Effective Date: January 1, 2023
Last Updated: May 31, 2024
- Introduction
1.1. This Privacy Policy (this “Privacy Policy”) informs you what Personal Information Healthsoft, LLC (“Healthsoft,” “we,” “us,” or “our”) may collect, how Healthsoft collects such Personal Information, how Healthsoft uses such Personal Information in connection with the Services we provide to you or our customers (i.e., Providers as defined below), and your choices related to your Personal Information. This Privacy Policy also provides additional information required under California law about our collection, use and disclosure of the information of California residents from both online and offline sources, along with other required information such as rights that may be available to California residents.
1.1.1. “Services” means Healthsoft’s products and services, such as our websites (“Sites”), laboratory information systems, iHealth.care, iHomehealth.care, ihealthevents.com, healthcare provider customer portals (“Provider Portals”), patient portals (“Patient Portals”, collectively with Provider Portals, “Portals”), software and mobile applications for the foregoing, etc.
1.2. In this Privacy Policy, we do not include Protected Health Information in the definition of Personal Information because, as discussed in Sections 2 and 4, Protected Health Information has different treatment under HIPAA (as defined below), other applicable laws, and the Customer Documents (as defined below). Accordingly, because Protected Health Information is handled differently under the Customer Documents, if you are a patient of a Provider (as defined below), your Protected Health Information is subject to the Customer Documents and your Provider’s terms of service and privacy practices.
1.3. This Privacy Policy applies wherever it is posted, and it is part of and incorporated into applicable Terms of Use Agreements (“Terms of Use”) for the Sites, the Portals, and other Services, and into any applicable Terms and Conditions for our software and mobile applications (“Terms and Conditions”). Any terms capitalized herein but not defined shall have the meanings assigned to such terms in the applicable Terms of Use or Terms and Conditions. By visiting or using the Services or otherwise affirming the acceptance of an agreement into which this Privacy Policy is incorporated by reference, you acknowledge and agree to accept the practices described in this Privacy Policy regarding the collection, use, disclosure, and transfer of your Personal Information. If you do not agree to the terms of this Privacy Policy, please do not use the Services. This Privacy Policy is not a contract and does not create any contractual rights or obligations. Your use of the Services is governed by the applicable Terms of Use or Terms and Conditions of the respective Services.
1.4. Please note that some privacy rights and obligations may differ in certain locations based on local law, in which case Healthsoft will comply with the local legal requirements. If you are a California resident, our Privacy Notice for California Residents in Section 18 may apply to you. Healthsoft reserves the right, at any time, to modify this Privacy Policy. If we make revisions that change the way we collect, use, or share Personal Information, we will post those changes in this Privacy Policy. If we make material changes to our Privacy Policy, we may also notify you by other means prior to the changes taking effect, such as by posting a notice on our Site or sending you notification. You should review this Privacy Policy periodically so that you keep up to date on our most current policies and practices. Healthsoft will note the effective date of the latest version of our Privacy Policy at the beginning of this Privacy Policy.
1.5. Employees and job applicants who are California residents receive a supplemental privacy notice that applies to their relationship with Healthsoft in the context of their employment or job application. In the event of any conflict with this Privacy Policy, the terms of the supplementary employee notice will control.
- The Personal Information We Collect
2.1. When you access and use the Services, we may collect the following types of information:
2.1.1. “Personal Information” is information that identifies an individual or relates to an identifiable individual or household. The types of Personal Information collected, and the uses thereof depend on the purposes for which we collect the Personal Information (e.g., whether you are a visitor to our Sites, a user of our Portals, or a customer of our Services). As used in this Privacy Policy, Personal Information does not include Protected Health Information.
2.1.2. “Protected Health Information” or “PHI” is individually identifiable health information that is protected by the Health Insurance Portability and Accountability Act of 1996, as amended, and its implementing regulations (“HIPAA”).
