Last updated: October 25, 2013
The Electronic Health Record
Elation Health provides the web-based Clinical EHR to customers who enter into an Elation Service Agreement (“Customers”), who then authorize Clinical EHR users, including physicians, physician assistants, nurse practitioners and non-physician staff members (“Authorized Users”). Customers and Authorized Users are responsible for determining uses and disclosures of patient medical information maintained in the Clinical EHR, in accordance with their legal and professional responsibilities as health care professionals and state and federal medical privacy laws, including the federal Health Insurance Portability and Accountability Act (“HIPAA”). To the extent that Elation Health receives or maintains patient medical information in the course of providing the Clinical EHR, that information is secured, used and disclosed only in accordance with Elation Health’s legal obligations as a “business associate” under HIPAA.
The Patient Portal
Elation Health Customers may choose to make the Patient Portal available to patients to enable certain interactions between the Customer, Authorized Users and patients, including scheduling appointments, discussing medical treatment, sending medication prescription-related messages, and enabling patient viewing of a portion of the Clinical EHR. Customers are solely responsible for the content of the patient’s medical record maintained in the Clinical EHR and determining the portion of the Clinical EHR that may be viewed by the patient through the Patient Portal.
Elation Health may utilize patient medical information on a limited basis as necessary to provide the Patient Portal services, including the following uses and disclosures:
- An email address and a cell phone number are required to be stored in the Clinical EHR before an invitation can be sent to the patient to open a Patient Portal account.
- When a letter or a response from a doctor is opened by the patient through the Patient Portal, the opened status will be communicated to the doctor inside the Clinical EHR.
- If instructed by the patient to fax a clinical profile derived from the patient’s medical record (a “Profile”) to a fax machine within the Portal, Elation Health will fax such documents on the patient’s behalf.
- Elation Health will send email or text notifications to the patient when a letter from the doctor or clinical document is available in the Patient Portal. The email or cell phone number used is documented in the patient’s chart in the Clinical EHR.
Elation Health will maintain aggregate information regarding usage of the Patient Portal for product improvement purposes, but that data will not identify individual patients. Elation Health will not sell any personal information provided by a patient through the Patient Portal to a third party.
Personal Information Provided by You
Disclosures to Third Parties Assisting In Our Operations
Elation Health may share your PII under confidentiality agreements with other companies that work with, or on behalf of, Elation Health to provide products and services. These companies, which may include members of Elation Health’s corporate family, may use your PII to assist Elation Health in its operations. However, these companies do not have any independent right to share this information.
Disclosures Under Special Circumstances
We may provide information about you to respond to subpoenas, court orders, legal process or governmental regulations, or to establish or exercise our legal rights or defend against legal claims. We believe it is necessary to share information in order to investigate, prevent or take action regarding illegal activities, suspected fraud, situations involving potential threats to the physical safety of any person, or as otherwise required by law.
Automatically Collected Information and Anonymous Information
Each time a visitor comes to the Website, Elation Health collects some information to improve the overall quality of the visitor’s online experience.
Elation Health collects aggregate queries for internal reporting and also counts, tracks, and aggregates the visitor’s activity into Elation Health’s analysis of general traffic-flow at the Website. To these ends, Elation Health may merge information about you into aggregated group data. In some cases, Elation Health may remove personal identifiers from PII and maintain it in aggregate form that may later be combined with other information to generate anonymous, aggregated statistical information. Such anonymous, group data may be shared on an aggregated basis with Elation Health’s affiliates, business partners, service providers and/or vendors; if it does so, Elation Health will not disclose your individual identity.
Web Server Logs and IP Addresses
An Internet Protocol (“IP”) address is a number that automatically identifies the computer/device you have used to access the Internet. The IP address enables our server to send you the web pages that you want to visit, and it may disclose the server owned by your Internet Service Provider. Elation Health may use IP addresses to conduct website analyses and performance reviews and to administer the Website.
Cookies and Web Beacons
Elation Health understands that storing our data in a secure manner is essential. Elation Health stores PII and other data using industry-standard physical, technical and administrative safeguards to secure data against foreseeable risks, such as unauthorized use, access, disclosure, destruction or modification. Please note, however, that while Elation Health has endeavored to create a secure and reliable website for users, the confidentiality of any communication or material transmitted to/from the Website or via e-mail cannot be guaranteed.
Children’s Privacy Protection
Elation Health understands the importance of protecting children’s privacy in the interactive online world. The Website is not designed for, or intentionally targeted at, children 13 years of age or younger. It is not our policy to intentionally collect or maintain information about anyone under the age of 13. No one under the age of 13 should submit any PII to Elation Health and/or the Website.
You may review and request changes to your PII that Elation Health has collected, including the removal of your PII from Elation Health’s databases in order to prevent receipt of future communications or to halt receipt of our Website services, using any of the following options:
You can send your request via e-mail to: email@example.com, or mail your request to the following postal address:
Elation Health, Inc.
550 15th Street, Suite 21
San Francisco, CA 94103