HIPAA Privacy Notice
Last updated: August 29, 2026
This HIPAA Privacy Notice describes how PharmDL LLC (“PharmDL”) collects, uses, safeguards, and discloses Protected Health Information (“PHI”) in connection with our prescription medication and healthcare-essentials delivery services. It is provided in accordance with the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) and its implementing regulations.
1. Our Role
PharmDL is a delivery service and acts as a Business Associate / healthcare logistics provider to licensed pharmacies and healthcare facilities. We do not practice pharmacy or medicine. PHI we handle originates from our partner pharmacies, facilities, and you as the authorized recipient.
2. Information We Collect
- Identifying information: name, address, phone, date of birth, account number;
- Delivery information: pickup and delivery addresses, scheduled times, delivery instructions, recipient/relationship details;
- Clinical logistics information: medication type, pharmacy name, hospital/hospice name, controlled-substance schedule, and special-handling requirements as needed to perform the delivery;
- Verification and proof of delivery: signatures, photo proof, and GPS/time confirmation.
3. How We Use Your Information
We use PHI solely to:
- Schedule, route, and complete deliveries;
- Verify recipient identity and authority to receive a delivery;
- Maintain chain-of-custody and proof-of-delivery records required by law and our partners;
- Protect against fraud, diversion of controlled substances, and unsafe handling;
- Provide customer support and respond to billing inquiries;
- Comply with legal, regulatory, and HIPAA requirements.
We do not use your PHI for marketing, sale of data, or any purpose unrelated to the delivery service.
4. Safeguards
PharmDL implements administrative, physical, and technical safeguards required by HIPAA, including:
- Encryption of PHI in transit and at rest;
- Role-based access control — staff access only the minimum information necessary for their role;
- Biometric and session security controls on user devices;
- Anti-screenshot and anti-camera protections on sensitive screens;
- Audit logging of access to PHI and security-relevant events;
- Inactivity-based automatic logout;
- Background-checked drivers and chain-of-custody tracking for controlled substances.
5. How We Share Your Information
We disclose PHI only:
- To our partner pharmacy or facility fulfilling your order, as necessary to complete the delivery;
- To the authorized recipient or their designated representative (spouse, power of attorney, caregiver, etc.) for delivery verification;
- When required by law, regulation, or legal process;
- To our service providers (e.g., payment processor Stripe) under written agreements that protect PHI to the extent applicable.
We do not sell your PHI.
6. Your Rights
Depending on your role, you may have rights to:
- Receive a copy of information we maintain for delivery purposes;
- Request correction of inaccurate information;
- Request restrictions on certain uses;
- Receive an accounting of certain disclosures.
To exercise these rights, contact us using the information below. Some requests may be fulfilled through our partner pharmacy that originated your order.
7. Data Retention
We retain delivery and chain-of-custody records for the period required by law and our partner agreements, then securely dispose of or de-identify the information.
8. Breach Notification
In the event of a breach of unsecured PHI affecting you, we will notify affected individuals and appropriate parties as required by HIPAA and applicable law.
9. Legal Consequences and Penalties for Breaching HIPAA
A breach of Protected Health Information — whether by PharmDL as an organization, by a workforce member, contractor, or any individual — carries serious legal and financial consequences under federal and state law. The penalties below are in addition to any contractual, civil, or licensing remedies that may apply.
9.1 Federal Civil Monetary Penalties (HITECH Act)
The U.S. Department of Health and Human Services Office for Civil Rights (“OCR”) enforces HIPAA and may impose tiered civil monetary penalties based on the level of culpability:
- Tier 1 — Lack of knowledge: up to $100 per violation, annual cap $25,000.
- Tier 2 — Reasonable cause: up to $1,000 per violation, annual cap $100,000.
- Tier 3 — Willful neglect (corrected): up to $10,000 per violation, annual cap $250,000.
- Tier 4 — Willful neglect (not corrected): up to $50,000 per violation, annual maximum $1,500,000.
These thresholds are periodically adjusted for inflation by HHS.
9.2 Federal Criminal Penalties (42 U.S.C. § 1320d-6)
The U.S. Department of Justice may prosecute individuals who knowingly obtain or disclose individually identifiable health information in violation of HIPAA:
- Knowingly obtaining or disclosing PHI: up to 1 year imprisonment and/or a fine of up to $50,000.
- Under false pretenses: up to 5 years imprisonment and/or a fine of up to $100,000.
- With intent to sell, transfer, or use PHI for commercial advantage, personal gain, or malicious harm: up to 10 years imprisonment and/or a fine of up to $250,000.
9.3 Enforcement Against PharmDL and Individuals
- Penalties may be imposed on PharmDL as a Business Associate, and OCR may hold individual workforce members, drivers, and contractors personally liable for wrongful disclosure.
- A breach may trigger mandatory breach notification obligations under the HIPAA Breach Notification Rule (45 CFR §§ 164.400–414), with penalties for failure to notify on time.
- Repeated or uncorrected violations may result in a Corrective Action Plan (CAP), extended OCR oversight, audit, and public posting on the HHS resolution-agreement list.
- PharmDL’s executed Business Associate Agreements (BAAs) require indemnification, and a breach may result in termination of partner contracts and loss of operating privileges.
9.4 State Law Penalties (California)
Where the delivery or recipient is located in California, additional state laws apply:
- California Confidentiality of Medical Information Act (CMIA), Cal. Civ. Code § 56 et seq.: up to $25,000 per violation in nominal damages, plus actual, punitive, and treble damages for malicious violations.
- California Consumer Privacy Act (CCPA), Cal. Civ. Code § 1798.150: statutory damages of $100–$750 per incident for certain unauthorized disclosures.
- California Business & Professions Code § 17200 (Unfair Competition Law): civil penalties and injunctive relief for unlawful business practices.
- Identity Theft (Cal. Penal Code § 530.5): criminal penalties for using another person’s PHI to commit fraud.
9.5 Controlled Substances and DEA Enforcement
Where the breach involves a controlled substance delivery, additional federal penalties may apply under the Controlled Substances Act (21 U.S.C. § 841) and DEA regulations, including loss of registration, criminal prosecution for diversion, and forfeiture. A breach affecting controlled-substance chain-of-custody will be reported to the DEA Diversion Control Division.
9.6 Internal Consequences for PharmDL Personnel
Workforce members who violate this Notice or HIPAA may face, at PharmDL’s discretion:
- Immediate suspension or termination of employment or contract;
- Revocation of system and facility access;
- Referral to OCR, law enforcement, or the applicable licensing board;
- Personal civil and criminal liability where applicable.
By using PharmDL’s services, you acknowledge that unauthorized access, use, or disclosure of PHI is a serious federal and state offense with the penalties described above.
10. Changes to This Notice
We may update this Notice. The “Last updated” date reflects the most recent version. A current copy is always available at pharmdl.com/hipaa-privacy-notice.
11. Contact and Questions
For privacy questions, to exercise your rights, or to report a privacy concern:
- PharmDL LLC — support@pharmdl.com
For formal complaints, you may also contact the U.S. Department of Health and Human Services Office for Civil Rights.
© 2026 PharmDL LLC. All rights reserved.