2.1.3. “Usage Data” is information that we automatically collect about your use of the Sites and includes the sort that Web browsers and servers typically make available, through Web server logs, Web beacons, cookies and other similar tracking technologies, about the devices you use to access our Sites, as well as information on how you interact with our Sites. We do not deploy non-essential third-party cookies or similar tracking technologies on the Portals; however, we may collect log information including Usage Data for internal uses or uses by our service providers on our behalf, such as ensuring the security and integrity of our Services. Usage Data may include the IP address of a device or internet service used to connect your device to the Internet and may provide information about your Location; computer and connection information such as your browser type and version; operating system and platform; confirmation when you open e-mail that we send you; purchase history; and the URLs which lead you to and around the Site including the date and time of access. Usage Data may overlap with Location Information. Usage Data generally does not directly identify an individual, but may constitute Personal Information in some instances.
- How We Collect Your Personal Information
3.1. Healthsoft uses information collected from users of the Services to personalize and improve your visit and experience, to provide the Services to you or our customers, and for other purposes set out below. When you use the Services, Healthsoft may collect Personal Information in the following ways described below.
3.2. Information You Provide to Healthsoft: Healthsoft collects Personal Information when you use and interact with the Services, such as when you:
3.2.1. Communicate with Healthsoft about our Services whether by letter, e-mail, online chat window, or telephone;
3.2.2. Complete and submit forms to us on our Sites or Provider Portals (e.g., to register for an account on a Provider Portal, authenticate yourself to verify your authorized use of the Services, to register for our events, or to subscribe to our newsletters);
3.2.3. Visit our offices; or
3.2.4. Visit our Sites or interact with us on social media and provide us Personal Information.
3.3. Information that Healthsoft Collects Automatically: When you use the Services, Healthsoft may automatically collect Usage Data subject to the settings of your device that you use to access the Services. With your consent, we may also collect information from your device to facilitate your use of certain features of the Services. Healthsoft may use this data to analyze trends and statistics to improve your online experience or our customer service. We do not deploy non-essential third-party cookies or similar tracking technologies on our Portals but may collect Usage Data for purposes such as ensuring the security and integrity of our Services.
3.4. Information from Other Sources: Healthsoft may collect Personal Information from other sources such as the Internet and other publicly-available sources and databases, data aggregators, marketing companies, and other third parties, including sources from which you authorize us to obtain Personal Information about you on your behalf. If you authorize us to collect information from a third party, or if you authorize a third party to send us information, and you later decide that you no longer want us to obtain that information, you may need to contact the third-party source directly and request that they stop transmitting information to us. For example, if you submit claims to the Centers for Medicare and Medicaid Services (“CMS”), you may decide to authorize us to obtain information directly from CMS. For more information about how those third parties collected and used your Personal Information, please review the privacy policy of the respective third party.
- Protected Health Information; Healthsoft as a Business Associate
4.1. Certain Services we provide to our customers or make available to their patients, such as the Portals, as well as certain support operations, involve access to, and the processing of, PHI. This PHI is provided to us pursuant to a service agreement, business associate agreement, or other document with terms and conditions for the Services (the “Customer Documents”) that we have entered with our customers (health care providers or their firms, “Providers”) that also govern our use of PHI of their patients provided by our Provider customers or their patient users.
4.1.1. This Privacy Policy supplements the Customer Documents. Healthsoft only uses such PHI as a “business associate” of its Providers, who are “covered entities,” in accordance with any instructions or restrictions provided to Healthsoft by the Provider and in full compliance with the applicable provisions of HIPAA.
4.1.2. If you are a patient of a Provider, our use and disclosure of your Protected Health Information is governed by HIPAA and other applicable law and the Customer Documents with your Provider — not by this Privacy Policy. Your Provider’s collection, use, disclosure, and transfer of such PHI are governed, in turn, by your Provider’s terms and conditions and privacy practices between you and your Provider. Please submit all requests and questions related to your PHI directly to your Provider. We are not responsible for how our Provider customers treat PHI we collect on their behalf, and we recommend you review their own privacy policies.
4.1.3. Our Sites are generally not intended to collect or retain any PHI. Thus, sections of this Privacy Policy that discuss Personal Information collection on the Sites do not apply to PHI, and we do not request, obtain, use or disclose any PHI through our Sites such as https://healthsoftus.com.
