TopDoc Privacy Policy
Last Updated: September 1, 2026
At Topdoc, Inc. (“TopDoc,” “we,” or “us”), we are committed to protecting your privacy, and we take great care with your personal information that we gather when you access or use TopDoc.com and related websites, applications, and services owned and operated by TopDoc and that link to this Privacy Policy (collectively, the “Services”). This Privacy Policy is meant to help those who use our Services to explore providers or book appointments (“Users”) and doctors, dentists, or other healthcare specialists, professionals, providers, organizations or agents, or affiliates thereof that use our electronic health record, revenue cycle management, patient engagement, marketing, and related services (“Healthcare Providers,” and collectively with Users, “you,” or “your”) understand how we treat your personal information.
By using or accessing the Services in any manner, you acknowledge that you accept the practices and policies outlined in this Privacy Policy, and you hereby consent that we will collect, use, and share your information in the following ways. If you do not agree with this Privacy Policy, you may not use the Services. If you use the Services on behalf of someone else (such as your child) or an entity (such as your employer), you represent that you are authorized by such individual or entity to accept this Privacy Policy on such individual’s or entity’s behalf.
Any use of TopDoc’s Services is at all times subject to the Agreement, as defined in our Patient Terms of Use or, for Healthcare Providers, our Provider Terms of Use, each of which incorporates this Privacy Policy. You may print a copy of this Privacy Policy at any time.
Privacy Policy Table of Contents
- HIPAA, PHI, and Information We Process for Healthcare Providers
- Personal Data
- Public Health Reporting
- User Personal Data
- Healthcare Provider Personal Data
- Voice, Call, and Encounter Recordings
- Tracking Tools, Advertising, and Opt-Out
- Data Security
- Data Retention
- Children’s Privacy
- How We Use Information That is Neither Personal Data nor PHI
- Controlling Your Personal Data & Notifications
- State Privacy Rights
- Exercising Your Rights
- Changes to this Privacy Policy
- Contact Information
HIPAA, PHI, and Information We Process for Healthcare Providers
Healthcare Providers use TopDoc’s electronic health record, revenue cycle management, and patient engagement services to create, store, and transmit information about their patients, including medical records, intake and consent forms, insurance and billing information, appointment and other communications, and recordings or transcripts of telephone calls and patient encounters where the Healthcare Provider has enabled those features (“Practice Data”). When TopDoc processes Practice Data, it does so on behalf of and at the direction of the Healthcare Provider, which is a “Covered Entity” under the Health Insurance Portability and Accountability Act and its implementing regulations (“HIPAA”). In that role TopDoc is a “Business Associate,” identifiable health information is “protected health information” or “PHI,” and its use and disclosure are governed by HIPAA, by TopDoc’s Business Associate Agreement with the Healthcare Provider, and by the Healthcare Provider’s own Notice of Privacy Practices, rather than by the remainder of this Privacy Policy.
The Healthcare Provider owns and controls Practice Data. TopDoc does not sell Practice Data and does not use identifiable PHI to train machine-learning models for use outside that Healthcare Provider’s account. TopDoc may communicate with you on behalf of your Healthcare Provider and, as permitted by HIPAA and our Business Associate Agreement, about your TopDoc account and TopDoc’s own services. TopDoc may create de-identified information from Practice Data in accordance with HIPAA and may use it for any lawful purpose.
If you are a patient and want to access, correct, or obtain copies of your medical or billing records, or have questions about how your Healthcare Provider uses your information, please contact your Healthcare Provider directly. TopDoc will refer such requests to the Healthcare Provider.
Personal Data that a User provides to TopDoc through TopDoc’s own consumer-facing services, when TopDoc is not acting as a Business Associate, is not PHI and is governed by this Privacy Policy. Examples include when you (i) create a TopDoc account, (ii) search for Healthcare Providers or available appointments, (iii) complete general medical history forms that are not required by a particular Healthcare Provider, (iv) post reviews, or (v) provide device / IP information by browsing our websites.
Personal Data
“Personal Data” means any information that identifies or relates to a particular individual and also includes information referred to as “personally identifiable information” or “personal information” under applicable data privacy laws. The following sections detail the categories of Personal Data that we collect and have collected over the past twelve (12) months. For each category, we describe the source, our commercial or business purpose for collecting it, and the categories of third parties with whom we share it.
Public Health Reporting
Where required or permitted by law, TopDoc or your Healthcare Provider may report health information (for example, immunization or communicable-disease data) to local, state, or federal public health authorities. Reporting made through the Practice Services is made on behalf of the Healthcare Provider under HIPAA.
