This Privacy Policy describes how Medcare Telehealth Inc, doing business as Medcare ("Medcare," "we," "us," or "our"), may collect, use, maintain, disclose, and otherwise process information in connection with:
- MedcareTelehealth.org;
- Medcare websites and applications;
- patient portals;
- membership services;
- telehealth services;
- live video visits;
- communications; and
- other services that reference this Privacy Policy,
collectively, the "Services."
By accessing or using the Services, you acknowledge that you have had an opportunity to review this Privacy Policy.
This Privacy Policy is intended to describe general privacy practices and does not replace Medcare's separate Notice of Privacy Practices where the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations ("HIPAA") apply.
To the extent information constitutes Protected Health Information ("PHI") subject to HIPAA, its use and disclosure may also be governed by Medcare's Notice of Privacy Practices and applicable law.
If this Privacy Policy and the Notice of Privacy Practices address the same PHI differently, applicable law and the Notice of Privacy Practices govern to the extent required.
1. Scope
This Privacy Policy applies to information collected in connection with the Services.
Different federal and state laws may apply to different categories of information.
The rights and obligations applicable to particular information may depend on factors including:
- the type of information;
- how it was collected;
- how it is used;
- the individual's location;
- the location where healthcare services are provided; and
- applicable federal and state law.
Nothing in this Privacy Policy is intended to waive, restrict, or create rights beyond those provided by applicable law.
2. Information That May Be Collected
Depending on how an individual uses the Services, Medcare Telehealth Inc or service providers acting in connection with the Services may collect various categories of information.
Identity and Contact Information
This may include:
- Name
- Date of birth
- Age
- Email address
- Telephone number
- Mailing address
- Billing address
- State of residence
- Patient identifiers
- Government-issued identification information where reasonably necessary
Account Information
This may include:
- Username
- Authentication credentials
- Account status
- Login activity
- Security information
- Account preferences
- Membership information
Family Membership Information
This may include:
- Names of family members
- Dates of birth
- Relationships
- Eligibility information
- Membership status
- Shared visit usage
- Information relating to consent, parental authority, guardianship, or authorization
Family membership administration and access to an individual's medical information are separate matters.
Access to medical information may depend upon applicable law, patient authorization, consent, parental rights, guardianship, or other legal authority.
Financial and Transaction Information
Information associated with payments and memberships may include:
- Membership plan
- Billing status
- Transaction amount
- Transaction date
- Refund information
- Payment method
- Billing address
- Payment status
- Limited payment-card information
Payment information may be processed by third-party payment processors.
Health and Medical Information
When an individual seeks healthcare through the Services, information may include:
- Reason for visit
- Symptoms
- Medical history
- Surgical history
- Family medical history
- Allergies
- Current medications
- Previous medications
- Prescription information
- Diagnoses
- Treatment information
- Provider assessments
- Provider notes
- Care plans
- Referral information
- Follow-up information
- Pharmacy information
- Laboratory information
- Imaging information
- Uploaded documents or photographs
- Height
- Weight
- Body mass index
- Vital signs
- Pregnancy-related information where clinically relevant
- Other information related to healthcare services
Payment for membership or services does not itself establish eligibility for any particular treatment or prescription.
Clinical decisions remain subject to the judgment of the treating healthcare professional and applicable law.
Communications
Information may also include:
- Portal messages
- Emails
- Text communications
- Telephone communications
- Customer-service communications
- Complaints
- Feedback
- Privacy requests
- Administrative communications
3. Telehealth and Video Visits
Telehealth encounters may involve live audio and video communications between patients and healthcare professionals.
Information communicated during a healthcare encounter may become part of the patient's medical record.
Technical information associated with a telehealth session may include:
- Session date and time
- Patient and provider identifiers
- Connection information
- Device information
- Browser information
- IP address
- Technical diagnostics
- Session status
Audio or video recording practices, if any, are subject to applicable law, consent requirements, platform configuration, clinical policy, and other applicable requirements.
