Legal

Privacy Notice

Version 1 · 30 September 2026

Contents

  1. Who we are, and who treats you
  2. What information do we collect?
  3. Where does it come from?
  4. How do we use it?
  5. Who do we share it with?
  6. How does HIPAA apply?
  7. Sensitive information
  8. How do we protect your information?
  9. Transcription and AI
  10. Prescriptions and pharmacies
  11. How long do we keep information?
  12. What are your choices and rights?
  13. If there is a data breach
  14. Cookies and tracking
  15. Text messages
  16. Children and young people
  17. De-identified information
  18. Accessibility and language
  19. Where we operate
  20. State-specific rights
  21. Disputes
  22. Changes to this notice
  23. How to reach us

The short version

Your medical record belongs to the independent practice that treats you. Its Notice of Privacy Practices covers that record. We handle health information for your practice under a HIPAA agreement. We do not sell your information and we do not use it for advertising. We do not run advertising or third-party analytics tools inside the signed-in part of the platform. Your visit may be transcribed so your clinician can write their notes, and you are told before you check in. We do not record video of your visit. You can ask your clinician to switch transcription off for the visit. We do not keep a voiceprint. You can ask us what we hold about you, correct it, delete it, or limit how we use sensitive information. Section 12 explains how.

This notice tells you what we do. It is not a contract. If anything in this summary differs from the detail below, the detail controls.

1. Who we are, and who treats you

This notice explains how Medcare Services Enterprise LLC, a Wyoming limited liability company doing business as OneYBT, handles your information. We call ourselves "OneYBT," "we," or "us." We operate YBT Health, an electronic health record and practice platform, together with its patient portal, and YBT Meet, the video platform.

ONEYBT AND MEDCARE SERVICES ENTERPRISE LLC ARE NOT AFFILIATED WITH, ENDORSED BY, OR APPROVED BY MEDICARE, THE CENTERS FOR MEDICARE & MEDICAID SERVICES, THE U.S. DEPARTMENT OF HEALTH AND HUMAN SERVICES, THE SOCIAL SECURITY ADMINISTRATION, OR ANY OTHER GOVERNMENT AGENCY OR PROGRAM. THE COMPANY NAME IS A LEGAL ENTITY NAME ONLY AND DOES NOT INDICATE ANY GOVERNMENT AFFILIATION, SPONSORSHIP, OR APPROVAL.

Two organisations are involved in your care. The independent professional practice your clinician works through — we call it "your Practice" — is responsible for your care, owns your medical record, and is the covered entity under HIPAA. Its Notice of Privacy Practices, not this notice, covers that record. Your registration materials and visit records tell you which practice is yours, and you can ask us at any time.

OneYBT is a technology and administrative services company. We are not a medical practice, we do not employ clinicians, and we do not practice medicine. We provide the platform, scheduling, billing and insurance support, patient messaging, and administrative services your Practice uses. Under HIPAA we are your Practice’s business associate, which means we handle health information on its behalf under a written agreement and only as that agreement allows.

We and your Practice share your health information with each other as needed to treat you, to get paid, and to run the practice, as HIPAA allows.

Where we serve more than one practice, each is a separate business and a separate covered entity under HIPAA. We do not share your information with any other practice on the platform unless you tell us to or the law requires it.

This notice is a disclosure, not a contract. It does not create any contractual obligation, promise, or warranty. Section 21 explains how disputes are handled.

Other documents you may see

  • Your Practice’s Notice of Privacy Practices — how your medical record is used, and your HIPAA rights.
  • Terms of Service — the agreement for using the platform, including how disputes are resolved.
  • Consent to Telehealth Treatment — your Practice’s consent for treating you by telehealth.
  • Patient Arbitration Agreement — a separate agreement your Practice may ask you to sign.
  • SMS Consent — your separate consent to receive text messages.
  • Notice at Collection — a short notice shown where we collect information.

