← Back to Home

HIPAA Compliance Statement

Unity Global Care, Inc. | ALBERTai

Effective Date: March 3, 2026 · Last Revised: Aug 3, 2026

1. OUR COMMITMENT TO PROTECTING HEALTH INFORMATION

Unity Global Care®, Inc. (“Unity Global Care,” “Company,” “we,” “us,” or “our”) treats the privacy and security of health information as a core obligation. This statement describes the role we occupy under the Health Insurance Portability and Accountability Act of 1996, as amended, including the HITECH Act, and their implementing regulations at 45 C.F.R. Parts 160, 162, and 164 (collectively, “HIPAA”), and the safeguards we apply to Protected Health Information (“PHI”) that we receive, create, maintain, or transmit.

Unity Global Care operates two customer-facing platforms: a business-to-business platform (“B2B”) and a business-to-consumer platform (“B2C”), each accessible through both web and mobile applications (collectively, the “Platforms”). Our obligations under HIPAA, and the role we occupy, differ across the Platforms according to the services we render and the nature of the information we process.

This statement should be read together with our Privacy Policy, which governs personal information generally, and our Terms of Use, which govern access to and use of the Platforms.

2. OUR ROLE UNDER HIPAA

2.1 B2B Platform

When we provide services to business customers that qualify as Covered Entities or Business Associates, including health care providers, health plans, employers, payers, senior living operators, care management organizations, and community-based organizations, and those customers submit, transmit, receive, or store PHI through our B2B web or mobile application, Unity Global Care acts as a Business Associate or Subcontractor. In that capacity:

2.2 B2C Platform

When individuals use our B2C web or mobile application directly to obtain an Aging-In-Place Score, to search for programs and services, or to apply for a need-based benefit, Unity Global Care is not a Covered Entity as that term is defined at 45 C.F.R. § 160.103. We are not a health care provider that conducts standard transactions electronically, a health plan, or a health care clearinghouse. Information you submit to us through the B2C Platform is therefore generally not PHI subject to HIPAA.

Where we deliver a B2C service on behalf of a Covered Entity customer, we act as that customer’s Business Associate, and the applicable BAA governs.

Should our service offerings change such that Unity Global Care meets the definition of a Covered Entity, we will maintain and publish a Notice of Privacy Practices describing how PHI is used, disclosed, and protected, and describing the rights of individuals under HIPAA, and we will revise this statement accordingly.

2.3 Information Outside HIPAA Is Still Protected

Health-related information that falls outside HIPAA is not unprotected. It remains subject to our Privacy Policy and to state law, including the consumer health data protections of the Washington My Health My Data Act, Nevada Senate Bill 370, and the Connecticut Data Privacy Act, which are described in Section 21 of the Privacy Policy, and the sensitive data protections of the comprehensive privacy laws described in Sections 14 through 19 of the Privacy Policy.

Where we receive substance use disorder treatment records from a program governed by 42 C.F.R. Part 2, we handle those records under that regulation and do not redisclose them except as it permits or with the individual’s written consent.

If you are unsure which role applies to your use of the Platforms, contact our Privacy Office using the information in Section 8.

3. ADMINISTRATIVE, PHYSICAL, AND TECHNICAL SAFEGUARDS

Consistent with the HIPAA Security Rule at 45 C.F.R. Part 164, Subpart C, we maintain an Information Security Program designed to protect the confidentiality, integrity, and availability of electronic Protected Health Information (“ePHI”) across all Platforms. Our safeguards include the following.

3.1 Administrative Safeguards

3.2 Physical Safeguards

3.3 Technical Safeguards

4. UNIFORM TREATMENT ACROSS WEB AND MOBILE APPLICATIONS

Our safeguards apply uniformly across the Platforms, without regard to the channel through which they are accessed.

On the B2B Platform, whether accessed through the web application or the mobile application, our handling of PHI is governed by the applicable BAA, and our obligations as a Business Associate or Subcontractor apply in full.

On the B2C Platform, whether accessed through the web application or the mobile application, our obligations as a Business Associate apply where we deliver the service on behalf of a Covered Entity customer. Where we do not, the information is governed by our Privacy Policy and by applicable state law as described in Section 2.3.

Mobile applications are held to the same encryption, authentication, audit logging, and access control standards as our web applications. Where an operating system or device-level constraint affects our ability to implement a specific safeguard, we implement compensating controls designed to achieve equivalent protection.

5. BREACH NOTIFICATION

In the event of a breach of unsecured PHI, we provide notification in accordance with the HIPAA Breach Notification Rule at 45 C.F.R. §§ 164.400 through 164.414, applicable state law, and the terms of any governing BAA.

Where we act as a Business Associate, notification to the applicable Covered Entity customer will be made without unreasonable delay and in no event later than sixty (60) calendar days following discovery of the breach, unless a shorter period is required by contract or by law. Many of our agreements specify a shorter period, and where they do, the agreement controls.

For information that falls outside HIPAA, we provide notification under applicable state breach notification law as described in Section 13 of our Privacy Policy.

6. INDIVIDUAL RIGHTS

To the extent we maintain PHI as a Business Associate, and are directed to act by the Covered Entity on whose behalf we hold it, individuals may have the following rights under HIPAA:

Rights that apply to information outside HIPAA. If your information is not PHI held under a BAA, your rights are those described in Sections 14 through 21 of our Privacy Policy, which include the rights to access, correct, delete, and obtain a copy of your information, to withdraw consent, to opt out of certain processing, and to appeal a denial. Requests under those provisions should be sent to UnityInfo@unityglobalcare.com. We will not treat a request differently because of which framework applies; where both could apply, we will apply the one that affords you greater protection.

7. NO WAIVER; RESERVATION OF RIGHTS

This statement does not expand, limit, or modify our obligations under any executed Business Associate Agreement, Master Services Agreement, or other contractual arrangement. In the event of a conflict between this statement and the terms of an applicable BAA, the BAA controls.

This statement is not a Notice of Privacy Practices and does not create rights in any third party. It is subject to change. We will post material updates and revise the “Last Revised” date when we do.

8. CONTACT OUR PRIVACY OFFICE

Questions about this statement, about our HIPAA compliance, or about our privacy practices, and requests to exercise rights described above, may be directed to:

Unity Global Care, Inc. Attn: Privacy Officer 203 Main Street, No. 179 Flemington, New Jersey 08822

Email: UnityInfo@unityglobalcare.com

Toll-free: 800.315.1217

You also have the right to file a complaint directly with the U.S. Department of Health and Human Services, Office for Civil Rights, at www.hhs.gov/ocr/complaints. We will not retaliate against you for filing a complaint.