Privacy Policy
Effective Date: February 26, 2026
Sam Dot Company (“Eureka,” “Company,” “we,” “our,” or “us”) operates the website located at eureka.md, related web applications, portals, communications channels, telehealth-enablement tools, and related services (collectively, the “Service”). This Privacy Policy explains how we collect, use, disclose, store, and otherwise process information about individuals who visit, access, use, or interact with the Service.
Please read this Privacy Policy carefully. By accessing or using the Service, you acknowledge this Privacy Policy.
1. Important Relationship Disclosures
1.1 Eureka is a technology platform, not a healthcare provider
Eureka provides software, administrative, technical, operational, communications, marketplace, and related support tools. Eureka does not practice medicine or any other licensed profession, does not diagnose or treat, does not make clinical decisions, and does not control the practice of medicine. Medical services, if any, are furnished by independent licensed healthcare providers, practices, or professional entities (each, a “Provider”).
1.2 Provider-controlled medical records and Notices of Privacy Practices
When you receive care from a Provider through or in connection with the Service, the Provider—not Eureka—is responsible for your medical care, the provider-patient relationship, and the medical record, subject to applicable law. Your Provider’s Notice of Privacy Practices or other legally required patient privacy notice governs the Provider’s use and disclosure of Protected Health Information (“PHI”) for treatment, payment, and healthcare operations.
Eureka may process PHI on behalf of Providers as a service provider, contractor, processor, or business associate, as applicable. If you want to exercise rights relating to your medical record or PHI—such as access, copies, amendments, restrictions, accountings, confidential communications, or similar rights—you should contact your Provider directly. If you contact Eureka about Provider-controlled PHI, we may redirect or forward your request to the appropriate Provider.
1.3 Scope of this Privacy Policy
This Privacy Policy applies to information that Eureka collects or processes in connection with the Service, including information submitted directly by users, information we process on behalf of Providers, and information collected through the public-facing portions of the Service. This Privacy Policy does not replace any Provider’s Notice of Privacy Practices or other patient-facing clinical privacy notice.
1.4 Adults only
The Service is intended only for adults age 18 or older. Individuals under 18 are not permitted to access or use the Service. We do not knowingly permit minors to create accounts, submit information, schedule care, or use the Service. If we learn that a minor has used the Service, we may suspend or terminate access, delete or de-identify information as appropriate, and take any other action we deem necessary.
2. Information We Collect
The specific information we collect depends on how you use the Service, your role (for example, patient, prospective patient, caregiver, clinician, practice representative, or site visitor), applicable law, and the features you use.
2.1 Information you provide directly
We may collect information you provide directly to us or through the Service, including:
- Contact and account information, such as name, email address, phone number, postal address, account credentials, authentication information, and communication preferences.
- Identity and eligibility information, such as date of birth, sex or gender information, government identifier information, photographs, selfie images, insurance information, payment card information (generally via payment processors), and other information used to verify identity, eligibility, location, age, or authority.
- Health and care-related information, such as symptoms, medical history, medications, allergies, diagnoses, treatment history, pharmacy information, laboratory information, intake forms, questionnaires, encounter notes, photographs, audio, video, chat messages, and other information you or your Provider submit through the Service.
- Scheduling and logistics information, such as appointment requests, time zone, physical location at the time of care, availability, cancellations, and communications relating to scheduling, rescheduling, or follow-up.
- Payment and transaction information, such as billing contact information, receipts, transaction history, amounts paid, refunds, disputes, and payment status.
- Professional and business information from clinicians or practice representatives, such as licenses, credentials, specialty, practice details, tax information, payout information, insurance information, and onboarding or compliance documentation.
- Support and communications, such as emails, text messages, calls, voicemails, support tickets, survey responses, and other correspondence you send to us or through the Service.
- Content you upload, such as documents, forms, attachments, images, PDFs, consents, and other materials you submit.
- Feedback and product input, such as ideas, comments, suggestions, bug reports, feature requests, and user research responses.
2.2 Information collected automatically
We and our service providers may automatically collect certain information when you use the Service, including:
- Device and browser information, such as IP address, device identifiers, browser type, operating system, language settings, mobile carrier, and app or browser version.