2. What information do we collect?

Information you give us

  • Your name, email address, phone number, date of birth, address, and sign-in details.
  • Intake information, including demographic details, emergency contacts, insurance information, and how you heard about us.
  • Health information, including your medical and psychiatric history, symptoms, medications, diagnoses, treatment plans, clinical notes, and assessment results.
  • Insurance and payment information.
  • Messages you send us or your care team, by platform message, email, or text.
  • Consent forms, signatures, and acknowledgements.
  • Answers you give before you become a patient, including screening questions and intake forms you start but do not finish.

Health information is created and kept for your Practice. We handle it only as its business associate and share it with your Practice as needed for your care.

Information about your visit

Where a visit is transcribed, session audio is processed to produce text your clinician uses to write notes, as Section 9 explains. We do not record video of your visit, and no video file of your visit is created or stored on our systems. The audio is deleted once the text is made.

Information we collect automatically

  • Your IP address, browser, operating system, device type, and device identifiers.
  • Pages you view, features you use, links you click, how long you stay, and the site you came from.
  • Server logs, which may include your IP address, access times, and activity in the Services.
  • Cookies and similar technologies, as Section 14 explains.

Information from other people

  • Clinical information or referral documents from your other healthcare providers.
  • Eligibility, benefits, and claims information from insurers.
  • Identity checks from verification services.
  • Dispensing and controlled-substance information from pharmacies and prescription monitoring programs, as Section 10 explains.

What we do not collect

We do not collect or keep biometric identifiers. No voiceprint, faceprint, or similar identifier is created, derived, or kept from your session, and we do not use voice recognition to identify you. We do not collect neural data. We do not collect your precise location.

3. Where does it come from?

We collect information directly from you; automatically from your device and browser; from your Practice and its clinicians; from your other healthcare providers and referral sources; from health plans, insurers, and clearinghouses; from pharmacies and prescription monitoring programs; from payment processors; and from the service providers and technology vendors that work for us.

4. How do we use it?

  • To support your care: running the platform your clinicians use, coordinating appointments and prescriptions, sending messages for your Practice, and sharing information with your Practice as needed to treat you.
  • To manage appointments: bookings, reminders, and setting up visits.
  • To handle billing and insurance: checking eligibility, submitting claims, taking payment, and managing your balance.
  • To support clinical documentation: producing text and a draft note from your visit for your clinician to review and use, as Section 9 explains.
  • To communicate with you about appointments, your care, and your account.
  • To improve quality: monitoring how the Services work, internal audits, and staff training.
  • To meet legal obligations, including HIPAA.
  • To keep the platform secure and prevent fraud and unauthorised access.
  • To operate, maintain, and improve the platform.

We use health information only as our agreement with your Practice and HIPAA allow. We do not use your health information for advertising or marketing, and we do not use it to train artificial intelligence models. We do not use sensitive personal information beyond the purposes California law permits.

5. Who do we share it with?

We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as California law defines those terms. We have not done either in the last 12 months. We share information in these situations:

  • With your Practice, so your clinicians can treat and document your care. We do not share it with any other practice on the platform unless you tell us to or the law requires it.
  • For treatment, payment, and running the practice: with other providers involved in your care, with insurers for billing and claims, and within our organisation for quality and operations, as HIPAA and our agreement with your Practice allow.
  • With service providers who help us run the Services, including electronic health record hosting, payment processing, insurance verification, scheduling, and messaging. Each works under a written contract that prevents them from using your information for anything other than the services they provide for us, and from selling or sharing it. Visit audio is transcribed by speech recognition software we run ourselves and is not sent to an outside transcription service.
  • When the law requires it, including in response to a subpoena, court order, or other legal process, or when needed to protect someone’s safety.
  • For public health and safety, as the law permits or requires, including reporting suspected abuse, neglect, or domestic violence.
  • If our business is sold or reorganised, in which case we will tell you about the change.
  • With your permission, for anything else.

Where a vendor handles health information, we put a HIPAA business associate agreement in place with the same protections we are subject to, and require those protections to pass down to their subcontractors.

Legal requests

We require valid legal process, apply HIPAA’s minimum necessary standard, and refer requests involving your medical record to your Practice as the record’s custodian. Where information concerns sensitive services, we apply the extra protections California law provides. Substance use records have further protection, as Section 6 explains.

