, and the Service
- Facilitate prescription compounding, dispensing, and shipment by a licensed 503A compounding pharmacy
- Coordinate delivery of dispensed medications to your address
- Respond to your questions and provide customer support
- Comply with legal and regulatory obligations (HIPAA, Florida Department of Health, state medical boards, FDA, etc.)
- Improve and maintain the Service
- Detect and prevent fraud, abuse, or security incidents
- Conduct internal analytics, with PHI de-identified per the HIPAA Safe Harbor method before use
We do not use PHI for advertising, marketing, or selling products to you beyond the Service you enrolled in.
3. WHAT WE DO NOT DO WITH YOUR HEALTH INFORMATION
We want to be explicit about this — it is the most important section of this Privacy Policy.
We do NOT share, sell, or transmit your Protected Health Information (PHI) — including information about your symptoms, conditions, treatments, prescriptions, lab results, identity verification data, or any other health-related data — with:
- Meta (Facebook, Instagram, WhatsApp)
- Google (including Google Analytics, Google Ads, YouTube)
- TikTok
- Snap, Pinterest, Reddit, X (formerly Twitter), or any other social media platform
- Any third-party advertising network or data broker
- Any other entity for marketing or advertising purposes
The telehealth pages of our Service where you enter or view health information do not contain Meta Pixel, Google Analytics tags, TikTok Pixel, LinkedIn Insight Tag, or any other third-party advertising tracking technology.
For our marketing analytics needs, we use HIPAA-eligible analytics tools (such as Freshpaint) that strip PHI from any event data before forwarding sanitized, de-identified conversion data to advertising platforms. Advertising platforms may know that an anonymous conversion occurred for ad optimization purposes — but they never receive your health information, identity, or any data that could be tied to you.
Per the 2024 HIPAA Privacy Rule to Support Reproductive Health Care Privacy, additional restrictions apply to any PHI potentially related to reproductive health care. See Section 3.5 of the HIPAA Notice of Privacy Practices.
4. WHO WE DO SHARE INFORMATION WITH (AND WHY)
We share your information only with parties who need it to provide the Service or as required by law. Each PHI-handling vendor signs a HIPAA Business Associate Agreement before receiving PHI with the Practice or with BFMS as a Business Associate.
- Your treating clinician(s) — All clinical information necessary for care. To provide medical care.
- 503A compounding pharmacy — Prescription details, name, date of birth, and shipping address required to fill and ship the prescription. To compound, dispense, and ship your medication on a patient-specific basis.
- Canvas Medical (electronic health record)— Your medical record, encounter data. To document and store your care.
- Stripe (payment processor) — Payment information. To process subscriptions.
- Identity verification vendor — Identity documents and verification signals. To satisfy telehealth identity-verification requirements.
- Freshpaint (HIPAA-eligible analytics) — Limited operational event data with PHI stripped. To operate the Service.
- Twilio, Postmark, or similar HIPAA-eligible communications providers — Phone/SMS/email content as needed for patient communications. To communicate with you.
- Shipping carriers (e.g., FedEx, UPS) — Name, shipping address, tracking ID. To deliver your medication.
- Hosting provider (AWS, with BAA) — Data at rest and in transit. To host the Service.
- Affiliated state medical practices (where applicable) — PHI necessary for continuity of care if your state of residence changes. To provide care across state lines.
- Legal, accounting, and compliance professionals— As needed for legal/audit/regulatory purposes. Compliance, legal defense.
- Government / regulators — As required by law (e.g., state medical boards, FDA, courts). Legal compliance.
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising as those terms are defined under California Civil Code § 1798.140.
5. COOKIES AND TRACKING TECHNOLOGIES
5.1 Two Zones on Our Site
Our Site is divided into two zones with different tracking practices:
- Marketing Zone (homepage, /about, /faq, /blog, /science) — no PHI is collected here. We may use standard cookies, Google Analytics, Meta Pixel, and similar marketing analytics to measure ad effectiveness and improve marketing.
- Patient / PHI Zone (intake, account, consultation, treatment pages, patient portal) — no third-party advertising or analytics cookies are used. We use HIPAA-eligible analytics (such as Freshpaint) for operational measurement only.
