
Leader Health is a healthtech platform operated by LH Ventures LLC as the technology and administrative-services company. Clinical care is delivered by independent licensed clinicians who practice through an Affiliated Provider Network under contract with us; those clinicians exercise their own independent clinical judgment under the Affiliated Provider Network's own clinical governance. The Affiliated Provider Network is the HIPAA Covered Entity for your medical record (the "Covered Entity" is the entity legally responsible under HIPAA for your medical records); Leader Health is its Business Associate (a "Business Associate" is a vendor that handles that data on the Covered Entity's behalf under a written agreement). Medical oversight of the platform program (a non-treatment, program-level function) is provided to Leader Health by a contracted physician entity (Ratcliff Health PLLC); to the extent that entity accesses PHI, it does so under the appropriate HIPAA arrangement. We do not sell your Protected Health Information, and we do not use your PHI for cross-context behavioral advertising. We are implementing support for Global Privacy Control (GPC) opt-out preference signals. Your state-law rights are listed below. Questions: privacy@myleaderhealth.com.
"Leader Health," "we," "our," or "us" means Leader Health, a brand of LH Ventures LLC, a Delaware limited liability company foreign-qualified in Texas, together with its affiliates. Leader Health is a technology and administrative-services company. Leader Health does not practice medicine.
Clinical services accessed through myleaderhealth.com (the "Site" or "Platform") are provided by independent licensed clinicians (the "Providers") who practice through one or more independently owned and operated professional medical entities under contract with Leader Health (each, an "Affiliated Provider Network"). The Affiliated Provider Network providing care to you, and the identity and licensure of the clinician treating you, are disclosed to you in your patient dashboard and at the visit; the current Network and the covered entity issuing the HIPAA Notice for your record are identified at registration and in the dashboard. Leader Health is the trade name used by LH Ventures LLC, a Delaware limited liability company foreign-qualified in Texas; LH Ventures LLC operates the Platform as the MSO and technology / administrative-services company. The "Leader Health" name and marks are owned by Leader Health LLC and used by LH Ventures LLC under license; LH Ventures LLC has no other connection to Leader Health LLC's businesses and does not operate any in-person clinic. Leader Health may, on notice to patients, add to, expand, or substitute the Affiliated Provider Network without revising this Policy.
Pharmacy services are provided by independently owned and operated licensed pharmacies (the "Pharmacies"). Laboratory services are provided by independent reference laboratories (the "Labs").
This Policy applies to information Leader Health collects in its role as a technology and administrative-services company. Protected Health Information (PHI) created and held by the Affiliated Provider Network is governed by the HIPAA Notice of Privacy Practices, which controls in case of conflict with respect to PHI. Leader Health acts as the Affiliated Provider Network's HIPAA Business Associate under a written Business Associate Agreement.
If you do not agree with this Policy, please do not use the Site or the Platform.
a. Information you provide.
Account information (name, email, password, phone, date of birth, address).
Intake and health-history information (symptoms, conditions, medications, allergies, lifestyle, photos when you choose to upload them).
Identity verification documents where required by law (government ID for controlled substances or age-restricted therapies).
Payment information processed through our payment processor; we do not store full card numbers on our servers.
Communications with our support team or the Affiliated Provider Network (messages, voicemails, recorded video consults).
b. Information generated by your use of the Site or Platform.
Device and connection data (IP address, browser type, operating system, device identifiers).
Usage data (pages viewed, links clicked, time on page, referring URL).
Cookies and similar technologies — see Cookies & Tracking Technologies.
c. Information we receive from third parties.
Lab results from the Labs.
Prescription, dispensing, and shipping data from the Pharmacies.
Clinical notes and prescriptions from the Affiliated Provider Network and its Providers.
Address verification, fraud-prevention, and identity-verification data from service providers.
If you connect a wearable, EHR, or health-record service, the data you authorize that service to share.
d. Sensitive information.