User Personal Data
The following subsections apply only to Users. If you are a Healthcare Provider, please see the Healthcare Provider Personal Data section below.
Categories of Personal Data We Collect from Users
- Payment Information: Payment card type, last four digits of payment card, billing contact, billing email. Source: You. Shared with: Service Providers (Stripe).
- Device / IP Information: IP address, device ID, domain server, type of device, operating system, and browser used to access the Services. Source: You and third parties. Shared with: Service Providers, Analytics Partners, Ad Networks, Third-Party Business Partners.
- Web Analytics: Web page interactions, referring webpage or source, non-identifiable request IDs, statistics associated with the interaction between your device or browser and the Services. Source: You and third parties. Shared with: Service Providers, Analytics Partners, Ad Networks, Third-Party Business Partners.
- Geolocation Data: IP-address-based location information. Source: You. Shared with: Service Providers, Analytics Partners, Ad Networks, Third-Party Business Partners.
- Other Identifying Information You Voluntarily Provide: Unique identifiers such as passwords, and Personal Data in emails, letters, or other communications you send us. Source: You. Shared with: Service Providers.
- User Contact Data: First and last name, email, phone number, mailing address. Source: You. Shared with: Service Providers, Healthcare Providers, Insurance Providers, Health Information Exchanges, parties you authorize.
- User Demographic Data: Gender and/or gender identity, age, date of birth, zip code, and other demographic information you choose to provide. Source: You. Shared with: Service Providers, Healthcare Providers, Health Information Exchanges, parties you authorize.
- Medical Data: Health conditions, Healthcare Providers visited, reasons for visit, dates of visit, medical history and health information you provide us. Source: You. Shared with: Service Providers, Healthcare Providers, Insurance Providers, Health Information Exchanges, parties you authorize.
- Insurance Information: Insurance carrier, plan, member ID, group ID, payer ID. Source: You. Shared with: Service Providers, Healthcare Providers, Health Information Exchanges, parties you authorize.
- Booking Appointment Data: Appointment date and time, provider information, appointment procedure, whether you are a new patient for a particular provider. Source: You and third parties. Shared with: Service Providers, Analytics Partners, Healthcare Providers, Health Information Exchanges.
- Social Network Data: Email, phone number, username, IP address, device ID. Source: You and third parties. Shared with: Service Providers, parties you authorize.
- Categories of data that may be considered “sensitive” under certain privacy laws: Health information, precise geolocation if you enable it, and unique identifiers such as your account login and password.
Categories of Sources of Personal Data
- From you, when you provide information directly: when you create an account, use our interactive tools and services (such as searching for Healthcare Providers or completing Medical History Forms), voluntarily provide information in free-form fields, respond to surveys, or post reviews; when you email or chat with us.
- From you, automatically as you use the Services: through Cookies (defined below); if you download our applications, information transmitted from your computing device; if you use a location-enabled browser, information about your location.
- From Service Providers: to help us analyze how you interact with the Services and provide customer support.
- From Analytics Partners: to help us understand website traffic and usage of the Services.
- From Healthcare Providers: certain data needed to facilitate booking appointments.
- From Social Networks: content and information from third-party accounts if you sign in via social login.
- From Advertising Partners: information about your interactions with our Services, advertisements, or communications.
Commercial or Business Purposes for Collecting Data
- Providing, customizing, and improving the Services: creating and managing your account, billing our Healthcare Provider clients, providing requested products and services, support and assistance, testing and product development, personalization, fraud protection, security, and debugging.
- Marketing the Services: marketing and selling the Services, showing you advertisements including interest-based advertising.
- Corresponding with you: responding to your messages, sending appointment reminders, sending information about TopDoc and the Services.
- Legal requirements: fulfilling our legal obligations under applicable law, regulation, court order, or other legal process; protecting the rights, property, or safety of you, TopDoc, or another party; enforcing agreements; responding to claims; resolving disputes.
How We Share Your Personal Data
We share Personal Data with the following categories of service providers and other third parties:
- Payment Processors (Stripe): to process voluntarily provided payment card information.
- Security and Fraud Prevention Consultants: to detect security incidents and protect against malicious or illegal activity.
- Hosting, Technology, Communications, Data Storage, Analytics, and Insurance Verification Providers: to perform operational services, debug errors, and enable Service features.
- Analytics Partners: to track how Users found or were referred to the Services.
- Ad Networks: for ad customizing, serving, and auditing.
- Healthcare Providers: when you choose to schedule with them, complete a Medical History Form and elect to share it, or in the event of an emergency.
