Volta Health
← Back to Home

Legal

Privacy Policy

Last updated: June 2026

Applies to volta.health, indehealth.care, the Volta mobile application, and related websites and services.

Provider: indeHealth, Inc., doing business as Volta Health ("Volta," "we," "us," or "our")

The short version

Volta builds the software that universities and their health centers use to run immunization compliance, insurance plan administration, and revenue cycle management, and that students use through the Volta app. Handling health information carefully is the core of our business. In plain terms:

  • We do not sell your data. We do not sell your personal information, and we do not share it for advertising. We do not run interest-based or behavioral advertising on the Services.
  • Your health data is protected. Most clinical, immunization, insurance, and billing data is health information that we process on behalf of your university or its health center, under a written agreement and a HIPAA Business Associate Agreement. We use it only to provide the Services and at the institution's direction.
  • We secure it. We hold ourselves to recognized security standards (HIPAA, SOC 2 Type II, FERPA, etc.) and encrypt data in transit and at rest.
  • You stay in control. You have rights to access, correct, delete, and limit the use of your information, described in Section 12.

This summary is for convenience only and does not replace the full Policy below.

1. About this Policy and who we are

indeHealth, Inc., doing business as Volta Health, provides a software platform for higher-education health. Our products include the Volta student app, immunization compliance, insurance plan administration, and revenue cycle management ("RCM") for university health centers. This Privacy Policy explains how we collect, use, disclose, and protect personal information when you use the Services, and the rights and choices available to you.

This Policy is a description of our practices. It is not a contract, and it does not replace the agreements we enter with universities, health centers, consultants, insurance carriers, or insurance brokers, or any notice your university or its health center provides to you directly.

2. Our role, and which rules apply to your information

The Services bring together universities, their health centers, insurance carriers, insurance brokers, consultants, and students. Because of this, the same Policy can apply to you in different roles, and different legal frameworks apply depending on the type of information and on whose behalf we hold it. Understanding this section is the key to understanding the rest of the Policy.

2.1 When we act on behalf of your university or its health center (Business Associate / service provider)

When we handle clinical records, immunization records, insurance eligibility and enrollment data, claims, and billing information, we generally do so on behalf of your university or its health center, which is the entity responsible for that data. For information protected by the Health Insurance Portability and Accountability Act ("HIPAA"), we act as a HIPAA Business Associate under a Business Associate Agreement ("BAA") with the institution, which is the Covered Entity. In that role we use and disclose protected health information ("PHI") only as needed to provide the Services, at the institution's direction, and as permitted by the BAA and HIPAA, using the minimum information necessary. For that data, the institution's and its health center's privacy notices (including any HIPAA Notice of Privacy Practices) govern, together with the BAA. This Policy does not expand or override those obligations.

2.2 When we act on our own behalf (the focus of this Policy)

When you interact with our public websites, create and manage a Volta account, use general features of the app, or communicate with us directly, we act on our own behalf as the entity responsible for that information. This Policy primarily governs that information. Where information is subject both to a BAA and to this Policy, the BAA and HIPAA control for the PHI it covers.

2.3 State of California

Our Services are designed and operated for California institutions in compliance with California-specific requirements, including the California Confidentiality of Medical Information Act ("CMIA," Cal. Civ. Code §56 et seq.), the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), California breach-notification law, and applicable California Insurance Code provisions. Where we operate outside California, we apply the privacy laws of the relevant jurisdiction as described in Section 12.

3. Information we collect

3.1 Information you provide to us

  • Account and contact information such as your name, email address, phone number, and account credentials.
  • Profile and eligibility information such as insurance and enrollment details, waiver requests, and immunization records you choose to submit or authorize us to retrieve.
  • Information you submit through the app such as messages, requests, symptom summaries, survey responses, and well-being inputs you provide through the app, and the content of communications you send us.

3.2 Information we receive from your university, health center, and partners

We may receive information about you from your university or its health center, from insurance carriers and brokers involved in your health plan, and from medical-records and clearinghouse providers, for example enrollment status, coverage and eligibility, immunization records, and claims and billing data needed to provide the Services.

3.3 Information we collect automatically

When you use the Services we collect limited technical information such as device type, browser, IP address, app and page interactions, and similar usage data, through cookies and similar technologies. We use these for security, authentication, and to operate and improve the Services. We do not use them for advertising. See Section 9.