Some information we collect is sensitive — health information, government ID, and precise location if you enable it. We use sensitive information only to deliver care, verify identity, prevent fraud, and comply with law.
California Notice at Collection (Cal. Civ. Code §1798.100(a)). At or before the point of collection, Leader Health notifies California residents of the following:
| Category of personal information collected | Purpose | Sold or shared? | Retention period |
|---|---|---|---|
| Identifiers (name, email, address, phone, DOB) | Account creation; communication; identity verification; coordinate care | No | While account active + 7 years after closure |
| Health information (intake, conditions, medications, allergies, photos when uploaded) | Coordinate clinical care; deliver Service | No | Per the Affiliated Provider Network's medical-record retention applicable to the state in which care was provided (minimum periods vary by state — for example, 7 years for adults under Texas law and longer for minors and in some other states; the longer of the applicable state minimum and any federal minimum applies) |
| Internet/network activity (cookies, device, IP, browsing) | Operate the Site; security; analytics | No (except essential and analytics cookies as disclosed in Cookies & Tracking) | Up to 13 months |
| Geolocation (approximate, from IP) | Determine state availability and route care | No | Up to 13 months |
| Inferences | Personalize the Site and Service | No | Up to 24 months |
| Sensitive personal information (HIPAA-protected health information, government identifiers if you choose to upload them) | Coordinate clinical care; identity verification | No | Per medical-record retention rules above |
Leader Health does not sell personal information and does not use or disclose sensitive personal information for purposes other than those listed in Cal. Civ. Code §1798.121(a). California residents can exercise their rights at privacy@myleaderhealth.com or via the Do Not Sell or Share My Personal Information page.
We use personal information to:
Create and administer your account.
Coordinate your care with the Affiliated Provider Network, Pharmacies, and Labs (PHI is governed by the HIPAA Notice).
Process payments, billing, refunds, and reimbursements.
Communicate with you — appointment reminders, lab and shipping updates, service announcements, and, if you opt in, marketing.
Operate, maintain, secure, and improve the Site and Platform.
Detect and prevent fraud, abuse, and security incidents.
Comply with legal obligations and respond to lawful requests.
Establish, exercise, or defend legal claims.
We do not use AI or automated decision-making to make material clinical decisions about your care. Providers make all prescribing decisions.
We use personal information to:
With the Affiliated Provider Network, Pharmacies, and Labs as needed to deliver your care. The Affiliated Provider Network is the HIPAA Covered Entity; Leader Health acts as its Business Associate for PHI under a written Business Associate Agreement.
With service providers that operate our infrastructure, payment processing, identity verification, customer support, analytics, and communications, under contracts that require confidentiality and limit use to the services they provide to us.
With professional advisors (auditors, lawyers, accountants) under confidentiality.
In a corporate transaction (merger, acquisition, financing, reorganization, asset sale, bankruptcy) — only to the extent permitted by law and subject to applicable safeguards for health information.
For legal and safety reasons — to comply with law, lawful process, or government request; to enforce our Terms; to protect Leader Health, our patients, or the public; and to respond to emergencies involving risk to life or health.
With your direction or consent — for example, when you ask us to share your lab results with your primary care physician.
We do not sell your Protected Health Information, and we do not share your PHI for cross-context behavioral advertising. Where Site analytics or advertising tags collect limited non-PHI information on non-PHI pages (such as IP and pageview data), you can manage that through the controls in Cookies & Tracking Technologies and our Do Not Sell or Share My Personal Information page.
