Effective: February 2018
Our policy regarding the collection and use of your information via DxPortal ("Portal" or "DxPortal") is set forth below. The Portal is part of a private website ("website") owned and managed by NextGen Management LLC d/b/a DxWeb Management LLC ("DxWeb") as your health care provider’s business associate, and DxWeb is committed to disclosing its privacy and data security policies. You have requested to electronically access your health information with your health care provider, and/or to receive electronic messages such as appointment reminders, prescription information including educational materials, guidance and third-party financial savings offers in the form of coupons and special offers for prescription cost savings, prescription refill reminders, as well as medication and patient compliance reminders. Please Note: If you are registering for DxPortal not as a patient of a particular health care provider, but for general health management reasons, the term "Patient", "you" or "your" means you as the registrant for DxPortal, and "health care provider" shall mean DxWeb which is providing you information about health care issues and/or products, but is not acting in conjunction with any medical professional nor is it providing medical advice of any kind. In some instances, depending on context, if you are a non-patient, the references to "health care provider" will not apply to you.
DXWEB MAY REVISE THIS POLICY REGARDING THE COLLECTION OF INFORMATION AT ANY TIME. SHOULD ANY NEW POLICY TAKE EFFECT, DXWEB WILL GIVE NOTICE TO YOU AND ALL USERS BY POSTING A NOTICE REGARDING THE NEW POLICY ON THIS WEBSITE, AND THE NEW POLICY WILL APPLY ONLY TO INFORMATION COLLECTED THEREAFTER. BY ACCESSING OR USING THIS WEBSITE AFTER SUCH CHANGES ARE POSTED, YOU AGREE AND CONSENT TO ALL SUCH CHANGES.
Disclosure of Information Practices
Whether you are a patient or a health care provider, if we collect information from or about you via the Portal, we will tell you what information we are collecting. The amount and type of information that we receive depends on how you use this Portal and the information you choose to submit to us via the Portal. Whether you are a health care provider or patient user, we may track use of your user name and may also capture the paths taken as you move from page to page (i.e., your "click stream" activity). When you log in, your user name and encrypted password will be logged by our system in an audit log but will not be used by us. As a user of the Portal and if available, you may also choose to use the secure messaging feature of the Portal which will allows the exchange of communications between patients and the clinicians who treat them and which may contain identifiable health information. Communications sent via this feature are recorded and maintained by DxWeb. Portal users have the ability to view the trail of messages received and sent via their Portal account. DxWeb does not edit the content of the communications between patients and health care providers.
Identifiable Health Information
You are not required to provide identifiable health information to visit this Website. However, if you are a patient or the legal representative of a patient, you must provide certain identifiable health information in order to complete your registration for the non-public Portal to access the health records maintained by your health care provider. If you are a patient (or the legal representative of a patient), we will collect identifiable health information from you with your knowledge during the registration process and in the event you request information or services. We may collect any identifiable health information that you provide to us, such as your name, address, e-mail address, gender, birth date and phone number. If you access the Portal patient registration via the link provided by your health care provider, certain basic information may be pre-filled into your Portal registration, which you will need to verify. When you register for the Portal via the Website, the registration process requires you to choose a user name and password for your account, which you should keep and maintain as confidential. If you choose to share your user name and password you understand that those individuals to whom you share that information will have access to your identifiable health information and will be able to add to your identifiable health information as though they were you. You will be responsible for all activities by users resulting from sharing or not maintaining the confidentiality of your user name or password. If you are a registered patient user of the Portal, your identifiable health information (or that of the patient for whom you are the legal representative) currently stored electronically in your health care provider records will become accessible to DxWeb in order to provide you access to such information through the Portal. Your electronic health records are not permanently stored in the Portal or Website, but a temporary copy of them is displayed via the Portal when you are logged in with your user name and password.
Non-Identifiable Health Information
Either DxWeb or a third web statistics vendor on behalf of DxWeb may also collect non-identifiable information, which is automatically collected as you browse or otherwise access this website and Portal. We may collect such information by tracking, or asking our third party vendor to track, your click-stream activity when such information is not tied to a user ID through the use of "cookie" technology or by tracking internet protocol (IP) addresses, as explained below.
