Effective Date: January 1, 2024
Platform: YourMD Telehealth (https://telehealth.yourmd.online)
Why We Use Cookies
YourMD Telehealth uses cookies and similar technologies to:
- Authenticate users securely
- Protect against fraud and unauthorized access
- Maintain HIPAA-compliant session continuity
- Improve site performance and user experience
Types of Cookies
Essential Cookies
Required for authentication, HIPAA compliance, and session management.
- Session cookies: Maintain your secure login state
- Authentication tokens: Verify your identity across pages
- Security tokens: Protect against cross-site request forgery (CSRF)
- Load balancing cookies: Ensure optimal server performance
Security Cookies
Used for fraud detection, CSRF prevention, and login protection.
- MFA cookies: Remember multi-factor authentication status
- Device fingerprinting: Detect unauthorized access attempts
- Rate limiting cookies: Prevent brute force attacks
- Security flags: Mark suspicious activities
Analytics Cookies (Optional)
Used for platform optimization; PHI is never stored.
- Usage patterns: Understand how users navigate the platform
- Performance metrics: Monitor page load times and errors
- Feature adoption: Track which tools are most helpful
- Anonymous analytics: All data is aggregated and de-identified
Cookie Details
| Cookie Name |
Type |
Purpose |
Duration |
| PHPSESSID |
Essential |
Session management |
Session |
| auth_token |
Essential |
User authentication |
24 hours |
| csrf_token |
Security |
CSRF protection |
Session |
| mfa_status |
Security |
MFA verification |
1 hour |
| device_id |
Security |
Device recognition |
30 days |
| _ga (optional) |
Analytics |
Google Analytics |
2 years |
User Control
By using our site, you consent to cookie use. You may disable non-essential cookies in your browser, but secure telehealth functions may be impacted.
How to Manage Cookies:
- Browser Settings: Most browsers allow you to refuse or delete cookies
- Cookie Preferences: Click "Cookie Settings" in our footer to manage preferences
- Essential Cookies: Cannot be disabled as they are required for platform security
- Third-Party Cookies: We do not use third-party tracking or advertising cookies
Cookie Security
We implement industry-standard security measures for all cookies:
- Secure flag: Cookies are only transmitted over HTTPS
- HttpOnly flag: Prevents client-side script access
- SameSite attribute: Protects against CSRF attacks
- Encryption: Sensitive cookie data is encrypted
Updates to This Policy
We may update this Cookie Disclosure as our platform evolves. Check this page periodically for changes. Your continued use of the platform constitutes acceptance of any updates.