- Usage and log information, such as pages viewed, clicks, navigation paths, session timestamps, referrers, crash reports, performance metrics, search queries, and interactions with features.
- Approximate location information, such as location inferred from IP address and, where enabled by your device or browser and permitted by law, more precise location information.
- Cookies and similar technologies data, including information collected through cookies, local storage, SDKs, pixels, tags, session replay tools, logs, and similar technologies for authentication, security, analytics, service functionality, fraud prevention, debugging, and improvement.
2.3 Information from third parties
We may receive information from third parties, including:
- Providers, practices, and affiliated clinical personnel;
- Laboratories, pharmacies, payment processors, communication providers, identity verification providers, fraud prevention vendors, insurers, and other operational partners;
- Referral sources, caregivers, family members, or authorized representatives acting on your behalf;
- Advertising, analytics, hosting, infrastructure, or support vendors;
- Public sources, licensure databases, sanctions lists, or professional verification sources;
- Corporate transaction counterparties and professional advisors.
3. How We Use Information
We may use information for the following purposes, subject to applicable law and, where applicable, Provider instructions, business associate agreements, service provider terms, or other contractual restrictions:
- To provide, operate, maintain, secure, and improve the Service;
- To create and administer accounts;
- To verify identity, age, eligibility, authority, location, or licensure;
- To connect users with Providers, facilitate scheduling, support virtual encounters, enable communications, and otherwise support the delivery of care by independent Providers;
- To receive, host, store, transmit, process, organize, and display information on behalf of Providers;
- To document, route, transmit, and support communications among users, Providers, pharmacies, laboratories, payers, and support personnel;
- To process payments, refunds, charge disputes, collections, and related financial operations;
- To provide customer service, technical support, troubleshooting, and quality assurance;
- To monitor, prevent, investigate, and respond to fraud, abuse, security incidents, harassment, spam, unauthorized access, and unlawful or prohibited activity;
- To conduct audits, logging, monitoring, analytics, performance measurement, debugging, and service optimization;
- To comply with legal, regulatory, contractual, accreditation, risk-management, professional, tax, accounting, insurance, reporting, and recordkeeping obligations;
- To protect the rights, safety, property, and security of users, Providers, Eureka, and others;
- To enforce our agreements, policies, and terms;
- To send administrative, transactional, security, support, service, legal, policy, and operational communications;
- To send marketing, educational, promotional, survey, and similar communications, subject to your preferences and applicable law;
- To create de-identified, anonymized, or aggregated data sets, reports, analytics, statistics, and business insights; and
- For any other purpose disclosed at the time of collection, authorized by you, or otherwise permitted or required by law.
3.1 Medical information and care-related uses
If Eureka processes medical information or PHI on behalf of a Provider, Eureka uses and discloses that information only as reasonably necessary to provide the Service and related administrative, technical, operational, security, support, and legal functions on behalf of the Provider, as permitted by contract and law.
3.2 De-identified and aggregated information
We may create and use de-identified, aggregated, or anonymized information for analytics, operations, service improvement, benchmarking, compliance, business planning, research, and any other lawful purpose. Information that has been de-identified, anonymized, or aggregated so that it cannot reasonably be linked to an identified or identifiable individual is not personal information for purposes of this Privacy Policy.
4. How We Disclose Information
We may disclose information in the following circumstances:
- To Providers and practices. We may disclose information to the Provider or practice with whom you choose to interact or from whom you seek care, and to their workforce members, contractors, and agents, as necessary to provide care and related operations.
- To service providers and processors. We may disclose information to vendors and partners that provide hosting, infrastructure, database, communications, telehealth, customer support, payment processing, analytics, security, identity verification, AI-assisted workflow, documentation, scheduling, storage, backup, monitoring, and similar services on our behalf.
- To subcontractors handling PHI. Where required, we enter into contracts, including business associate agreements or equivalent contractual restrictions, with subcontractors that create, receive, maintain, or transmit PHI on our behalf.