4. Automatically Collected Information
When individuals access the Services, certain technical information may be collected automatically.
This may include:
- IP address
- Browser type
- Operating system
- Device type
- Device identifiers
- Pages viewed
- Links clicked
- Referring webpage
- Date and time of access
- Session information
- General location derived from IP address
- Cookies
- Authentication activity
- Security events
- Performance information
- Error logs
Such information may be used for purposes including:
- Operating the Services
- Security
- Authentication
- Fraud prevention
- Troubleshooting
- Performance analysis
- Website administration
- Audit purposes
- Improvement of functionality
5. Cookies and Similar Technologies
The Services may use cookies, pixels, local storage, software development kits, logging technologies, or similar technologies.
These technologies may be used for purposes including:
- Authentication
- Security
- Session management
- Fraud prevention
- User preferences
- Website functionality
- Performance measurement
- Analytics
- Other lawful operational purposes
The use of particular technologies may vary over time based on the Services, vendors, legal requirements, system configuration, and business needs.
Where applicable law requires consent or other choices concerning certain technologies, those requirements apply.
6. How Information May Be Used
Subject to applicable law, information may be used for purposes including:
Healthcare Services
- Providing telehealth services
- Evaluating symptoms
- Conducting assessments
- Developing treatment plans
- Prescribing medication when clinically appropriate
- Coordinating with pharmacies
- Ordering or reviewing testing
- Providing follow-up care
- Making referrals
- Maintaining medical records
- Coordinating care
Membership Administration
- Establishing accounts
- Managing memberships
- Managing family memberships
- Tracking included visits
- Processing additional visits
- Managing membership renewal
- Managing cancellation
- Providing account information
Billing and Business Operations
- Processing transactions
- Managing billing
- Processing refunds
- Accounting
- Fraud prevention
- Vendor management
- Internal administration
- Operational analysis
- Quality activities
- Auditing
Security
- Authentication
- Access control
- Fraud detection
- Investigation of suspicious activity
- Security monitoring
- Incident investigation
- Audit logging
Communications
- Account communications
- Membership communications
- Payment notifications
- Visit-related communications
- Customer-support communications
- Security notifications
- Other service-related communications
Legal and Regulatory Purposes
- Compliance with law
- Responding to legal process
- Maintaining required records
- Regulatory compliance
- Licensing compliance
- Exercising legal rights
- Defending legal claims
- Enforcing agreements
7. Treatment, Payment, and Healthcare Operations
Where HIPAA applies, PHI may be used or disclosed for treatment, payment, healthcare operations, and other purposes permitted or required by applicable law.
Additional information regarding uses and disclosures of PHI may be contained in Medcare Telehealth Inc's Notice of Privacy Practices.
8. Information Sharing and Disclosure
Information may be disclosed as reasonably necessary or legally permitted in connection with the Services.
Recipients may include:
Healthcare Professionals
- Physicians
- Nurse practitioners
- Physician assistants
- Nurses
- Pharmacists
- Other healthcare professionals
Pharmacies and Prescription Services
Information may be transmitted to:
- Retail pharmacies
- Mail-order pharmacies
- Specialty pharmacies
- Electronic-prescribing systems
- Pharmacy networks
Other Healthcare Organizations
Information may be shared with:
- Laboratories
- Imaging providers
- Specialists
- Hospitals
- Clinics
- Other healthcare organizations involved in care
Vendors and Service Providers
Third parties may provide services including:
- Electronic health records
- Patient portal technology
- Telehealth technology
- Video technology
- Hosting
- Cloud infrastructure
- Cybersecurity
- Data storage
- Electronic prescribing
- Payment processing
- Identity verification
- Communications
- Customer support
- Scheduling
- Software
- Information technology
- Analytics
- Professional services
Where applicable law requires particular agreements or safeguards in connection with such services, those requirements apply.
