Patient User Privacy Policy
Patient User Privacy Policy
July 2023
We at Digital Care Solutions Corp (“we,” “us,” “the Company,” or “Digital Care Solutions”) value your privacy and are committed to keeping your data confidential.
Digital Care Solutions uses your collected data solely in the context of providing the program and Digital Care Solutions electronic health record program (collectively, the “Platform”), principal care management (“PCM”) services, remote therapeutic monitoring (“RTM”) services, remote physiological monitoring (“RPM”) services including all relevant content and functionality associated with the Platform and the PCM; RTM; RPM; services (collectively, the “Services”) for use by qualified clinical staff including care managers, health coaches, nurses, and, physicians (“Provider Users”) to provide services and care to patients (“Patient Users”). If you read this Patient User Privacy Policy, you are a Patient User.
Privacy Policy Applicability
This Patient User Privacy Policy applies to personal data that Digital Care Solutions collects from Patient Users of the Digital Care Solutions Platform and the Services (“Personal Data”). The term “Personal Data” includes any information that can be used or with other information to identify or contact one of our users. Some of the Personal Data we collect and transmit may be considered “health data” (i.e., data related to your physical or mental health), “protected health information,” or “PHI” (i.e., information that relates to your past, present, or future physical or mental health or condition(s); the provision of health care to you; or the past, present, or future payment for the provision of health care to you), and medical records as defined by state law.
To collect your information with this application, you must log in using a unique user ID and password provided to you by the care coordinator at Digital Care Solutions. Before receiving the unique ID and password, you would have already reviewed and signed a PATIENT USER TERMS OF USE (the “Terms”) opting into the program that disclosed what data are collected, who is collecting the data, how data will be managed and how the data will be used.
We believe privacy and transparency about using your Personal Data are paramount. Therefore, our privacy practices are intended to comply with the Health Insurance Portability and Accountability Act (“HIPAA”) and relevant state law related to using and disclosing medical records, where applicable. In this Patient User Privacy Policy, we provide detailed information about our collection, use, maintenance, and disclosure of your Personal Data. The Patient User Privacy Policy explains what kind of information we collect, when and how we might use your Personal Data, how we protect Personal Data, and your rights regarding your Personal Data.
For additional information on how we use and disclose your Personal Data, health data, PHI, and medical records data, please contact our Privacy Officer at Privacy@DigitalCare Solutions.com.
Note regarding third-party sites: Our Services may contain links to other sites that Digital Care Solutions do not operate. You will be directed to that third party’s site if you click a third-party link. We strongly advise reviewing every site’s privacy policy(ies). Digital Care Solutions has no control over and assumes no responsibility for third-party sites or services’ content, privacy policies, or practices. This Patient User Privacy Policy does not apply to your use of or access to any third-party sites or services.
Agreement to Patient User Privacy Policy Terms
By accessing and using the Services and Platform, you know that you have read and agree to the terms of this PATIENT USER Privacy Policy. If you disagree, you must immediately cease using the Services and Platform.
Patient User Privacy Policy Updates
Please keep in mind that we sometimes update this Patient User Privacy Policy, and it is your responsibility to stay updated with any amended versions. Any revisions to the Patient User Privacy Policy will be posted on the Patient User login page(s) of the Platform. Any changes to this Patient User Privacy Policy will be effective immediately upon the notice via the Patient User login page(s) and apply to all Personal Data that we maintain, use, and disclose. You agree with those changes if you continue using the Services and Platform following such notice.
Account Deletion
Suppose at any point you no longer agree to the use and disclosure of Personal Data, as described in this Patient User Privacy Policy. In that case, you can delete your user account on the Platform (“User Account”) by sending a deletion request to your ordering provider and programsupport@Digital Care Solutions.com with the following information:
- Practice name
- Provider name
- Medical Record Number (MRN)
- Provide a statement that you are requesting account deletion and disenrollment.
Questions or Concerns
If you have any questions or concerns after reading this Patient User Privacy Policy, please do not
hesitate to contact us at Privacy@Digital Care Solutions.com. We appreciate your feedback.
COLLECTION, MAINTENANCE, AND USE OF PERSONAL DATA
What Personal Data Does Digital Care Solutions Collect?
We collect and maintain four types of information from our Patient Users: (i) demographic data; (ii) medical data; (iii) support data; and (iv) technology data. Each category of data is explained in depth below.
Demographic Data: Digital Care Solutions collects demographic data from Patient Users, which may include, but not be limited to, your Name, birth year, gender, height, weight, phone number, and email address. The collection of this demographic data is primarily used to create your patient account, which is used to provide the Services securely.
Medical Data: In addition to demographic information, we will collect information regarding your health conditions, including, but not limited to, images, age, gender, weight, height, medical history, symptoms, and communications between you and your healthcare provider who is ordering services to you.