Regulation & Security
Certain information provided to Us may be Protected Health Information as that term is defined in the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), American Recovery and Reinvestment Act ("ARRA"), Health Information Technology for Economic and Clinical Health Act ("HITECH") and in regulations promulgated there under and it may also be subject to regulation under state law ("PHI"). We offer and provide the Company Site and Our products and services in a manner that complies with all applicable laws and regulations we are aware of and/or become known to us and will continue to do so. If you request services that require you to provide personal health information that is protected under any federal or state laws (including HIPAA), You grant to us a non-exclusive, perpetual, irrevocable, royalty-free right and license to use de-identified patient and administrative data ("De-Identified Use Data" as defined under 45 C.F.R. § 165.514) collected or provided through your use of the Portal or website for any lawful business purpose, provided that such data is not personally identifiable. We have the right to de-identify such patient and administrative data and then utilize the De-Identified Use Data for any lawful purpose, including but not limited to creating statistical norms and reports de-identified score cards, regional or national benchmarking, or to be used for research considerations, provided however that the data shall not include member identities and claims information that is unprotected. Personally identifiable patient, health care provider and your information shall remain confidential and shall not be released unless you have agreed that it can be released. Further, should we choose to place the De-Identified Use Data in its national database or in any way incorporate such data in studies and/or analyses conducted directly or indirectly by Us, no such data shall be identified as originating from You, or Your patients, members, or health care providers. The De-Identified Use Data shall also not be utilized in any study, report or publication without first being integrated with a significant body of other data such that you cannot be identified, unless appropriate, advance and written consents to such identification are obtained.
We may also log and track IP addresses for systems administration purposes and for reporting usage trends. Your IP address is usually associated with the physical place from which you enter the Internet, the name of the domain and host from which you access the Internet, the browser software you use and your operating system, and the date and time you access the Website or Portal. By collecting your IP address, we may record the page that linked you to this Website, the web pages you visit, the ads you see or click on, and other information about the type of web browser, computer, platform and settings you are using, and any search terms you enter on this Website or Portal. IP addresses are not used to track an individual user’s session. This information only helps us determine how often different areas of our Website and Portal are visited. We may combine non-identifiable information collected automatically (such as through IP addresses, cookies or click-stream monitoring) with any previously submitted personal information that we may have received from you.
We may collect your geographic location based on your IP address and other location-based data.
We may also use various third party internet vendors to collect, track and analyze track analytical data regarding Website usage and trends.
Users of the Portal may have the opportunity to participate through the Portal in various DxWeb surveys depending on the survey and as permitted by law. If you choose not to receive survey invitations through the Portal you may change your privacy settings within the Portal. Any survey responses that you choose to submit may be aggregated, deidentified and provided or sold to third parties as set forth below.
Use and Disclosure of Your Information
Identifiable Health Information
We may use any identifiable health information or other information that you voluntarily provide us in order to provide you with information, products or services that you may request from DxWeb. If you are a patient or the legal representative of a patient, any identifiable health information that you share via the Portal will be made accessible to your health care provider and will become a part of the records maintained by your health care provider, which records are subject to your health care provider's Notice of Privacy Practices. DxWeb has no control over or responsibility for your health care provider's use or disclosure of information that you may provide via the Portal or Website. Consistent with the HIPAA Authorization below, to the extent permitted by applicable law, DxWeb may use your participation in the Portal to communicate to you special offers and featured items from third parties, DxWeb, DxWeb's affiliates, and/or other suppliers and vendors. If you are receiving additional communications and special offers, you may revoke your authorization to receive such materials from DxWeb via the Portal at any time by contacting us using the contact information below or as outlined in the applicable communication. We will implement your revocation as soon as is commercially reasonable. DxWeb cannot control any communications and other materials that you may receive directly from third parties. We will also use your information to customize your browsing experience and communicate with you and otherwise respond to your questions and suggestions regarding use of the Portal as may be permitted by applicable law. We may share your information only with our suppliers and vendors to the limited extent permitted by applicable law. We require those suppliers and vendors to comply with all applicable data privacy laws and regulations, including HIPAA. We do not sell, lease or rent your identifiable health information. We may also use your geographic location to provide you with specific content and direct you to your closest service providers to the extent permitted by applicable law.
Non-Identifiable Health Information
The non-identifiable, aggregated health information we collect may be shared with our suppliers and vendors and used in the aggregate to create summary statistics that help us analyze website usage trends, assess what information is of most and least importance, determine technical design specifications, arrange the Website in the most user-friendly way, and identify system performance or problem areas.