- Use of Information Collected By Healthsoft
5.1. Healthsoft uses the Personal Information collected to provide Services to our customers and their authorized users to improve user experience with the Services, and to communicate with you about requested information. Healthsoft may use Personal Information to help target specific offers to customers and others and to develop and improve its Services. Additionally, Healthsoft may disclose your Personal Information as discussed below in Section 7, and use your Personal Information to:
- Respond to user service requests, user questions and concerns, and administer user accounts. We may use your information to verify your identity, register you, administer your account, or provide you the information, products, and services that you request.
- Provide service to our customers, which include Providers. If you are a patient of a Provider, we use your information when providing the Services to the Provider.
- Communicate with users about our products, services, and related issues. We may use your information to try to identify if you may be interested in any of the Services or our business partners’ products and services. If we think something may interest you, we may send you information and promotional materials. You may unsubscribe from receiving marketing e-mails from us by using the unsubscribe link included in marketing e-mails.
- Administer fees and provide users with invoices or resolve billing issues. We may use your information to verify your identity in order to process your payments.
- Ensure the security and integrity of our Services.
- Conduct research and analysis, including auditing related to advertising impressions. We may use your information, subject to your consent, or otherwise in de-identified or aggregate form as part of research studies.
- Verify and maintain the quality of our Services, improve the Services, or develop new Services.
- In the event of a business transaction. If we are exploring or go through a business transition or financial transaction, such as a merger, acquisition, divestiture, restructuring, reorganization, dissolution, bankruptcy, securities offering, or sale of all or a portion of our assets, we may use your information in connection with exploring or concluding such transaction.
- To comply with law. We may disclose your information to comply with any applicable laws and/or regulations, such as to comply with valid legal processes such as a search warrant, subpoena, or order from a court or tribunal of competent jurisdiction.
- Data Collection Technologies
6.1. We and our service providers may use cookies, Web beacons, log files, and other technologies (collectively, “Data Collection Technologies”) to help us provide, customize, and improve the Sites. We do not deploy non-essential third-party cookies or similar tracking technologies on our Portals. The Data Collection Technologies we use on our Sites include:
6.1.1. Web Beacons: A Web Beacon is a Web page element (such as a clear gif, pixel tag or single-pixel gif) that may be embedded into our Sites or e-mail communications, and which may employ cookie technology to enable Healthsoft to record clickstream data
6.1.2. Cookies: Cookies are small text files placed on your device to store data that can be recalled by a Web server in the domain that placed the cookie. Cookies enable Healthsoft to collect clickstream data, including traffic on the Sites. You may set your browser to reject certain cookies or to notify you when you are sent a cookie. Rejecting cookies may limit functionality of the Sites. Third parties also provide software that allows you to visit the Sites without providing certain types of this information. Our Sites may use the following types of cookies:
6.1.2.1. Essential/Strictly Necessary Cookies: These cookies are necessary for the Sites to function and cannot be switched off in our systems. They are usually only set in response to actions made by you which amount to a request for services, such as setting your privacy preferences, logging in or filling in forms. You can set your browser to block or alert you about these cookies, but some parts of the Sites will not then work.
6.1.2.2. Analytics/Performance Cookies: These cookies allow us to count visits and traffic sources, so we can measure and improve the performance of our Sites. They help us know which pages are the most and least popular and see how visitors move around the Sites.
6.1.2.3. Targeting/Advertising Cookies: These types of cookies may be set by our advertising partners at Sites at which a cookie banner is displayed. These cookies may be used by those advertising partners to build a profile of your interests and to show you relevant adverts on other websites. You may disallow these targeting/advertising cookies using the cookie banner. California residents may also opt-out of certain sharing of information through these cookies including by visiting the “Your Privacy Choices” section of our website and following the instructions there, as described further in Section 18.5.1. If you do not allow these cookies, you will experience less targeted advertising.
