kerbsidehealth
Directory
InsightsAbout
For Providers
Directory

Privacy Policy

Effective Date: May 29, 2026

Last Updated: May 29, 2026

Kerbside Health, Inc. ("Kerbside Health," "we," "our," or "us") operates a public health library, a provider directory, and provider-facing workflow automation services, including digital agents that help healthcare organizations handle administrative workflows such as prior authorization. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our websites, directory, and provider services (collectively, the "Services").


Medical Disclaimer

Kerbside Health does not provide medical care to patients. Our health library content, calculators, and directory information are provided for general informational purposes and are not medical advice. Always seek the advice of a qualified clinician with any questions you may have.


Information We Collect

A) Information you provide to us

  • Account and onboarding information: name, email, role, practice or organization details, and other information you submit when you create an account, request a pilot, contact us, or use provider-facing Services.
  • Verification information: organization information, employment or role confirmation, professional or employer-associated email address, and similar information used to confirm authorized access and prevent misuse.
  • Workflow configuration: EHR names, payor lists, practice preferences, routing rules, templates, escalation instructions, and other information you provide to configure a digital agent for your organization.
  • Support & feedback: content you send to us, such as messages, correction requests, support inquiries, and feedback.

B) Provider workflow data

When a healthcare organization uses provider-facing workflow automation services, we may collect and process information needed to provide those Services. This may include patient identifiers, demographics, insurance information, clinical documentation needed for administrative workflows, orders, diagnoses, procedure information, prior authorization requests, status updates, payor responses, case notes, audit logs, and related operational data.

We may also process system access information, such as account identifiers, connection metadata, API keys, tokens, credentials, and configuration details for EHRs, payor portals, clearinghouses, fax or intake tools, referral systems, and other systems approved by the healthcare organization.

C) Information we collect automatically

  • Device & usage data: IP address, browser type, device identifiers, approximate location derived from IP address, referring pages, pages visited, page titles, and interactions with our Services.
  • Cookies & similar technologies: used for security, analytics, attribution, advertising on the public website, remembering preferences, and improving performance.
  • Service logs: technical logs, security events, access logs, error reports, workflow status events, and audit records used to operate and secure the Services.
  • Public-site searches and interactions: directory searches, filters, clicks, scroll events, support-widget activity, and similar interactions. Search terms entered on a public health website may reveal health interests even when we do not know your name.

D) Directory data from public sources

We compile and display provider profile information from publicly available sources, such as the NPPES NPI Registry and provider, practice, hospital, or institutional websites. This may include a provider's professional name, specialty/subspecialty, education/training history, publications, awards, practice location(s), and headshots or other profile imagery when available.

Providers may request corrections to inaccurate information by contacting us.

E) Calculator inputs

Our risk/suitability calculators run in your browser. We do not intentionally collect or store your calculator selections on our servers as part of the calculator experience.


How We Use Information

  • To operate, maintain, secure, and improve the Services.
  • To configure, provision, operate, monitor, and support provider-facing workflow automation services and digital-agent accounts.
  • To access and interact with EHRs, payor portals, clearinghouses, fax or intake tools, referral systems, and other systems approved by a healthcare organization.
  • To prepare, route, submit, track, write back, or escalate administrative workflow tasks as instructed by the healthcare organization.
  • To verify account authority, prevent fraud, and protect Service integrity.
  • To respond to support requests, correction requests, and other inquiries.
  • To process billing for paid Services. Payments are handled by third-party payment processors; we do not store full payment card numbers.
  • To monitor and analyze usage, performance, security, and effectiveness of our Services.
  • To comply with legal obligations and enforce our terms.

Protected Health Information

When we process Protected Health Information for a covered entity or business associate, we do so as a business associate under a Business Associate Agreement or other required written arrangement. In that context, we use and disclose Protected Health Information only as permitted by that agreement, by the customer's instructions, and by applicable law.

The public health library, calculators, and directory are not a patient portal and are not intended for patients to submit medical records or other Protected Health Information. Do not submit Protected Health Information through public website forms unless we specifically provide an approved workflow for that purpose.