We do not let advertising networks, marketing platforms, or third-party analytics providers collect information from the signed-in parts of the Services, including the patient portal and visit pages.

6. How does HIPAA apply?

Your Practice is a covered entity under HIPAA. We are its business associate. We are directly responsible under HIPAA for protecting the health information we handle, for using and disclosing it only as our agreement allows, and for reporting any breach to your Practice.

Your Practice’s Notice of Privacy Practices explains in full how your health information may be used and how to exercise your rights over it. You can ask your Practice for a paper copy free of charge.

Substance use records

Records about substance use diagnosis, treatment, or referral have stronger protection under federal law than HIPAA gives. They generally cannot be shared without your written consent, cannot be passed on again by whoever receives them except as permitted, and cannot be used against you in legal proceedings without your consent or a court order.

Therapy notes

Notes a mental health professional writes about what happens in a counselling session have extra protection under HIPAA. They are kept separately from the rest of your record and generally need your specific written permission to use or share. They belong to your Practice, and its Notice of Privacy Practices covers them.

When information must be shared for safety

What you share with your clinician is confidential. The law makes a few exceptions, and they exist to keep people safe. If a clinician believes there is a serious risk of harm to you or someone else, the law may require or allow them to share limited information with a person who can help prevent that harm, which may include a potential victim or law enforcement. Clinicians must also report suspected abuse or neglect. These duties come from the law and cannot be waived by you or by us.

7. Sensitive information

California law treats some information as sensitive. For us that means your health information, your sign-in details, and any information you give us about racial or ethnic origin, religious beliefs, sexual orientation, or sex life. We collect it to provide the Services and support your care, and we do not use it beyond the purposes California law permits. You can still ask us to limit how we use it, and we will honour that, as Section 12 explains.

8. How do we protect your information?

We maintain administrative, physical, and technical safeguards appropriate to the information we handle, and review them as our Services and applicable requirements change. They include:

  • Encryption of information in transit and at rest, using industry-standard methods.
  • Access controls, so staff can only see what their role requires.
  • Logging of access to patient records.
  • Real-time visits, where audio and video travel over encrypted connections. Video is not recorded, and audio is kept only temporarily to produce the transcript.
  • HIPAA business associate agreements with each vendor that handles health information.

We work hard to protect your information, but no method of electronic transmission or storage is completely secure. If you think your account or information has been compromised, please contact us straight away.

9. Transcription and AI

Visits happen in real time, and session audio and video travel over encrypted connections. We do not record video of your visit, and no video file of your visit is created or stored on our systems.

Your clinician determines whether a visit is transcribed. Where a visit is transcribed, the audio is turned into text, either during the visit or shortly after it ends, so your clinician does not have to type while talking with you, and the audio is deleted once the text is made. Your clinician uses that text to write their clinical notes. You are told before you check in that the visit may be transcribed and that audio is kept temporarily to create the transcript.

Your clinician can stop transcription for the rest of a visit; what was already transcribed is kept. You may ask your clinician to do so. You may also contact us before your appointment, or choose not to check in. If someone else is with you or joins your visit, please tell your clinician so they can be told as well.

The transcript and the draft note produced from it become part of the record your Practice keeps, and are kept under your Practice’s retention schedule and applicable law. In the video service, transcripts and summaries are deleted automatically after the period the practice chooses (1 to 30 days; 30 by default). Your clinician is responsible for what your record says. Transcripts and draft notes can contain errors, so they are a starting point rather than a substitute for your clinician’s judgement.

Visit audio is transcribed by speech recognition software we run ourselves in our hosting environment and is not sent to an outside transcription service. AI drafting uses AWS Bedrock in the same region.

We do not keep a voiceprint or any other biometric identifier, we do not use voice recognition to identify you, and we do not use your audio, video, transcripts, draft notes, or other communications content to train our own or any third party’s artificial intelligence or machine learning models.