4. Health and other sensitive information

Much of the information involved in the Services is health information, and some of it is especially sensitive, including mental-health and emotional well-being information, and consumer health data as defined under laws such as Washington's My Health My Data Act and Nevada's SB 370. We treat this information as sensitive and protect it accordingly.

We collect and use sensitive and health information only to provide the Services, to meet legal and compliance obligations, and, for any optional sensitive features (such as well-being inputs), with your consent. You can decline or withdraw consent to optional features at any time.

We do not use health or other sensitive information for advertising, and we do not sell it.

Substance-use disorder records protected by 42 C.F.R. Part 2 receive the additional protections that law requires and are excluded from the de-identified-data uses described in Section 8.

5. How we use information

We use personal information to:

  • Provide the Services. Operate, provide, maintain, and secure the Services, including immunization compliance, insurance plan administration, RCM, and the student app.
  • Administration and billing. Verify eligibility, process waivers and enrollment, and prepare, submit, and follow up on insurance claims and billing on behalf of your health center.
  • Communicate with you. Respond to your requests, send service and transactional messages, and provide support.
  • Security and integrity. Protect against fraud, secure our systems, and investigate and prevent prohibited or illegal activity.
  • Legal compliance. Comply with legal, regulatory, accreditation, and contractual obligations.
  • Improve the Services. Improve and develop the Services, using de-identified and aggregated data as described in Section 8.

We do not use your personal information for interest-based or behavioral advertising, and we do not sell it.

6. Automated processing

We use automation and machine-learning tools to help operate the Services, for example to assist with insurance and billing workflows. We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing without a lawful basis and appropriate disclosure, and you may request information about, and where applicable opt out of, such processing as described in Section 12.

7. How we share information

We share personal information only as described below, and we require recipients who handle it on our behalf to protect it by contract. We do not sell personal information, and we do not share it for cross-context behavioral advertising.

  • Your university and its health center. We share information with your university and its health center, which are responsible for the underlying data and direct how it is used in the Services.
  • Insurance carriers and brokers. We share information with insurance carriers and brokers as needed to administer your student health plan, for example eligibility, enrollment, waivers, and claims.
  • Service providers and authorized partners. We share information with vendors who process it on our behalf, such as hosting, clearinghouses used for HIPAA-compliant electronic claims, and security providers. Each such partner that handles PHI executes a Subcontractor Business Associate Agreement with us and is bound by confidentiality and data-protection obligations.
  • Legal and safety. We may disclose information where required by law or legal process, or to protect the rights, safety, and property of you, Volta, or others.
  • Corporate transactions. If we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred subject to this Policy; we will make reasonable efforts to notify you of any material change to how your information is handled.
  • With your direction. We share information with anyone you direct us to, or with your consent.

8. De-identified and aggregated data

We may create and use de-identified and aggregated data, from which information that identifies you has been removed in accordance with the HIPAA de-identification standard (45 C.F.R. §164.514), for purposes such as benchmarking among comparable health centers, analytics, machine-learning model development, product improvement, and research. We do not attempt to re-identify this data, and we contractually prohibit recipients from doing so. Records protected by 42 C.F.R. Part 2 are excluded from these uses.

9. Cookies, tracking, and your signals

We use strictly necessary cookies to operate and secure the Services (for example, to keep you signed in) and a limited set of first-party analytics to understand and improve how the Services perform. We do not use advertising or cross-site tracking cookies. You can control cookies through your browser settings, though some features may not work without essential cookies. Where applicable law gives effect to a Global Privacy Control (GPC) or similar opt-out preference signal, we honor it.

10. How we protect information

We maintain an information-security program with administrative, physical, and technical safeguards consistent with recognized standards (HIPAA, SOC 2 Type II, FERPA, etc.). These safeguards include encryption of data in transit (TLS 1.2 or greater) and at rest, access controls and authentication, secure transfer methods for health data, vendor due diligence, and ongoing monitoring. No system can be guaranteed perfectly secure, but we work continuously to protect your information and to detect and respond to incidents.

If a breach of unsecured PHI or other personal information occurs, we will notify the affected institution and, where required, individuals and regulators, in accordance with the applicable Business Associate Agreement and with HIPAA, CMIA, and California and other breach-notification laws.