This matrix summarizes the categories of personal information Leader Health may disclose to categories of service providers and third parties to operate the Site and deliver the Service. PHI shared with the Affiliated Provider Network, Pharmacies, and Labs to deliver clinical care is governed by HIPAA and the BAA framework described above, not by this matrix.
| Personal information category | Categories of service providers | Categories of third parties |
|---|---|---|
| Personal identifiers (name, email, postal, phone) | IT infrastructure, customer-support tools, fraud-prevention, identity verification | None |
| Internet activity (cookies, pageviews) on non-PHI pages | Analytics providers, sales & marketing tools | Ad networks (only with consent) |
| Commercial information (purchases) | IT infrastructure, payment processors, sales & marketing tools | None for PHI; ad networks (non-PHI only, with consent) |
| Financial information (card data — tokenized) | Payment processors | None |
| Health data and PHI | Affiliated Provider Network, Pharmacies, Labs, technology vendors under BAA | None |
| Consumer communications (support messages) | Customer-support tools, governance/risk/compliance software | None |
| Government-ID and identity-verification data | Identity-verification providers, fraud-prevention | None |
We do not retain personal information longer than necessary for the purposes described in this Policy. We retain data as follows.
| Type of data | Retention period |
|---|---|
| Cookies and online data collected through Site use (online identifiers, internet activity) | Deleted or anonymized within 18 months of collection |
| Order, prescription, and shipping data necessary to fulfill the Service (name, address, phone, government ID where required, purchases, payment tokens) | For as long as needed to fulfill the contract and for 15 years after your last interaction with the Service, except where federal or state law (medical or pharmacy records) requires longer |
| Customer-support communications | Up to 7 years from last contact, in case of dispute or complaint |
| Marketing preferences and opt-ins | Until you opt out or request deletion; a suppression record is retained indefinitely to prevent future contact |
| Reviews, surveys, and product feedback (including any sensitive content you submit) | De-identified within 24 months of submission and retained in aggregated, non-identifiable form for product, clinical-quality, and service-improvement analysis. Identifiable reviews used with attribution on the Site are retained while displayed and for 24 months after removal. |
| Privacy-rights requests and verification records | As long as necessary to comply with applicable law |
| Security and audit logs | As long as necessary to comply with applicable law and to maintain information security |
| HIPAA-governed records (PHI, BAA records, breach records) | For the period required by federal and state law (generally at least 6 years from creation or last effective date for HIPAA records; longer where state medical or pharmacy record-retention rules require) |
We may de-identify your information, including your PHI, and use such de-identified information for any business or other purpose not prohibited by applicable law, including operational and research purposes. We will not attempt to re-identify information that has been de-identified under HIPAA standards, except to determine whether our de-identification processes meet applicable legal standards.
Universal choices.
Update your account information in your dashboard.
Opt out of marketing emails by clicking "unsubscribe"; transactional and care-related messages will continue.
Request a copy of your medical record from the Affiliated Provider Network via the dashboard or by contacting records@myleaderhealth.com.
b. State privacy rights. Depending on your state of residence (including California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and others), you may have rights to:
Know / Access the personal information we hold about you.
Correct inaccurate personal information.
Delete personal information, subject to exceptions (for example, where we are legally required to retain medical or pharmacy records).
Portability — receive a copy in a portable format.
Opt out of sale, sharing, or targeted advertising — see Do Not Sell or Share My Personal Information.
Limit use of sensitive personal information.
Non-discrimination for exercising your rights.
To exercise a right, email privacy@myleaderhealth.com or submit a request through the dashboard. We will verify your identity before responding. We respond within the time required by your state's law (generally 45 days, extendable once when necessary). You may designate an authorized agent. If we deny a request, you may appeal by emailing privacy@myleaderhealth.com with "Appeal" in the subject line.
c. California "shine the light" notice.
If you are a California resident with an established business relationship with us, you may request once per calendar year a notice disclosing the categories of personal information we shared with third parties for the third parties' direct marketing purposes during the preceding calendar year. Email privacy@myleaderhealth.com with "Shine the Light" in the subject line. Allow 30 days for a response.
d. HIPAA rights.
Rights with respect to PHI held by the Affiliated Provider Network are described in the HIPAA Notice of Privacy Practices.
