Effective Date: August 28, 2026
This Statement explains how Koble Cares (“Koble Cares,” “we,” “us,” or “our”) approaches compliance with the Health Insurance Portability and Accountability Act (“HIPAA”) in connection with our patient advocacy platform. It is not a HIPAA Notice of Privacy Practices. If you are a patient, the Notice of Privacy Practices from your own healthcare provider describes your rights and how your provider may use your health information. This Statement also does not replace the Business Associate Agreement between Koble Cares and each partner practice.
Koble Cares acts as a “Business Associate,” as defined at 45 CFR §160.103, to the physician practices, medical groups, and health systems (“Covered Entities”) we partner with. We do not provide medical treatment, and we are not a healthcare provider or health plan.
Before any Protected Health Information (“PHI”) is accessed through our platform, we enter into a Business Associate Agreement with the partner practice governing our permitted uses and disclosures of PHI.
Koble Cares is a business associate because our platform receives, maintains, and transmits PHI on behalf of partner practices — for example, when our application runs inside a practice’s electronic health record, when eligibility results are displayed in the practice’s dashboard, and when a patient’s authorization is recorded. Each Business Associate Agreement limits how we may use and disclose PHI, and we require the same written commitments from any subcontractor that handles PHI for us (45 CFR §164.502(e) and §164.504(e)).
Administrative safeguards:
Physical safeguards:
Technical safeguards:
A patient identified through the platform is not contacted by Koble Cares directly. Their own physician’s practice sends an outreach communication under the practice’s name. Only if the patient signs a HIPAA authorization is any information shared with a resource partner. Declining has no effect on the patient’s care, and a patient who has authorized sharing may revoke that authorization in writing at any time, except to the extent Koble Cares or the resource partner has already acted on it (45 CFR §164.508(b)(5)).
How Koble Cares is paid. Koble Cares does not charge partner practices. We are compensated by resource partners when a patient who has authorized sharing is connected to that partner. We disclose this to patients before they decide, and the partner practice does not receive any payment for sending outreach.
A patient’s treating provider — not Koble Cares — is the HIPAA Covered Entity responsible for the patient’s medical record. Requests to access, amend, or receive an accounting of disclosures of PHI should be directed to the healthcare provider as described in its Notice of Privacy Practices. When a practice asks us to, we will make PHI we hold available so the practice can respond to those requests, and we will record disclosures we make so the practice can include them in an accounting (45 CFR §164.504(e)(2)(ii)). Patients may also contact our Privacy Officer directly (Section 12) with questions or to revoke an authorization.
You may also file a complaint with the U.S. Department of Health and Human Services, Office for Civil Rights, at www.hhs.gov/ocr.
If Koble Cares discovers a breach of unsecured PHI, we will notify the affected partner practice without unreasonable delay and in no case later than the deadline in our Business Associate Agreement, which is always shorter than the 60-day outer limit in the HIPAA Breach Notification Rule (45 CFR §164.410). The practice, as the Covered Entity, is responsible for notifying affected patients, HHS, and (where required) the media. We also comply with state breach notification laws that apply to personal information we hold.
Where a Business Associate Agreement permits it, Koble Cares may de-identify PHI and use the de-identified data for platform improvement, matching accuracy, or research. That data is de-identified consistent with the HIPAA de-identification standard at 45 CFR §164.514.
Koble Cares uses machine learning and natural language processing to flag patients whose records may match an opportunity. These tools do not make medical decisions and do not contact anyone on their own. The partner practice reviews flagged matches and decides whether to send outreach, and every outreach message is approved by the practice before it is sent.
Some information we handle is not PHI — for example, business contact details for practice staff, or information a person sends us directly through our website. That information is covered by our Privacy Policy and by federal and state consumer protection laws, including Section 5 of the Federal Trade Commission Act and state privacy laws.
We may update this Statement from time to time to reflect changes in our practices or applicable law. The current version will always be posted on our website with its effective date.
Questions about this Statement can be emailed to privacy@joinkoblecares.com or submitted through our Contact Us form. You may also write to:
Koble Cares
Attn: Privacy & Security Officer
Arizona, United States