6.1.3. Analytics Services: We may use third-party Web analytics services (such as those of Google Analytics) and other technologies on our Sites to: collect and analyze usage information through cookies and similar tools; engage in activities such as auditing, research, or reporting; and provide certain features to you. To prevent Google Analytics from using your information for analytics, you may install the Google Analytics Opt-out Browser Add-on.
6.2. Notice Concerning Do Not Track: Do Not Track (“DNT”) is a privacy preference that users can set in certain web browsers. We are committed to providing you with meaningful choices about the information collected on our website for third-party purposes, and that is why we provide the variety of opt-out mechanisms listed above and recognize “Global Privacy Control” through our vendor, OneTrust. However, we do not currently use technology that specifically recognizes DNT signals from your Web browser. You can learn more about DNT here.
- Disclosing Your Information
We may disclose your Personal Information for the following reasons:
7.1.1. At Your Request: Healthsoft may disclose Personal Information to third parties at your request, direction, or authorization. For example, if you direct Healthsoft to disclose your Personal Information to a third-party entity, whether and Healthsoft business partner or other third party to use the third party’s service, we will share your information with the third party.
7.1.2. Internal Sharing: Healthsoft may disclose Personal Information to its affiliates (including parents, entities under common ownership, and subsidiaries, such as Healow, LLC), and other related companies without authorization.
7.1.3. With Our Service Providers: Healthsoft may disclose Personal Information to service providers for the purposes of operating our business, delivering, improving, and customizing our products or services, sending marketing and communications related to our business, payment processing, and for other legitimate purposes permitted by applicable law.
7.1.4. With Our Customers: Healthsoft may disclose Personal Information, including Sensitive Personal Information, to its customers consistent with the Customer Documents. Sensitive Personal Information” refers to Personal Information regarding more sensitive areas, such as government ID and certain other financial information, gender, marriage status, race/ethnicity, or veteran or disability status.
7.1.5. Compliance with Law: To the extent permitted by law, Healthsoft will disclose Personal Information to government authorities or third parties pursuant to a legal request, subpoena, or other legal process. Healthsoft may also use or disclose your Personal Information as permitted by law to perform charge verifications, apply, or enforce the Service’s Terms of Use or Terms and Conditions, or protect Healthsoft’s rights, interests, or property as well as those of Healthsoft affiliates, customers, or Service users
7.1.6. Business Transaction: If Healthsoft sells all or part of its business or makes a sale or transfer of assets or is otherwise involved in a merger or business transfer, Healthsoft may transfer your Personal Information to a third party as part of that transaction.
- Advertising and Third-Party Data Collection
Healthsoft may enter into relationships with third-party advertising companies to drive traffic to and serve ads on our Site. These third-party companies may also collect information through Data Collection Technologies described in Section 6 to measure the effectiveness of their ads and to personalize advertising content. The Network Advertising Initiative offers useful information about Internet advertising companies (also called “ad networks” or “network advertisers”), including information about how to opt-out of their information collection. We do not use such providers on our Portals.
8.1. You may opt-out of receiving marketing communications from us by following the instructions included in such a communication or by contacting us as provided in the Contact Information Section 17. If you opt out, we may still send you non-marketing communications, such as those about your account or our ongoing business relationship.
8.2. You may review and request changes to the Personal Information we have collected about you by contacting us as provided in the Contact Information Section 17 below.
- Biometric Data
In connection with the Services, Healthsoft may collect or store biometric data, such as fingerprints or facial geometry scans that may identify you, which are used for authentication and verification of your identity. This information may be biometric data under certain laws governing the collection, use, storage, and disclosure of biometric data. By providing such information, you acknowledge that you have been advised of, and understand that, Healthsoft, and its agents and contractors, may collect, use, store, and disclose biometric data for the purposes described in this Privacy Policy, or as otherwise described in the Services. We will not sell, lease, or trade your biometric information. We will retain such biometric data only until the occurrence of the first of the following, at which point the data will be scheduled for deletion: (a) the purposes outlined in this Section 9 have been satisfied, (b) any date of deletion required by applicable law, or (c) three (3) years have passed since your last interaction with our Services. Notwithstanding the foregoing, (1) Healthsoft will not delete biometric data that is PHI unless requested by the applicable Provider, and (2) except as provided in subsection (1), the collection, use, storage, disclosure, and retention of biometric data that is PHI through the use of any of the Services shall be governed by Section 4 of this Privacy Policy and any applicable Customer Documents, not by this Section 9.
