Effective Date: August 11, 2024
Last Updated: August 2, 2026
Applies to: United States and Canada
Replaces: the BirthBridge HIPAA Policy
Why this document changed
The previous version of this page was written as a Notice of Privacy Practices, which is a document that a health care provider issues to its patients under HIPAA. BirthBridge is not a health care provider and does not treat anyone, so issuing that kind of notice was not accurate and it described rights that your provider, not BirthBridge, is the right party to give you.
This version says what BirthBridge actually does with information about health, what your birth professional is responsible for, and what applies in the United States and in Canada, which have completely different laws on this subject.
1. The short version
- BirthBridge is a communication and coordination platform, not a medical record system. You can share what you need to arrange care. Do not use it as your clinical chart.
- We protect information about health as sensitive information, always, regardless of whether a particular law technically applies.
- We never use health information for advertising, we never sell it, and we do not use it to train artificial intelligence models.
- We are not your health care provider. If your professional is a regulated health professional, your legal rights over your health record run against them, and we help them meet their obligations rather than replacing them.
- HIPAA is a United States law. It does not apply in Canada. Section 6 covers Canada.
- In an emergency, call 911 or your local emergency number. Do not use platform messaging for anything urgent.
2. What we mean by health information
Information about health is any information that relates to a person's physical or mental health, their pregnancy, their birth, their postpartum recovery, their feeding, or the care they are seeking or have received.
On BirthBridge this can include:
- A due date, gestational age, or number of previous births.
- Where you plan to give birth, and what kind of birth you are hoping for.
- The kind of support you are looking for, such as labour support, lactation help, or postpartum mental health support.
- What you tell a professional in a message.
- Documents or photos you upload and share with a professional.
We treat all of it as sensitive.
3. What BirthBridge does with health information
We use it to help you find and arrange care, and for nothing else.
Specifically:
| We do | We do not |
|---|---|
| Use search criteria to show you relevant professionals | Use health information to target advertising |
| Pass your request to the professional you contacted | Sell health information |
| Deliver, store, and display messages between you and your professional | Use health information to train machine learning or AI models |
| Keep records needed for bookings, payments, and disputes | Share health information with data brokers or advertising partners |
| Investigate a report of abuse, fraud, or a safety concern | Access message content out of curiosity or for product analytics |
| Disclose where legally compelled, applying the protections in Section 7 | Provide health information voluntarily to law enforcement |
3.1 How messaging actually works
We want to be precise about this, because vague security language is not useful to you.
- Messages are encrypted at rest in our database using a key pair for each user, so message content is not stored in readable plain text.
- Messages are protected in transit with TLS between your device and our servers.
- This is not end-to-end encryption. BirthBridge holds the technical means to decrypt message content. We do so to investigate reports of abuse or fraud, to respond to a support request you make, and where legally required.
- Notification emails never contain message content. When someone messages you we send an email saying only that you have a message and who it is from, with a link to sign in. Message text is not placed in email, because email is not an encrypted channel.
- BirthBridge does not provide video calling. When an appointment is marked as virtual, the professional supplies their own meeting link, usually Zoom or Google Meet. That call happens entirely outside BirthBridge. We store the link and the appointment details, and nothing else about the call. We do not join it, we cannot see or hear it, we do not record it, and we hold no recording, transcript, or attendance record of it. What happens to anything said or shared on that call is governed by the professional and by whichever video service they chose, not by us. If we ever build video calling into the platform, we will update this page before it ships.
- Message content is not used to train artificial intelligence models, by us or by any vendor.
3.2 What to share, and what not to
Share what you need to. Telling a doula your due date and that you are planning a hospital birth is the entire point of the platform, and you should feel comfortable doing it.
Do not use the platform as a medical record. Do not upload your full prenatal chart, lab results, imaging, or a complete medical history unless your professional has specifically asked for it and explained why. Do not use messaging for anything time-critical or clinical.
In an emergency, call 911 or your local emergency number. Messages are not monitored in real time and there is no guaranteed response time.
4. Who is responsible for what
This is the part that causes the most confusion, so here it is plainly.
4.1 Your birth professional
Your professional is responsible for their own privacy and record-keeping obligations. Those obligations depend on what kind of professional they are, and they are different for regulated and unregulated professionals.
Regulated health professionals include midwives, nurses, physicians, and in some jurisdictions other practitioners. They belong to a regulatory college or licensing board, they hold protected titles, and they are subject to health privacy law directly. They must keep clinical records, retain them for a set period, and give you access to them.