- To pharmacies, laboratories, imaging centers, insurers, payers, and other healthcare participants. We may disclose information as directed by the Provider, as necessary to support healthcare services, or as otherwise permitted by law.
- For legal compliance and protection. We may disclose information if we believe disclosure is necessary or appropriate to comply with applicable law, regulation, legal process, subpoena, court order, government request, public health obligation, licensing requirement, law enforcement request, or to protect rights, safety, property, or security.
- For corporate transactions. We may disclose information in connection with an actual or proposed merger, acquisition, financing, reorganization, investment, sale of assets, bankruptcy, receivership, diligence process, or similar transaction.
- At your direction or with your consent. We may disclose information when you instruct us to do so or otherwise consent.
- In de-identified or aggregated form. We may disclose de-identified, anonymized, or aggregated information for lawful purposes.
- With family members or caregivers. Where permitted by law and appropriate to the circumstances, we may disclose limited information to a caregiver, family member, or personal representative involved in your care or payment.
- To professional advisors and insurers. We may disclose information to auditors, accountants, attorneys, consultants, insurers, and similar professional advisors under appropriate obligations of confidentiality.
4.1 No sale to data brokers; no advertising use of patient health data
We do not sell personal information to data brokers. We do not disclose identifiable patient health information to advertisers or advertising networks for cross-context behavioral advertising. We do not use identifiable patient health information for unrelated advertising or data brokerage.
5. Cookies, Analytics, and Similar Technologies
We use cookies and similar technologies to operate the Service, remember preferences, authenticate users, secure accounts, maintain sessions, detect fraud, understand usage, improve performance, troubleshoot issues, and measure the effectiveness of our communications and site features.
We may use analytics and monitoring tools, including tools that help us understand traffic patterns, usage behavior, session activity, product performance, and feature adoption. These tools may collect technical and usage information through cookies, logs, SDKs, session replay technologies, and similar mechanisms.
You may be able to manage cookies through your browser or device settings. If you disable cookies or similar tools, some features of the Service may not function properly.
Where required by law, we honor consent choices or provide additional controls regarding cookies and similar technologies. Where applicable law requires recognition of an opt-out preference signal for processing such as targeted advertising or sale of personal data, we will treat qualifying signals in accordance with applicable law.
6. AI and Automated Tools
Eureka and Providers may use AI-enabled, machine-learning, or automated tools to support administrative, technical, documentation, communications, quality assurance, fraud prevention, analytics, and other permitted operational functions. Providers may also use AI-assisted tools to support clinical documentation, summarization, decision support, or related workflows, but clinical judgment and care decisions remain the responsibility of the Provider.
We do not use identifiable patient health information for unrelated advertising or data brokerage. Where we use third-party AI-enabled vendors to process patient information, we do so subject to contractual restrictions, and where applicable, business associate agreements or equivalent obligations.
7. Data Retention
We retain information for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide the Service, comply with Provider instructions, maintain records, resolve disputes, enforce agreements, satisfy legal or professional obligations, and protect against fraud, abuse, and security incidents.
Retention periods vary depending on the type of information, your relationship with the Service, your Provider’s policies, applicable law, litigation holds, and technical constraints. Medical records and PHI may be retained by Providers or on their behalf for periods required by healthcare laws and professional recordkeeping obligations, even if you close your account or ask us to delete information.
We may also retain information in backups, archives, logs, and de-identified or aggregated form for longer periods.
8. Security
We use commercially reasonable administrative, technical, and physical safeguards designed to protect information from unauthorized access, acquisition, disclosure, alteration, misuse, and destruction. Depending on the system, data category, and context, these measures may include:
- encryption of data in transit using industry-standard protocols;
- encryption at rest for production systems and, where supported, encrypted backups;
- role-based access controls and least-privilege permissions;
- authentication controls, credential protections, and session safeguards;
- logging, monitoring, and audit capabilities;
- change management and access review processes;
- vendor diligence and contractual security obligations;
- backup, recovery, and continuity procedures;
- workforce confidentiality, training, and incident-response processes; and
- measures designed to preserve the confidentiality, integrity, and availability of electronic protected health information.