11. How long we keep information

We keep personal information only as long as needed for the purposes described in this Policy, to provide the Services, and to meet our legal, regulatory, and contractual obligations, after which we delete or de-identify it. Retention of PHI is governed by our agreements and BAAs with institutions. When our services to an institution end, we return or securely destroy the institution's PHI in accordance with the applicable agreement, except where law requires longer retention. Records-retention requirements applicable to billing and claims may require us to retain certain data for defined periods.

12. Your privacy rights and choices

Depending on where you live and the role in which we hold your information, you may have some or all of the following rights:

  • Access and portability to know what personal information we hold and how we use and share it, and to obtain a copy or portable export.
  • Correction of inaccurate personal information.
  • Deletion of personal information, subject to legal exceptions.
  • Limit the use of your sensitive personal information to what is necessary to provide the Services.
  • Withdrawal of any consent you have given, including for optional features.
  • Opt-out to opt out of any sale or sharing for targeted advertising. Note that we do not sell or share for advertising.
  • Non-discrimination and to appeal a decision on your request where the law provides for an appeal.

12.1 California (CCPA/CPRA and CMIA)

California residents have the rights described above, including the right to know, access, correct, and delete personal information, to limit the use of sensitive personal information, and to be free from discrimination for exercising these rights. Because we do not sell or share personal information for cross-context behavioral advertising, there is nothing to opt out of in that respect. Medical information is additionally protected under the CMIA. To make a request, use the contact details in Section 15; we will verify your identity before responding, and an authorized agent may act on your behalf with proof of authorization.

12.2 Consumer health data (Washington, Nevada, Connecticut)

Where these laws apply, you may confirm whether we process your consumer health data, access it, withdraw consent to its collection or sharing, and request its deletion. We collect and share consumer health data only with your consent or as otherwise permitted by law, and we do not use geofencing around health-care facilities.

12.3 Records held on behalf of your institution

For clinical, immunization, insurance, and billing records that we process as a Business Associate or service provider, the institution and its health center control the data. We will refer requests about that information to the appropriate institution and assist it in responding. Corrections or deletions in clinical or medical records maintained by a provider should be directed to that provider.

12.4 EU/UK and other jurisdictions

If your information is subject to the EU or UK GDPR, you also have rights to access, rectification, erasure, restriction, objection, and portability, and to lodge a complaint with a supervisory authority. We process such information based on performance of a contract, our legitimate interests, legal obligations, or your consent, and we use appropriate safeguards for any cross-border transfer.

13. Children and minors

The Services are intended for use by adults aged 18 and over, typically university students. We do not seek to collect personal information from anyone under 18 through the consumer Services without appropriate authorization, and we do not sell or use minors' data for targeted advertising. If we learn that we have collected information from a minor without a proper basis, we will take steps to delete it. Where an institution provides student information to us as part of the Services, the institution is responsible for any consents required for individuals under 18.

14. FERPA and student records

Student health records maintained by a university health center acting as a health-care provider are generally subject to HIPAA rather than the Family Educational Rights and Privacy Act ("FERPA"), under the FERPA health-records exception (34 C.F.R. §99.3). To the extent any records we handle are "education records" subject to FERPA, the institution is responsible for obtaining required consents or confirming an applicable exception before sharing them with us, and we process such records in accordance with FERPA and HIPAA as applicable.

15. Third-party services, changes, and contact

15.1 Third-party services

The Services may link to or integrate with third-party websites and services, including those of universities, carriers, brokers, and medical-records providers. Their privacy practices are governed by their own policies, and we are not responsible for them. We encourage you to review those policies.

15.2 Changes to this Policy

We may update this Policy from time to time. We will post the updated version with a new "Last updated" date and, where a change is material, provide additional notice as appropriate. Your continued use of the Services after an update takes effect reflects the updated Policy, except where additional consent is required by law.

15.3 How to contact us

indeHealth, Inc. is the entity responsible for personal information handled under this Policy (and, for GDPR/UK GDPR purposes where applicable, the data controller). To exercise your rights or ask a question, contact us at:

Email

legal@volta.health

Mail

indeHealth, Inc. (Volta Health), Attn: Privacy
370 Jay St.
New York, NY 11201

For data your school holds

Contact your university or its health center directly for records they control.