Legal

Privacy Policy

Effective date: April 1, 2026Last updated: April 12, 2026

1. Introduction

Revella Health, Inc. (“Revella Health,” “we,” “us,” or “our”) deploys clinical teams into communities to deliver point-of-care preventive screenings, close HEDIS care gaps, capture risk adjustment data, and improve quality outcomes for the health plans that contract with us. We serve Medicare Advantage plans, ACA Marketplace plans, network providers, and the members enrolled in those plans.

We respect your privacy and are committed to protecting the information you share with us, whether you are a health plan executive evaluating a partnership, a provider learning about our services, or a member receiving care at one of our community clinics.

This Privacy Policy explains:

If you have questions, contact us using the information in Section 13.


2. Scope

This Privacy Policy applies to information we collect through:

Health information collected during clinical care is also governed by our HIPAA Notice of Privacy Practices, which describes in detail how protected health information (PHI) may be used and disclosed. The Notice is provided at every service location and is available on request.


3. Information We Collect

The information we collect depends on how you interact with us. We collect only what we need to deliver our services, support our business relationships, and meet our legal and contractual obligations.

3.1 Website Visitors

When you visit revellahealth.com, we automatically collect:

3.2 Health Plan Prospects and Business Contacts

When you book a demo through Calendly, fill out a contact form, email us, or call us to discuss a partnership, we collect:

We do not require or collect Personal Health Information (PHI) during sales or business development conversations.

3.3 Providers and Practice Inquiries

When a provider or practice reaches out about working with us, we collect business contact information, practice information (name, location, specialty, payer mix), and notes from our conversations.

3.4 Health Plan Members (Service Recipients)

When you receive services from us at a community event or mini-clinic, when you RSVP to an event, or when you opt in to our SMS program, we collect:

3.5 Information from Health Plan Partners

Health plans that contract with us (such as Ambetter of Alabama / Celtic Insurance Company) may share with us:

This sharing is authorized under HIPAA for treatment, payment, and healthcare operations and is governed by Business Associate Agreements (BAAs) and Data Use Agreements where applicable.


4. How We Use Your Information

We use the information we collect for the following purposes:

Clinical and care coordination:

Communications:

Reporting and quality improvement:

Business operations:


5. Information Sharing: We Do Not Sell Your Data

Information collected through SMS opt-in, including mobile numbers and consent records, is never shared with third parties or affiliates for marketing or promotional purposes. We do not sell, rent, or trade personal information collected through our website, our SMS program, or our clinical services.

We share information only in the following limited circumstances:


6. Cookies and Online Tracking

Our website uses cookies and similar technologies to:

You can disable cookies in your browser settings. Doing so may limit some site functionality.

We do not use advertising cookies or third-party advertising trackers on member-facing pages, including the RSVP page, intake forms, or any page where personal health information is collected.


7. Third-Party Services We Use

We rely on a small number of vetted vendors to operate our website and services. Each is contractually limited in how they may use the information they process on our behalf:

We do not authorize any of these vendors to sell, rent, or use your information for their own marketing.


8. SMS Communications

If you opt in to our SMS program, you will receive messages such as event invitations, RSVP confirmations, appointment reminders, location and timing updates, and post-visit follow-ups. The full program terms are available in our SMS Terms and Conditions.

Specifically with respect to SMS:


9. Data Security

We use administrative, technical, and physical safeguards designed to protect your information, including:

No system can be made perfectly secure. If a breach affects your information, we will notify you as required by HIPAA and applicable state law.


10. Your Rights

Depending on the type of information and the law that applies, you may have the right to:

To exercise any of these rights, contact our Privacy Officer using the information in Section 13. We will respond within the timeframes required by HIPAA and applicable state law.

360Care app accounts

If you use the 360Care member app, you can ask us to delete your account and the personal information we hold to run the app, and you can do it without installing or reinstalling the app:

We confirm your identity with a one-time code sent to the phone number or email address already on your record. Your request is reviewed by a person before anything is removed, and we contact you to confirm. Portions of the clinical and billing record that health-records law and payer rules require us to retain are kept for the required period; we tell you what was kept when we confirm your request.


11. Children's Privacy

We provide preventive health services to members of all ages as authorized by their health plan. However, our website RSVP and SMS opt-in forms are intended for use by adults age 18 and older. A parent or legal guardian must complete any opt-in or registration on behalf of a minor.

We do not knowingly collect personal information online from children under 13 without verifiable parental consent.


12. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last Updated” date at the top of this page. If changes are material, we will provide additional notice (for example, by email, SMS to opted-in members, or a banner on our website) before the changes take effect.


13. Contact Us

If you have questions about this Privacy Policy, want to exercise your rights, or wish to report a privacy concern, please contact:

Revella Health, Inc.

Attn: Privacy Officer

1 Perimeter Park South, Suite 100N

Birmingham, AL 35243

Phone: 888-415-7054

Email: privacy@revellahealth.com

For SMS-specific questions, you may also reply HELP to any message you receive from us.


Revella Health is a HIPAA-covered healthcare provider. This Privacy Policy supplements, but does not replace, our HIPAA Notice of Privacy Practices, which describes in detail how protected health information may be used and disclosed.