HIPAA & Health Privacy
Last updated: April 2026
Issued by NETTULTECH CORPORATION · Nettulz AI™ · nettulzai.ai
Important Health Data Notice
Nettulz AI's Health Awareness and Mental Support agents are general wellness tools only. We are not a healthcare provider, health plan, or healthcare clearinghouse. This page explains how we handle health-related information you voluntarily share, and the protections we apply.
1. HIPAA Applicability & Our Status
The Health Insurance Portability and Accountability Act (HIPAA) and its implementing regulations (the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule) govern Covered Entities (healthcare providers, health plans, healthcare clearinghouses) and their Business Associates.
NETTULTECH CORPORATION and Nettulz AI are NOT a Covered Entity or Business Associate under HIPAA as defined in 45 CFR § 160.103. We do not provide medical treatment, do not bill insurance, and do not transmit health information in connection with covered healthcare transactions.
However, we recognize the sensitivity of health-related information and voluntarily apply HIPAA-inspired safeguards to any health or mental health data you choose to share with us. We also comply with applicable state health privacy laws and international equivalents (see Section 10).
2. What We Are NOT
To be unambiguous about the nature of our service:
- We are not a healthcare provider, doctor, therapist, psychiatrist, or any other licensed health professional.
- We are not a health plan or insurance company.
- We are not an Electronic Health Record (EHR) system.
- We are not a telehealth platform.
- We do not create, maintain, or transmit Protected Health Information (PHI) as defined by HIPAA.
- We are not a substitute for professional medical or mental health care.
Always consult licensed healthcare professionals for any medical or mental health needs. In emergencies, call 911 (US), 999 (UK), 112 (EU), or your local emergency number immediately.
3. Health Information We Handle
When you use the Health Awareness or Mental Support agents, you may voluntarily share information such as: general wellness habits, stress levels, sleep patterns, lifestyle factors, or emotional experiences.
This is not Protected Health Information (PHI) under HIPAA because it is not created or received in connection with a covered healthcare transaction by a covered entity. It is user-volunteered wellness context provided directly to an AI.
We classify this as sensitive personal data and apply heightened protections regardless of HIPAA's technical applicability, consistent with GDPR Art. 9 (special category data), CCPA sensitive personal information categories, and equivalent laws.
4. How We Protect Health-Related Data
We apply the following protections to any health or mental health information you share:
- Purpose Limitation: Health-related conversation data is used solely to provide the wellness guidance you requested. It is never used for advertising, sold to third parties, or shared with employers or insurers.
- Minimal Disclosure: We only share health-related data with the AI model provider necessary to generate your response, under strict data processing agreements.
- Separation: Health and mental health conversations are treated as a distinct sensitive data category in our systems.
- Deletion on Request: You can delete health-related conversations at any time from your conversation history. We will permanently remove them within 30 days.
- No Secondary Use: Health data is never used for AI model training without your explicit, separate consent.
5. Safeguards We Implement
Inspired by the HIPAA Security Rule's Administrative, Physical, and Technical Safeguard requirements (45 CFR §§ 164.308–164.312), we implement:
- Administrative Safeguards: Access controls limiting which personnel can access user data; privacy and security training; incident response procedures; regular risk assessments.
- Physical Safeguards: Data hosted on SOC 2-certified cloud infrastructure with physical access controls, environmental protections, and workstation security policies.
- Technical Safeguards: TLS 1.2+ encryption in transit; AES-256 encryption at rest; access audit logging; automatic session timeouts; multi-factor authentication for staff access to production systems.
- Breach Response: In the unlikely event of a breach involving health-related data, we will notify affected users and relevant authorities as required by applicable law, including within 72 hours under GDPR.
6. Limitations of AI Health Guidance
Our AI agents can discuss general wellness topics but have critical limitations:
- AI cannot diagnose conditions, interpret lab results, or prescribe treatments.
- AI does not have access to your medical history, medications, or clinical records.
- AI responses may be inaccurate, outdated, or inapplicable to your specific medical situation.
