MHEA logo

MHEA

Maternal Health Equity Access

Honoring Mothers. Protecting Futures. Uniting Generations.

MHEA -- Maternal Health Equity Access

Privacy Policy

Effective Date: August 1, 2026 | Last Updated: July 22, 2026

1. Who We Are

MHEA (Maternal Health Equity Access) is a digital health platform operated by MHEA Inc., a Delaware corporation. We provide remote patient monitoring, health information, and care coordination services for pregnant and postpartum patients, with a focus on reducing maternal health disparities in Black and underserved communities. Our platform is accessible at mhea.health and its associated subdomains.

Contact: privacy@mhea.health

2. Information We Collect

2.1 Information You Provide

  • Account information: name, email address, date of birth, expected due date
  • Health information: blood pressure readings, mood scores, symptoms, sleep hours, medication list, birth plan preferences
  • Insurance and billing information: insurance plan name (not financial account numbers)
  • Communications: messages sent through the MHEA Secure Messenger
  • Consent records: records of authorizations you have signed

2.2 Information We Collect Automatically

  • Device readings: blood pressure and vital sign data from connected Withings and Fitbit devices
  • Usage data: check-in completion rates, feature usage (never sold or used for advertising)
  • Technical data: device type, operating system, session identifiers

2.3 Information from Third Parties

  • CRISP (Maryland Health Information Exchange): with your explicit authorization, we access your health history from CRISP to provide better care coordination
  • Medplum FHIR server: clinical data from your care providers when shared through interoperable health records

3. How We Use Your Information

We use your health information exclusively to provide the MHEA service. Specifically:

  • To generate health alerts and flags for your care team when your readings indicate a potential concern
  • To create pre-appointment briefs for your providers summarizing your between-visit health data
  • To send you check-in reminders and appointment notifications
  • To operate the Ubuntu Network medical blockchain record system on your behalf
  • To process RPM (Remote Patient Monitoring) insurance billing under CPT codes 99454 and 99457
  • To comply with legal obligations and respond to legal process

We do NOT use your health information for advertising, marketing profiling, or sale to third parties under any circumstances.

4. HIPAA Notice of Privacy Practices

MHEA is a covered entity under the Health Insurance Portability and Accountability Act (HIPAA). Your health information is Protected Health Information (PHI) under HIPAA. This Privacy Policy serves as our Notice of Privacy Practices required by HIPAA.

4.1 Your HIPAA Rights

  • Right to access: You may request a copy of your health records at any time through the MHEA app under Settings → Data Export
  • Right to amendment: You may request corrections to your health information
  • Right to restriction: You may request restrictions on how we use or disclose your information
  • Right to accounting: You may request a list of disclosures of your health information
  • Right to deletion: You may request deletion of your account. We will destroy your encrypted vault records within 30 days. Some records may be retained as required by law.
  • Right to complain: You may file a complaint with HHS Office for Civil Rights at hhs.gov/ocr without retaliation

4.2 How We May Disclose Your PHI

  • Treatment: to your physicians, nurses, and care coordinators involved in your care
  • Payment: to insurance companies for RPM billing claims
  • Healthcare operations: for quality improvement, care coordination, and platform improvement
  • As required by law: court orders, mandatory reporting requirements, public health authorities
  • With your authorization: CRISP data sharing, family member access, and Makoto AI training data (each requires separate, explicit consent)

5. 42 CFR Part 2 -- Substance Use Disorder Records

Federal law (42 CFR Part 2) provides special protections for records related to substance use disorder treatment. These records require your separate, explicit authorization before they can be accessed or shared by MHEA. We store substance use disorder records in a separate, encrypted partition that is accessible only with your distinct 42 CFR Part 2 consent. This consent is separate from your HIPAA authorization and can be revoked independently.

6. Ubuntu Network and Blockchain Records

MHEA uses the Ubuntu Network Medical Blockchain to give you control over your health records. Your MATRIARCH token is a unique, non-transferable digital identity token that you hold. Records anchored to the blockchain are encrypted such that only you hold the decryption key.

Deleting your MHEA account destroys your encryption key, rendering all blockchain-anchored records permanently inaccessible. The cryptographic hash of those records remains on the blockchain (it cannot be deleted from a public ledger) but without your key, the underlying data is unrecoverable. This mechanism satisfies your HIPAA right to deletion.

7. Children's Privacy (COPPA)

The PIA (Pediatric Interdisciplinary Access) platform within MHEA collects health information about children. We collect this data only with explicit parental consent under the Children's Online Privacy Protection Act (COPPA). Parents may review, correct, or delete their child's health information at any time. We never use children's health data for any purpose other than providing the PIA health monitoring service.

8. Data Security

We implement the following technical safeguards to protect your health information:

  • Encryption at rest: all PHI is encrypted using AES-256 encryption via AWS KMS with automatic key rotation
  • Encryption in transit: all data transmitted between your device and MHEA servers uses TLS 1.3
  • Access controls: role-based access control ensures each care team member sees only the data required for their role
  • Immutable audit log: every access to your health data is logged permanently and cannot be modified or deleted
  • Session timeout: all MHEA portals automatically sign out after 15 minutes of inactivity
  • Multi-factor authentication: required for all provider accounts

9. Data Retention

  • Health records: retained for 6 years from the date of creation as required by HIPAA
  • Audit logs: retained for 6 years in an immutable archive
  • Account data: deleted within 30 days of account deletion request, subject to legal retention requirements
  • Training data (if consented): de-identified records retained for model training purposes; withdrawal of consent does not affect previously trained model weights

10. Your Choices

  • CRISP authorization: you may revoke MHEA's access to your CRISP records at any time through Settings
  • Family member access: you control which family members see limited information about your health through the Ubuntu Wallet
  • Training data consent: you may withdraw consent for Makoto AI training data use at any time with no effect on your care
  • Account deletion: you may request account deletion at any time through Settings → Account → Delete Account

11. Changes to This Policy

We will notify you of material changes to this Privacy Policy through the MHEA app and by email at least 30 days before the changes take effect. Your continued use of MHEA after the effective date constitutes acceptance of the revised policy.

12. Contact Us

Privacy Officer: privacy@mhea.health

MHEA Inc.

Baltimore, Maryland

To exercise your HIPAA rights or file a privacy complaint, contact privacy@mhea.health or the HHS Office for Civil Rights at hhs.gov/ocr.