- Insurance Providers: to determine eligibility, cost-sharing obligations, and benefit plan information.
- Health Information Exchanges: organizations that collect and organize User information to make it more securely accessible to your Healthcare Providers.
- Other Users: anything you reveal in a review posting or public discussion is intentionally open to the public.
- Third-Party Business Partners You Access Through the Services: if you choose to use a third-party service to log in or to interact with the Services.
We may also share information for legal obligations (responding to lawful requests), in connection with a business transfer (such as a merger, acquisition, or bankruptcy), and as aggregated or de-identified data that cannot identify you.
Healthcare Provider Personal Data
The following subsections apply only to Healthcare Providers. If you are a User, please see the User Personal Data section above.
Categories of Personal Data We Collect from Healthcare Providers
- Payment Information: Payment card type, last four digits, billing contact, billing email. Source: You. Shared with: Service Providers (Stripe).
- Device / IP Information: IP address, device ID, domain server, type of device / operating system / browser used. Source: You and third parties. Shared with: Service Providers, Analytics Partners, Ad Networks, Third-Party Business Partners.
- Web Analytics: Webpage interactions, referring webpage, non-identifiable request IDs, statistics. Source: You and third parties. Shared with: Service Providers, Analytics Partners, Ad Networks, Third-Party Business Partners.
- Geolocation Data: IP-address-based location information. Source: You and third parties. Shared with: Service Providers, Analytics Partners, Ad Networks, Third-Party Business Partners.
- Other Identifying Information You Voluntarily Provide: Unique identifiers such as passwords, personal data in emails or letters, information disclosed over the phone. Source: You. Shared with: Service Providers.
- Healthcare Provider Contact Data: First and last name, email, phone number, mailing address. Source: You and third parties. Shared with: Service Providers, Healthcare Providers, Insurance Providers, Health Information Exchanges, parties you authorize.
- Healthcare Provider Demographic Data: Gender, date of birth, zip code, spoken languages. Source: You and third parties. Shared with: Service Providers, Health Information Exchanges, parties you authorize.
- Professional License Information: Professional licenses, education history, specialties and certifications. Source: You and third parties. Shared with: Service Providers.
- Categories of data that may be considered “sensitive” under certain privacy laws: Unique identifiers such as your account login and password.
Categories of Sources of Personal Data
- From you, when you provide information directly: when you create an account or contact us via email.
- From you, automatically as you use the Services: through Cookies; if you download applications, information transmitted from your device; if you use a location-enabled browser, location information.
- From Service Providers: to analyze how you interact with the Services, provide customer support, generate leads, and create user profiles.
- From Analytics Partners: to provide analytics on website traffic or usage of the Services.
- From Government or Public Records: for onboarding or verifying Healthcare Providers.
- From Advertising Partners: information about your interactions with our Services, advertisements, or communications.
Commercial or Business Purposes for Collecting Data
- Providing, customizing, and improving the Services: creating and managing accounts, producing invoices, fulfilling requests, providing support, improving the Services, personalization, fraud protection, security, and debugging.
- Marketing the Services: marketing and selling the Services, showing advertisements.
- Corresponding with you: responding to correspondence, sending appointment reminders, sending communications.
- Legal requirements: fulfilling legal obligations, protecting rights, enforcing agreements, responding to claims, resolving disputes.
- Onboarding verification: confirming providers have the necessary credentials to practice in the state where advertised.
How We Disclose Your Personal Data
We disclose Personal Data to the following categories of service providers and other third parties: Payment Processors (Stripe); Security and Fraud Prevention Consultants; Hosting, Technology, Communications, Fulfillment, Data Storage, Analytics, and Insurance Verification Providers; Analytics Partners; Ad Networks; Health Information Exchanges; and Third-Party Business Partners You Access Through the Services.
We may also share information for legal obligations (responding to lawful requests), in connection with a business transfer (such as a merger, acquisition, or bankruptcy), and as aggregated or de-identified data that cannot identify you.
Voice, Call, and Encounter Recordings
Some Services, when enabled by a Healthcare Provider, record and transcribe telephone calls (including calls handled by an automated or AI-assisted phone agent) and in-person or telehealth encounters in order to schedule appointments, answer questions, and generate clinical documentation for the Healthcare Provider. These recordings and transcripts are Practice Data processed on behalf of the Healthcare Provider. The Healthcare Provider is responsible for notifying you and obtaining any consent required by law before recording. If you do not wish to be recorded, tell the Healthcare Provider or the agent at the start of the call or visit. Calls to TopDoc’s own support lines may be recorded for quality and training purposes, and you will be told at the start of the call.
