Privacy Policy
Effective Date: August 25, 2025
Last Updated: August 25, 2025
1. Introduction
Virtual Concierge MD ("we," "us," "our," or the "Company"), operated by Theressia L. Washington, MD, P.C. and doing business as TessMD, is committed to protecting the privacy and security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our telemedicine services, website, mobile applications, SMS services, and patient portal (collectively, the "Services").
This Privacy Policy applies to all users of our Services, including patients ranging from pediatric to geriatric care. By using our Services, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access or use our Services.
2. Services We Offer
Virtual Concierge MD provides comprehensive telemedicine services including:
- Primary Care Services: General medical care for all ages
- Testosterone Replacement Therapy (TRT): Hormone optimization and monitoring
- Medical Weight Loss Programs: Including GLP-1 medications and comprehensive weight management
- Sexual Health & Wellness: Confidential treatment for sexual health conditions
- Urgent Care Services: On-demand medical care for non-emergency conditions
- Virtual Second Opinions: Expert specialist consultations for complex medical conditions
3. Age Requirements and Pediatric Services
3.1 Age Restrictions by Service Type
General Medical Care:
- Available for patients from newborn through geriatric ages
- Patients under 18 require parental or guardian consent
- Parent or guardian must be present during all consultations for minors
Mental Health Services:
- Available for patients ages 10-17 with parental consent
- Not available for behavioral health conditions requiring specialized pediatric psychiatry
Specialized Services:
- Testosterone Replacement Therapy: Ages 18 and older only
- Medical Weight Loss Programs: Ages 18 and older only
- Sexual Health Services: Ages 18 and older only
- Primary Care Memberships: Ages 18 and older only
3.2 COPPA Compliance
In compliance with the Children's Online Privacy Protection Act (COPPA):
- We do not knowingly collect personal information from children under 13 without verifiable parental consent
- Parents must create and manage accounts for children under 18
- We implement age verification mechanisms to prevent unauthorized access by minors
3.3 Adolescent Privacy Rights (Ages 13-17)
While adolescents ages 13-17 require parental consent for our Services, we recognize their developing privacy rights:
- Certain state laws may permit adolescents to consent to specific health services independently
- We maintain confidentiality as required by applicable state laws
- Parents will be informed of privacy limitations based on state regulations
4. Information We Collect
4.1 Personal Information
We collect information you provide directly to us, including:
Account Information:
- Name, date of birth, gender
- Contact information (address, phone number, email)
- Government-issued identification for identity verification
- Insurance information (if applicable)
- Emergency contact information
Health Information:
- Medical history and current medications
- Symptoms and health concerns
- Laboratory results and diagnostic imaging
- Biometric data (blood pressure, weight, heart rate)
- Treatment preferences and care goals
- Mental health information
Payment Information:
- Credit/debit card information
- Billing address
- Transaction history
4.2 Automatically Collected Information
Device and Usage Data:
- IP address and device identifiers
- Browser type and operating system
- Mobile device information
- Usage patterns and preferences
- Location data (with your consent)
Telehealth Session Data:
- Video and audio during consultations
- Session timestamps and duration
- Technical quality metrics
4.3 SMS Communication Data
When you opt into our SMS services, we collect:
- Mobile phone number
- Carrier information
- Opt-in date, time, and method
- Message delivery confirmations
- Opt-out requests
- Response data to our messages
4.4 Biometric Data Collection
We may collect biometric data through:
- Facial recognition for identity verification
- Voice recordings during telehealth sessions
- Health monitoring device data (with your consent)
- At-home testing kit results
4.5 Artificial Intelligence and Automated Processing
We use AI and machine learning technologies to:
- Assist in symptom assessment and triage
- Analyze health trends and patterns
- Improve diagnostic accuracy
- Personalize treatment recommendations
- Detect potential drug interactions
5. How We Use Your Information
5.1 Healthcare Operations
We use your information to:
- Provide telemedicine consultations and medical treatment
- Process prescriptions and coordinate with pharmacies
- Communicate with you about your care
- Send appointment reminders via SMS (with your consent)
- Process payments and insurance claims
- Maintain and improve our Services
- Send health alerts and medication reminders via SMS (with your consent)
5.2 SMS Communications
With your explicit consent, we use your phone number to:
- Send appointment reminders and confirmations
- Notify you of prescription readiness
- Alert you to lab results availability (not the results themselves)
- Provide health tips and wellness updates
- Send promotional offers and discounts
- Deliver customer care messages
- Notify you of order shipments
All SMS communications:
- Include opt-out instructions
- Are sent between 8 AM - 9 PM local time (except emergencies)
- Comply with TCPA regulations
- Can be stopped at any time by texting STOP
5.3 Legal and Regulatory Compliance
We use your information to:
- Comply with healthcare regulations including HIPAA
- Report to prescription monitoring programs as required by law
- Respond to legal processes and government requests
- Prevent fraud and ensure Service security
- Meet state-specific telemedicine requirements
- Comply with TCPA and CTIA messaging guidelines
5.4 Research and Analytics
With appropriate safeguards, we may use de-identified information for:
- Medical research and clinical studies
- Quality improvement initiatives
- Population health management
- Service enhancement and development
6. How We Share Your Information
6.1 Healthcare Providers and Medical Staff
We share your health information with:
- Licensed physicians providing your care
- Clinical support staff involved in your treatment
- Specialists for consultations and second opinions
- Your designated primary care physician (with your consent)
6.2 Third-Party Service Providers
We work with trusted third parties including:
Pharmacy Partners:
- Licensed pharmacies for prescription fulfillment
- Compounding pharmacies for specialized medications
- Prescription benefit managers
Laboratory Services:
- CLIA-certified laboratories for diagnostic testing
- At-home testing kit providers
- Diagnostic imaging centers
Technology Partners:
- Telehealth platform providers (with signed Business Associate Agreements)
- Electronic health record systems
- Payment processors (PCI-DSS compliant)
- Cloud storage providers (HIPAA-compliant)
- SMS service provider (RingCentral - with Business Associate Agreement)
6.3 Legal Disclosures
We may disclose your information when required by law:
- Court orders and subpoenas
- Law enforcement requests (with appropriate legal process)
- Public health authorities
- Healthcare oversight agencies
- To prevent serious threats to health or safety
6.4 SMS Service Providers
We share limited information with RingCentral for SMS delivery:
- Phone number
- Message content
- Delivery confirmations All sharing is governed by a Business Associate Agreement ensuring HIPAA compliance.
