Who we are
Atticus Health, Inc. ("Atticus", "we", "us") is a care-management company. We furnish care coordination and care management directly to the people enrolled in our programs, which makes Atticus a HIPAA covered health care provider. The full legal notice of how we use and disclose health information, and your rights over it, is our Notice of Privacy Practices.
This policy covers two things: this website (atticushealth.com) and the Atticus app that members use. If you use the app, the in-app terms and consents you accept there also apply.
Information we collect
On this website
- Contact information you choose to send us — for example, your name, email, and organization when you email us or request a demo.
- Basic analytics — anonymous, aggregate information about how the site is used, so we can make it better. We do not build advertising profiles.
In the Atticus app (members)
- Health information — your records, medications, lab results, hospital events, and the care activity we manage for you. This is protected as PHI under HIPAA and used as described in our Notice of Privacy Practices.
- Account information — your phone number and the profile details you add, used to sign you in and keep your account yours.
How we use it
We use your information for one purpose: to provide care management — spotting things that need attention, coordinating your care, and keeping you and your care team informed.
We never sell your information. We never use it for advertising. Not yours, not anyone's, not in aggregate, not "anonymized." It isn't our business model and it never will be.
PHI & HIPAA
Atticus is a HIPAA covered health care provider. Your HIPAA rights — to see your records, get copies, request corrections, and ask who has accessed them — are exercised directly with us. See our Notice of Privacy Practices for the full description of your rights and how to use them.
Not sure how to make a request? Email hello@atticushealth.com and we'll walk you through it.
Sharing
We share health information only in these cases:
- Your care team — the clinicians and care managers involved in your care, so they can act on what we find.
- Your family circle — only the people you invite, and only what you choose to share with each of them. You control this in the app and can change it at any time.
- Subprocessors — a small number of service providers (like our cloud host) that help us run the service. Every one that touches PHI operates under a BAA and the same safeguards we hold ourselves to.
- When the law requires it — and only to the extent it requires.
We never sell your information, and we never share it for anyone's marketing. No mobile information is shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent are not shared with any third party. The only providers who see a phone number are the carriers and messaging vendors that deliver the message itself, and they may not use it for anything else.
Text messages
If you turn on Atticus by Text, we use your mobile number to send and receive text messages with you, and we keep the conversation as part of your health record so your care team can see it.
Turning it on is a separate, explicit choice you make inside the app — it is never on by default and is never bundled into signing up. Allowing health details in a text is a second, separate choice, also off by default, because a text can be read by anyone holding your phone.
You can turn it off at any time by replying STOP to any message, or in the app under Settings. Reply HELP for help. Message and data rates may apply, and message frequency varies with your care.
Retention & deletion
We keep health information for as long as healthcare law requires and as needed to provide your care. If your enrollment with Atticus ends, you may request a complete export of your records; audit records are retained as long as healthcare law requires.
Security
Everything we hold is encrypted at rest and in transit, isolated in an encrypted clinical store, and covered by a tamper-evident audit trail that is verified daily. The full picture is on our security page.
Children
This website is not directed at children, and we do not knowingly collect information from children through it. Where a health plan enrolls a minor in care management, that happens under the plan's authorization and a parent or guardian's consent, not through this site.
Changes
If we change this policy, we'll update this page and the date at the top. Material changes to our Notice of Privacy Practices are posted on that page directly, with an updated effective date.
Contact
Questions about privacy? Email hello@atticushealth.com. A person reads it.