Professional Advisors
Information may be disclosed where appropriate to:
- Attorneys
- Accountants
- Auditors
- Insurers
- Consultants
- Compliance professionals
- Security professionals
Government and Regulatory Authorities
Information may be disclosed in circumstances permitted or required by law, including to:
- Courts
- Regulators
- Licensing boards
- Government agencies
- Public-health authorities
- Law-enforcement authorities
- Healthcare oversight organizations
9. Legal Process and Other Disclosures
Information may be disclosed where permitted or required in connection with matters such as:
- Court orders
- Warrants
- Subpoenas
- Administrative proceedings
- Government investigations
- Healthcare oversight
- Public-health activities
- Abuse or neglect reporting
- Threats to health or safety
- Workers' compensation
- Law-enforcement activities
- Other legally authorized matters
All such disclosures remain subject to applicable law.
10. Corporate Transactions
Information may be reviewed, transferred, disclosed, or otherwise processed in connection with a proposed or completed:
- Merger
- Acquisition
- Financing
- Reorganization
- Sale of assets
- Change of control
- Bankruptcy
- Corporate restructuring
- Due-diligence process
Any limitations imposed by applicable healthcare or privacy law continue to apply.
11. Email, Text, and Electronic Communications
Electronic communications may involve privacy and security risks.
Information transmitted through ordinary email, SMS, personal devices, telecommunications providers, internet connections, or other systems outside Medcare Telehealth Inc's control may be subject to risks beyond Medcare Telehealth Inc's control.
Communications may include:
- Account notifications
- Membership notices
- Visit communications
- Payment communications
- Security notifications
- Administrative notices
- Customer-support communications
Marketing communications, where used, are subject to applicable legal requirements.
12. Artificial Intelligence and Automation
Technology, software, automated systems, machine learning, or artificial intelligence may be used in connection with administrative, operational, security, documentation, customer-service, or other functions where permitted by applicable law.
Such technologies may be used for purposes including:
- Scheduling
- Workflow management
- Administrative assistance
- Documentation support
- Customer-service support
- Security
- Fraud prevention
- Quality review
- Operational analysis
Clinical decision-making remains subject to applicable healthcare laws, professional standards, and the professional judgment of licensed healthcare professionals.
13. De-identified and Aggregated Information
Information may be de-identified, anonymized, aggregated, or otherwise processed so that it is no longer reasonably identifiable to an individual, subject to applicable law.
Such information may be used for purposes including:
- Analytics
- Statistical analysis
- Service improvement
- Business planning
- Quality improvement
- Operational analysis
- Research
- Development
Legal requirements governing de-identification and re-identification apply where applicable.
14. Advertising and Analytics Technologies
Public-facing portions of the Services may use analytics, measurement, or advertising technologies where legally permissible.
The application of advertising, analytics, and tracking technologies to healthcare-related information is subject to applicable federal and state privacy requirements.
Different technologies and vendors may be added, removed, or modified over time.
Nothing in this Privacy Policy should be interpreted as authorizing processing prohibited by applicable healthcare privacy law.
15. Payment Processors and Third-Party Services
Third-party providers may process certain information in connection with payments, software, communications, identity verification, or other functions.
Some third parties may operate under their own terms, privacy policies, or independent legal obligations.
Medcare Telehealth Inc's responsibility for third-party conduct is subject to applicable law, the nature of the relationship, applicable contracts, and whether the third party acts on Medcare Telehealth Inc's behalf.
16. Third-Party Links
The Services may include links to third-party websites or services.
A link does not necessarily indicate endorsement, control, affiliation, or responsibility for the practices of the third party.
When a user leaves the Services and interacts directly with an independent third party, that third party's privacy practices may apply.
17. Family Memberships and Privacy
Medcare's Family Membership may allow multiple eligible family members to share membership benefits.
The included visits associated with a Family Membership may be used by eligible family members in accordance with applicable membership terms.
Membership administration does not automatically provide unrestricted access to another person's medical information.