California and several other states require everyone taking part in a conversation to agree before it is recorded or transcribed. We tell you before transcription starts, and by continuing with the visit after that notice you agree to it. If anyone else is with you, please let your clinician know so they can be told as well.

Your session is encrypted while it travels between you and your clinician. That is not the same as end-to-end encryption. Because the audio may be transcribed to help your clinician, we do not claim your session is end-to-end encrypted.

Automated decisions

We do not use automated systems to decide whether you get care, what care you get, or whether services are covered. Licensed clinicians of your Practice make those decisions. Where software helps with scheduling, triage, or documentation, a licensed clinician of your Practice is responsible for any clinical reliance on its output.

If a health plan uses artificial intelligence in reviewing whether care is necessary, California law requires a licensed physician to supervise that tool and prohibits denying care based only on an automated decision.

AI in messages

If we ever use generative artificial intelligence to write a message to you about clinical information, that message will say so and tell you how to reach a person. In an ongoing chat, the notice stays visible throughout. This does not apply where a licensed clinician reviews the message before it is sent. No AI tool we use presents itself as a licensed health professional or uses titles or wording implying that care or advice comes from one.

10. Prescriptions and pharmacies

When your clinician prescribes medication, the prescription goes to the pharmacy you choose. As the law requires, it may also be reported to or looked up in state prescription monitoring programs, and clinicians must check those programs before prescribing certain medications, including controlled substances. Information in those programs has its own confidentiality rules. Prescription and dispensing information may also go to your health plan or pharmacy benefit manager for coverage and payment.

11. How long do we keep information?

We keep information for as long as we need it for the purposes in this notice, to meet legal obligations, and to resolve disputes, and no longer than that. We keep health information only as long as our agreement with your Practice allows, and we return or destroy it when that agreement ends.

  • Medical records: your Practice owns and retains your medical record under its own retention schedule and applicable state law.
  • Billing and insurance records: at least seven years, as federal and state rules require.
  • Account information: while your account is open and for a reasonable period afterwards.
  • Session audio: deleted once the transcript is made, and in any case within 72 hours. Transcripts and draft notes: part of the record your Practice keeps, under its retention schedule. Your clinician’s notes stay in your medical record.
  • Answers you give before becoming a patient, including unfinished intake forms: kept as part of your medical record under the practice’s retention schedule and state law.
  • Website and device logs: kept as long as we need them to run and secure the Services.
  • Messages and message logs: kept as part of your medical record under the practice’s retention schedule and state law.
  • Consent records, including SMS consent and records of transcription notices: kept as part of your record under the practice’s retention schedule and state law.

When we no longer need information, we securely destroy or de-identify it.

12. What are your choices and rights?

Depending on where you live, you may have the rights below. They cover information we hold in our own right. Your rights over your medical record are in Section 6 and in your Practice’s Notice of Privacy Practices.

  • Know what we collect: the categories and specific pieces of information we hold, where it came from, why we collected it, and who we share it with.
  • Get a copy, in a portable format.
  • Correct information that is wrong.
  • Delete information, with some exceptions such as records the law requires us to keep.
  • Limit how we use sensitive information, to what is needed to provide the Services.
  • Opt out of any sale or sharing. We do not sell or share your information as California law defines those terms.
  • Opt out of non-essential messages, including marketing emails and texts.
  • Be treated the same. We will not deny you service, charge you differently, or treat you worse for using any of these rights.

How to ask

Email support@oneybt.com, or use the settings in your patient portal if you have an account. We confirm we have your request within 10 business days and respond within 45 calendar days. If we need longer, we may take up to another 45 days and will tell you why.

Checking who you are

Before we give you access to information, correct it, or delete it, we take reasonable steps to confirm your identity. If you do not have an account, this usually means asking you to confirm details from your booking, such as the date of a visit or the email address or phone number you gave us. We do not ask you to prove who you are before honouring a request to opt out or to limit sensitive information. We only collect what we need to check a request, and we do not use it for anything else. You can use an authorised agent; we may ask them for written proof and may ask you to confirm directly.