Personal Data: Besides medical information, we collect information on behavior, preferences, opinions, location, travel, activity, and other measures relevant to health. You can use the Personal Data as you answer questions. Or you are collected automatically (passively), such as by a sensor, when using this application.
Personal Data may be collected using the following and similar services:
Assessment or Survey
Digital Care Solutions creates surveys or assessments that collect information from you by soliciting responses to questions. These questions will be presented in surveys that we ask you to initiate voluntarily or in response to a prompt programmed by us.
Camera, Video, and Audio
Digital Care Solutions may create an assessment that requests that you take a picture or record a video or audio. You can grant or withhold permission for the Applications to access the camera or microphone.
We collect this information to provide you with the Services and your health care provider (i.e., the Provider User associated with your account) with the information required to address medical care through the Platform.
Support Data: If you contact us for support or to complain, we may collect technical or other information from you through log files and other technologies, some of which may qualify as Personal Data (e.g., IP address). Such information will be used for troubleshooting, customer support, software updates, and improvement of the Platform and related Services by this Patient User Privacy Policy. Calls with Digital Care Solutions may be recorded or monitored for training, quality assurance, customer service, and reference purposes.
Technology Data: Data which may include IP address (or proxy server), device and application identification numbers, location, browser type, Internet service provider and mobile carrier, the pages, and files you viewed, your searches, your operating system and system configuration information, and date/time stamps associated with your usage. This information is used to analyze overall trends, help us provide and improve our Services, and ensure the proper functioning and security of the Platform and Services.
How Will Digital Care Solutions Use Your Data?
Digital Care Solutions processes your Personal Data based on legitimate business interests, the fulfillment of our Services to you, compliance with our legal obligations, and your consent. We only use or disclose your Data when it is legally mandated or where it is necessary to fulfill those purposes described in this Patient User Privacy Policy. Where the law requires, we will ask for your consent before disclosing your Personal Data to a third party.
More specifically, Digital Care Solutions processes your Personal Data for the following legitimate business purposes:
To provide Services;
To fulfill our obligations to you under the Patient User Terms of Use;
To communicate with you about and manage your User Account;
To properly store and track your data within our system;
To respond to lawful requests from public and government authorities and to comply with applicable state/federal law, including cooperation with judicial proceedings and court orders;
To protect our rights, privacy, safety, or property, and that of you or others by providing proper notices, pursuing available legal remedies, and acting to limit our damages;
To handle technical support and other requests from you;
To enforce and ensure your compliance with our Patient User Terms of Use or the terms of any other applicable services agreement we have with you;
To manage and improve our operations and the Platform, including the development of additional functionality;
To evaluate the quality of service, you receive, identify usage trends, and improve your user experience;
To keep our Platform safe and secure;
To send you information about changes to our terms, conditions, and policies;
To allow us to pursue available remedies or limit the damages that we may sustain; and
To enable you to connect with or share Personal Data with the authorized Provider User, which enables that Provider User to monitor your progress and overall condition as he/she deems appropriate.
Does Digital Care Solutions Use Personal Data for Analytics?
Digital Care Solutions may use third-party service providers to monitor and analyze the use of the Platform as part of our Services. Our analytics services may include but are not limited to Microsoft Power BI.
Where Is Personal Data Processed?
The Personal Data we collect through the Platform will be stored on secure servers in the United States. Personal Data may be transmitted to third parties, which parties may store or maintain the data on their secure servers. These third parties are not permitted to transfer your Data outside the United States.
With Whom Does Digital Care Solutions Share Personal Data?
We may share your personal information with the following categories of individuals/entities:
Business Partners and Vendors: We share Personal Data with a limited number of partners, service providers, and other persons/entities who help run our business (“Business Partners”). Specifically, we may employ third-party companies and individuals to facilitate our Services, provide Services on our behalf, perform Service-related functions, or assist us in analyzing how our Services are used. Our Business Partners are contractually bound to protect your Personal Data and to use it only for the limited purpose(s) for which it is shared. Business Partners’ use of Personal Data may include but is not limited to, the provision of services such as data hosting, IT services, customer services, and payment processing.
Our Advisors: We may share your Personal Data with third parties that provide advisory services to Digital Care Solutions, including, but not limited to, our lawyers, auditors, accountants, and banks (collectively, “Advisors”). Personal Data will only be shared with Advisors if Digital Care Solutions has a legitimate business interest in sharing such data.
Provider Users: To use the Services, Patient Users must be affiliated with one or more Provider Users. As part of the Services, we will share your Personal Data with your specified Provider User(s). If at any point you want to disenroll from the program, you must contact your ordering provider and email programsupport@Digital Care Solutions.com.
