HIPAA & Your Health Information
Last updated: August 7, 2026
MemoRx isn't a doctor's office, hospital, health plan, or insurance company, so the federal HIPAA law doesn't regulate us the same way it regulates them. That doesn't mean your information isn't protected — we've built MemoRx to safeguard your family's health information carefully, and this page explains exactly what that means.
What HIPAA covers, and why MemoRx sits outside it
The Health Insurance Portability and Accountability Act (HIPAA) is a federal law that sets privacy and security rules for "covered entities" — such as healthcare providers, health plans, and healthcare clearinghouses — and their "business associates," who handle health data on those entities' behalf.
MemoRx is a consumer software company. You use MemoRx directly and on your own behalf, not because your doctor, hospital, or insurer hired us to process records for them. That means MemoRx generally does not meet the legal definition of a HIPAA "covered entity" or "business associate," and the information you store in MemoRx isn't regulated by HIPAA the way your medical chart at your doctor's office is.
This is true of most consumer health and wellness apps, not just MemoRx. If you import information from a source like MyChart, your healthcare provider and MyChart's operator remain separately responsible for their own HIPAA obligations regarding the records they hold. MemoRx's responsibilities for the copy of that information you bring into our app are the ones described on this page and in our Privacy Policy.
What protects your information instead
- We apply HIPAA-style administrative, physical, and technical safeguards to your health information as a matter of our own policy — see the security details below.
- The Federal Trade Commission's Health Breach Notification Rule requires companies like MemoRx to notify affected users (and in some cases the FTC and the media) after a breach of unsecured identifiable health information. We take this obligation seriously.
- State laws that protect consumer health data may also apply to MemoRx depending on where you live, and we design our practices with those obligations in mind.
- Our Privacy Policy explains what we collect, how we use it, and your choices — including how to access, export, or delete your information.
Family sharing and your responsibility
Because MemoRx lets you enter information about other people (like a spouse or aging parent) and share access with caregivers, please only add someone else's health information with their permission, and only share access with people you trust. MemoRx can't independently verify family relationships or consent — see our Terms of Service for more.
The emergency access feature
MemoRx's optional emergency access feature is designed to show select information quickly to first responders. Turning it on is your choice, and it doesn't change MemoRx's HIPAA status — it's a feature you control to help in an emergency, not a medical or legal disclosure.
Security: encryption
Information you send to MemoRx is encrypted in transit using industry-standard protocols (TLS/HTTPS). We also encrypt data at rest.
Security: access controls
You control who can see each profile in your MemoRx account, and you can change that access at any time. Internally, MemoRx team members only access user data when necessary to operate or support the Service, limited to what's needed for their role.
Security: infrastructure
MemoRx is hosted on reputable cloud infrastructure that maintains its own physical and network security safeguards, and we take regular backups to help protect against data loss.
Account protection
Help keep your account secure by choosing a strong, unique password, never sharing your login, and keeping your device's operating system and the MemoRx app up to date.
Monitoring and testing
We monitor our systems for unusual activity and work to identify and fix security issues as we find them.
If something goes wrong
If we discover a security incident affecting your information, we'll notify affected users consistent with the FTC's Health Breach Notification Rule and any other applicable law, and take steps to address it.
Reporting a security issue
If you're a security researcher or just noticed something that looks off, please tell us before telling anyone else: email privacy@memorx.online with details, and we'll investigate promptly.
Your part
A few things you can do to help protect your family's information: keep your login private, lock your phone with a passcode or biometrics (especially since the emergency access feature can display information from the lock screen), and log out of shared or public devices.
Questions
If you have questions about how MemoRx handles health information, or you're a healthcare organization interested in a formal data-sharing relationship with us, email privacy@memorx.online.