Logged-in provider-facing workflow areas may include Protected Health Information or customer workflow data. We do not use Google AdSense, Google Analytics, or third-party advertising pixels in those authenticated workflow areas. We may use operational, security, audit, and performance logs, and BAA-covered or customer-approved service providers, to provide and protect the Services.


How We Share Information

  • Service providers and subprocessors: vendors who help us run the Services, such as hosting, security, logging, support, communications, analytics, billing, and workflow infrastructure providers. They may access information only to perform services for us and must protect it.
  • Customer-directed workflow connections: when a healthcare organization enables provider-facing workflow automation, we may share or transmit information to approved EHRs, payors, payor portals, clearinghouses, fax services, referral sources, and other systems as needed to provide the Services.
  • Legal & safety: we may disclose information to comply with law, respond to lawful requests, protect rights/safety, or investigate misuse.
  • Business transfers: if we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to applicable contractual and legal restrictions.

Advertising & Analytics

We use analytics and advertising services such as Google Analytics and Google AdSense to understand usage and help fund the public website. These partners may use cookies or similar technologies to collect information about your activity on our public Services and across other sites/apps over time.

Public pages may include condition, treatment, directory, and search content that can suggest health interests. We configure analytics to avoid sending raw public search terms to Google Analytics, and we do not intentionally send names, emails, medical record numbers, insurance or member IDs, or other directly identifying health information to advertising or analytics providers.

We do not use Protected Health Information processed through provider-facing workflow automation services for targeted advertising, and we do not use third-party advertising trackers in authenticated provider workflow areas.

Your choices: you can control cookies through your browser settings, use the Privacy choices link in our footer to manage optional analytics and advertising on the public site, and use platform or industry tools where available to limit personalized advertising. Where required by applicable law, we honor Global Privacy Control (GPC) signals as an opt-out of certain targeted advertising uses.


Your Privacy Rights

Depending on where you live and how you use the Services, you may have rights under state privacy laws to request access to, correction of, or deletion of personal information; to receive a copy of certain personal information in a portable format; to opt out of sale, sharing, targeted advertising, or certain profiling; to limit certain uses of sensitive personal information; and to appeal a decision we make about your request.

To exercise privacy rights, contact [email protected]. We may need to verify your request before acting on it. You may use an authorized agent where permitted by law, and we will not discriminate against you for exercising privacy rights.

Some information is handled for healthcare organizations under a Business Associate Agreement or other service agreement. For that information, we may refer your request to the relevant healthcare organization or follow that organization's instructions, as required by law and contract.


Directory Corrections & Image Requests

If you are a provider or authorized representative and you believe a profile is inaccurate, you can request corrections by contacting [email protected]. We may require verification before making certain changes.

If you believe an image displayed on a profile infringes your copyright or you have a legal basis for removal, please contact [email protected] with the profile URL(s) and a description of your request. We review and respond to valid legal requests.


Data Retention

We retain information for as long as reasonably necessary to operate the Services, comply with legal obligations, resolve disputes, maintain security, and support authorized customer workflows. Provider workflow data and Protected Health Information are retained according to the applicable service agreement, Business Associate Agreement, customer instructions, and legal requirements.


Security

We use reasonable administrative, technical, and organizational safeguards designed to protect information, including access controls, logging, encryption where appropriate, and procedures for handling sensitive workflow data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.


Children's Privacy

The Services are not intended for children, and we do not knowingly collect personal information from children under 13.


Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will post the updated policy here with a new effective date.


Contact Us

If you have questions about this Privacy Policy, contact us at [email protected].

Kerbside Health, Inc.

kerbsidehealth

Democratizing access to expert eye care.

Explore

Find a ProviderHealth LibraryInsights

Company

Provider WebsitesAbout Us

Legal

Privacy PolicyTerms & Conditions

© 2026 Kerbside Health. All rights reserved.

•

Based in San Francisco, CA

FacebookXLinkedIn