Tracking Tools, Advertising, and Opt-Out
The Services use cookies and similar technologies (collectively, “Cookies”), including pixel tags, web beacons, clear GIFs, mobile identifiers, and JavaScript, so our servers can recognize your browser and understand how and when you use our Services. We use these to analyze trends, advertise to our user base, and operate and improve our Services.
We use the following types of Cookies:
- Essential Cookies: required to provide features or services you have requested (for example, logging into secure areas).
- Functional Cookies: to record your choices and settings and recognize you when you return.
- Performance / Analytical Cookies: to understand how visitors use our Services and measure the performance of our advertising campaigns. Google Analytics is one example; you can opt out via Google’s opt-out tools.
- Retargeting / Advertising Cookies: to identify your interests and provide advertising we believe is relevant to you.
- Web Beacons: tiny graphic image files embedded in a webpage or email to track usage and engagement.
- Mobile Device Identifiers: data stored on mobile devices to learn about Users’ demographics and behaviors.
- Cross-Device Matching: to determine if Users have interacted with content across multiple devices and to match those devices.
You can disable Cookies through your browser settings; however, some Service functionality may not work properly without them. We honor browser-based opt-out preference signals such as the Global Privacy Control (“GPC”) as a request to opt out of the sale or sharing of Personal Data and of targeted advertising, where required by applicable law. We do not respond to older “Do Not Track” signals.
We may also serve interest-based advertisements through ad networks. We comply with the Digital Advertising Alliance (“DAA”) Self-Regulatory Principles for Online Behavioral Advertising; you can opt out via the DAA or NAI opt-out pages, or by installing the DAA’s AppChoice app on your mobile device. Even after opting out of interest-based ads, you may still see TopDoc advertisements that are not interest-based. We use advertising and analytics Cookies only on our public, unauthenticated web pages. We do not deploy advertising or retargeting Cookies, pixels, or similar technologies on authenticated portions of the Services, including the patient portal, intake and payment pages, telehealth, and Healthcare Provider applications, or on any page that displays Practice Data.
Data Security
The security of your Personal Data is important to us. We seek to protect your Personal Data from unauthorized access, use, and disclosure using appropriate physical, technical, organizational, and administrative security measures, including encryption of Personal Data and PHI in transit using TLS and at rest, a security program aligned with the HIPAA Security Rule, and access controls that limit access to personnel who need it to perform their jobs. We store PHI in data centers located in the United States. Our personnel and service providers, some of whom are located outside the United States, may access information solely to provide the Services and under written confidentiality and business associate obligations. You should also help protect your data by selecting a strong password and protecting your devices.
No method of transmitting or storing data is completely secure, and we cannot guarantee the complete security of any data you share with us. If we believe that the security of your Personal Data may have been compromised, we will use reasonable efforts to notify you, generally via the email address on file. You can update that email address anytime in your account profile, and you may also email us at [email protected] to request notice via U.S. mail.
Data Retention
We retain Personal Data about you as necessary to provide our Services or to perform our business or commercial purposes. We may retain Personal Data for longer if necessary to comply with our legal obligations, resolve disputes, collect fees owed, or as otherwise permitted by law. We may further retain information in an anonymous or aggregated form where that information would not identify you personally.
- We retain your account information and credentials for as long as you have an account with us.
- We retain your device / IP data for as long as we need it to ensure our systems work correctly.
- We retain any PHI consistent with our obligations under our Business Associate Agreements with Covered Entities and HIPAA.
- We retain Practice Data for as long as the Healthcare Provider maintains an account with us and for an export period after termination, and thereafter return or delete it at the Healthcare Provider’s direction as provided in our Business Associate Agreement, except where retention is required by law or the data has been de-identified.
Children’s Privacy
The Services are not directed to or intended for use by children under 13 years of age. If you are under 13, please do not attempt to register for or use the Services or send us any Personal Data. We do not knowingly collect or solicit Personal Data from children under 13. If we learn that we have received Personal Data directly from a child under 13 without parental consent, we will use that data only to respond to the child or parent and will then delete it. If you believe a child under 13 may have provided us with Personal Data, please contact us at [email protected].
If you are between 13 and the age of majority in your jurisdiction, you may use the Services only with the consent of or under the supervision of your parent or legal guardian. If you are a parent or legal guardian of a minor child, you may, in compliance with the Agreement, use the Services on behalf of such minor child. Any information you provide while using the Services on behalf of your minor child will be treated as Personal Data as otherwise provided herein. Information about a pediatric patient that a Healthcare Provider maintains through the Practice Services is Practice Data and PHI processed on behalf of the Healthcare Provider under HIPAA, and is not information collected by TopDoc directly from a child.
