Legal

Privacy policy

How theSleepMD collects, uses, and protects your personal and health information — on this site, in the SleepMD app, and in the messages we send you.

Last updated: September 2, 2026

The short version

  • We collect what we need to care for you: your contact details, your answers to sleep questionnaires, your insurance and payment information, the readings from a sleep-test device you use, and records your other clinicians send us.
  • We never sell your personal or health information, and we never share your phone number or your text-message consent for anyone else's marketing.
  • Your medical record is protected by HIPAA. Our Notice of Privacy Practices governs it; this policy explains everything else, including the website and the app.
  • You can ask for a copy of your record, ask us to correct it, or reach our privacy officer at any time — details at the bottom of this page.

Who this policy covers

theSleepMD is the patient-facing name of The Sleep Doctor PLLC, a physician-led sleep medicine practice with offices in Texas, California, Virginia, North Carolina, Georgia, Florida, and Washington, and telehealth visits across the country. This policy applies to thesleepmd.com, the SleepMD mobile app for iPhone and Android, our online booking and intake flows, the patient dashboard, and the emails and text messages we send you.

Information created or received while we care for you — your chart, test results, prescriptions, and clinical notes — is protected health information under HIPAA. Our Notice of Privacy Practices describes your rights over that information and controls wherever the two documents overlap. Ask any team member for a copy, or call the number at the bottom of this page.

Information we collect

Most of what we hold, you give us — while booking, during intake, or in a visit. Some arrives from other clinicians involved in your care, some is measured by a sleep-test device you wear, and a small amount is recorded automatically when you use the site or the app.

  • Account and contact details — your name, date of birth, phone number, email, mailing address, and the one-time codes used to sign you in.
  • Health information you enter — answers to sleep questionnaires such as STOP-BANG and the Insomnia Severity Index, symptoms, medications, allergies, height and weight, and photos or documents you upload for a clinician to review.
  • Sleep-test measurements — the readings a paired device records overnight, such as blood-oxygen level, pulse rate, and movement, along with the study file built from them.
  • Insurance and payment details — your carrier and member ID, images of your insurance card, and the card you pay with. Card numbers are handled by our payment processor; we keep only the card type and last four digits so you can recognize it.
  • Eligibility and identity documents — identification, and military, referral, or program documents when a program requires them.
  • Technical information collected automatically — IP address, device and browser type, app version, pages and screens viewed, and similar data recorded through cookies and diagnostics.
  • Information from others — referring clinicians, laboratories and sleep-testing partners, pharmacies, equipment suppliers, and health plans send us records related to your care.

The SleepMD app

The app does more than the website, so it asks for more from your phone. Every permission below is optional, requested the first time the feature needs it, and revocable in your phone's settings — declining one turns off that feature, not the app.

  • Bluetooth — to find, pair with, and read data from your sleep-test ring or monitor. We never scan for anything but supported devices, and the connection stays on your phone.
  • Camera — to scan the pairing code on a device, and to take a photo when a clinical step asks for one.
  • Photos and files — to attach an image or document you choose, such as an insurance card, a profile photo, or a completed form.
  • Microphone — only to record a voice note you send to your care team in a message. The app does not listen while you sleep.
  • Location — to work out your local sunrise and sunset for sleep timing, and because Android requires it to scan for Bluetooth devices. We do not track your movements or keep a location history.
  • Calendar and notifications — to add a visit you choose to add, and to schedule appointment and study reminders on your device.

Your overnight recording is captured on your phone and saved as a standard sleep-study file. To have it scored, we send that file to our sleep-study analysis partner with the identifiers needed to match it to you — your name, date of birth, sex, height, weight, phone number, and the device's model and serial number. The scored result comes back to your physician and into your chart. That partner works under a written agreement and may not use your information for anything else.

The app also holds your messages and attachments with the care team, the forms and consents you sign, your weight and wellness entries, your orders from the store, and support conversations. Sleep sessions and drafts are stored on your phone — in the app's private storage, with sign-in credentials in your device's encrypted keystore — and synced to your chart. Deleting the app removes those local copies; it does not delete your medical record, which we keep as the law requires.

The app carries no advertising. It ships with the advertising identifier removed, shows no ads, and sends no health information to advertising networks. Crash reports and basic usage counts help us fix what breaks; they describe the app and the device, not your health.

How we use your information

We use your information to care for you and to run the practice — not to build advertising profiles.

  • Providing care — reviewing your answers, ordering and interpreting home sleep tests, prescribing and adjusting treatment, and keeping your chart current.
  • Scheduling — booking, confirming, rescheduling, and reminding you about visits.
  • Verifying it's you — sending one-time codes, confirming a phone number belongs to you, and protecting your account and your session.
  • Payment and delivery — charging program fees and copays, billing your health plan, and shipping devices and supplies to your address.
  • Communicating with you — reminders, results, secure messages from your care team, and answers when you contact support.
  • Improving our programs — understanding which steps people find confusing, using aggregated or de-identified information.
  • Meeting legal obligations — record-keeping, public-health reporting, and responding to lawful requests.