5.2 Cookie Categories on Marketing Pages
- Strictly necessary — required for the Site to function
- Functional — improve usability
- Performance / analytics — help us understand site usage
- Advertising — used for marketing (only with your consent)
5.3 Your Choices
- Cookie banner — manage preferences on first visit and at any time via the Site footer
- Global Privacy Control (GPC) — we honor browser-level GPC signals as a valid opt-out of “sale” or “sharing” of personal information under California, Colorado, and Connecticut law where applicable
- “Do Not Track” — we respect DNT signals where technically feasible
- Industry opt-outs — manage advertising cookies at aboutads.info/choices/ or optout.networkadvertising.org
6. DATA SECURITY AND BREACH NOTIFICATION
6.1 Safeguards
We implement administrative, technical, and physical safeguards designed to protect your information, including:
- Encryption in transit (TLS) and at rest
- Access controls and role-based permissions
- Annual security training for personnel
- Vendor due diligence (BAAs with all PHI-handling vendors)
- Incident response procedures
- Network monitoring and logging
- Periodic security testing
No system is 100% secure.
6.2 Breach Notification
If we become aware of a breach affecting your information, we will notify you and applicable regulators consistent with:
- The HIPAA Breach Notification Rule (45 CFR §§ 164.400-414) — for PHI
- The FTC Health Breach Notification Rule (16 CFR Part 318) — for non-HIPAA personal health record information, where applicable
- The Florida Information Protection Act (Fla. Stat. § 501.171) — for Florida residents (notification within 30 days of determination)
- Any other applicable state breach-notification law in your state of residence (we apply the shorter timeline where state law is stricter than federal law)
7. DATA RETENTION
We retain information for the period reasonably required for the purpose for which it was collected, or as required by law.
- PHI (medical records) — Minimum required by HIPAA and Fla. Stat. § 456.057 — generally five (5) years from the last patient encounter for adult patients (longer for pediatric records)
- Payment records — Seven (7) years for tax and audit purposes
- Identity verification documents — Retained for the duration of the patient relationship + seven (7) years
- Marketing analytics (de-identified) — Indefinitely, in de-identified form
- Server logs — Up to 90 days, except as needed for security investigations
- Marketing opt-in preferences — Until you unsubscribe
When you cancel your account, your PHI is retained per legal requirements but is not used for any purpose other than continuity-of-care, compliance, and legal defense.
8. YOUR RIGHTS UNDER HIPAA
If you are a patient of the Practice, you have rights under HIPAA, including:
- Right to access your PHI (including in electronic form)
- Right to direct your PHI to a third party of your choosing
- Right to request amendment
- Right to an accounting of disclosures
- Right to request restrictions on uses or disclosures
- Right to request confidential communications
- Right to a paper or electronic copy of this Privacy Policy and the HIPAA NPP
- Right to be notified of a breach
The full description of your HIPAA rights and how to exercise them is in the HIPAA Notice of Privacy Practices.
9. YOUR RIGHTS UNDER STATE PRIVACY LAWS
Depending on your state of residence, you may have additional rights under state privacy law. The most common rights are summarized below. To the extent that information is regulated as PHI under HIPAA, the HIPAA rights in Section 8 (and the HIPAA NPP) govern that information.
9.1 California (CCPA / CPRA — Cal. Civ. Code § 1798.100 et seq.)
California residents may:
- Request to know what categories and specific pieces of personal information are collected, used, disclosed, and sold or shared
- Request deletion of personal information (subject to medical record retention requirements)
- Request correction of inaccurate personal information
- Opt out of “sale” or “sharing” of personal information — we do not sell or share PHI or personal information for cross-context behavioral advertising
- Limit use of “sensitive personal information” — we do not use sensitive personal information beyond the purposes you enrolled in
- Designate an authorized agent to make requests on your behalf
- Not be discriminated against for exercising your rights
9.2 Virginia, Colorado, Connecticut, Utah, Texas, Iowa, Oregon, Delaware, New Hampshire, New Jersey, Kentucky, Indiana, Tennessee, Maryland, Minnesota, and similar state laws
Residents of these states may have rights to:
- Access personal information we hold about them
- Correct inaccurate personal information
- Delete personal information (subject to medical record retention requirements)
- Port (receive a portable copy of) personal information in a usable format
- Opt out of targeted advertising, sale of personal information, or certain profiling decisions
- Designate an authorized agent to exercise these rights on their behalf (where applicable)
- Appeal denial of a privacy request (where applicable)
9.3 Florida (Fla. Stat. § 456.057, § 501.171)
Florida residents have additional rights regarding medical records under Fla. Stat. § 456.057, including the right to obtain a copy upon written request and the right to authorize or refuse disclosure subject to enumerated exceptions. Notification of any breach of personal information affecting Florida residents is provided in accordance with Fla. Stat. § 501.171.
