Skip to main content

Privacy Policy

Last updated: August 2026

myDxHub is a platform for patient-owned health records. Privacy is not a side concern for us; it is the product. This policy explains, in plain language, what information we handle, why, and the choices you have.

Who we are

myDxHub (“we”, “us”) operates a secure platform that connects practices, diagnostic laboratories, and patients. Dental practices order tests, laboratories return results, and patients access their own records through a personal portal.

Information we collect

We handle the following categories of information:

  • Account information: name, email address, phone number, and login credentials (managed through our identity provider; we never store your password in plaintext).
  • Health information: lab test results, biomarker data, x-rays and other imaging, reports, and related clinical records created by your practice or its laboratories. This is protected health information (PHI).
  • Order information: products purchased in our store, shipping contact details, and payment status. Card details go directly to our payment processor (Stripe); we never see or store your full card number.
  • Usage and audit data: records of who accessed which records and when. We keep these logs to protect you: they power the access history shown in your portal.

How we use your information

  • To deliver your test results to you and to the providers you have authorized.
  • To generate reports, trends, and plain-language summaries of your results.
  • To fulfill store orders and provide customer support.
  • To send service emails, such as result notifications and retest reminders.
  • To secure the platform: audit logging, fraud prevention, and abuse detection.

We do not sell your personal or health information, and we do not use your health information for advertising.

HIPAA and protected health information

Health information on myDxHub is handled in accordance with the Health Insurance Portability and Accountability Act (HIPAA). We act as a business associate of the practices that use our platform and enter into business associate agreements governing how PHI is handled.

Our safeguards include:

  • Encryption of all data in transit and at rest.
  • Row-level security in our database, so every query is scoped to the requesting user.
  • Audit logging of access to patient records.
  • Role-based access control: staff, providers, and administrators each see only what their role permits.

When we share information

We share information only in these circumstances:

  • With your care team: the providers and practice staff connected to your record. You can see and manage this list from the Privacy & Access section of your portal.
  • With people you choose: when you create a secure share link for a report, the recipient can view it until the link expires or you revoke it.
  • With service providers: vendors that host and operate the platform on our behalf (such as our cloud infrastructure and payment processor), bound by contractual confidentiality and, where PHI is involved, business associate agreements.
  • When required by law: in response to valid legal process, or to protect the rights and safety of our users and the public.

Your choices and rights

  • View every provider with access to your record, and revoke or restore that access at any time from your portal.
  • Review the access history of your records.
  • Create, monitor, and revoke secure share links.
  • Download a complete export of your records from your portal.
  • Request correction or deletion of your information by contacting support@mydxhub.com. Some records must be retained where the law or your practice's obligations require it.

Data retention

We keep your health records for as long as you have an account. We do not delete them just because they have reached a certain age, because a record you may need later is not less yours for being old. If you want something removed, ask us and we will remove it, except where a law requires us to keep it.

Access is separate from storage, and it is the part that expires. When you stop a provider’s access, anything they never opened becomes unavailable to them immediately, and anything they did open stays available to them for 30 days and then lapses. You can see exactly what is still held, and when each item lapses, on the Privacy & access tab of your dashboard.

Audit logs are kept separately and for longer, because security and compliance obligations require it. Those records say who looked at what, not what your results were, and they are not removed on request.

Security

No system is perfectly secure, but we build for security first: encrypted storage and transport, strict access controls, continuous audit logging, and monitoring of our infrastructure. If a breach affecting your information ever occurs, we will notify you and the relevant authorities as required by law.

Children

Patient records for minors are established and managed through the minor's practice with parental or guardian involvement. myDxHub is not directed to children, and we do not knowingly collect information from children outside of that provider-managed context.

Changes to this policy

If we make material changes to this policy, we will update the date above and notify you through the platform or by email before the changes take effect.

Contact us

Questions about privacy or this policy? Email us at support@mydxhub.com.