7. International Users and Cross-Border Data Transfers
7.1 GDPR Compliance
For users in the European Union, we provide additional protections:
- Legal basis for processing (consent or legitimate interests)
- Right to data portability
- Right to restriction of processing
- Right to object to processing
- Right to lodge complaints with supervisory authorities
7.2 International Data Transfers
When transferring data internationally, we use:
- Standard Contractual Clauses approved by the European Commission
- Appropriate technical and organizational safeguards
- Encryption for all data transfers
8. Data Security and Retention
8.1 Security Measures
We implement comprehensive security measures including:
- End-to-end encryption for all telehealth sessions
- Multi-factor authentication for account access
- Regular security assessments and penetration testing
- Employee training on privacy and security
- Incident response and breach notification procedures
- Secure SMS gateway with encryption
8.2 Data Retention
We retain your information for:
- Medical records: As required by applicable state laws (typically 7-10 years)
- Account information: Duration of your relationship with us plus legal retention period
- Payment records: As required for tax and accounting purposes
- SMS consent records: Minimum 4 years per TCPA requirements
- De-identified data: Indefinitely for research and analytics
9. Your Privacy Rights
9.1 Access and Correction Rights
You have the right to:
- Access your personal and health information
- Request corrections to inaccurate information
- Receive your information in a portable format
- Request an accounting of disclosures
9.2 California Privacy Rights (CCPA/CPRA)
California residents have additional rights to:
- Know what personal information we collect
- Delete personal information (subject to legal exceptions)
- Opt-out of the sale of personal information (we do not sell personal information)
- Limit use of sensitive personal information
- Non-discrimination for exercising privacy rights
9.3 Marketing and Communications
You may opt-out of:
- Marketing emails by clicking "unsubscribe"
- Text messages by replying "STOP" to any SMS
- Push notifications through your device settings
SMS Opt-Out: Text STOP to any message to immediately stop all SMS communications. You will receive a confirmation that you've been opted out.
SMS Opt-In: After opting out, text START to resume SMS communications.
9.4 SMS-Specific Rights
You have the right to:
- Opt out of SMS at any time by texting STOP
- Request help by texting HELP
- Know the frequency of messages (up to 10 per month)
- Be informed of any charges (message and data rates may apply)
- File complaints about unwanted messages
10. Third-Party Websites and Applications
Our Services may contain links to third-party websites and applications. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any information.
11. Changes to This Privacy Policy
We may update this Privacy Policy periodically. We will notify you of material changes by:
- Posting the updated Privacy Policy on our website
- Sending email notifications to registered users
- Sending SMS notifications (if opted in) for significant changes
- Requiring acknowledgment for continued use of Services
12. Contact Information
For questions about this Privacy Policy or to exercise your privacy rights, contact us at:
Privacy Officer
Virtual Concierge MD / TessMD
9663 Santa Monica Blvd, Suite 957
Beverly Hills, CA 90210
Email: privacy@virtualconciergemd.com
Phone: (310) 275-8377
Website: virtualconciergemd.com
Legal Center: https://legalcenter.virtualconciergemd.com
HIPAA Complaints: You may also file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights.
SMS Complaints: For SMS-related issues, you may also file complaints with:
- Federal Communications Commission (FCC)
- Your state attorney general
- CTIA by forwarding unwanted messages to 7726 (SPAM)
13. SMS Privacy Addendum
This section provides additional details about our SMS practices:
Message Types
- Transactional: Appointment reminders, prescription notifications
- Promotional: Special offers, wellness tips (with separate consent)
- Customer Care: Follow-ups, satisfaction surveys
Carrier Compatibility
Our SMS service works with all major US carriers including AT&T, Verizon, T-Mobile, Sprint, and others.
No Sharing for Marketing
We never share your phone number with third parties for their marketing purposes.
Frequency Control
You control message frequency through your preferences. Default is up to 10 messages per month.
By using our Services, you acknowledge that you have read and understood this Privacy Policy and agree to be bound by its terms.
For a complete description of how we use and disclose your health information for treatment, payment, and healthcare operations, please see our Notice of Privacy Practices available at https://legalcenter.virtualconciergemd.com