How We Use Information That is Neither Personal Data nor PHI
Certain information that TopDoc collects may be neither Personal Data nor PHI, including information that does not include any identifiable information at collection or which we have de-identified and aggregated. We may use this information for any purpose permitted by applicable law, including to better understand who uses TopDoc and how we can deliver a better digital healthcare experience.
Controlling Your Personal Data & Notifications
If you are a registered User, you can modify certain Personal Data or account information by logging in and accessing your account. If you wish to close your account, please email us at [email protected]. We will use reasonable efforts to delete your account as soon as reasonably possible. TopDoc reserves the right to retain information from closed accounts consistent with our internal data retention policies and procedures. You must promptly notify us if any of your account data is lost, stolen, or used without permission.
State Privacy Rights
Depending on where you live, you may have rights under state privacy laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”) and the comprehensive privacy laws of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, and other states as they take effect. Subject to the exceptions in those laws, these rights include:
- Access: request information about our collection and use of your Personal Data, including the categories of Personal Data we have collected, the categories of sources, the business or commercial purpose, the categories of third parties with whom we have shared it, and the specific pieces of Personal Data we have collected about you.
- Portability: request a copy of your Personal Data in a portable and readily usable format.
- Deletion: request that we delete the Personal Data we have collected from you (subject to exceptions, such as our need to retain it to provide you with the Services or to comply with law).
- Correction: request that we correct inaccurate Personal Data we have collected about you.
- Limit Use of Sensitive Personal Information: direct us to limit our use of your sensitive Personal Data to what is necessary to perform the requested services.
- Opt Out of Sale, Sharing, Targeted Advertising, and Profiling: opt out of the “sale” or “sharing” of your Personal Data for cross-context behavioral or targeted advertising, and of profiling that produces legal or similarly significant effects. We do not sell Personal Data. We share device, web-analytics, and IP-based location information collected on our public web pages with advertising and analytics partners, which may be considered “sharing” for cross-context behavioral advertising under the CCPA; we do not share Contact Data, Demographic Data, Medical Data, Insurance Information, or Booking Appointment Data for these purposes. You may opt out by enabling the Global Privacy Control in your browser, through the DAA or NAI opt-out tools described above, or by emailing [email protected].
- Appeal: if we decline to act on your request, you may appeal by emailing [email protected] with “Privacy Appeal” and your state in the subject line. We will respond within the time required by your state’s law, and if we deny your appeal you may contact your state’s Attorney General.
These rights generally do not apply to PHI or other information governed by HIPAA, which your Healthcare Provider handles as described in the HIPAA section above; please direct requests about your medical or billing records to your Healthcare Provider. We will not discriminate against you for exercising your rights; we will not deny you our goods or services, charge you different prices, or provide you with a lower quality of service. From time to time we may offer a financial incentive in exchange for your participation in user research; participation is entirely optional and you may withdraw at any time. Under California Civil Code Sections 1798.83-1798.84, California residents may contact us at [email protected] to prevent disclosure of Personal Data to third parties for those third parties’ direct marketing purposes.
Consumer Health Data. If you are a resident of Washington, Nevada, or Connecticut, health-related information about you that is not PHI may be “consumer health data” under those states’ laws. We collect and use such data only as described in this Privacy Policy, do not sell it, and do not share it for advertising. You may exercise the rights described above with respect to consumer health data, and Washington residents may also request a list of the third parties with whom we have shared it, by contacting us as described above.
Exercising Your Rights
To exercise the rights described above, send us a request that (1) provides sufficient information to allow us to verify that you are the person about whom we have collected Personal Data and (2) describes your request in sufficient detail to allow us to understand, evaluate, and respond to it. Each request that meets both of these criteria will be considered a “Valid Request.” You do not need an account to submit a Valid Request. We will respond within the applicable time period required by law and will not charge you a fee unless your request is excessive, repetitive, or manifestly unfounded. Submit a Valid Request by emailing us at [email protected].
Changes to this Privacy Policy
We reserve the right to amend our Privacy Policy at our discretion and at any time. When we make changes, we will notify you by email or through a notice on our website homepage. Use of the information we collect is subject to the Privacy Policy in effect at the time such information is collected.
Contact Information
If you have any questions or comments about this Privacy Policy, the ways we collect and use your Personal Data, or your choices and rights, please contact us at:
- Email: [email protected]
- Address: Topdoc, Inc., 232 Mott Street, Unit 2, New York, NY 10012
- Phone: (347) 604-7436