Unregulated professionals include most doulas, most childbirth educators, most postpartum support professionals, and many lactation consultants. They may hold meaningful certifications from a training organization, but they are not licensed by a government body, they do not have a regulatory college, and health privacy laws written for licensed providers generally do not apply to them.
That does not mean unregulated professionals have no obligations. General privacy law applies to them if they operate as a business, professional ethics apply, and our Terms require them to handle client information with care. But it does mean you should ask your professional how they handle your information, because the answer varies.
4.2 BirthBridge
We are responsible for the platform. We protect the information you put into it, we limit who can see it, we tell you what we do with it, and where a regulated professional needs a formal agreement from us in order to use the platform lawfully, we provide one. See Health Information Agreements.
We are not responsible for what your professional does with information after they receive it, or for what they store in their own systems. If you have a concern about that, raise it with them, and with their regulator if they have one.
4.3 You
If you share information about someone else, including your partner, another child, or a family member, share only what is necessary and only with their agreement.
5. United States
5.1 HIPAA, and when it actually applies
HIPAA applies to covered entities, which are health plans, health care clearinghouses, and health care providers who transmit health information electronically in connection with certain standard transactions, generally insurance billing. It also applies to business associates, which are organizations that handle protected health information on behalf of a covered entity.
BirthBridge is not a covered entity. We do not provide health care and we do not bill insurance.
BirthBridge may be a business associate. When a covered entity, such as a midwifery practice or a clinic, uses our platform to communicate protected health information with its patients or with other providers, we act as a business associate of that entity for that purpose. In that case we sign a Business Associate Agreement, which sets out what we may do with the information and what safeguards we apply. See Health Information Agreements.
Many birth professionals on BirthBridge are not covered entities. A doula who is paid directly by families and does not bill insurance is generally not a HIPAA covered entity, and HIPAA does not apply to the information she holds. This surprises people, so it is worth stating clearly. It does not mean her clients' information is unprotected. It means the protection comes from state law, professional ethics, contract, and our Terms rather than from HIPAA.
5.2 Your HIPAA rights, and who to ask
If your professional is a covered entity, HIPAA gives you rights over the health record they hold about you:
- To inspect and get a copy of your record.
- To ask for it to be amended if it is inaccurate or incomplete.
- To an accounting of certain disclosures.
- To ask for restrictions on how it is used or disclosed.
- To ask for confidential communications by a particular method or at a particular address.
- To receive their Notice of Privacy Practices.
Ask your professional to exercise these rights, not us. They hold the record. If you ask us, we will tell you who to contact, and where we hold information on their behalf we will support them in responding.
We will separately give you access to and a copy of the information BirthBridge holds about you, including your messages, under our Privacy Policy. That is a different thing from your clinical record, and it is available to you whether or not HIPAA applies.
5.3 When we act as a business associate
When we are a business associate under a signed agreement, we:
- Use and disclose protected health information only as the agreement permits or as the law requires.
- Apply administrative, physical, and technical safeguards, and comply with the HIPAA Security Rule with respect to electronic protected health information.
- Limit use and disclosure to the minimum necessary for the purpose.
- Require any subcontractor that handles protected health information on our behalf to agree in writing to the same restrictions and conditions.
- Report a breach of unsecured protected health information to the covered entity without unreasonable delay and no later than 60 days after discovery, and report any other security incident or unauthorized use or disclosure promptly.
- Make information available so the covered entity can meet its access, amendment, and accounting obligations.
- Return or destroy protected health information at the end of the agreement where feasible, and where it is not feasible, extend the protections for as long as we retain it.
5.4 Texas
BirthBridge is a Texas company. Texas has its own health privacy law, the Texas Medical Records Privacy Act, which defines "covered entity" more broadly than HIPAA and reaches organizations that assemble, collect, analyse, use, evaluate, store, or transmit protected health information, whether or not they bill insurance.
We treat ourselves as subject to it. In practice:
- We do not sell protected health information.
- We obtain authorization before any electronic disclosure of protected health information except where an exception applies.
- Staff who handle personal information are trained on the handling of health information.
- The Act requires that an electronic copy of health information be provided to a requesting individual within 15 business days, which is faster than HIPAA's 30 days. We treat 15 business days as our deadline for anyone asking for health information we hold, in any state. You do not have to invoke the Act to get that timing, and you do not have to be in Texas.
5.5 Puerto Rico
If you are in Puerto Rico, you are in the United States for the purposes of this policy, and federal law applies to you in full. HIPAA's definition of "State" expressly includes Puerto Rico, so where we act as a business associate for a covered entity in Puerto Rico, the obligations in Section 5.3 apply exactly as they would on the mainland.
