All posts
Privacy GuidesPublished Updated

Phreesia Opt Out Guide: Revoke Consent and Data Rights

Use Phreesia's authorization revocation and privacy-rights routes while keeping provider-held medical records and platform data clearly separate.

Phreesia Platform Privacy Policy viewed in a browser
DRDominik Rapacki
5 minutes read

A Phreesia opt out is usually a consent or privacy-rights task, not a generic advertising-cookie switch. Use the current Phreesia Platform Privacy Policy for the official consent and data-rights routes. If you granted Phreesia an optional Authorization for personalized health-related materials, revoke it through the platform or contact the Privacy Officer. For access, correction, or deletion of eligible platform data, use the current privacy-policy contact route. Phreesia may ask for your name, date of birth, home address, and provider name to confirm identity. Keep provider-held medical records separate because those records can follow the provider's own HIPAA process.

Phreesia Opt Out Guide quick facts

QuestionCurrent answer
Official routePhreesia Platform Privacy Policy, in-platform Authorization controls, and privacy@phreesia.com
Main scopeRevocation of optional Authorization plus eligible access, correction, and deletion requests for platform data
VerificationName, date of birth, home address, and healthcare provider name may be requested
TimingThe policy describes a 45-calendar-day access response, with one possible 45-day extension
Reappearance riskNew consent, a new provider workflow, or a separate provider-held record can require another action

Last checked August 28, 2026. Provider policies, forms, device menus, and legal-right availability can change. Start from the current official page rather than an old third-party form.

How to complete the phreesia opt out

Phreesia Platform Privacy Policy viewed in a browser
Phreesia's current Platform Privacy Policy captured on August 28, 2026.
  1. Identify whether the issue is an optional Phreesia Authorization, platform personal data, or a medical record held by your healthcare provider.
  2. To stop the authorized personalized-material use, revoke the Authorization in the Phreesia platform or contact the Privacy Officer through the official policy route.
  3. For access, correction, or deletion, email privacy@phreesia.com or use the current contact method stated in the policy.
  4. Provide only the matching details requested for identity confirmation, which may include your name, date of birth, home address, and provider name.
  5. Keep the confirmation and respond promptly if Phreesia requests clarification or uses the additional response period.
  6. Contact the healthcare provider separately for provider-held medical-record questions or HIPAA rights.

Choose the right route before submitting

Revoke an optional Authorization

Phreesia explains that personalized health-related materials depend on an optional Authorization. Revoking that Authorization stops future use under that permission. The platform or Privacy Officer route is the appropriate place to withdraw it. Revocation does not undo uses that occurred while the authorization was active.

Request platform data rights

The platform policy describes state privacy rights that can include access, correction, and deletion, subject to eligibility and exceptions. Use privacy@phreesia.com or the current policy route. Include enough information to locate the account or interaction, but do not email clinical details unless the official process specifically requires them.

Contact the healthcare provider

Phreesia can process information on behalf of a healthcare provider. Provider-held protected health information is governed by the provider's notice and process, not automatically by the platform policy described here. Ask the provider's privacy office which request form applies.

Verification and expected processing

For an access request, the current policy describes a response within 45 calendar days and allows one additional 45-day period when reasonably necessary. The company should notify the requester about an extension. Save the original submission date so the timeline is clear.

Identity confirmation may use the requester name, date of birth, home address, and provider name. These details help match a platform interaction while reducing disclosure to the wrong person. Send them only through the current official route and retain the case response.

Deletion and correction can be limited by legal obligations, security needs, provider instructions, or records needed to complete a transaction. A response that explains a retained category is not the same as ignoring the request. Use the appeal or follow-up route if the policy provides one and the explanation appears incomplete.

What the request changes and what it does not

Revoking an Authorization changes future personalized-material use under that permission. It does not erase a healthcare provider's medical chart or records already lawfully used before revocation. It also does not automatically cancel appointments, billing communications, or care-related messages.

Phreesia's platform policy says the company does not sell or share personal data as those terms are defined under the state laws it addresses. Do not frame the request as proof of a sale. Focus on consent withdrawal and the specific access, correction, or deletion right you want to exercise.

The policy is focused on U.S. services and says Phreesia does not provide the covered services in the United Kingdom or European Economic Area. People outside the stated scope should confirm which provider and policy governed their interaction before submitting personal information.

Why the data or advertising choice can return

A privacy choice follows the identifier and scope described by the provider. Browser cookies can disappear, mobile advertising IDs can reset, and new devices can create new identifiers. Partners can also send later data. A successful request should therefore be treated as a dated result, not a permanent state.

Recheck the same browser or device after the provider's stated processing window, then again after one month. Repeat the check after clearing cookies, resetting a device, changing phones, or restoring application permissions. If the same identifier returns, use the saved confirmation in a focused follow-up.

Do not send repeated requests every day. That can create duplicate cases without clarifying scope. Confirm the original request, the covered identifier, and the current status first. Escalate through the policy's appeal or privacy contact only when the documented result does not match the stated choice.

Build the request into a broader privacy plan

Treat the provider choice as one layer of a wider exposure cleanup. Advertising and analytics companies can receive identifiers from many partners, while people-search sites publish a different type of profile. A request to one company does not notify independent recipients or erase their source records. Start with the data broker opt-out list and the manual data-broker removal guide to separate advertising controls from public-profile removals.

Keep a simple removal log with the provider, route, request type, browser or device covered, submission date, confirmation number, and next review date. That record prevents duplicate submissions and makes a later appeal or follow-up much easier. Use the opt-out guide hub to find the correct workflow for each provider.

Use only the information the official workflow requires. Confirm the domain before sharing an advertising identifier or identity details, and avoid sending identity documents through an unverified email address. A privacy request can require matching data, but that does not mean every field is necessary.

If you want a wider inventory before choosing manual targets, start a CrabClear privacy scan. A scan can help prioritize exposure, but every provider still controls its own verification, exceptions, and timing.

Related workflows include the OptimizeRx opt-out guide, the HealthLink Dimensions opt-out guide, and the data broker removal guide. Use them only when those services or identifiers appear in your own exposure.

Phreesia Opt Out Guide FAQ

Does revoking Phreesia authorization delete my medical record?

No. Revocation stops future use under that optional Authorization. A healthcare provider's medical record follows the provider's own process and can be subject to separate retention duties.

Do I need to repeat the choice on another browser or device?

Usually yes when the workflow is browser, cookie, advertising-ID, or device based. Repeat it for each relevant environment and after a reset that creates a new identifier.

Can the provider ask me to verify my identity?

Yes for access, correction, deletion, or other rights that could reveal or change personal information. Use the official route and provide only the matching details it requests.

Can the data or choice reappear later?

Yes. A new identifier, cleared cookie, restored permission, later partner data, or an independent source can create a new record. Save the confirmation and schedule a measured recheck.

Continue reading

Related privacy guides

View Data Broker Opt-Out Guides

Start Protecting Your Privacy

Join thousands of users who have already removed their data from 1,500+ brokers. Take control of your privacy today.

Ready to get started? Create your account and begin data removal in minutes.