Legal
Privacy Policy
This Privacy Policy describes how CCN Health collects, uses, shares, retains, and protects information collected through our website, applications, and services. By using this website, you agree to the most recent version of this Privacy Policy.
Effective date: June 3, 2026·Last updated: June 3, 2026·Last reviewed: June 3, 2026
Introduction
The information we receive, and how we use it, depends on what you do when visiting our website and using our services. We collect and use non-personal information (information that is not identifiable to you personally) differently than your personal information.
What Is Non-Personal Information?
Non-personal information is information we collect that does not identify you as an individual person. It may include:
- ○The type of web browser software you use
- ○The domain from which you access the Internet
- ○The Internet address of the website from which you linked to our website
- ○The date and time you access our website
- ○Which pages you have visited on our website
- ○The search terms you use and the links you click
- ○Personal information that has been de-identified or anonymized so that it no longer reasonably identifies you
What Does CCN Do With Non-Personal Information?
Because non-personal information cannot identify you, we use it to operate, maintain, and improve our website and services. For example, we may use non-personal or aggregated information to:
- ○Create internal reports to develop programs, products, services, or content
- ○Customize the information or services that may interest you
- ○Provide aggregated statistics (such as traffic and response rates) to service providers who act on our behalf
We do not sell your personal information. Where we share aggregated or de-identified information with service providers or business partners, we do so only for the legitimate business purposes described in this policy.
What Is Personal Information?
Personal information is information we collect or that you submit (including through products that send information to us) that can be used to identify you, such as your:
- ○Name
- ○Date of birth
- ○Home address and telephone number
- ○Email address
- ○Protected health information (see Section 5)
Protected Health Information (PHI)
Protected health information is information that may identify you and that relates to your physical or mental health or condition and related health care services. We are committed to safeguarding all PHI we collect while providing health-related products, services, education, and training. Examples include:
- ○Information about your health condition (e.g., your blood pressure or glucose readings)
- ○Information about health care products or services provided to you
- ○Geographic and demographic information
- ○Unique identifiers (e.g., Social Security number, phone number, or a state-issued identifier)
We handle PHI in accordance with HIPAA, applicable state law, and our Business Associate Agreements with the providers and facilities we serve.
How Does CCN Keep and Use Personal Information?
We may keep and use personal information to provide and operate our website and services, including to:
- ○Respond to your requests
- ○Send information to third parties (family members, caregivers, friends) whom you authorize us to share with
- ○Share with service providers and business partners to deliver and improve our products, under appropriate confidentiality and data-protection terms
- ○Personalize your experience
- ○Provide information to your care team (such as your physician or diabetes educator)
- ○Maintain records, including records of your personal information
- ○Contact you with information that may interest you (subject to your communication preferences)
- ○Enforce this Privacy Policy and protect our rights, property, and the health, safety, or welfare of others
- ○Provide treatment-related services and run normal business operations
Where we de-identify personal information using the standards set out under HIPAA, the resulting information is no longer PHI and we may use it as non-personal information. We do not sell de-identified information.
Does CCN Share Personal Information With Third Parties?
CCN will not share your personal information with an unrelated third party without your permission, except as described in this Privacy Policy.
In the ordinary course of business, we share limited personal information with service providers we engage to perform functions on our behalf. In every case, we contractually require those parties to protect your information and to use it only for the purpose of providing the services we requested. When the information involves PHI, we enter into Business Associate Agreements as required by HIPAA.
We do not sell, rent, or trade your personal information. We may transfer personal information in connection with a corporate sale, merger, reorganization, dissolution, or acquisition, subject to this Privacy Policy and applicable law.
As Required by Law
We may disclose your personal information if required by federal, state, or local law, or in response to a subpoena, court order, discovery request, or other properly authorized legal process. We may also disclose information in civil litigation where you have put your medical condition at issue.
Authorization and Consent
Except as described in this Privacy Policy, we will obtain your written or online authorization before using your personal information or disclosing it to persons or organizations outside CCN. We will obtain authorization for any marketing communications and for any disclosure that would constitute a sale of personal information.
You may revoke any authorization in writing at any time. After we receive your revocation, we will stop using or disclosing your personal information for the purposes covered by that authorization, except to the extent we have already acted in reliance on it. We cannot retract disclosures already made with your permission.
Your Privacy Rights
Subject to applicable law and to our legal and regulatory obligations to retain certain health records, you may exercise the following rights regarding your personal information:
- ○Right to access — Request confirmation of whether we hold personal information about you and a copy of that information.
- ○Right to correction / amendment — Request that we correct inaccurate or incomplete personal information.
- ○Right to deletion — Request that we delete personal information we hold about you. Please note we may be legally required to retain certain medical and health records (see Section 11), and we will inform you when an exception applies.
