Phreesia Opt Out Guide: Revoke Consent and Data Rights
Use Phreesia's authorization revocation and privacy-rights routes while keeping provider-held medical records and platform data clearly separate.

A Phreesia opt out is usually a consent or privacy-rights task, not a generic advertising-cookie switch. Use the current Phreesia Platform Privacy Policy for the official consent and data-rights routes. If you granted Phreesia an optional Authorization for personalized health-related materials, revoke it through the platform or contact the Privacy Officer. For access, correction, or deletion of eligible platform data, use the current privacy-policy contact route. Phreesia may ask for your name, date of birth, home address, and provider name to confirm identity. Keep provider-held medical records separate because those records can follow the provider's own HIPAA process.
Phreesia Opt Out Guide quick facts
| Question | Current answer |
|---|---|
| Official route | Phreesia Platform Privacy Policy, in-platform Authorization controls, and privacy@phreesia.com |
| Main scope | Revocation of optional Authorization plus eligible access, correction, and deletion requests for platform data |
| Verification | Name, date of birth, home address, and healthcare provider name may be requested |
| Timing | The policy describes a 45-calendar-day access response, with one possible 45-day extension |
| Reappearance risk | New consent, a new provider workflow, or a separate provider-held record can require another action |
Last checked August 28, 2026. Provider policies, forms, device menus, and legal-right availability can change. Start from the current official page rather than an old third-party form.
How to complete the phreesia opt out

- Identify whether the issue is an optional Phreesia Authorization, platform personal data, or a medical record held by your healthcare provider.
- To stop the authorized personalized-material use, revoke the Authorization in the Phreesia platform or contact the Privacy Officer through the official policy route.
- For access, correction, or deletion, email privacy@phreesia.com or use the current contact method stated in the policy.
- Provide only the matching details requested for identity confirmation, which may include your name, date of birth, home address, and provider name.
- Keep the confirmation and respond promptly if Phreesia requests clarification or uses the additional response period.
- Contact the healthcare provider separately for provider-held medical-record questions or HIPAA rights.
Choose the right route before submitting
Revoke an optional Authorization
Phreesia explains that personalized health-related materials depend on an optional Authorization. Revoking that Authorization stops future use under that permission. The platform or Privacy Officer route is the appropriate place to withdraw it. Revocation does not undo uses that occurred while the authorization was active.
Request platform data rights
The platform policy describes state privacy rights that can include access, correction, and deletion, subject to eligibility and exceptions. Use privacy@phreesia.com or the current policy route. Include enough information to locate the account or interaction, but do not email clinical details unless the official process specifically requires them.
Contact the healthcare provider
Phreesia can process information on behalf of a healthcare provider. Provider-held protected health information is governed by the provider's notice and process, not automatically by the platform policy described here. Ask the provider's privacy office which request form applies.
Verification and expected processing
For an access request, the current policy describes a response within 45 calendar days and allows one additional 45-day period when reasonably necessary. The company should notify the requester about an extension. Save the original submission date so the timeline is clear.
Identity confirmation may use the requester name, date of birth, home address, and provider name. These details help match a platform interaction while reducing disclosure to the wrong person. Send them only through the current official route and retain the case response.
Deletion and correction can be limited by legal obligations, security needs, provider instructions, or records needed to complete a transaction. A response that explains a retained category is not the same as ignoring the request. Use the appeal or follow-up route if the policy provides one and the explanation appears incomplete.
What the request changes and what it does not
Revoking an Authorization changes future personalized-material use under that permission. It does not erase a healthcare provider's medical chart or records already lawfully used before revocation. It also does not automatically cancel appointments, billing communications, or care-related messages.
Phreesia's platform policy says the company does not sell or share personal data as those terms are defined under the state laws it addresses. Do not frame the request as proof of a sale. Focus on consent withdrawal and the specific access, correction, or deletion right you want to exercise.
The policy is focused on U.S. services and says Phreesia does not provide the covered services in the United Kingdom or European Economic Area. People outside the stated scope should confirm which provider and policy governed their interaction before submitting personal information.
Why the data or advertising choice can return
A privacy choice follows the identifier and scope described by the provider. Browser cookies can disappear, mobile advertising IDs can reset, and new devices can create new identifiers. Partners can also send later data. A successful request should therefore be treated as a dated result, not a permanent state.
Recheck the same browser or device after the provider's stated processing window, then again after one month. Repeat the check after clearing cookies, resetting a device, changing phones, or restoring application permissions. If the same identifier returns, use the saved confirmation in a focused follow-up.
Do not send repeated requests every day. That can create duplicate cases without clarifying scope. Confirm the original request, the covered identifier, and the current status first. Escalate through the policy's appeal or privacy contact only when the documented result does not match the stated choice.
Build the request into a broader privacy plan
Treat the provider choice as one layer of a wider exposure cleanup. Advertising and analytics companies can receive identifiers from many partners, while people-search sites publish a different type of profile. A request to one company does not notify independent recipients or erase their source records. Start with the data broker opt-out list and the manual data-broker removal guide to separate advertising controls from public-profile removals.
Keep a simple removal log with the provider, route, request type, browser or device covered, submission date, confirmation number, and next review date. That record prevents duplicate submissions and makes a later appeal or follow-up much easier. Use the opt-out guide hub to find the correct workflow for each provider.
Use only the information the official workflow requires. Confirm the domain before sharing an advertising identifier or identity details, and avoid sending identity documents through an unverified email address. A privacy request can require matching data, but that does not mean every field is necessary.
If you want a wider inventory before choosing manual targets, start a CrabClear privacy scan. A scan can help prioritize exposure, but every provider still controls its own verification, exceptions, and timing.
Related workflows include the OptimizeRx opt-out guide, the HealthLink Dimensions opt-out guide, and the data broker removal guide. Use them only when those services or identifiers appear in your own exposure.
Phreesia Opt Out Guide FAQ
Does revoking Phreesia authorization delete my medical record?
No. Revocation stops future use under that optional Authorization. A healthcare provider's medical record follows the provider's own process and can be subject to separate retention duties.
Do I need to repeat the choice on another browser or device?
Usually yes when the workflow is browser, cookie, advertising-ID, or device based. Repeat it for each relevant environment and after a reset that creates a new identifier.
Can the provider ask me to verify my identity?
Yes for access, correction, deletion, or other rights that could reveal or change personal information. Use the official route and provide only the matching details it requests.
Can the data or choice reappear later?
Yes. A new identifier, cleared cookie, restored permission, later partner data, or an independent source can create a new record. Save the confirmation and schedule a measured recheck.
Continue reading
Related privacy guides
Aura vs OneRep: Pricing, Coverage, and Best Fit
Compare Aura and OneRep on current pricing, provider-defined coverage, household limits, removal workflow, monitoring, bundled tools, and best fit.
Read articleNexxen Opt Out Guide: Browser, Device, and Data Rights
Use Nexxen's current Privacy Center for browser and device advertising choices, sale or sharing opt-outs, and separate access or deletion requests.
Read articleOptimizeRx Opt Out Guide: Device and Privacy Requests
Use OptimizeRx's current device-disassociation and privacy-rights routes, then handle email preferences and browser controls separately.
Read article