CarePortals LLC (“CarePortals,” “we,” “our,” or “us”) provides technology infrastructure that enables healthcare organizations, telehealth businesses, and other digital health companies to build, operate, and manage healthcare experiences.
Privacy and security are fundamental to the services we provide. This Privacy Policy explains how CarePortals handles personal information in connection with our corporate websites, business relationships, and Services.
It also explains an important distinction between information CarePortals collects for its own business purposes and information we process on behalf of organizations using the CarePortals platform.
1. Scope and Our Role
CarePortals operates primarily as a technology provider to healthcare and digital health organizations (“Customers”).
Our Customers may use CarePortals technology to operate patient experiences and workflows, including e-commerce, patient portals, intake and eligibility, telehealth, electronic health records, customer relationship management, communications, prescriptions, orders, subscriptions, payments, and integrations with other healthcare services.
As a result, CarePortals may handle information in different capacities.
Information CarePortals Controls
This Privacy Policy applies when you interact directly with CarePortals, including when you:
- visit our corporate website;
- request information or a demonstration;
- communicate with our sales or support teams;
- work for or represent a CarePortals Customer or prospective Customer;
- create or administer a business account with us; or
- otherwise interact with CarePortals in a business capacity.
In these situations, CarePortals may determine how and why your personal information is processed.
Information We Process for Customers
CarePortals also processes information on behalf of Customers that use our technology.
This can include information relating to patients and other end users of Customer-operated healthcare experiences.
When we process this information on behalf of a Customer, our handling of the information is governed by our agreement with that Customer and applicable law. Where the information constitutes Protected Health Information (“PHI”) and CarePortals acts as a Business Associate, it is also governed by the applicable Business Associate Agreement (“BAA”) and the Health Insurance Portability and Accountability Act and its implementing regulations (“HIPAA”).
If you are a patient or end user of a healthcare organization or brand powered by CarePortals, that organization is generally the appropriate point of contact for questions or requests concerning your information.
CarePortals assists its Customers in fulfilling their privacy and data protection obligations as required by applicable law and our agreements with them.
2. Information Handled Through the CarePortals Platform
Because CarePortals provides infrastructure for healthcare businesses, the types of information processed through the platform depend on how each Customer configures and uses our Services.
Information processed on behalf of Customers may include:name and contact information;
- account and authentication information;
- demographic information;
- patient intake and eligibility responses;
- medical history and other health information;
- treatment and prescription information;
- provider and telehealth interactions;
- pharmacy and fulfillment information;
- laboratory information;
- orders, subscriptions, and transaction information;
- appointment information;
- patient communications; and
- other information submitted through a Customer’s healthcare experience.
CarePortals processes this information to provide the technology and functionality requested by the applicable Customer.
Depending on the Customer’s configuration, this may include transmitting information among the Customer and authorized healthcare providers, physician networks, pharmacies, laboratories, payment providers, and other services involved in the Customer’s operations.
CarePortals does not use PHI that it processes as a Business Associate for independent advertising purposes.
3. Information We Collect Directly
When you interact directly with CarePortals, we may collect the following categories of information.
Business and Contact Details
This may include your:
- name;
- business email address;
- telephone number;
- company;
- job title; and
- business address.
CarePortals Account Information
If you are an authorized user of a Customer account, we may collect:
- username and authentication information;
- organization and role;
- account permissions;
- preferences; and
- activity associated with your account.
Commercial and Billing Information
We may maintain information concerning:
- your CarePortals subscription;
- products or Services purchased;
- billing contacts;
- invoices;
- payments; and
- transaction history.
Payment information may be processed by third-party payment processors. CarePortals does not necessarily receive or store complete payment card or bank account credentials.
Communications With CarePortals
We may maintain communications and information you provide when you:
- request a demo;
- contact sales;
- communicate with customer support;
- participate in onboarding;
- submit product feedback;
- respond to a survey; or
- otherwise communicate with our team.
Website and Technical Information
When you visit our websites or use our Services, certain information may be collected automatically, including:
- IP address;
- browser and device information;
- operating system;
- device identifiers;
- referring pages;
- pages and features accessed;
- approximate location based on IP address;
- timestamps;
- log information; and
- diagnostic, security, and performance information.
We may collect this information through server logs, cookies, pixels, and similar technologies.
4. What We Do With Information
When CarePortals determines the purposes of processing, we may use personal information to operate and improve our business, including to:
Deliver our Services. We use information to establish accounts, authenticate users, provide platform functionality, process subscriptions, support integrations, and fulfill our contractual obligations.