Text messages and calls

We text you for three reasons: one-time sign-in codes, appointment reminders and scheduling, and messages from your care team. You agree to these when you give us your mobile number, and you can stop them at any time by replying STOP; reply HELP for help. Message and data rates may apply, and message frequency varies.

No mobile information is sold, rented, or shared with third parties or affiliates for their marketing purposes. Your phone number and your consent to be texted go only to the messaging providers that deliver our messages, and they may not use either for anything else.

Opting out of texts never affects your care — we'll reach you by phone, email, or mail instead.

How we share information

We do not sell your personal or health information, and we do not share it so that another company can advertise to you. We share it in these situations:

  • Your care team — the physicians, nurses, and staff involved in your treatment.
  • Service providers under contract — our electronic health record and telehealth platform, cloud hosting and databases, sleep-study scoring, payment processing, shipping carriers, text-message delivery, and the form and e-signature tools used during intake. Each is bound by a written agreement — a business associate agreement where HIPAA requires one — to protect your information and use it only for the work we've asked them to do. We'll name the current ones on request.
  • Health plans and payers — to check eligibility, obtain authorization, and be paid for your care.
  • Others involved in your treatment — laboratories and sleep-testing partners, pharmacies, and medical equipment suppliers.
  • When the law requires it — public-health reporting, court orders, subpoenas and other lawful process, and where necessary to prevent a serious threat to health or safety.
  • With your written authorization — anything else, including most marketing uses. You can revoke that authorization in writing at any time.

Cookies and analytics

Essential cookies keep you signed in, remember your language, protect your session from tampering, and end it after a period of inactivity. Booking and the patient dashboard can't work without them, so blocking them will sign you out.

On our public marketing pages we may also use Google Analytics and the Meta Pixel to see how people find the site and where they get stuck. Those events carry names only — never your name, phone number, visit type, or anything else you typed. We don't run advertising trackers inside the patient dashboard, the intake questions, or the app.

You can block or delete cookies in your browser settings and install Google's Analytics opt-out add-on. Because we don't sell or share personal information for advertising, there is nothing further to opt out of.

How we protect your information

Traffic between your device and our systems is encrypted. Access is limited to workforce members who need it for their job, patient records live in HIPAA-eligible systems covered by business associate agreements, and a signed-in session expires after a period of inactivity and is re-checked on every request.

No system is perfectly secure. Protect your part of it: keep your phone locked, never share a one-time code with anyone — we will never ask you for one — and tell us right away if you think someone else has access to your account.

How long we keep information

We keep medical records for as long as state and federal law require. In Texas that is at least seven years from the date we last treated you, and for a patient under 18, until their 21st birthday or seven years, whichever is longer. Other states where we practice may require longer, and we follow whichever rule applies to you.

Billing and insurance records follow the same schedule. Website logs, analytics, and unfinished intake answers are kept for a shorter period and then deleted or de-identified. Answers saved in your browser or in the app so you can close it and come back stay on your device until you finish or clear them.

Your rights and choices

For the medical record we hold about you, HIPAA gives you the right to:

  • Get a copy of your record, electronically or on paper.
  • Ask us to correct something you believe is wrong or incomplete.
  • Get a list of certain disclosures we have made.
  • Ask us to limit what we share, and to contact you at a particular number or address.
  • Receive a paper copy of our Notice of Privacy Practices, even if you agreed to receive it electronically.
  • Choose someone to act for you — a guardian or someone with medical power of attorney can exercise these rights.

For account and website information, you can update your details in the app or the dashboard, ask us to close your account, and opt out of marketing messages at any time. Residents of states with consumer privacy laws — including California, Virginia, and Texas — have additional rights over information that is not part of a medical record; most of the health information we hold is exempt from those laws because HIPAA already covers it.

To exercise any of these, call or write us with the details below. We'll confirm who you are before acting on a request, and we'll respond within the time the law allows — generally 30 days for a records request.

Children and teens

We treat pediatric patients, and a parent or legal guardian creates and manages the account, gives consent, and receives our messages. We don't knowingly collect information online directly from a child under 13 without a parent or guardian involved.

Some states give adolescents privacy over particular kinds of care. Where that applies, we follow state law, which may limit what a parent or guardian can see.

Other sites, apps, and stores

Some steps hand you to a partner — a hosted checkout page, a lab's portal, a pharmacy, or the Apple App Store and Google Play. Once you're there, that company's privacy policy applies, not ours. The SleepMD app follows this policy along with the data disclosures shown on its app store listing.

Changes to this policy

We update this policy as our practice and our systems change. The date at the top always reflects the current version. When a change materially affects how we handle your information, we'll tell you — by email, text, or a notice on this site — before it takes effect.

Contact us

Questions about this policy, or a request about your information? Reach our privacy officer:

By phone or text
(833) 327-5337
833-32-SLEEP
By fax
(855) 448-9510
By mail
Privacy Officer, The Sleep Doctor PLLC, 6960 Pitt St, El Paso, TX 79912

If you believe your privacy rights have been violated, you may file a complaint with us or with the U.S. Department of Health and Human Services, Office for Civil Rights, at hhs.gov/ocr/complaints. We will never retaliate against you for filing one.