Skip to content
HIPAA-Aligned Platform

Your Health Information, Protected at Every Step

Heyzl is built on a foundation of security and compliance. We meet and exceed HIPAA requirements to ensure your sensitive health information remains private, secure, and under your control—no matter where in the world you receive care.

HIPAA-Aligned
SOC 2 (In Progress)
256-bit SSL
GDPR-Aligned
ISO 27001 (In Progress)

Understanding HIPAA and Why It Matters

What is HIPAA?

The Health Insurance Portability and Accountability Act (HIPAA) is a United States federal law enacted in 1996 that establishes national standards for protecting sensitive patient health information. HIPAA requires healthcare organizations and their business partners to implement comprehensive safeguards to ensure the confidentiality, integrity, and availability of Protected Health Information (PHI).

What is Protected Health Information?

PHI includes any information that can identify an individual and relates to their health:

  • Identifiers: Name, address, date of birth, email, phone
  • Medical: Diagnoses, treatments, test results, medications
  • Financial: Insurance details, payment information
  • Communications: Messages with providers, appointment history

Why HIPAA Matters for Medical Tourism

When seeking healthcare abroad, your medical information crosses borders. Heyzl ensures that regardless of where your care takes place, your data receives the same rigorous protection required by U.S. law. We've implemented a global compliance framework that meets or exceeds HIPAA standards in every country where we operate.

Our Privacy Promise to You

Six foundational pillars that guide how we protect your health information.

Minimal Data Collection

We Only Collect What's Necessary

We follow the principle of data minimization. We only collect the health information necessary to connect you with appropriate providers and facilitate your care. We never sell your data to third parties, and we never use your health information for advertising purposes.

Explicit Consent

You Control Your Information

We never share your medical information without your explicit, informed consent. Before any data is shared with a provider, you'll know exactly what information is being shared, with whom, and for what purpose. You can revoke consent at any time.

Secure Transmission

Military-Grade Encryption

All data transmitted through our platform is protected with 256-bit AES encryption—the same standard used by banks and government agencies. Your information is encrypted in transit and at rest, making it unreadable to anyone without authorization.

Limited Access

Need-to-Know Basis Only

Access to your health information is strictly limited to those who need it to provide your care. Our staff undergoes background checks and HIPAA training. Every access to patient data is logged and auditable.

Secure Infrastructure

Enterprise-Grade Protection

Our systems are hosted on SOC 2 Type II certified infrastructure with 24/7 monitoring, intrusion detection, and automatic threat response. We undergo regular third-party security audits and penetration testing.

Your Rights Respected

Full Data Control

You have the right to access, correct, or delete your health information at any time. You can request a complete copy of your data or ask us to permanently remove it from our systems. We make exercising these rights simple and straightforward.

How We Protect Your Data: Technical Safeguards

Enterprise-grade security measures protecting your information at every layer.

In Transit

  • TLS 1.3 encryption for all data transmission
  • Perfect Forward Secrecy (PFS) enabled
  • HSTS (HTTP Strict Transport Security) enforced
  • Certificate pinning for mobile applications

At Rest

  • AES-256 encryption for all stored data
  • Encrypted database fields for PHI
  • Encrypted file storage for medical documents
  • Hardware Security Modules (HSMs) for key management

End-to-End

  • Video consultations use end-to-end encryption
  • Direct messaging between patients and providers is encrypted
  • Medical documents shared through secure, encrypted channels

Your Health Information Rights

As a Heyzl user, you have specific rights regarding your health information under HIPAA.

Protecting Your Data Across Borders

Medical tourism inherently involves sharing health information internationally. Here's how we handle this.

When You Share Information with International Providers:

1

Informed Consent

Before any international data transfer, you explicitly authorize the sharing and understand what will be shared.

2

Data Minimization

Only the information necessary for your care is shared with international providers.

3

Contractual Protections

International providers sign agreements requiring them to protect your information according to standards equivalent to HIPAA.

4

Secure Transmission

All international data transfers use encrypted channels.

5

Audit Trail

Every international disclosure is logged in your account.

GDPR Compliance

For users in the European Union, we also comply with GDPR, providing additional protections including right to erasure, data portability, and 72-hour breach notification.

Country-Specific Compliance

We verify that providers in Thailand, Mexico, India, Costa Rica, and all other destinations meet our security and privacy standards before joining our network.

How We Ensure Provider Compliance

Every healthcare provider on Heyzl must meet our rigorous data security requirements.

Gold Standard

  • JCI or equivalent international accreditation
  • ISO 27001 certified
  • Demonstrated HIPAA-equivalent practices
  • Regular third-party security audits

Verified Secure

  • National accreditation
  • Documented security policies
  • Completed security assessment
  • Staff training confirmed

Meets Requirements

  • Basic security requirements met
  • Data protection agreement signed
  • Security questionnaire completed
  • Ongoing monitoring

Provider security tier is displayed on their profile so you can make informed decisions.

Common Questions About Privacy & Security

Find answers to frequently asked questions about how we protect your data.

Contact Our Privacy Team

Privacy Officer Contact

For questions about your privacy, to exercise your rights, or to report concerns:

Contact privacy teamRequest a callback
Response within 5 business days

Report a Security Concern

If you believe you've identified a security vulnerability or have witnessed a potential security incident:

Report security concern

We appreciate responsible disclosure and have a formal vulnerability disclosure program.

File a Complaint

If you believe your privacy rights have been violated:

  1. Contact our Privacy Officer at privacy@heyzl.com
  2. If not resolved, file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights at www.hhs.gov/ocr

You will not face retaliation for filing a complaint.

Our Commitment to You

At Heyzl, protecting your privacy isn't just a legal obligation—it's a core value. Healthcare is deeply personal, and we understand the trust you place in us when you share your health information.

We've built our platform from the ground up with security and privacy as foundational principles, not afterthoughts. Every feature, every integration, and every process is evaluated through the lens of "how does this protect our patients?"

TransparencyControlSecurityAccountability

Your trust is earned, and we work every day to deserve it.

James Mitchell

Chief Privacy Officer, Heyzl

Last Updated: August 2026 • Policy Version: 2.0

HIPAA-Aligned
SOC 2 (In Progress)
256-bit SSL
GDPR-Aligned
ISO 27001 (In Progress)