Puerto Rico also has protections of its own:
- A constitutional right to privacy. Article II, Section 8 of the Constitution of Puerto Rico protects every person against attacks on their honour, reputation, and private or family life. Unlike the federal constitutional right, Puerto Rico courts have applied this between private parties, not only against the government, so it is a directly relevant protection rather than a background principle.
- Breach notification is faster than almost anywhere else. Puerto Rico's Citizen Information on Data Banks Security Act (Act No. 111 of 2005) requires a business holding personal information about Puerto Rico residents to notify the Department of Consumer Affairs (DACO) within 10 days of detecting a breach, followed by notice to the affected people. That deadline is shorter than the federal and state deadlines described in our Privacy Policy, and where it applies we follow the shortest deadline, not the most convenient one.
- Language. Spanish and English are both official languages in Puerto Rico. We publish in English today. If you would prefer to correspond with us in Spanish, write to hello@mybirthbridge.com and we will respond in Spanish.
Note that Puerto Rico is not a state, so the comprehensive state privacy laws listed in Schedule A of our Privacy Policy do not apply there. We extend the same rights to Puerto Rico residents anyway, because drawing that line would be arbitrary.
5.6 State health privacy laws
Several US states protect health information more broadly than HIPAA does, including information a platform like ours collects even where HIPAA does not apply.
Washington and Nevada have consumer health data laws that cover information about pregnancy and reproductive health, and that require separate consent to collect it beyond what is necessary to provide a requested service, and separate written authorization to share it. Washington's law carries a private right of action.
We treat pregnancy and reproductive health information as sensitive everywhere, and we do not sell it or use it for advertising in any jurisdiction.
Our [Consumer Health Data Policy](/legal/consumer-health-data-policy) is the separate notice those laws require. It is a distinct document, reachable by its own link, because Washington's law requires that rather than a section inside a general privacy policy. Read it if you live in Washington, Nevada, or Connecticut.
5.7 Reproductive health information and legal requests
We know that people share pregnancy information on this platform at a time when that information can be sensitive in ways beyond the ordinary.
Our commitment: we apply heightened scrutiny to any request for information that would reveal a person's pregnancy status, pregnancy outcome, or the reproductive health care they sought or received. We require legally valid and enforceable process, we object to requests that are overbroad or that we believe lack legal authority, we challenge process where we have a good faith basis to do so, and where we are permitted to we notify the affected person before disclosing so they can object. Where the law permits us to require an attestation about the purpose of a request before disclosing, we require one.
We do not provide this information voluntarily.
5.8 The FTC Health Breach Notification Rule
The FTC's Health Breach Notification Rule (16 CFR Part 318) applies to businesses that hold health information about individuals and are not covered by HIPAA. Since amendments that took effect in July 2024, the Rule reaches health apps and connected platforms, and it treats an unauthorized disclosure of identifiable health information as a breach, not only a hacking incident.
We operate to the standard the Rule sets, so that you get its protection regardless of how the Rule is ultimately applied to a platform like ours:
- If identifiable health information is disclosed or accessed without authorization, we will notify affected individuals and the FTC without unreasonable delay and no later than 60 calendar days after discovery.
- Where 500 or more people are affected, we will notify the FTC within 10 business days and give prominent media notice in the affected areas.
- Our notice will say what happened, when, what information was involved, who obtained it if we know, what we are doing, and what you can do.
We would rather hold ourselves to the more demanding deadline than the more convenient one.
6. Canada
HIPAA does not apply in Canada. If you are a Canadian professional and someone tells you that you need to be "HIPAA compliant," that is not right. Your obligations come from Canadian law.
6.1 Which law applies to you
If you are a regulated health professional, such as a registered midwife, you are almost certainly a custodian or trustee of health information under your province's health privacy legislation:
| Province or territory | Legislation | Term used | Agreement instrument |
|---|---|---|---|
| Ontario | Personal Health Information Protection Act (PHIPA) | Health information custodian | Agent agreement under s. 10(3), and Health Information Network Provider obligations under O. Reg. 329/04 s. 6(3) |
| Alberta | Health Information Act (HIA) | Custodian, affiliate, information manager | Information Manager Agreement under s. 66 |
| British Columbia | Personal Information Protection Act, and the E-Health Act for designated systems | Organization | Service provider terms under PIPA |
| Saskatchewan | Health Information Protection Act (HIPA) | Trustee | Information management service provider agreement under s. 18(2) |
| Manitoba | Personal Health Information Act (PHIA) | Trustee | Information manager agreement under s. 25 |
| Nova Scotia | Personal Health Information Act | Custodian | Information manager agreement |
| New Brunswick | Personal Health Information Privacy and Access Act | Custodian | Agent agreement |
| Newfoundland and Labrador | Personal Health Information Act | Custodian | Information manager agreement |
| Prince Edward Island | Health Information Act | Custodian | Information manager agreement |
| Quebec | Law 25, and the Act respecting health and social services information for health and social services bodies | Depends on status | Written mandate under Law 25, plus a privacy impact assessment for transfer outside Quebec |
If you are not a regulated health professional, and most doulas, childbirth educators, and postpartum professionals in Canada are not, then health privacy legislation written for custodians generally does not apply to you. What applies instead is:
- PIPEDA, or your province's substantially similar private-sector privacy law, if you collect personal information in the course of commercial activity. This is a real obligation, not an optional one.
