Bloom Medical

Privacy Policy

PRIVACY POLICY

Last Updated: July 30, 2026

1. Introduction and Scope

Bloom Medical Group (“Bloom,” “Bloom Medical” “we,” “us,” or “our”) provides telehealth pulmonary rehabilitation, cardiac rehabilitation, and chronic care management services. This Privacy Policy explains how we collect, use, disclose, and protect information when you visit our website, use our telehealth platform, or communicate with us by phone, text, or online form.

This Policy works alongside, and does not replace, our HIPAA Notice of Privacy Practices, which separately governs how we use and disclose your Protected Health Information (PHI).

2. Information We Collect

  • Identifying information: name, date of birth, address, phone number, email address, and insurance information
  • Health information: medical history, diagnoses, treatment plans, and other Protected Health Information (PHI) shared with us in connection with your care
  • Communications data: records of calls, texts, emails, and messages with our team, including AI-assisted call recordings if you opt in (see Section 4)
  • Technical information: IP address, browser type, device information, and website usage data collected through cookies and similar technologies

3. How We Use Your Information

We use your information to:

  • Provide, coordinate, and manage your pulmonary and cardiac rehabilitation care
  • Verify insurance coverage and process billing
  • Schedule appointments and send reminders
  • Communicate with you about your care
  • Improve the quality and speed of our services, including through AI-assisted tools (see Section 4)
  • Comply with legal, regulatory, and accreditation requirements

We do not sell your personal information or Protected Health Information.

4. AI-Assisted Call Recording and Conversation Analysis

With your consent, Bloom uses AI-assisted technology to record and analyze phone calls and conversations with our team. This helps us maintain quality assurance, respond to your needs more quickly, and improve service delivery.

This feature is opt-in only. We will not record or analyze your calls using AI unless you affirmatively consent, and you may decline or withdraw consent at any time by contacting our office (Section 13). If you do not opt in, your calls are still handled through our standard operations without AI recording.

Some states require every participant on a call to consent before it can legally be recorded. Where that applies, we will also provide notice at the start of the call itself, and your continued participation on that call, together with your prior opt-in, confirms your consent.

Any recordings or transcripts created this way are treated as part of your confidential records and are protected by the same safeguards described in Section 7.

5. How We Share Your Information

We may share information with:

  • Business associates who perform services on our behalf (such as our EHR vendor, billing services, and AI service providers), each bound by a Business Associate Agreement where required under HIPAA
  • Insurance companies and payers, to verify coverage and process claims
  • Regulators or government agencies, when required by law
  • Other providers involved in your care, with your authorization where required

We do not share or sell your information to third parties for their own marketing purposes without your consent.

6. Telehealth-Specific Disclosures

Our services are delivered through audio, video, and remote monitoring technology. By using our telehealth platform, you acknowledge that:

  • Telehealth involves the electronic transmission of your health information
  • No technology is completely free of risk of interruption or unauthorized access, and we take reasonable steps to secure all transmissions
  • Telehealth is not appropriate for medical emergencies. If you are experiencing a medical emergency, call 911 or go to the nearest emergency room

7. Data Security

We use administrative, technical, and physical safeguards designed to protect your information, consistent with the HIPAA Security Rule, including encryption, access controls, and staff training. No system is completely secure, and we cannot guarantee absolute security of information transmitted online or by phone.

8. Data Retention

We retain your information for as long as necessary to provide care, comply with legal and regulatory recordkeeping requirements, and resolve disputes, after which it is securely destroyed or de-identified.

9. Your Privacy Rights

Depending on your state of residence, you may have rights regarding your personal information, including the right to know what we collect, request a copy of it, request correction or deletion (subject to legal and medical recordkeeping requirements), and opt out of certain uses. These rights are separate from, and in addition to, your rights under HIPAA regarding your PHI, which are described in our Notice of Privacy Practices. To exercise any of these rights, contact us using the information in Section 13.

10. Cookies and Website Tracking

Our website may use cookies and similar technologies to improve site functionality and understand how visitors use our site. You can control cookies through your browser settings.

11. Children’s Privacy

Our services are intended for adults. We do not knowingly collect information from children without appropriate parental or guardian consent.

12. Changes to This Policy

We may update this Privacy Policy from time to time. The “Last Updated” date at the top reflects the most recent revision. Continued use of our services after changes are posted constitutes acceptance of the updated Policy.

13. Contact Us

Bloom Medical Group
Email: [email protected]


Scroll to Top