Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
US healthcare provider network and patient portal for booking appointments, messaging care teams, viewing records and paying bills.
Privia Health is a United States healthcare provider network whose myPrivia patient portal lets patients book appointments, message their care team, view lab results and medical records, and pay bills online. The clinical record is managed on the athenahealth electronic health record platform, and all data is hosted in the United States. Because the service handles medical information, it processes some of the most sensitive personal data that exists.
The portal processes identity details, contact information, insurance data, appointment history, clinical notes, lab results and billing records. Session cookies keep patients securely logged in, while the public marketing website may load analytics and advertising tags. Special care is needed because trackers placed on authenticated health pages can leak protected health information to third parties, an issue that has drawn regulatory enforcement in the United States.
In the United States, HIPAA and the HITECH Act govern protected health information and require business associate agreements with vendors such as athenahealth. If any patient is located in the EEA or the United Kingdom, the GDPR also applies and treats health data as a special category requiring stronger protection. Under the GDPR the usual basis is explicit consent under Article 9(2)(a), alongside contract or consent for the portal services themselves.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Because hosting is in the United States, any access by EEA or UK patients is a transfer to a third country with no adequacy decision, so Standard Contractual Clauses and supplementary technical measures are required. Consent for health data must be explicit, informed and clearly separated from general terms. Patients should be told who can see their records, that athenahealth acts as the records platform, and how to exercise their rights.
Conduct a DPIA, keep analytics and advertising trackers off all authenticated portal pages, and audit any tags on pages that reference health services. Maintain business associate agreements, encrypt data in transit and at rest, and enforce strict access controls and breach notification procedures. For EEA or UK patients, put transfer safeguards in place and provide a clear privacy notice that explains the United States hosting.
Websites using Privia Health must obtain user consent under GDPR regulations.
DPIA considerations
A DPIA is strongly recommended and often mandatory because the portal processes special category health data on a large scale. Key risks include sensitive patient health information, United States hosting on athenahealth infrastructure, potential exposure of analytics or advertising trackers on health pages, and cross border transfers for any EEA or UK patients. Assess tracker leakage on logged in pages, the role of athenahealth as a sub processor, breach notification duties, and the lawful basis for processing special category data.
Sample consent text
By creating a Privia Health patient portal account you agree that your personal and health information will be processed to deliver your care, hosted in the United States, and shared with your care team and athenahealth as our records platform. Where required we will obtain your explicit consent for processing health data.
Third-party domains contacted
myprivia.comathenahealth.comportal.athenahealth.comgoogle-analytics.comgoogletagmanager.comconnect.facebook.netCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| PHPSESSID | Necessary | Session | Maintains the authenticated patient portal session while the user is logged in |
| athena_session | Necessary | Session | Keeps the secure session with the athenahealth records platform that powers the portal |
| _ga | Analytics | 2 years | Google Analytics cookie on the public marketing site that distinguishes unique visitors |
| _gid | Analytics | 24 hours | Google Analytics cookie that distinguishes visitors over a short period |
| _fbp | Marketing | 3 months | Meta Pixel cookie used on public pages for advertising measurement and audiences |
| cookie_consent | Necessary | 1 year | Stores the visitor cookie consent preferences for the marketing website |
This service may collect user data. Ensure GDPR compliance with FlowConsent.
The authenticated portal uses necessary session cookies to keep patients securely logged in to myPrivia and the athenahealth records platform. The public marketing site may also set analytics and advertising cookies such as Google Analytics and the Meta Pixel. Trackers should never run on logged in health pages.
Yes. Patients consent to treatment and to the processing of their health information, and any non essential cookies on public pages require consent. Where the GDPR applies, explicit consent is needed for special category health data.
In the United States, HIPAA authorises processing for treatment, payment and healthcare operations. Where the GDPR applies, the basis is explicit consent under Article 9(2)(a) for health data, combined with contract or consent for the portal itself.
Yes, from an EU perspective. All data is hosted in the United States, so access by any EEA or UK patient is a third country transfer without an adequacy decision and requires Standard Contractual Clauses and supplementary measures.
Yes. Processing special category health data on a large scale almost always triggers a mandatory DPIA under the GDPR. The assessment should cover tracker leakage, United States hosting, the athenahealth sub processor and breach risks.
Keep analytics and advertising trackers off all authenticated pages, sign business associate agreements, and encrypt data in transit and at rest. Enforce strict access controls, breach notification procedures and, for EU patients, transfer safeguards and a clear privacy notice.
For patients this depends on the provider network, but comparable portals are built on athenahealth, Epic MyChart, Cerner or NextGen. Organisations choosing a platform should weigh HIPAA controls and tracker governance heavily.
Separate strictly necessary portal session cookies from the analytics and advertising cookies on public pages, and confirm that no trackers fire on authenticated health pages. Disclose United States hosting and review the policy after any vendor or tag change.