Support Customers. We use information to provide implementation, technical support, customer success, troubleshooting, and other assistance.
Communicate with you. We may send administrative communications, security notifications, product updates, responses to inquiries, and other information relating to our business relationship.
Maintain and improve our technology. We may analyze how our websites and Services perform and are used to troubleshoot issues, improve functionality, develop features, and enhance the user experience.
Protect CarePortals and its users. We use information to authenticate users, maintain platform security, investigate suspicious activity, prevent fraud or misuse, and protect our Customers, users, and systems.
Meet legal and contractual obligations. We may process information to comply with law, respond to lawful requests, maintain required records, enforce agreements, and establish or defend legal claims.
Communicate about CarePortals. Where permitted by law, we may use business contact information to provide information about CarePortals products, services, events, and developments.
You can unsubscribe from marketing communications at any time.You may continue to receive operational, transactional, security, or other non-marketing communications where appropriate.
5. How Information Moves Through Our Ecosystem
Operating a healthcare technology platform requires CarePortals to work with other organizations.Depending on the context, information may be disclosed or made available to:
Our Customers
Authorized Customer administrators may access information associated with their organization, users, and use of the CarePortals Services.
Healthcare Participants
At a Customer’s direction or as necessary to provide configured Services, CarePortals may facilitate information exchange with organizations such as:
- healthcare providers;
- physician networks;
- pharmacies;
- laboratories;
- fulfillment organizations; and
- other healthcare service providers.
These organizations may have independent legal obligations and privacy practices.
Technology and Operational Providers
We use third parties to help operate our business and technology infrastructure, including providers of:
- cloud infrastructure;
- information security;
- communications;
- authentication;
- analytics;
- payment processing;
- customer support; and
- other business and technology services.
Where required by HIPAA, organizations that create, receive, maintain, or transmit PHI on our behalf are subject to appropriate Business Associate Agreements.
Advisors and Authorities
We may disclose information to legal counsel, accountants, auditors, insurers, financial institutions, regulators, courts, law enforcement, or governmental authorities when appropriate or legally required.
Corporate Transactions
Information may also be transferred or disclosed as part of an actual or proposed financing, merger, acquisition, restructuring, sale of assets, bankruptcy, or similar corporate transaction, subject to applicable law.
We may also disclose information at your direction or with your authorization.
6. Health Information and HIPAA
Certain information processed through CarePortals may constitute PHI under HIPAA.
When CarePortals acts as a Business Associate, we process PHI only as permitted by HIPAA, the applicable BAA, and our agreement with the Customer.
Our responsibilities may include safeguarding PHI, limiting its use and disclosure, supporting Customer compliance obligations, and requiring appropriate protections from subcontractors that handle PHI on our behalf.
This Privacy Policy does not expand CarePortals’ rights to use PHI beyond the rights provided by applicable law and our contractual obligations.
Healthcare providers and other organizations using CarePortals may have separate obligations to provide patients with privacy notices describing their own practices.
7. Data Analytics and De-Identified Information
CarePortals may generate statistical, aggregated, or de-identified information from information processed through our Services where permitted by applicable law and our agreements.We may use such information to:
- understand platform performance and usage;
- improve products and features;
- identify operational trends;
- perform research and analytics;
- improve security and reliability; and
- develop and enhance our technology.
Where information has been de-identified in accordance with applicable requirements, CarePortals will not attempt to re-identify the information except where permitted by law, including for purposes of validating the effectiveness of the de-identification process.
Our processing of PHI remains subject to applicable HIPAA requirements and BAAs.
8. Website Analytics and Cookies
Our corporate websites may use cookies and similar technologies to provide website functionality, remember preferences, understand how visitors interact with our websites, measure performance, and support our business and marketing activities.
Your browser may allow you to block or delete cookies. Where required, we may also provide additional cookie preference controls.
Some website functionality may not operate properly if certain cookies are disabled.
CarePortals distinguishes its public corporate websites from authenticated healthcare and patient-facing environments. We restrict the use of tracking and advertising technologies in environments where healthcare information may be processed as required by applicable law and our contractual obligations.
9. Protecting Information
CarePortals maintains administrative, technical, and organizational safeguards designed to protect information against unauthorized access, disclosure, alteration, loss, or misuse.
Our security measures are designed to account for the sensitivity of the information being processed and the risks associated with that processing.