If we say no

If we turn down your request, in whole or in part, we tell you why. Where your state gives you a right to appeal, you can appeal by replying to us or writing to support@oneybt.com. We respond within the time your state requires, and where required we tell you how to contact your state attorney general.

13. If there is a data breach

As your Practice’s business associate, we report breaches of unsecured protected health information to your Practice without unreasonable delay and within the period HIPAA requires. Your Practice, as the covered entity, is responsible for notifying affected individuals, the US Department of Health and Human Services, and where required the media. If your Practice asks us to, we can handle that notification for it.

Where applicable law requires us to offer credit monitoring or identity protection services, we will do so as that law requires.

We also follow state breach notification laws, which may require faster notice, extra reports to state agencies, or both. Where we hold health information that HIPAA does not cover, the Federal Trade Commission’s Health Breach Notification Rule may also apply.

14. Cookies and tracking

We use cookies and similar technologies to run the platform, remember your preferences, and understand how the site is used:

  • Essential cookies, needed for the platform to work, including keeping you signed in securely.
  • A first-party cookie set by the performance monitoring inside the Services.
  • Preference cookies, which remember your settings.

We do not use cookies for third-party advertising or behavioural targeting. You can control cookies in your browser settings, though turning some off may affect how the platform works.

Our public website runs no analytics. Inside the Services, Datadog performance monitoring records page loads, errors and actions; it masks what you type, does not replay your screen, and sets a first-party cookie. We do not run advertising, chat, or heat-mapping tools. We do not use web addresses, page titles, or search terms that could suggest a health condition for advertising, and our page addresses are built so they do not name a condition or treatment.

We do not use session replay or keystroke logging on our website, and we do not let anyone else intercept or record your messages to us.

Do Not Track and Global Privacy Control

Some browsers send a "Do Not Track" signal. There is no agreed standard for responding to it, so our Services do not respond to it. As explained above, we do not do third-party advertising tracking or cross-site targeting.

We do not sell personal information or share it for cross-context behavioural advertising, so there is nothing for a Global Privacy Control signal to opt you out of.

15. Text messages

If you opt in through our separate SMS Consent, we may text you about your appointments, forms, documents, sign-in, and your care. How often depends on your care and your account. Message and data rates may apply. Care messages and marketing messages are consented to separately, and consent is never a condition of getting care.

Reply STOP to stop texts; your consent is withdrawn and recorded. For help, email support@oneybt.com. You can withdraw consent in any reasonable way and we will process it within 10 business days.

Carriers are not liable for delayed or undelivered messages.

We apply HIPAA’s minimum necessary standard to texts and keep clinical detail out of them. Text messaging is not a fully secure channel. You can ask us to contact you a different way or at a different number or address, and we will accommodate reasonable requests.

We use a third-party messaging provider to deliver texts. Your number and the message content go to that provider only to deliver messages to you. We do not sell, rent, or share your number, your opt-in information, or your messaging consent with anyone for their marketing.

16. Children and young people

Our Services are not directed to children under 18. We do not knowingly collect information from a child under 18 without a parent or guardian’s consent. If we find we have, we delete it promptly. Please contact us at support@oneybt.com if you think your child has given us information without your consent.

We do not sell or share the personal information of anyone under 16.

In some states a young person can consent to their own care and keep information about that care private from a parent or guardian. Where that applies, we and your Practice follow that law, which means a parent or guardian may not be able to see everything in a young person’s record.

17. De-identified information

We may remove the details that could identify you, following the standard in the HIPAA Privacy Rule, using either the safe harbour method or an expert determination. We only do this where our agreement with your Practice allows it.

We use de-identified and aggregate information only for internal quality improvement, measuring how the Services perform, and reporting the law or our payers require. We do not sell it, and we do not use it to train artificial intelligence models. We will not try to re-identify it, we keep it de-identified, and we require any vendor who receives it to do the same.

18. Accessibility and language

We work to make this notice and our Services usable by people with disabilities, and we aim for WCAG 2.1 AA. If you need this notice in another format, email support@oneybt.com and we will provide it. We provide our Services and this notice without discrimination on the basis of race, colour, national origin, age, or disability.