Third Parties Upon Your Direction or Consent: You may direct Digital Care Solutions to share your Personal Data with third parties. Upon your request and consent, we may share such Personal Data with those third parties that you identify. Third Parties Pursuant to Business Transfers: In the event of a reorganization, merger, sale, joint venture, assignment, transfer, or other disposition of all or any portion of Digital Care Solutions’ corporate entity, assets, or stock (including in connection with any bankruptcy or similar proceedings), we may share your Personal Data with a third party.
Government and Law Enforcement Authorities: If reasonable and necessary, we may share your Personal Data to (i) comply with legal processes or enforceable governmental requests, or as otherwise required by law; (ii) cooperate with third parties in investigating acts or omissions that violate this Patient User Privacy Policy or the Patient User Terms of Use; or (iii) bring legal action against someone who may be violating the Patient User Terms of Use or who may be causing intentional or unintentional injury or interference to the rights or property of Digital Care Solutions or any third party, including other users of our Services.
How Long Does Digital Care Solutions Retain Personal Data?
Digital Care Solutions retains your Personal Data only as long as necessary and as required for our business operations, the provision of Services, archival purposes, and to satisfy legal requirements. The exact period of retention will depend on the following:
- The amount, nature, and sensitivity of the Personal Data.
- The personal risk of harm for unauthorized use or disclosure.
- The purposes for which we process your Personal Data, including whether those purposes can be achieved through other means.
- Business operations and legal requirements.
Digital Care Solutions will generally not retain your data after your User Account is closed (the “Retention Period”); however, the above factors may extend or decrease this.
Retention Period.
At the end of the applicable Retention Period, we will remove your Personal Data from our databases. We will require that our Business Partners remove any identifiable Personal Data from their databases. If there is any data that we cannot delete entirely from our systems for technical reasons, we will put in place appropriate measures to prevent any further processing of such data. Please note that once we disclose your Personal Data to third parties, we may not be able to access that Personal Data, and we cannot force the deletion or modification of such information by third parties.
Digital Care Solutions and its Business Partners reserve the right to use de-identified data indefinitely, even after removing Personal Data from Digital Care Solutions’ databases. We may continue to disclose de-identified data to third parties in a manner that does not reveal personal information, as described in this Patient User Privacy Policy. Our continued use of de-identified data will comport with applicable law.
What Happens to Personal Data Submitted by Minors?
Digital Care Solutions does not knowingly collect Personal Data from individuals under 18. Additionally, our Services are not directed to individuals under 18. We request that these individuals not provide Personal Data to us. If we learn that Personal Data from users under 18 has been collected, we will deactivate the User Account associated with that data and take reasonable measures to delete such data from our records promptly. If you are aware of a user under the age of 18 accessing the Services or Platform, please contact us at programsupport@Digital Care Solutions.com.
If you are a resident of California under the age of 18 and have registered for a User Account with us, you may ask us to remove content or information you have posted to our Platform.
PATIENT USER RIGHTS
What Rights Do Patient Users Have Concerning Their Personal Data?
As a user of Digital Care Solutions’ Services and Platform, you have certain rights relating to your Personal Data.
These rights are subject to local data protection and privacy laws and may include the right to:
Access Personal Data held by Digital Care Solutions; Erase/delete your Personal Data, to the extent permitted by applicable data protection and privacy laws and to the extent technologically feasible;
Receive communications related to the processing of your Personal Data; Restrict the processing of your Personal Data to the extent permitted by law; Object to the further processing of your Personal Data, including the right to object to marketing;
Request that your Personal Data be transferred to a third party, if possible;
Receive your Personal Data in a structured, commonly used, and machine-readable format; Rectify inaccurate personal information and, considering the purpose of processing the Personal Data, ensure it is complete.
Where the processing of your Personal Data by Digital Care Solutions is based on consent, you can withdraw that consent at any time. If you want to withdraw your consent or exercise the above rights, please contact us at programsupport@Digital Care Solutions.com.
If you delete your User Account entirely, contact your ordering provider and email programsupport@Digital Care Solutions.com. By terminating your User Account, you agree that you cannot access any information previously contained in your User Account. You further understand that removing all your Personal Data from our systems may not be technologically possible.
PROTECTION OF PERSONAL DATA
Is Personal Data Secure?
Digital Care Solutions understands the importance of data confidentiality and security. We use a combination of reasonable physical, technical, and administrative security controls to:
- Maintain the security and integrity of your Personal Data.
- Protect against any threats or hazards to the security or integrity of your Personal Data.
- Protect against unauthorized access to or use of such information in our possession or control that could substantially harm you.