Access to sensitive information is limited to authorized personnel and service providers with an appropriate business need and subject to applicable confidentiality and security requirements.
No technology or method of electronic transmission or storage can guarantee absolute security. Accordingly, while we maintain safeguards designed to protect information, we cannot guarantee that information will never be subject to unauthorized access or a security incident.
If you believe information associated with CarePortals has been compromised, please contact us at privacy@portals.care.
10. How Long We Keep Information
CarePortals retains personal information for periods reasonably necessary for the purposes for which it was collected, including to:
- provide our Services;
- maintain Customer relationships;
- meet contractual commitments;
- comply with legal, regulatory, accounting, and reporting requirements;
- resolve disputes;
- maintain security and business records; and
- enforce our agreements.
Retention periods vary based on the nature of the information and applicable legal and contractual requirements.
Information CarePortals processes on behalf of Customers, including PHI, is retained, returned, or deleted in accordance with applicable law and our agreements with those Customers.
11. Your Choices and Privacy Requests
Depending on your location and the laws applicable to your information, you may have rights to:
- access personal information;
- obtain a copy of certain information;correct inaccurate information;request deletion;
- withdraw consent where processing is based on consent;
- object to or restrict certain processing;
- opt out of certain marketing communications; or
- exercise other rights provided by applicable privacy law.
Certain rights are subject to exceptions and limitations. We may also need to verify your identity before fulfilling a request.
If You Are a Patient
If your information was collected through a healthcare organization, telehealth company, clinic, or other Customer using CarePortals, please generally submit your privacy request directly to that organization.
Because CarePortals processes that information on its behalf, we may forward a request to the applicable Customer or assist the Customer with responding.
Requests Relating Directly to CarePortals
For information CarePortals controls directly, you can submit a privacy request to: privacy@portals.care
We will respond in accordance with applicable law.
12. Location-Specific Privacy Protections
Privacy rights vary depending on where you live and which laws apply.
United States
Residents of certain U.S. states may have additional rights concerning their personal information, including rights relating to access, correction, deletion, portability, and certain uses or disclosures of information.
Information regulated by HIPAA and certain other healthcare or sector-specific laws may be exempt from some state consumer privacy laws.
Where applicable, CarePortals will honor legally valid requests and will not unlawfully discriminate against individuals for exercising their privacy rights.
Canada
Where Canadian privacy laws apply, including the Personal Information Protection and Electronic Documents Act (“PIPEDA”) and applicable provincial privacy legislation, CarePortals handles personal information in accordance with applicable requirements.
Individuals may have rights to access and correct personal information and, where applicable, withdraw consent or submit a complaint concerning the handling of their information.
Cross-Border Processing
CarePortals and organizations supporting our Services may process information in the United States, Canada, or other jurisdictions.
As a result, information may be subject to the laws of the jurisdiction in which it is processed. Where required, CarePortals implements appropriate safeguards for cross-border transfers.
13. Third-Party Products and Integrations
Customers can configure CarePortals to connect with third-party products and services.
When information is transmitted to an independent third party at the direction of a Customer or user, that third party’s handling of information may be governed by its own privacy policy and legal obligations.
Our websites may also contain links to third-party websites.
CarePortals does not control the privacy practices of independent third parties, and we encourage you to review their privacy policies before providing information to them.
14. Information About Minors
CarePortals’ corporate websites and business-facing Services are not intended for children.
Our Customers may, where legally permitted, use CarePortals technology to provide healthcare services to minors.
When CarePortals processes information about a minor on behalf of a Customer, we do so pursuant to the Customer’s instructions, our contractual obligations, and applicable law.
15. Updates to This Policy
CarePortals may update this Privacy Policy as our Services, business, or legal obligations evolve.
When we update the Policy, we will revise the effective date shown at the top of this page. Where required by applicable law, we will provide additional notice of material changes.
We encourage you to review this Policy periodically.
16. Questions, Requests, and Complaints
Questions or concerns regarding this Privacy Policy or CarePortals’ privacy practices can be directed to:
CarePortals LLC
5830 E 2nd St, Ste 7000 #18776
Casper, Wyoming 82609
United States
Email: privacy@portals.care
Phone: +1 (585) 636-3534
If you are a patient or end user whose information was collected through a CarePortals Customer, please contact the healthcare organization or brand through which you received services first. CarePortals will work with our Customers as appropriate to support their privacy obligations.