19. Where we operate

Our Services are for use in the United States, and only where your Practice’s clinicians are licensed. We do not knowingly collect information from people outside the United States. Your information, including session audio and transcripts, is processed in the United States. The Services are hosted in AWS US West (Oregon). Visit audio is transcribed by speech recognition software we run ourselves in that environment and is not sent to an outside transcription service. AI drafting uses AWS Bedrock in the same region.

The law of the state you are in when you receive care generally governs your care and the privacy of your information. Where your state gives you more protection than this notice describes, your state’s law applies.

20. State-specific rights

If you live in California

You have additional rights under the California Consumer Privacy Act.

What this section covers. Health information covered by HIPAA and medical information covered by California’s Confidentiality of Medical Information Act are exempt from the CCPA. That exemption applies to the information, not to us as a company. So this section covers the information described in Section 2 under "Information we collect automatically" and "Information from other people," and the answers you give before becoming a patient.

What we collected. In the last 12 months we collected identifiers; information listed in the California Customer Records statute; characteristics of protected classifications, where you gave them; commercial information; internet and network activity information; audio and electronic information; professional information; inferences; and the sensitive personal information in Section 7. Sources are in Section 3, purposes in Section 4, and how long we keep it in Section 11. If your request covers information collected on or after 1 January 2022, we will provide it unless doing so is impossible or would take disproportionate effort.

Who we shared it with. We share information for business purposes with the recipients in Section 5 — your Practice; technology and hosting providers; payment processors; insurance, eligibility, and claims services; messaging providers; pharmacies and prescription monitoring programs; and professional advisers including lawyers. Each works under a written contract limiting them to providing services for us. We have not sold your personal information or shared it for cross-context behavioural advertising in the last 12 months, and we have no actual knowledge of selling or sharing information about anyone under 16. We do not use sensitive personal information beyond the purposes California law permits.

Your rights. Section 12 explains your rights and how to use them.

Financial incentives. We do not offer discounts, different prices, or different service in exchange for your information.

Shine the Light. We do not give your personal information to other companies for their own direct marketing, and we honour any request to opt out of that at no cost.

Do Not Track. Section 14 explains how we respond.

If you live in another state

If your state has a comprehensive privacy law — including Colorado, Connecticut, Virginia, Utah, and Texas — you may have similar rights. Depending on your state, those can include confirming whether we process your information, getting access or a copy, correcting or deleting it, opting out of targeted advertising, opting out of any sale, opting out of profiling used for decisions with legal or similar effects, and appealing our decision as Section 12 describes. Where your state requires your consent before we process sensitive data, including health data, we get it. We recognise universal opt-out mechanisms where your state requires. As we begin serving patients in more states, we add state-specific detail in the addenda to this notice.

21. Disputes

Disputes about your use of the Services, including any requirement to write to us before starting a proceeding, are covered by Section 12 of our Terms of Service. Disputes about your clinical care are covered by your agreements with your Practice. Nothing in this notice waives any right that cannot be waived, including rights under the California Consumer Privacy Act, and nothing in this notice creates a contract.

22. Changes to this notice

We may update this notice as our practices, the law, or our Services change. When we make a material change, we update the "Last updated" date. We will give at least 30 days’ notice of material changes by email or in the Services. You may ask us for any prior version by writing to support@oneybt.com. We will not apply a material change backwards to information we already collected without your consent.

23. How to reach us

OneYBT

Medcare Services Enterprise LLC, doing business as OneYBT

30 N Gould St Ste R, Sheridan, WY 82801

Email: support@oneybt.com — for support, privacy questions, and requests about your information

Legal notices: Bryan Bergman, bergman@bmblegal.com

Our Privacy Officer and Security Officer oversee privacy and security and can be reached at the email address above.

If you think your privacy rights have been violated, you can complain to us, to your Practice, to your state attorney general, or to the US Department of Health and Human Services Office for Civil Rights at www.hhs.gov/hipaa/filing-a-complaint. We will not retaliate against you for complaining.