- Quebec's Law 25, if you are in Quebec, which applies to every private-sector enterprise and treats health information as sensitive requiring express consent.
- Your certifying organization's code of ethics.
- Our Terms.
Practically, that means: get consent, collect only what you need, keep it secure, keep it only as long as you need it, and give clients access to what you hold about them if they ask.
6.2 What BirthBridge provides to Canadian professionals
We can enter into the appropriate agreement for your province, including an Alberta Information Manager Agreement, an Ontario PHIPA agent agreement, or the equivalent instrument elsewhere. See Health Information Agreements.
Ontario law also has a specific category, the Health Information Network Provider, which applies where a provider enables two or more custodians to disclose personal health information to one another electronically. Ontario custodians considering that use of BirthBridge should contact us at hello@mybirthbridge.com so that we can put the right written agreement in place first. A plain language description of our services and safeguards is published on the Health Information Agreements page.
6.3 Your rights in Canada
Your rights over your clinical record come from your province's health privacy legislation and run against your custodian, meaning your midwife or clinic, not against BirthBridge. Generally these include the right to access and get a copy of your record, to request correction, and to complain to your provincial Information and Privacy Commissioner.
Your rights over the information BirthBridge holds are set out in Schedule B of our Privacy Policy and apply regardless of whether your professional is regulated.
6.4 Where your information is stored
BirthBridge stores and processes information in the United States. For Canadian users this includes information about health.
If you are a Canadian custodian or trustee considering using BirthBridge for anything involving personal health information, this matters to your own compliance analysis. Cross-border storage is not prohibited by Canadian privacy law, but you remain accountable for information you transfer, you must be satisfied that it receives comparable protection, and in Quebec you must complete a privacy impact assessment before the transfer. Alberta requires you to notify individuals when a service provider outside Canada is used.
We will give you the information you need for your assessment. Contact hello@mybirthbridge.com.
We do not currently offer Canadian data residency. If that changes we will update this page.
6.5 Breach notification in Canada
If a breach of security safeguards affects information we hold, we will:
- Notify any affected custodian or trustee at the first reasonable opportunity, so they can meet their own notification obligations to individuals and to their Commissioner.
- Notify affected individuals and the Office of the Privacy Commissioner of Canada where there is a real risk of significant harm, and notify the Commission d'acces a l'information for Quebec residents.
- Keep a record of every breach for at least 24 months, whether or not it was reportable.
Custodians should be aware that under Alberta's Health Information Act and Ontario's PHIPA there are separate obligations to notify the Commissioner, and in Alberta the Minister, which are yours rather than ours.
6.6 Record retention
Regulated health professionals have record retention periods set by their regulator, often ten years or longer. BirthBridge's retention schedule is not designed to satisfy your professional record retention obligations. Do not rely on platform messages as your clinical record. Keep your records in a system you control.
7. Safeguards
We protect information about health with:
- Encryption. Messages encrypted at rest with per-user key pairs. TLS in transit.
- Access control. Role-based access, limited to staff who need it, reviewed periodically.
- Logging. Access to production systems and to personal information is logged.
- Vendor management. Contracts with the service providers we rely on, including Business Associate Agreements where protected health information is involved.
- Workforce training. Staff who handle personal information are trained on the handling of health information.
- Incident response. A documented process for detecting, investigating, containing, and reporting incidents.
What we do not claim. No system is completely secure. We do not offer end-to-end encryption. Using BirthBridge does not, by itself, make you compliant with HIPAA, PHIPA, HIA, Law 25, or any other law. You are responsible for your own compliance. See Section 4.
Report a security issue to hello@mybirthbridge.com.
8. Changes
We will post updates here with a new "Last Updated" date. For changes that materially affect how we handle information about health, we will notify users directly before the change takes effect, and where consent is required for the change, we will ask for it.
9. Contact
BirthBridge, LLC
Texas, United States
For any question about this policy, about health information we hold, or to report a security issue, contact hello@mybirthbridge.com.
Related documents