We may aggregate and deidentify in accordance with HIPAA identifiable health information, either alone or with other data to create anonymous "aggregate data" regarding the users of our Website and Portal. Aggregate and deidentified data is information that describes the habits, treatment plans, usage patterns, other medical record data and/or demographics of users as a group but does not reveal the identity of particular users. This data will not identify you, but will be used as statistical information to determine such things as user demographics and usage patterns of our Website and Portal. DxWeb may use aggregate data to understand the needs of our community of users and determine what kinds of programs and services we can help provide. Aggregate data may also be provided or sold to third parties, including for the purpose of getting targeted content to you by third party vendors, suppliers, business partners and/or affiliates a picture of our community and services and/or participation in surveys or receipt of emails from third parties.
Other Use and Ownership
As part of use of the Portal, you may elect to access in the Portal or receive emails concerning educational materials, guidance and third-party financial savings offers in the form of coupons and special offers for prescription cost savings (“Financial Savings Offers”). This may include emails containing information from sponsors such as brands, manufacturers, payors, pharmacy benefit managers (PBM) and retailers, which can provide needed medication education, improve health care provider-patient dialogue and reduce medication-related costs. These communications are provided directly from us; you will not be contacted by any third party concerning these communications on account of electing to receive such communications through the Portal. Some of the Financial Savings Offers, although related to your health care and treatment, may be considered as marketing under HIPAA since your health care provider is communicating about a product or service in a way that encourages you to purchase or use that product or service such as the name brand product that appears on a prescription coupon. The Financial Savings Offers may be considered as advertising. Accordingly, in order to receive Financial Savings Offers, you are asked to agree to and sign a separate HIPAA Authorization form for such use and/or disclosure that appears at the end of this agreement. Your execution of the HIPAA Authorization form permitting such uses and/or disclosures is voluntary.
While no web site can guarantee security, we maintain physical, administrative, electronic, technical and procedural safeguards to help protect your personal information collected via the Portal as required by applicable law. While we cannot guarantee that loss, misuse or alteration to data will not occur, we use industry standards, such as Secure Socket Layers ("SSL") technology, to help safeguard against such occurrences. In certain areas, the information passed between your browser and our system is encrypted with SSL technology (which covers any messages, PHI or communications a person directs to DxWeb or the clinician team) to create a protected connection between you and our website to ensure confidentiality. Our data center is both physically and electronically secured. Our servers are protected from open access to the Internet by using firewall and encryption technology. We limit access to personally identifiable information about you to our employees and third-party agents, who we reasonably believe need to have access to your information to provide you with the information or services you request via the Portal. In the event that a breach in our security systems occurs and there is a possibility that an unauthorized person acquires your personal information, we will notify you of such a breach as may be required by applicable law. In order to help maintain security, you should never share your user ID or password and should always sign out when you are finished using the Portal.
We will maintain your information and allow you to request updates at any time by logging into your Portal account to access your information. We will also take steps to make sure that any updates that you provide are processed in a timely and complete manner.
Third Party Websites
Accessing this Portal from outside of the United States
Transfer of Data
Important Note Regarding Children
This Website and Portal is not directed toward children under 18 years of age and DxWeb does not knowingly collect or use information from children under 18 through this Website or Portal. Any information submitted via the Portal regarding a minor under the age of 18 must be submitted by the minor's legal representative. To the extent permitted by applicable state law, minors may access their identifiable health information through their health care provider.
Disputes and Interpretation
This agreement shall be governed by, interpreted and construed in accordance with the laws of the State of Florida, excluding its choice of law provisions and any controversy or claim arising out of or relating to the terms of this agreement, or the breach thereof, shall be settled by arbitration administered by the American Arbitration Association sitting in Palm Beach County or Broward County, FL, in accordance with its Consumer Arbitration Rules, and judgment on the award rendered by the arbitrator(s) may be entered in any court having jurisdiction thereof. You understand that by agreeing to these terms, you are giving up the right to bring a claim in court or in front of a jury, and that you are giving up the right to proceed with any class action or other representative action. Except as otherwise prohibited by applicable law, any claim with respect to this agreement must be commenced within one (1) year after the action or claim arises. Certain provisions, by their nature or as explicitly stated, will survive any termination or expiration of this Agreement. If any of these conditions shall be deemed invalid, void, or for any reason unenforceable, that condition will be severable and shall not affect the validity and enforceability of any remaining condition.
HIPAA PATIENT AUTHORIZATION