Who we are
Atticus Health, Inc. ("Atticus", "we", "us") is a care-management company. We work for health plans, ACOs, and providers as a HIPAA Business Associate — which means we handle health information on their behalf, under a signed Business Associate Agreement (BAA), and only for the purposes that agreement allows.
This policy covers two things: this website (atticushealth.com) and the Atticus app that members use. If you use the app, the in-app terms and consents you accept there also apply.
Information we collect
On this website
- Contact information you choose to send us — for example, your name, email, and organization when you email us or request a demo.
- Basic analytics — anonymous, aggregate information about how the site is used, so we can make it better. We do not build advertising profiles.
In the Atticus app (members)
- Health information — your records, medications, lab results, hospital events, and the care activity we manage for you. This is processed under your health plan's authorization and our BAA with them, and protected as PHI under HIPAA.
- Account information — your phone number and the profile details you add, used to sign you in and keep your account yours.
How we use it
We use your information for one purpose: to provide care management — spotting things that need attention, coordinating your care, and keeping you and your care team informed.
We never sell your information. We never use it for advertising. Not yours, not anyone's, not in aggregate, not "anonymized." It isn't our business model and it never will be.
PHI & HIPAA
Because we work as a Business Associate, your HIPAA rights — to see your records, get copies, request corrections, and ask who has accessed them — flow through your health plan, which is the covered entity. If you send a HIPAA individual-rights request to your plan, we honor it: we locate, produce, correct, or account for the information we hold, as the law and our BAA require.
Not sure who to contact? Email privacy@atticushealth.com and we'll point you to the right place — including your plan's privacy office if that's where your request needs to go.
Sharing
We share health information only in these cases:
- Your care team — the clinicians and care managers involved in your care, so they can act on what we find.
- Your family circle — only the people you invite, and only what you choose to share with each of them. You control this in the app and can change it at any time.
- Subprocessors — a small number of service providers (like our cloud host) that help us run the service. Every one that touches PHI operates under a BAA and the same safeguards we hold ourselves to.
- When the law requires it — and only to the extent it requires.
Retention & deletion
We keep information only as long as our agreement with your health plan requires. When an engagement ends, we deliver a complete export of everything we hold to the plan, then delete it on the schedule the BAA sets. Audit records are retained as long as healthcare law requires.
Security
Everything we hold is encrypted at rest and in transit, isolated in an encrypted clinical store, and covered by a tamper-evident audit trail that is verified daily. The full picture is on our security page.
Children
This website is not directed at children, and we do not knowingly collect information from children through it. Where a health plan enrolls a minor in care management, that happens under the plan's authorization and a parent or guardian's consent, not through this site.
Changes
If we change this policy, we'll update this page and the date at the top. If a change meaningfully affects how member information is handled, we'll notify the health plans we work with directly.
Contact
Questions about privacy? Email privacy@atticushealth.com. A person reads it.