- Security of Personal Information
Healthsoft has reasonable and appropriate safeguards in place to help protect the Personal Information Healthsoft collects from loss, misuse, and unauthorized access, disclosure, alteration, and destruction. Although Healthsoft attempts to protect the Personal Information in our possession, no security system is perfect, and Healthsoft cannot promise that your Personal Information will remain absolutely secure in all circumstances.
- Retention of Personal Information
Healthsoft will retain your Personal Information as needed to fulfill the purposes for which it was collected. Healthsoft will retain and use your Personal Information as necessary to comply with Healthsoft’s business requirements, legal obligations, resolve disputes, protect our assets, and enforce our agreements. Additional information for California residents about our data retention practices is available in our Privacy Notice for California Residents.
- Aggregated De-Identified Information
Healthsoft may provide aggregated information related to your Personal Information to some of Healthsoft’s business partners. This information is used in a collective manner and does not identify you individually in any way. If you are a patient of a Provider, we may only create, use or disclose aggregated or certain de-identified PHI as authorized by your Provider in the Customer Documents.
- Links to Third Party Websites
Our Sites may contain certain links to third party websites. Healthsoft is not responsible or liable for the privacy practices or content found on these websites. You should check the privacy notice and policies of each website you visit. Links to third party websites are provided solely for your convenience and any use or submission of data to such websites shall be at your sole risk.
- Children’s Privacy
Our Sites are not directed toward individuals under the age of 18. We do not promote our Sites to individuals under 18, and we do not knowingly collect any Personal Information through our Sites from individuals under 18. Access to our Portals is separately governed by the Portals’ posted Terms of Use.
- United States Only
The Services are intended for use only in the United States of America. If you use the Services or contact us from outside of the United States of America, please be advised that (i) any information you provide to us or that we automatically collect will be transferred to the United States of America; and (ii) by using the Services or submitting information, you explicitly authorize its transfer to and subsequent processing in the United States of America in accordance with this Privacy Policy.
- Changes to the Privacy Policy
Healthsoft may change this Privacy Policy at any time. Unless we say otherwise, changes will be effective upon the last updated date at the top of this Privacy Policy. Please check this Privacy Policy regularly to ensure that you are aware of any changes. We may try to notify you of material changes to this Privacy Policy, which if we do so may be by means such as by posting a notice directly on the Services, by sending an e-mail notification (if you have provided your e-mail address to us), or by other reasonable methods. In any event, if you use the Services after changes to this Privacy Policy, you have accepted the changes. If you do not agree with the changes, please stop using the Services.
- Contact Information
If you have any questions or concerns related to this Privacy Policy or if you need to report a Privacy incident, please contact the Healthsoft Chief Privacy Officer at:
Healthsoft, LLC
357 Crystal Downs Way
Suwanee, GA 30024
Attn: Chief Privacy Officer
If you have any questions or concerns related to Security or if you need to report a Security incident, please contact the Healthsoft Chief Information Security Officer at:
Healthsoft, LLC
357 Crystal Downs Way
Suwanee, GA 30024
Attn: Chief Information Security Officer
[email protected]
These e-mail addresses are monitored only for privacy- and security-related inquiries. If you are a patient and have a question related to accessing the Patient Portal, please contact your healthcare provider.
Pursuant to applicable law, Healthsoft may be required to send you notice of known or suspected security breaches that impact your Personal Information. In the event that Healthsoft must provide a notice of a security breach to you, Healthsoft will send security breach notices to the contact information contained in your account information unless Healthsoft is required by law to notify you using another method. Otherwise, if Healthsoft needs, or is required, to contact you concerning any event that involves information about you we may do so by e-mail, telephone, or mail.