- AI cannot substitute for a clinical evaluation, physical examination, or ongoing therapeutic relationship.
These limitations apply even if the AI provides information that sounds clinically accurate. Always verify health information with a licensed healthcare provider.
7. User Rights Regarding Health Data
In addition to the rights described in our Privacy Policy and GDPR page, you have specific rights regarding health-related data:
- Access: Request a copy of all health-related conversations and wellness data we hold.
- Deletion: Delete individual conversations from your history, or request full deletion of all health data.
- Portability: Export your health-related conversations in JSON format.
- Restriction: Request that health-related data not be used for any purpose beyond immediate service delivery.
- Withdrawal: Stop sharing health information at any time by simply not using the Health Awareness or Mental Support agents.
Submit health data rights requests to: privacy@nettulzai.ai
8. No PHI Storage Policy
We maintain a strict No PHI Storage Policy: we do not store, process, or transmit Protected Health Information (PHI) as defined under 45 CFR § 160.103. This includes but is not limited to: medical record numbers, health plan beneficiary numbers, diagnosis codes (ICD codes), procedure codes, clinical notes, lab results, prescription information, or biometric identifiers linked to an individual's healthcare treatment.
If you inadvertently share such information, it will be processed solely to respond to your request and will not be retained in a manner that creates PHI records.
9. Third-Party Health Data Processors
Health-related conversation content passes through our AI model provider(s) to generate responses. These providers operate under:
- Data Processing Agreements (DPAs) that include prohibitions on using your data for their own model training.
- SOC 2 Type II and/or ISO 27001 certifications.
- GDPR-compliant data handling frameworks.
We do not share health-related data with advertising networks, data brokers, employers, insurers, or government agencies except as required by law.
10. State-Level & International Health Privacy Laws
In addition to HIPAA-inspired standards, we recognize the following applicable laws:
- California: CMIA (Confidentiality of Medical Information Act), CCPA sensitive personal information provisions covering health data.
- Washington State: My Health MY Data Act (MHMD) — we do not sell consumer health data.
- Nevada, Connecticut, and other US states with health data privacy laws: we apply equivalent protections.
- EU/EEA/UK: GDPR Art. 9 (special category data — health data requires explicit consent and heightened protection). We rely on Art. 9(2)(a) — explicit consent provided at the point of sharing.
- Brazil (LGPD): Health data is treated as sensitive data under Art. 5(II) with equivalent protections.
- Canada (PIPEDA/CPPA): Health information receives heightened sensitivity treatment.
- Australia: Health information is treated as sensitive information under the Privacy Act 1988.
- India (DPDP Act): Health data treated as sensitive personal data with elevated protections.
- South Africa (POPIA): Health data is a special personal information category requiring strict conditions for processing.
11. Children's Health Data
We do not knowingly collect health or mental health information from users under 13 (or 16 in the EU/EEA). The Health Awareness and Mental Support agents are intended for users 18 and older. If you believe a minor has shared health information with us, contact privacy@nettulzai.ai immediately.
12. Mental Health Information
Mental health information is among the most sensitive categories of personal data. We apply additional safeguards:
- Mental health conversations are never used in marketing or shared with third parties outside of service delivery.
- The Mental Support agent is instructed to always recommend professional help for serious concerns and to provide crisis resources when applicable.
- We comply with applicable mental health privacy laws including 42 CFR Part 2 (US substance use disorder records), state mental health confidentiality statutes, and international equivalents.
⚠️ Crisis Resources: If you or someone you know is in mental health crisis, please contact emergency services or a crisis helpline. US: 988 Suicide & Crisis Lifeline (call or text 988). International: findahelpline.com
13. Contact
For health data privacy inquiries, requests, or concerns:
Email: privacy@nettulzai.ai
General support: support@nettulzai.ai
NETTULTECH CORPORATION · Nettulz AI™ · nettulzai.ai
© 2026 NETTULTECH CORPORATION. All rights reserved.
Nettulz AI™ is a product of NETTULTECH CORPORATION. For legal inquiries: legal@nettulzai.ai