No method of transmission over the internet, electronic storage, or security control is perfectly secure. Accordingly, we cannot and do not guarantee absolute security.
9. Your Choices and Rights
9.1 Account information
You may access or update certain account information through the Service. You are responsible for maintaining accurate information and promptly updating your account when needed.
9.2 Marketing communications
You may opt out of promotional emails by using the unsubscribe mechanism included in the email. You may opt out of promotional text messages by replying as directed in the message (for example, “STOP”), subject to applicable program terms. Even if you opt out of promotional messages, we may continue to send transactional, service, legal, operational, security, and care-related communications.
9.3 Medical records and PHI
Rights relating to medical records and Provider-controlled PHI should generally be directed to your Provider. Eureka may lack authority to independently grant or deny such requests and may redirect or forward your request to the Provider.
9.4 Privacy rights requests
Subject to applicable law, and after we verify your identity and authority, you may request that we:
- confirm whether we process certain personal information about you;
- provide access to certain personal information;
- correct inaccuracies in certain personal information;
- delete certain personal information;
- provide a portable copy of certain personal information; or
- limit or opt out of certain processing where applicable law grants that right.
These rights are not absolute. We may deny, limit, condition, or defer a request where permitted by law, including where the request would conflict with legal obligations, provider recordkeeping obligations, security requirements, fraud prevention, the rights of others, technical constraints, or our need to provide a product or service you requested.
To submit a privacy request, email support@eureka.md with the subject line Privacy Request. We may require additional information to verify your identity, authority, and the scope of your request. Where required by law, we will provide an appeal process for denied requests.
9.5 Account deletion
You may request deletion of your account by contacting support@eureka.md. Deleting an account does not necessarily delete medical records, encounter information, claims information, legal records, backup data, logs, fraud-prevention data, or information that we or a Provider are required or permitted to retain. We may also retain de-identified or aggregated information after account deletion.
10. Additional State-Specific and Health-Data Disclosures
10.1 California medical information
To the extent California medical information laws apply to medical information that Eureka processes as a contractor, service provider, or similar entity, Eureka uses and discloses such information only as reasonably necessary to support the provision of healthcare services by independent Providers and related administrative, technical, operational, security, support, payment, compliance, and legal functions, or as otherwise permitted or required by law.
10.2 Consumer health data outside HIPAA
Certain state laws may regulate “consumer health data” or similar categories of health-related information that fall outside HIPAA exemptions. Where such laws apply, we may provide additional notices, obtain separate consents, or offer additional rights mechanisms within the Service or through a separate consumer health data privacy notice.
10.3 No geofencing for health-facility tracking
We do not use geofencing to identify or track consumers for advertising or data-brokerage purposes based on visits to health care facilities.
10.4 State consumer privacy rights
Depending on where you live and the type of information involved, you may have additional rights under state privacy laws. These may include rights to access, correct, delete, appeal, withdraw consent, or opt out of certain processing. We may verify your identity and authority before acting and may deny requests as permitted by law.
11. International Use
The Service is intended for use in the United States. If you access the Service from outside the United States, you understand that your information may be transferred to, stored in, and processed in the United States and other jurisdictions where our service providers operate, subject to applicable law.
12. External Sites and Services
The Service may contain links to third-party websites, applications, tools, or services not operated by Eureka. This Privacy Policy does not apply to the privacy practices of those third parties. We are not responsible for the content, security, or privacy practices of third-party services.
13. Changes to this Privacy Policy
We may update this Privacy Policy from time to time in our discretion. The updated version will become effective when posted, unless otherwise stated. If we make changes that we determine are material, we may provide notice through the Service, by email, or by other means, where appropriate or required by law. Your continued use of the Service after the effective date of an updated Privacy Policy constitutes your acknowledgment of the revised Privacy Policy.
If applicable law requires a different form of notice, consent, or implementation for certain changes, we will follow the requirements of that law.
14. Contact Us
If you have questions about this Privacy Policy or want to submit a privacy request, contact us at:
Sam Dot Company
2261 Market St #10190
San Francisco, CA 94114
Email: support@eureka.md
Website: eureka.md