NoTimeRx Privacy Policy
Effective date: August 22, 2026 · Last updated: September 11, 2026
Independent licensed healthcare providers make medical and prescribing decisions.
When HIPAA applies, PHI is handled under HIPAA, applicable agreements, and the Provider's Notice of Privacy Practices.
We do not sell PHI or use identifiable clinical information as an advertising audience.
1. Scope and Who We Are
This Privacy Policy describes how Biotica Consulting LLC d/b/a NoTimeRx ("NoTimeRx," "we," "us," or "our") collects, uses, discloses, retains, and protects personal information when you use the NoTimeRx website, patient-facing technology, intake tools, messaging features, administrative services, payment and fulfillment workflows, and related services (collectively, the "Services").
NoTimeRx is a non-clinical management services organization ("MSO") and technology platform. NoTimeRx does not independently practice medicine, diagnose conditions, determine medical necessity, or make prescribing decisions. Medical care is provided by independent licensed healthcare providers and professional medical entities ("Providers"). Pharmacies, laboratories, payment processors, carriers, and other third parties involved in a service may have their own privacy obligations and privacy notices.
This Privacy Policy applies to information handled by NoTimeRx. It works together with any applicable HIPAA Notice of Privacy Practices, Telehealth Consent, Terms of Use, cookie controls, and other notices presented when information is collected. If HIPAA applies to particular information, HIPAA and the applicable Notice of Privacy Practices govern that PHI.
2. NoTimeRx, Providers, and HIPAA
When NoTimeRx creates, receives, maintains, or transmits PHI on behalf of a HIPAA covered Provider or other covered entity while performing administrative, technology, practice management, or related services, NoTimeRx may act as that entity's Business Associate. In that role, NoTimeRx handles PHI only as permitted by HIPAA, applicable law, and the relevant Business Associate Agreement.
The independent Provider remains responsible for medical judgment, clinical documentation, treatment decisions, prescribing, and the Provider's obligations to patients under applicable healthcare law. HIPAA rights relating to a Provider's designated record set, including access or amendment rights, may be fulfilled by the Provider with assistance from NoTimeRx where appropriate.
NoTimeRx may also handle information in circumstances where HIPAA does not apply. This Privacy Policy describes our practices for that information as well.
3. Information We May Collect
Account and identity information
- Name, email address, telephone number, date of birth, account credentials, and contact information.
- Billing and shipping address, state of residence, and information used to determine service availability.
- Identity-verification information where needed to confirm identity, age, eligibility, reduce fraud, or support regulated workflows.
Health and care-related information
- Medical history, symptoms, diagnoses reported by you, allergies, current medications, supplements, prior treatments, and treatment preferences.
- Questionnaire and intake responses, photographs or documents you upload, laboratory information, pharmacy information, and information related to a requested treatment.
- Provider communications, care-related messages, prescription and fulfillment information, and other information generated through a clinical workflow.
Transaction and fulfillment information
- Order history, subscription status, amounts charged, refunds, transaction identifiers, and limited payment metadata.
- Payment-card information is generally transmitted to authorized payment processors rather than stored as a complete card number by NoTimeRx.
- Shipping status, carrier events, delivery address, and fulfillment information needed to coordinate an order.
Communications and support information
- Messages you send to customer support, Providers, pharmacies, or other participants through the Services.
- Emails, portal messages, service requests, complaints, feedback, and records of administrative communications.
Device and usage information
- IP address, browser type, device type, operating system, approximate location derived from network information, and security-related device signals.
- Pages or features used, timestamps, referral information, session events, error logs, and other technical information needed to operate and secure the Services.
4. Where Information Comes From
We may receive information:
- Directly from you when you create an account, complete an intake, upload a document or image, place an order, make a payment, or contact us.
- From independent Providers when they use the platform to document or coordinate care.
- From pharmacies, laboratories, fulfillment partners, and other service participants when needed to coordinate a service you requested.
- Automatically from your browser, device, cookies, security tools, and similar technologies when you use the Services.
- From vendors that help with identity verification, fraud prevention, payments, infrastructure, communications, or account security.
5. How We Use Information
Depending on the type of information and the context in which we receive it, we may use information to:
- Operate, maintain, secure, troubleshoot, and improve the Services.
- Create and maintain accounts and authenticate users.
- Route intake information and patient requests to an appropriate independent Provider.
- Support Provider workflows, secure communications, documentation, prescriptions, pharmacy coordination, laboratory coordination, and follow-up.
- Verify identity, age, state, location, eligibility, and other information relevant to lawful telehealth or fulfillment workflows.
- Process payments, subscriptions, refunds, billing events, and fraud reviews.
- Coordinate pharmacy fulfillment, shipping, tracking, and customer support.
- Detect, investigate, prevent, and respond to fraud, abuse, diversion, security incidents, prohibited conduct, and technical problems.