9.4 How to Exercise Your Rights
Email [email protected] or use the request form on the Site. To protect your information, we will verify your identity before processing a request (typically by confirming information already on file). If you use an authorized agent, we will require evidence of their authority.
We will respond within 45 days of receiving a verifiable request. Where allowed by law, we may extend that period by an additional 45 days, with notice to you. If we deny a request, you may appeal by replying to our response email; we will respond to the appeal within 60 days.
10. SENSITIVE PERSONAL INFORMATION
Several state privacy laws (CCPA/CPRA, VCDPA, CPA, CTDPA, and others) treat certain categories of personal information as “sensitive” and impose additional limits on their use. These categories include health and medical information, genetic information, biometric information, precise geolocation, and others.
We process sensitive personal information only as necessary to provide the Service you enrolled in and as described in this Privacy Policy. We do not use sensitive personal information to infer characteristics about you for advertising purposes.
11. AUTOMATED DECISION-MAKING AND AI
We may use artificial intelligence and machine-learning technologies (“AI”) in non-clinical workflows — for example, to assist customer support, draft messages for a licensed clinician to review, or summarize information for the care team. AI is never used to make clinical decisions. Clinical messages, prescriptions, and treatment decisions are reviewed and approved by a licensed clinician of the Practice. See Section 4.5 of the Terms of Service for additional detail.
Where state law requires it, you have the right to know when automated processing is used in a manner that produces legal or similarly significant effects, and to request human review of such decisions.
12. CHILDREN
The Service is not directed to and not available to individuals under the age of 18. To be eligible for the Service, you must be at least 18 years old.
In addition, in accordance with the Children’s Online Privacy Protection Act (“COPPA,” 15 U.S.C. § 6501 et seq.), we do not knowingly collect personal information from any child under the age of 13 through any part of the Site or Service. If you believe we have inadvertently collected personal information from a child under 13, contact us at [email protected] and we will delete the information promptly.
13. INTERNATIONAL VISITORS
The Service is intended for U.S. residents only. Information collected through the Service is stored in the United States. If you access the Site from outside the United States, you consent to the transfer and processing of your information in the U.S., which may have data-protection laws different from those of your country of residence.
14. LANGUAGES AND ACCESSIBILITY
This Privacy Policy is available in English. Upon request, we will provide a Spanish-language version and, where reasonably available, other languages. Visitors with limited English proficiency or with disabilities affecting reading, vision, or comprehension may request language assistance services or reasonable accommodation at no cost by emailing [email protected].
15. RELATIONSHIP TO OTHER DOCUMENTS
This Privacy Policy is intended to be read together with:
- Terms of Service — contractual terms governing your use of the platform
- HIPAA Notice of Privacy Practices — HIPAA rights and Covered Entity practices (controls in case of any conflict on a HIPAA-governed matter)
- Telehealth Informed Consent — your consent to receive care via telehealth
- Compounded Medication Acknowledgment — risks and acknowledgments specific to compounded medications
16. CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time. The “Last Updated” date and Version at the top of this Policy will reflect the most recent revision. Material changes will be communicated via email and a prominent notice on the Site at least 30 days before they take effect. Continued use of the Service after the effective date constitutes acceptance.
17. SMS AND MOBILE INFORMATION
If you opt in to receive text messages from us, we collect and use your mobile phone number to send the messages described at opt-in, such as order and account notifications. Message frequency varies. Message and data rates may apply. You can opt out at any time by replying STOP to any message, or reply HELP for assistance.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties, excluding vendors acting on our behalf solely to deliver those messages (such as our text messaging provider).
18. CONTACT US
Privacy questions or requests:
Privacy Officer
Black Forest Management Services LLC
1000 Brickell Avenue, Suite 550, Miami, FL 33131
Email: [email protected]