- ○Right to restrict or object — Request that we restrict or stop certain uses or disclosures of your information.
- ○Right to portability — Request a copy of certain information in a portable, machine-readable format.
- ○Right to revoke authorization — Withdraw a previously granted authorization, as described in Section 9.
- ○Right to non-discrimination — We will not discriminate or retaliate against you for exercising any of these rights.
How to exercise your rights. To submit a request, contact us using the details in Section 15. We will verify your identity before fulfilling a request, and we will respond within the timeframe required by applicable law (generally within 30–45 days; we will notify you if we need additional time). You may use an authorized agent to submit a request on your behalf where the law permits.
If your request concerns PHI held by us on behalf of a healthcare provider, we may direct the request to that provider, who is responsible for responding under HIPAA. Patients also retain the HIPAA rights to access and amend their records, to receive an accounting of certain disclosures, and to file a complaint with the U.S. Department of Health and Human Services, Office for Civil Rights.
Data Retention
We retain personal information and PHI only as long as necessary to fulfill the purposes described in this Privacy Policy and to meet our legal, regulatory, and contractual obligations, including our Business Associate Agreements with the providers and facilities we serve.
- ○Protected health information and health-related records — retained in accordance with our Business Associate Agreements and applicable state law. Where CCN retains such records, we do so for the longer of the period required by the applicable client agreement or by state law, generally 7 to 10 years from the last date of service, and for records of minors, until the patient reaches the age of majority plus any additional period required by state law.
- ○HIPAA compliance documentation (policies, authorizations, Business Associate Agreements, audit logs, risk assessments, and breach records) — retained for at least 6 years from creation or the date last in effect, whichever is later.
- ○Account and contact information — retained for the duration of your relationship with us and for up to 6 years afterward to meet legal and operational needs.
- ○Website analytics and non-personal information — retained for up to 14 months, consistent with our analytics tools, then deleted or aggregated.
When information is no longer required, we securely delete, destroy, or de-identify it.
Cookies and Tracking Technologies
Our website uses cookies and similar technologies to operate the site, remember your preferences, measure traffic, and improve performance. You can control cookies through your browser settings; disabling some cookies may affect site functionality. Where required by law, we obtain consent before placing non-essential cookies.
We use PostHog (product analytics) and Google Analytics to understand how visitors use our website and to improve it. These analytics tools are configured so that they do not receive or store protected health information (PHI).
Your Rights Under U.S. State Privacy Laws (Including California / CCPA-CPRA)
If you are a resident of California or another U.S. state with a comprehensive privacy law, you have the rights described in Section 10, including the rights to know, access, correct, and delete your personal information, and to opt out of the “sale” or “sharing” of personal information as those terms are defined by law.
We do not sell or share your personal information as those terms are defined under the California Consumer Privacy Act (as amended by the CPRA). We do not use or disclose sensitive personal information for purposes other than those permitted under applicable law. Certain medical information governed by HIPAA and state health-privacy laws is exempt from these statutes and is handled as described in Sections 5–11.
To exercise your state privacy rights, contact us using the information in Section 15.
U.S.-Based Services
CCN Health is based in the United States, and our website, applications, and services are intended for healthcare organizations and individuals located in the United States. We do not target or offer our services to data subjects in the European Economic Area or the United Kingdom. If you access our website from outside the United States, you do so on your own initiative and are responsible for compliance with applicable local laws, and you consent to your information being collected and processed in the United States, where data-protection laws may differ from those in your location.
How to Contact CCN
If you have questions, comments, concerns, or wish to exercise a privacy right, please contact us:
CCN Health operates as a fully remote company, so the fastest way to reach us is by email. You may also contact us through the form on our website.
Website Security
Security is important to us. We take reasonable administrative, technical, and physical safeguards — including encryption in transit, access controls, and monitoring — to protect personal information and PHI from loss, misuse, and unauthorized access, disclosure, alteration, or destruction. No method of Internet transmission or electronic storage is 100% secure. Email sent to or from this site may not be secure, so please use care in deciding what information you send by email.
We maintain an incident-response process to detect, investigate, and respond to security events. If a breach affects your personal information or PHI, we will notify affected individuals, the providers and facilities on whose behalf we hold the information, and regulators, as required by applicable law and our Business Associate Agreements.
Children's Privacy
Our website is intended for healthcare organizations and adults. We do not knowingly collect personal information from children under 13 through our website. Health information about pediatric patients is processed only on behalf of, and under the direction of, the treating provider and in accordance with HIPAA and applicable law.
Changes to This Privacy Policy
If this Privacy Policy is revised, the most current version will be posted on this page with an updated “Last updated” date. Please review it periodically, and especially before providing personal information.
This policy is published at https://ccnhealth.com/privacy-policy and is accessible without login.
Last updated: June 3, 2026