Data Security
We use administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, and destruction. These include encryption in transit and at rest, access controls on a need-to-know basis, logging and monitoring, vendor due diligence, and incident-response procedures. No system is perfectly secure; we cannot guarantee that information will never be accessed, disclosed, altered, or destroyed by a security breach
SMS and data-no-sale
Customer information collected as part of any SMS or text-messaging program will not be shared or sold to third parties for any purpose related to any SMS program. This sentence is included to satisfy carrier and CTIA short-code-registry requirements.
Children's privacy
Leader Health is intended for adults aged 18 or older. We do not knowingly collect personal information from children under 18. If we learn we have collected information from a person under 18, we will delete it. If you believe a minor has provided us with information, contact privacy@myleaderhealth.com. "Under 18" is the eligibility age for the Service; it is separate from the lower minor-protections age (under 16) used in certain state privacy laws — see the Do Not Sell or Share My Personal Information page.
International users
The Site and Platform are operated from, and intended for, users in the United States. If you access the Site from outside the United States, your information will be transferred to, processed, and stored in the United States, where data-protection laws may differ from those in your country.
10A. State consumer-health-data and comprehensive-privacy laws
Leader Health operates nationally and is subject to a growing set of U.S. state consumer-health-data laws and comprehensive consumer-privacy laws. We draft to the strictest-common-denominator of these laws and apply our consumer-health-data practices to residents of all states whose law currently provides heightened protections for consumer health data, and our state-privacy-rights practices to residents of all states with a comprehensive consumer-privacy law. The list of applicable states changes over time; this Policy is updated as new laws come into force, and the controlling list at any given moment is the list of state laws then in effect (not the named examples below).
Consumer-health-data laws — examples (non-exhaustive). These include the Washington My Health My Data Act (RCW ch. 19.373), Nevada SB370 (NRS 603A.400–603A.470), the Connecticut Data Privacy Act consumer-health-data provisions, and any equivalent or successor laws
Washington My Health My Data Act. Our practices for consumer health data collected from Washington consumers, and the specific rights of Washington consumers under the My Health My Data Act (RCW ch. 19.373), are described in our separate Consumer Health Data Privacy Policy, linked prominently in our site footer and in the patient dashboard. That policy controls with respect to consumer health data of Washington consumers.
Comprehensive consumer-privacy laws — examples (non-exhaustive). These include the California Consumer Privacy Act / CPRA, Virginia Consumer Data Protection Act (VCDPA), Colorado Privacy Act (CPA), Connecticut Data Privacy Act (CTDPA), Utah Consumer Privacy Act (UCPA), Iowa, Indiana, Tennessee, Montana, Oregon, Texas (TDPSA), Delaware, New Jersey, New Hampshire, Kentucky, Maryland, Minnesota, Rhode Island, and other states whose comprehensive consumer-privacy laws are then in effect.
Universal consumer-health-data practices. Regardless of which state's law applies to you:
No sale of consumer health data. We do not sell consumer health data.
No sharing of consumer health data for targeted advertising without your affirmative authorization.
No use of a geofence to identify or track individuals seeking health-care services.
Right to know, access, correct, delete, and port your personal information, to the extent provided by the law of your state.
Right to withdraw consent. You may withdraw any prior consent at any time.
Appeals. If we deny a request you submit under a state consumer-health-data or consumer-privacy law, you may appeal to privacy@myleaderhealth.com with the subject line "State Privacy Appeal." We will respond within the time required by your state's law.
When you exercise a state-law right, identify your state of residence so we can apply the correct framework. If you do not identify a state, we will apply the strictest framework available under the laws then in effect.
Changes to this Policy
We may update this Policy. If we make material changes, we will post the updated Policy with a new "Effective Date" and, where required, notify you by email or through the Platform. Your continued use of the Site or Platform after the Effective Date constitutes acceptance.
Contact
Privacy team: privacy@myleaderhealth.com Mailing address: Leader Health, c/o LH Ventures LLC, 321 S Persimmon St, Tomball, TX 77375