- Maintain records, audit activity, enforce our agreements, and comply with legal, regulatory, tax, accounting, and reporting obligations.
- Develop statistics, operational metrics, and service improvements using information that has been appropriately de-identified or aggregated when required.
6. Clinical Information and Access Controls
We treat clinical information differently from ordinary website and administrative data. Access to sensitive information is intended to be limited according to role, job function, operational need, and applicable law. Provider-facing clinical functions are intended for authorized clinical users, while non-clinical personnel use the information reasonably necessary to perform permitted administrative, technical, payment, fulfillment, compliance, or support functions.
NoTimeRx does not use administrative control over the platform to substitute its judgment for the professional judgment of an independent Provider. NoTimeRx also does not use a solely automated system to independently decide whether you should receive a prescription. Clinical prescribing decisions are made by the independent Provider.
7. When We May Disclose Information
We may disclose information in the following circumstances, subject to applicable law:
Providers and professional medical entities
We disclose information to the Provider responsible for evaluating or treating you so the Provider can review your request, communicate with you, document care, make clinical decisions, and coordinate treatment.
Pharmacies and laboratories
Information may be transmitted to a pharmacy or laboratory when needed to fill a valid prescription, perform testing, communicate results, coordinate fulfillment, or support a service ordered or authorized by a Provider.
Vendors and service providers
We use vendors for functions such as hosting, communications, security, identity verification, payments, customer support, analytics, and technical operations. When a vendor creates, receives, maintains, or transmits PHI on behalf of a regulated entity and qualifies as a Business Associate or subcontractor, appropriate HIPAA contractual protections are required. Other vendors may operate under confidentiality, data protection, or service-provider obligations appropriate to their role.
Shipping and fulfillment
We may provide a carrier or fulfillment service with information reasonably necessary to prepare and deliver an order, such as your name, delivery address, contact details, order identifier, and delivery instructions. We seek to avoid disclosing unnecessary clinical information in ordinary shipping workflows.
Legal, regulatory, and safety obligations
We may use or disclose information when required or permitted by law, including in response to lawful process, regulatory requests, licensing obligations, audits, fraud investigations, public-health requirements, or circumstances involving protection of rights, security, or safety. Where legally appropriate, we seek to limit a disclosure to information reasonably necessary for the applicable purpose.
Business transactions
Information may be reviewed or transferred in connection with a financing, merger, acquisition, reorganization, sale of assets, or similar corporate transaction, subject to applicable confidentiality, privacy, and legal obligations. PHI remains subject to applicable HIPAA requirements where HIPAA continues to apply.
8. What We Do Not Do With Health Information
NoTimeRx does not sell Protected Health Information to data brokers, advertisers, or other third parties.
We do not provide identifiable clinical information to advertising networks for their independent cross-context behavioral advertising.
Advertising relationships, if any, do not determine whether an independent Provider prescribes a medication or recommends a treatment.
If a use or disclosure of PHI requires a HIPAA authorization, that authorization must satisfy HIPAA requirements. A general cookie banner or acceptance of this Privacy Policy is not a substitute for a HIPAA authorization.
9. Cookies, Analytics, and Tracking Technologies
We may use cookies, local storage, logs, and similar technologies to operate the website, remember preferences, maintain sessions, prevent fraud, understand performance, and improve the public-facing experience.
We take special care with authenticated patient areas, intake workflows, and other pages that may involve PHI. Third-party tracking technologies must not be configured to impermissibly disclose PHI. Where a tracking vendor receives PHI on behalf of a HIPAA regulated entity, HIPAA requirements, including an appropriate Business Associate Agreement when required, apply.
Where required by applicable privacy law, we honor legally recognized opt-out preference signals for processing to which those signals apply. Cookie and privacy controls may also be available through the website footer or consent interface.
10. Security
We maintain administrative, technical, and organizational safeguards designed to protect personal information and PHI against unauthorized access, use, disclosure, alteration, and destruction. Depending on the system and information involved, safeguards may include encryption, authentication controls, role-based permissions, audit logging, monitoring, secure development practices, vendor oversight, backups, access reviews, incident response, and workforce privacy and security requirements.
Security controls evolve as technology, threats, legal requirements, and our Services change. No internet-connected system can be guaranteed to be completely secure, and this Privacy Policy does not create a guarantee that a security incident can never occur.
If we become aware of a breach or security incident that requires notice under HIPAA, a state breach-notification law, or another applicable law, we will provide or support legally required notices as applicable to our role.
11. Data Retention
We retain information for as long as reasonably necessary for the purposes described in this Policy, to provide the Services, maintain transaction and security records, resolve disputes, enforce agreements, and satisfy legal, regulatory, tax, accounting, pharmacy, healthcare, and recordkeeping obligations.
Medical-record retention periods vary by state, Provider type, patient age, and the type of record. NoTimeRx may retain PHI on behalf of a Provider for the period required by the Provider, applicable law, or our agreements. Closing an account does not automatically require deletion of information that must be preserved for medical, legal, fraud-prevention, security, accounting, or regulatory reasons.