Access to another patient's medical information may depend on:
- Patient authorization
- Parental rights
- Guardianship
- Legal representative status
- Applicable federal law
- Applicable state law
- Other legally recognized authority
18. Minors
Healthcare services involving minors are subject to applicable federal and state laws concerning consent, parental authority, confidentiality, medical decision-making, and access to records.
Requirements may vary based on:
- Patient age
- State
- Type of healthcare service
- Parental authority
- Guardianship
- Whether the minor may legally consent independently
Documentation of legal authority may be requested where reasonably necessary.
19. Information Provided About Another Person
Individuals who provide information concerning another person are responsible for having any authority required by applicable law to provide such information.
This may apply when:
- Adding family members
- Acting for a minor
- Acting as a guardian
- Acting as an authorized representative
- Assisting another patient
The existence of a membership relationship does not itself establish legal authority over another person's medical information.
20. Information Security
Administrative, physical, organizational, and technical safeguards may be used in connection with personal information.
The particular safeguards used may vary based on:
- The system
- Type of information
- Level of sensitivity
- Operational needs
- Technological capabilities
- Risk assessments
- Applicable legal requirements
Security measures may include:
- Authentication
- Access controls
- Encryption
- Audit logging
- Monitoring
- Network protections
- Workforce training
- Vendor controls
- Incident-response procedures
- Backup systems
No electronic system, transmission method, database, application, network, or device can be guaranteed to be completely secure.
21. Security Incidents
Potential privacy or security incidents may be investigated, documented, addressed, or reported as appropriate.
Notification obligations concerning security incidents or breaches are governed by applicable law.
22. Data Retention
Information may be retained for periods considered appropriate or required based on:
- Healthcare requirements
- Medical-record retention laws
- Licensing obligations
- Membership administration
- Accounting requirements
- Tax requirements
- Fraud prevention
- Security requirements
- Litigation
- Regulatory matters
- Contractual obligations
- Business operations
- Other lawful purposes
Retention periods may differ by state, patient age, type of information, and other circumstances.
Cancellation of a membership does not necessarily require deletion of information.
23. Legal Holds and Preservation
Information may be preserved beyond an otherwise applicable retention period where appropriate in connection with:
- Actual or anticipated litigation
- Government investigations
- Regulatory matters
- Audits
- Subpoenas
- Court orders
- Preservation requests
- Legal claims
- Other lawful matters
24. HIPAA Rights
Where HIPAA applies, individuals may have rights concerning PHI as provided by applicable law.
These may include rights involving:
- Access
- Copies of certain records
- Amendments
- Restrictions
- Confidential communications
- Accounting of certain disclosures
- Privacy complaints
- Copies of the Notice of Privacy Practices
The scope of these rights and applicable exceptions are governed by law and Medcare Telehealth Inc's Notice of Privacy Practices.
25. State Privacy Rights
Certain state laws may provide additional rights concerning particular categories of personal or health-related information.
Depending on applicable law, rights may include:
- Access
- Correction
- Deletion
- Copies of information
- Restrictions on processing
- Consent withdrawal
- Information regarding disclosures
- Appeals
Exceptions and limitations may apply.
Certain healthcare information or healthcare entities may be exempt from some state consumer privacy laws.
Requests are evaluated according to the law applicable to the individual, entity, and information involved.
26. Consumer Health Data
Certain states regulate "consumer health data" separately from HIPAA.
Where applicable, additional privacy notices, consents, authorizations, or consumer rights may apply.
A state-specific Consumer Health Data Privacy Notice may be provided where appropriate.
27. Privacy Request Verification
Identity, authority, account ownership, guardianship, parentage, or authorized representative status may be verified before processing certain privacy requests.
Requests may be limited or denied where permitted by applicable law, including where identity or legal authority cannot reasonably be verified.
28. Authorized Representatives
Where applicable law permits an authorized representative to exercise privacy rights on behalf of another individual, documentation or verification of that authority may be required.