While Digital Care Solutions uses reasonable security controls, we cannot guarantee or warrant that such techniques will prevent unauthorized access to your personal DATA. DIGITAL CARE SOLUTIONS IS UNABLE TO GUARANTEE THE SECURITY OR INTEGRITY OF PERSONAL DATA TRANSMITTED OVER THE INTERNET, AND THERE IS NO GUARANTEE THAT YOUR PERSONAL DATA WILL NOT BE ACCESSED, DISCLOSED, ALTERED, OR DESTROYED BY BREACH OF ANY OF OUR PHYSICAL, TECHNICAL, OR ADMINISTRATIVE SAFEGUARDS. ACCORDINGLY, WE DO NOT AND CANNOT ENSURE OR WARRANT THE SECURITY OR INTEGRITY OF ANY PERSONAL DATA YOU TRANSMIT TO US. You assume the risk that unauthorized entry or use, hardware or software failure, and other factors may compromise the security of your personal DATA at any time.
What Safeguards Does Digital Care Solutions Have in Place to Secure Personal Data?
Digital Care Solutions stores Personal Data on secured servers and uses a combination of technical, administrative, and physical safeguards to protect your personal information. Such safeguards include but are not limited to authentication, encryption, backups, and access controls.
How Can Patient Users Protect Their Personal Data?
You are solely responsible for preventing unauthorized access to your devices and your User Account by protecting your account credentials and limiting access to your devices. Digital Care Solutions has no access to or control over your device’s security settings, and it is your responsibility to implement any device-level security features and protections you feel are appropriate (e.g., password protection, encryption, remote wipe capability). We recommend that you take all appropriate steps to secure any device you use to access our Services and Platform.
Please note that Digital Care Solutions will never send you an email requesting confidential information, such as account numbers, usernames, passwords, or Social Security Numbers. If you receive a suspicious email from Digital Care Solutions, please notify us at programsupport@Digital Care Solutions.com.
Further, if you know of or suspect any unauthorized use or disclosure of your User Account information or any other security concern, please notify Digital Care Solutions immediately.
What If Digital Care Solutions Experiences a Data or Security Breach?
Digital Care Solutions takes the security of your Personal Data seriously. In the event of a data or security breach, Digital Care Solutions will take the following actions:
- Promptly investigate the security incident, validate the root cause, and, where applicable, remediate any vulnerabilities within Digital Care Solutions’ control which may have given rise to the security incident.
- Comply with laws and regulations directly applicable to Digital Care Solutions concerning such security incidents.
- As applicable, cooperate with any affected Digital Care Solutions user or client in accordance with the terms of Digital Care Solutions’ contract with such user or client.
- Document and record actions taken by Digital Care Solutions in connection with the security incident and conduct a post-incident review of the circumstances related to the incident and actions/recommendations taken to prevent similar security incidents in the future.
Digital Care Solutions will notify you of any data or security breaches as required by and in accordance with applicable law.
What Is Digital Care Solutions’ Cookie Policy?
CALIFORNIA PRIVACY RIGHTS
The California Consumer Privacy Act (“CCPA”) may apply if you are a California resident. Please see the CCPA for an explanation of your rights.
CALIFORNIA CONSUMER PRIVACY ACT OF 2018
Categories of Personal Information We Collect
We collect information that identifies, relates to, describes, references, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular California consumer or household (“personal information”). We may have collected the following categories of personal information from consumers through our websites, apps, services, devices, or other services within the twelve (12) months preceding the effective date of this Privacy Policy:
- Identifiers such as
o Name
o Address
o Unique personal identifier (e.g., device ID, online identifier)
o Internet Protocol address
o Email address
o Telephone number
o Account name
o Other similar identifiers
- Characteristics of protected classifications under California/federal law (e.g., age, race, sex, medical condition, etc.)
- Medical information
- Health insurance information
- Financial information, including credit card numbers
- Commercial information (e.g., purchase history)
- Internet or other electronic network activity information (e.g., browsing history, interaction with our website, etc.)
- Geolocation data
- Audio, electronic, visual, thermal, olfactory, or similar information (e.g., call recordings)
- Professional, employment-related, or other similar information
“Personal information” under the California Consumer Privacy Act does not include information that is
- publicly available from government records,
- de-identified or aggregated consumer information,
- health or medical information covered by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the California Confidentiality of Medical Information Act (CMIA) or clinical trial data, or
- certain personal or financial information is covered under specific sector-specific privacy laws.
Under California Civil Code sections 1798.83-1798.84, California residents are entitled to ask for and
obtain from us an annual list identifying the categories of personal customer information which we shared, if any, with our affiliates and third parties in the preceding calendar year for marketing purposes. This list will be provided free of charge. Contact information for such affiliates and third parties must be included. If you are a California resident and want a copy of this notice, please submit a written request to the following email address: Privacy@Digital Care Solutions.