When information is no longer required, we may delete it, destroy it, de-identify it, or aggregate it in accordance with applicable requirements.
12. Your Privacy Rights
Your rights depend on what information is involved, why it is held, where you live, and which laws apply.
HIPAA rights
If information is PHI maintained for a HIPAA covered Provider, you may have rights described in that Provider's HIPAA Notice of Privacy Practices, such as rights to access or obtain copies of certain records, request amendment, request certain restrictions, request confidential communications, or receive an accounting of certain disclosures. NoTimeRx may assist the Provider in fulfilling these requests where required by our role.
State privacy rights
Depending on your state and whether a particular privacy law applies to NoTimeRx or the information at issue, you may have rights to:
- Know or access categories or specific pieces of personal information we maintain about you.
- Correct inaccurate personal information.
- Delete certain personal information, subject to legal exceptions and record-retention obligations.
- Receive certain information in a portable format.
- Opt out of certain sales, sharing, targeted advertising, or profiling where those rights apply.
- Limit certain uses or disclosures of sensitive personal information where applicable.
- Appeal a denial of a privacy request where applicable law provides an appeal right.
- Exercise privacy rights without unlawful discrimination.
NoTimeRx does not sell PHI. We also do not sell personal information as a business model. If our practices change in a way that creates a legally defined sale or sharing right, we will provide the notices and controls required by applicable law before relying on that practice.
How to submit a request
Email privacy@notimerx.com using the email address associated with your account when possible. We may need to verify your identity before fulfilling a request. Authorized agents may submit requests where permitted by law, subject to appropriate verification.
We respond within the period required by the law that applies to the request. Different laws use different response periods, extensions, verification standards, and exceptions.
13. Consumer Health Data Laws
Some states have enacted laws that protect certain consumer health information even when that information is outside HIPAA. Where one of those laws applies, we will process covered consumer health data in accordance with the rights, consent requirements, disclosure restrictions, and other obligations applicable to our role.
Certain states may require a separate consumer health data privacy notice rather than using a general privacy policy for that purpose. Where required, an additional state-specific notice may be provided separately.
14. De-Identified and Aggregated Information
We may create or receive information that has been de-identified or aggregated so that it does not identify you as required under the applicable legal standard. We may use such information for service improvement, operational planning, security analysis, quality measurement, statistics, and other lawful business purposes.
When HIPAA de-identification requirements apply, information treated as de-identified PHI is handled in accordance with the applicable HIPAA standard. We do not represent information as de-identified merely because obvious identifiers have been removed if the applicable law requires a stronger standard.
15. Communications and Marketing
We may send transactional, operational, account, fulfillment, legal, security, and care-related communications needed to provide or administer the Services. You may also receive marketing communications where permitted by law and consistent with your choices.
SMS and Mobile Information
If you provide your mobile telephone number and consent to receive SMS messages from NoTimeRx, we may use that number to send transactional messages such as one-time passcodes, login verification, account-security notifications, and other account-related communications you request. Message frequency varies and message and data rates may apply. You may reply STOP to opt out or HELP for assistance. Mobile telephone numbers, SMS opt-in information, and SMS consent records are not sold, rented, or shared with third parties or affiliates for their marketing or promotional purposes. We may disclose mobile information to communications service providers and other vendors solely as necessary to deliver, secure, and operate our messaging services on our behalf and subject to appropriate confidentiality and data-protection obligations.
You can unsubscribe from marketing email using the unsubscribe control in the message. Opting out of marketing does not prevent us or other authorized participants from sending non-marketing communications that are needed for your account, an order, legal compliance, security, or care coordination.
PHI is not used for marketing in a manner that requires HIPAA authorization unless a valid authorization or another lawful basis exists.
16. Minors
The Services are intended for adults age 18 and older unless a specific service expressly states otherwise and is implemented in accordance with applicable law. We do not knowingly invite children under 18 to create ordinary patient accounts through Services that are designated for adults.
17. U.S. Services and Data Processing
NoTimeRx's patient-facing telehealth Services are directed to users in the United States. Information may be processed and stored in the United States and is subject to applicable U.S. federal and state law. Availability of a particular service depends on Provider licensure, patient location, pharmacy availability, and other legal and operational requirements.
18. Changes to This Policy
We may update this Privacy Policy as our Services, technology, vendors, or legal obligations change. When we make changes, we will update the date at the top of this page. Where required by law, we will provide additional notice or obtain consent before applying a materially different practice to information already collected.
19. Contact Us
For privacy questions or requests, contact:
Biotica Consulting LLC d/b/a NoTimeRx
Attn: Privacy
1404 Oak Tree Rd
Ste 4 #282
Iselin, NJ 08830
USA
Email: privacy@notimerx.com