Your Health Information, Protected at Every Step
Heyzl is built on a foundation of security and compliance. We meet and exceed HIPAA requirements to ensure your sensitive health information remains private, secure, and under your control—no matter where in the world you receive care.
Understanding HIPAA and Why It Matters
What is HIPAA?
The Health Insurance Portability and Accountability Act (HIPAA) is a United States federal law enacted in 1996 that establishes national standards for protecting sensitive patient health information. HIPAA requires healthcare organizations and their business partners to implement comprehensive safeguards to ensure the confidentiality, integrity, and availability of Protected Health Information (PHI).
What is Protected Health Information?
PHI includes any information that can identify an individual and relates to their health:
- Identifiers: Name, address, date of birth, email, phone
- Medical: Diagnoses, treatments, test results, medications
- Financial: Insurance details, payment information
- Communications: Messages with providers, appointment history
Why HIPAA Matters for Medical Tourism
When seeking healthcare abroad, your medical information crosses borders. Heyzl ensures that regardless of where your care takes place, your data receives the same rigorous protection required by U.S. law. We've implemented a global compliance framework that meets or exceeds HIPAA standards in every country where we operate.
Our Privacy Promise to You
Six foundational pillars that guide how we protect your health information.
Minimal Data Collection
We Only Collect What's Necessary
We follow the principle of data minimization. We only collect the health information necessary to connect you with appropriate providers and facilitate your care. We never sell your data to third parties, and we never use your health information for advertising purposes.
Explicit Consent
You Control Your Information
We never share your medical information without your explicit, informed consent. Before any data is shared with a provider, you'll know exactly what information is being shared, with whom, and for what purpose. You can revoke consent at any time.
Secure Transmission
Military-Grade Encryption
All data transmitted through our platform is protected with 256-bit AES encryption—the same standard used by banks and government agencies. Your information is encrypted in transit and at rest, making it unreadable to anyone without authorization.
Limited Access
Need-to-Know Basis Only
Access to your health information is strictly limited to those who need it to provide your care. Our staff undergoes background checks and HIPAA training. Every access to patient data is logged and auditable.
Secure Infrastructure
Enterprise-Grade Protection
Our systems are hosted on SOC 2 Type II certified infrastructure with 24/7 monitoring, intrusion detection, and automatic threat response. We undergo regular third-party security audits and penetration testing.
Your Rights Respected
Full Data Control
You have the right to access, correct, or delete your health information at any time. You can request a complete copy of your data or ask us to permanently remove it from our systems. We make exercising these rights simple and straightforward.
How We Protect Your Data: Technical Safeguards
Enterprise-grade security measures protecting your information at every layer.
In Transit
- TLS 1.3 encryption for all data transmission
- Perfect Forward Secrecy (PFS) enabled
- HSTS (HTTP Strict Transport Security) enforced
- Certificate pinning for mobile applications
At Rest
- AES-256 encryption for all stored data
- Encrypted database fields for PHI
- Encrypted file storage for medical documents
- Hardware Security Modules (HSMs) for key management
End-to-End
- Video consultations use end-to-end encryption
- Direct messaging between patients and providers is encrypted
- Medical documents shared through secure, encrypted channels
Your Health Information Rights
As a Heyzl user, you have specific rights regarding your health information under HIPAA.
Protecting Your Data Across Borders
Medical tourism inherently involves sharing health information internationally. Here's how we handle this.
When You Share Information with International Providers:
Informed Consent
Before any international data transfer, you explicitly authorize the sharing and understand what will be shared.
Data Minimization
Only the information necessary for your care is shared with international providers.
Contractual Protections
International providers sign agreements requiring them to protect your information according to standards equivalent to HIPAA.
Secure Transmission
All international data transfers use encrypted channels.
Audit Trail
Every international disclosure is logged in your account.
GDPR Compliance
For users in the European Union, we also comply with GDPR, providing additional protections including right to erasure, data portability, and 72-hour breach notification.
Country-Specific Compliance
We verify that providers in Thailand, Mexico, India, Costa Rica, and all other destinations meet our security and privacy standards before joining our network.
How We Ensure Provider Compliance
Every healthcare provider on Heyzl must meet our rigorous data security requirements.
Gold Standard
- JCI or equivalent international accreditation
- ISO 27001 certified
- Demonstrated HIPAA-equivalent practices
- Regular third-party security audits
Verified Secure
- National accreditation
- Documented security policies
- Completed security assessment
- Staff training confirmed
Meets Requirements
- Basic security requirements met
- Data protection agreement signed
- Security questionnaire completed
- Ongoing monitoring
Provider security tier is displayed on their profile so you can make informed decisions.
Common Questions About Privacy & Security
Find answers to frequently asked questions about how we protect your data.
Compliance Documentation & Resources
Download our compliance documents for your records.
Notice of Privacy Practices (NPP)
Full legal document describing privacy practices
Privacy Policy
Detailed privacy policy
Terms of Service
Complete terms governing platform use
Security Whitepaper
Technical deep-dive into security architecture
HIPAA Compliance Summary
One-page overview for quick reference
Patient Rights Summary
Easy-to-understand rights overview
Contact Our Privacy Team
Privacy Officer Contact
For questions about your privacy, to exercise your rights, or to report concerns:
Report a Security Concern
If you believe you've identified a security vulnerability or have witnessed a potential security incident:
We appreciate responsible disclosure and have a formal vulnerability disclosure program.
File a Complaint
If you believe your privacy rights have been violated:
- Contact our Privacy Officer at privacy@heyzl.com
- If not resolved, file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights at www.hhs.gov/ocr
You will not face retaliation for filing a complaint.
Our Commitment to You
At Heyzl, protecting your privacy isn't just a legal obligation—it's a core value. Healthcare is deeply personal, and we understand the trust you place in us when you share your health information.
We've built our platform from the ground up with security and privacy as foundational principles, not afterthoughts. Every feature, every integration, and every process is evaluated through the lens of "how does this protect our patients?"
Your trust is earned, and we work every day to deserve it.
James Mitchell
Chief Privacy Officer, Heyzl
Last Updated: August 2026 • Policy Version: 2.0