Consumer Health Data Privacy Policy
Last updated: September 4. 2025
This notice supplements our Privacy Policy by explaining the additional rights provided to residents under applicable state law and how to exercise those rights, subject to exceptions. It applies to personal data defined as “consumer health data” subject to the Washington State My Health My Data Act (MHMDA). For example, the Consumer State Privacy Notice does not apply to protected health information (PHI) subject to the Health Insurance Portability and Accountability Act of 1996 (HIPAA) or to certain data that we process as HIPAA-covered entities and business associates. Please refer to the Notice of Privacy Practices which governs this data.
Consumer Health Data We Collect
As described in the Privacy Policy, the data we collect depends on the context of your interactions with us and the choices you make (including your privacy settings), the Services and features you use, your location, and applicable law.
Examples of consumer health data may include:
- Information about your health-related conditions, symptoms, status, diagnoses, testing, or treatments (including surgeries, procedures, medications, or other interventions). For example, we may collect such information through surveys or other communication with you for research studies and improving product accessibility.
- Measurements of bodily functions, vital signs, or characteristics, including photographs.
- Information that could identify your attempt to seek health care services or information, including services that allow you to assess, measure, improve, or learn about your or another person’s health.
- Other information that may be used to infer or derive data related to the above or other health information.
Sources of Consumer Health Data
As described further in our Privacy Policy, we collect personal data (which may include consumer health data) directly from you, from your interactions with our Services, from third parties, and from publicly available sources.
Why We Collect and Use Consumer Health Data
We collect and use consumer health data for the purposes described in our Privacy Policy. Primarily, we collect and use consumer health data as reasonably necessary to provide you with the Services you have requested or authorized. This may include delivering and operating the Services and their features, personalization of certain Service features, ensuring the secure and reliable operation of the Services and the systems that support them, troubleshooting and improving the Services, and other essential business operations that support the provision of the
Services (such as analyzing our performance, meeting our legal obligations, developing our workforce, and conducting research and development).
We may use consumer health data for other purposes for which we give you choices and/or obtain your consent as required by law – for example, for advertising or marketing purposes. See our Privacy Policy and the How to Exercise Your Rights section below for more details on the
controls and choices you may have.
As described in our Privacy Policy, we may create aggregate/de-identified data from the information we collect through the Services and our disclosure of such aggregate/de-identified data is at our discretion.
Our Sharing of Consumer Health Data
We may share each of the categories of consumer health data described above for the purposes described in our Privacy Policy. In particular, we may share personal data, including consumer health data, with your consent or as reasonably necessary to complete any transaction or provide
any Service you have requested or authorized, as described above.
We share your data with third parties when you tell us to do so. If you make a purchase, we will share information about the transaction as necessary to process the payment, including protection against fraud. And we may disclose data when we believe that doing so is necessary to comply with applicable law or respond to valid legal process.
Third Parties with which We Share Consumer Health Data
As necessary for the purposes described above, we share consumer health data with the following categories of third parties:
- Service providers. Vendors or agents (“processors”) working on our behalf may access consumer health data for the purposes described above. For example, companies we’ve hired to provide customer service support or assist in protecting and securing our systems and services may need access to data to provide those functions. We may also share consumer health data with third-party service providers that assist with the Services, including for generating documentation and supporting certain workflows.
- Business partners. We may share consumer health data with other companies, for example, where you use a Service that is cobranded and jointly operated with another company, or where you use our services to interact with another company.
- Financial institutions & payment processors. When you make a purchase or enter into a financial transaction, we will disclose payment and transactional data to banks and other entities as necessary for payment processing, fraud prevention, credit risk reduction, analytics, or other related financial services.
- Parties to a corporate transaction. We may disclose consumer health data as part of a corporate transaction or proceeding such as a merger, financing, acquisition, bankruptcy, dissolution, or a transfer, divestiture, or sale of all or a portion of our business or assets.
- Affiliates. We enable access to data across our subsidiaries, affiliates, and related companies, for example, where we share common data systems or where access helps us to provide our Services and operate our business.
- Government agencies. We may disclose data to law enforcement or other government agencies when we believe doing so is necessary to comply with applicable law or respond to valid legal process.
- Other third parties. In certain circumstances, it may be necessary to provide data to other third parties, for example, to comply with the law or to protect our rights or those of our customers.
- Other users and individuals. If you use our Services to interact with other users of the Service or other recipients of communications, we will share data, including consumer health data, as directed by you and your interactions.
- The public. You may select options available through our Services to publicly display and disclose certain information, such as your profile, demographic data, content and files, or geolocation data, which may include consumer health data.
Your Consumer Rights
- The right of access. Upon verifying your identity, you have the right to confirm whether we are processing personal data and to access or obtain a copy of your personal data. This right does not require us to disclose any trade secrets.
- The right to data portability. When exercising the right of access, you have the right to obtain your personal data in a portable and, to the extent technically feasible, readily usable format that allows you to transmit the data to another entity without hindrance.
- The right of correction. You have the right to request that we correct inaccuracies in the personal data we collected and maintain about you, taking into account the nature of the data and the purposes for which it is processed. We may require documentation to verify the accuracy of requested corrections and may deny requests for certain reasons under state law. If denied, we will provide the reasons in our response.
- The right to request deletion. You have the right to request that we delete the personal data we have concerning you. Upon verifying your identity, we will delete (and direct our service providers to delete) your personal data, unless an exception applies. We may also have a reason under state laws to deny your deletion request, either in whole or in part. If so, we will explain the reason in our response.
- The right to opt-out. To the extent applicable, you have the right to opt-out of our processing of your personal data for the purposes of: (i) targeted advertising; (ii) the sale of your personal data; or (iii) profiling in furtherance of decisions that produce legal effects or similarly significant effects concerning consumers.
- The right not to receive discriminatory treatment. We will not discriminate against you, in violation of applicable state law, for exercising any of your consumer rights.
How to Exercise Your Rights
The MHMDA provides certain rights with respect to consumer health data, for example rights to access, delete, or withdraw consent relating to such data, subject to certain exceptions. Please refer to our Privacy Policy for more details on ways to request to exercise such rights, for example, through product controls. And if you want to access or control consumer health data processed by us that is not available via those tools or directly through the Services you use, you can always contact us at privacy@sollishealth.com.
If your request to exercise a right under the MHMDA is denied, you may appeal that decision by contacting our Privacy Officer at privacy@sollishealth.com. If your appeal is unsuccessful, you can raise a concern or lodge a complaint with the Washington State Attorney General at https://www.atg.wa.gov/file-complaint.