Peak Vitality
Privacy Policy
Last updated: June 22, 2026
Template pending legal review.This policy is a working draft prepared for the practice. It must be reviewed and finalized by the practice's legal counsel and its designated Privacy Officer before it is treated as binding.
1. Who we are
Peak Vitalityis the biomarker-analysis and longevity-assessment platform operated by and for the practice (“the practice,” “we,” “us”). This policy explains how we collect, use, store, and protect personal and health information processed through the platform.
2. Information we process
- Health information (PHI): laboratory results, biomarkers, body-composition and fitness metrics, clinician notes, assessments, and care pathways you or your provider enter or upload.
- Identifiers: name, date of birth, and contact details used to match results to the correct patient record.
- Account information: email address and an encrypted (hashed) password for clinicians and staff. Patients do not have accounts — the platform is used only by the practice's clinical team.
- Activity logs: a record of who accessed or changed patient data and when, kept for security and HIPAA accountability.
3. How we use it
We process health information solely to provide care-related services: ingesting lab panels, generating clinician-reviewed assessments and reports, and supporting care pathways. Your provider gives you your assessment directly, as a printed or downloaded report. We do not sell personal or health information, and we do not use it for advertising.
4. Artificial intelligence
The platform uses AI to extract values from uploaded documents and to draft assessments. All AI processing is performed within the practice's private, access-controlled cloud environment (Google Cloud / Vertex AI) under a Business Associate Agreement. Health information is never sent to a public, consumer AI service. Every AI-generated report is a draft that a licensed clinician reviews and approves before it is released.
5. How we protect it
- Encryption in transit (TLS) and at rest.
- Additional encryption of direct identifiers — name, date of birth, and record numbers are separately encrypted within the database, so they are not readable even to someone with direct database access.
- Mandatory two-factor authentication for every clinician and staff account before any patient data can be reached.
- Role-based access control and strict separation between organizations — a clinician can only access their own practice's patients.
- Private storage for original lab files; no document is publicly accessible.
- Audit logging of access to patient data.
- A dedicated, HIPAA-aligned database and infrastructure.
6. How we share it
We share health information only with your care team and with service providers (such as our cloud infrastructure provider) that are bound by a Business Associate Agreement and process data only on our instructions. We may disclose information where required by law.
7. Your rights
Depending on your location and applicable law, you may have the right to access, correct, or request a copy of your information, and to ask questions about how it is used. Patients should direct requests to their practice's care team. See the HIPAA Notice of Privacy Practices for your rights regarding protected health information.
8. Retention
We retain medical records and related information for the period required by applicable medical-records and HIPAA regulations, after which it is securely deleted or de-identified.
9. Contact
Questions about this policy or your information may be directed to the practice's Privacy Officer.
[Privacy Officer name, address, phone, and email — to be completed by the practice.]