The policy includes a disclaimer that Ro cannot guarantee the security of data transmitted through its services and states that users acknowledge and accept that data transmission occurs at their own risk.
This analysis describes what Ro's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision is a standard security disclaimer common across digital services; however, in the context of a telehealth platform collecting sensitive health information, its interaction with HIPAA's security rule obligations and state breach notification requirements is relevant. The agreement's assertion that transmission risk is assumed by the user does not override statutory obligations Ro holds as a covered entity or business associate.
The updated policy establishes that Ro has enabled contractual settings with certain advertising partners that restrict those partners' use of data to service provision only, meaning those partners may not use the information for their own advertising or profiling purposes. The policy also expands the list of states where Ro does not sell sensitive personal information for tailored advertising, adding New Jersey, New Hampshire, Nebraska, Iowa, and Delaware. For residents of the newly added states and others covered by partner settings, default restrictions on data use may apply even without an explicit opt-out. You can manage advertising preferences through the policy's stated opt-out mechanisms, including the 'Your Privacy Choices' page and Global Privacy Control signals.
View change record →Under these terms, Ro acknowledges that data security cannot be guaranteed and states that data transmission is at the user's own risk. Applicable law, including HIPAA and state breach notification statutes, independently establishes obligations for entities handling health data regardless of this disclaimer.
Cross-platform context
See how other platforms handle Security Disclaimer and User Assumption of Risk and similar clauses.
Compare across platforms →"However, no method of transmission over the Internet, and no means of electronic or physical storage, is absolutely secure. As such, you acknowledge and accept that we cannot guarantee the security of your information transmitted to, through, or on our Services or via the Internet and that any such transmission is at your own risk.Excerpt from Ro's Privacy Policy
REGULATORY LANDSCAPE: HIPAA's Security Rule requires covered entities and business associates to implement reasonable and appropriate technical, physical, and administrative safeguards for electronic protected health information.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision is a standard security disclaimer common across digital services; however, in the context of a telehealth platform collecting sensitive health information, its interaction with HIPAA's security rule obligations and state breach notification requirements is relevant. The agreement's assertion that transmission risk is assumed by the user does not override statutory obligations Ro holds as a covered entity or …
Under these terms, Ro acknowledges that data security cannot be guaranteed and states that data transmission is at the user's own risk. Applicable law, including HIPAA and state breach notification statutes, independently establishes obligations for entities handling health data regardless of this disclaimer.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Ro.