A person paying for a membership is not necessarily an authorized representative for medical privacy purposes.
29. International Access
The availability of a website or portal in a particular geographic location does not establish that healthcare services are legally available in that location.
Healthcare services may be limited based on:
- Patient location
- Provider licensing
- State law
- Federal law
- Clinical policy
- Other regulatory requirements
A patient's physical location may be requested or verified in connection with telehealth services.
30. User Account Responsibility
Users are responsible for taking reasonable precautions regarding systems and credentials under their control.
This may include:
- Protecting passwords
- Protecting email accounts
- Protecting authentication devices
- Logging out of shared devices
- Preventing unauthorized access
Account access may be restricted or suspended where reasonably necessary for security, fraud prevention, investigation, legal compliance, or account administration.
31. Changes to This Privacy Policy
This Privacy Policy may be revised periodically.
Changes may relate to:
- Changes in law
- Changes in technology
- Changes in vendors
- Changes in Services
- Changes in operations
- Regulatory developments
- Business changes
The "Last Updated" date identifies the version then in effect.
Any additional notice or consent legally required for particular changes will be governed by applicable law.
32. No Additional Contractual Rights
This Privacy Policy is intended primarily to provide information regarding privacy practices.
Except where applicable law provides otherwise or a separate written agreement expressly states otherwise, this Privacy Policy is not intended to:
- Create additional contractual rights;
- Expand duties beyond those imposed by applicable law;
- Waive any legal defense;
- Waive any privilege;
- Waive any exemption;
- Waive any limitation;
- Restrict any legally available right or remedy.
Nothing in this Privacy Policy alters any right or obligation that cannot legally be modified by agreement.
33. No Warranty Regarding Technology
The Services may depend upon internet connections, telecommunications systems, software, third-party platforms, cloud systems, devices, and other technology.
No representation is made that electronic systems are immune from:
- Interruption
- Unauthorized access
- Cyberattack
- Technical failure
- Transmission error
- Device failure
- Internet outage
- Third-party failure
This provision does not eliminate obligations imposed by applicable privacy or security law.
34. Severability
If any provision of this Privacy Policy is determined to be invalid or unenforceable, it may be limited or interpreted to the extent necessary to preserve enforceability where permitted by law.
The remaining provisions continue to apply to the extent legally permissible.
35. No Waiver
Failure to exercise a right does not constitute a waiver of that right.
Nothing in this Privacy Policy waives any defense, privilege, immunity, exemption, limitation, or other protection available under applicable law.
36. Privacy Requests and Questions
Privacy-related questions, requests, complaints, or medical-record matters may be submitted through the contact methods made available by Medcare Telehealth Inc through MedcareTelehealth.org or the Medcare patient portal.
Medcare may require reasonable verification of identity, authority, account ownership, guardianship, parentage, or authorized representative status before processing certain requests.
Sensitive medical information should not be submitted through unsecured communications unless appropriate.
37. Notice of Privacy Practices
Individuals receiving healthcare through Medcare may also be subject to Medcare Telehealth Inc's separate:
NOTICE OF PRIVACY PRACTICES
That notice may contain additional information concerning:
- Uses and disclosures of PHI
- Treatment
- Payment
- Healthcare operations
- Patient rights
- Medical-record access
- Amendments
- Restrictions
- Confidential communications
- Disclosure accounting
- Privacy complaints
- Other legally required HIPAA information
38. General Legal Limitation
This Privacy Policy should be interpreted consistently with applicable federal and state law.
Nothing contained in this Privacy Policy is intended to:
- Provide medical advice;
- Provide legal advice;
- Create rights beyond those required by law;
- Increase Medcare Telehealth Inc's obligations beyond applicable legal requirements;
- Limit any right, defense, privilege, exemption, immunity, or remedy available to Medcare Telehealth Inc under applicable law; or
- Waive any protection that may otherwise apply.
To the extent a provision conflicts with non-waivable applicable law, applicable law controls.
