Privacy Policy of Medarch
1. Introduction
This privacy policy ("Privacy Policy") of Medarch, Inc. ("Medarch," "Us," or "We") sets forth the terms applicable to you ("You" or "Your") and describes how we collect, use, process, and disclose your personal information, in conjunction with your access to and use of the Medarch Platform, including https://www.medarch.com (the "Website") and any application(s), including updates, available on the Website (the "Application") and the terms of service that apply to any services accessible through any such Application (collectively, the "Services"), plus any information we collect in our capacity as a Business Associate to your health care provider, which is a Covered Entity under the Health Insurance Portability and Accountability Act ("HIPAA"). Your trust is important to us and we're committed to protecting the privacy and security of your personal information.
1.1 Our Role Under HIPAA
Medarch provides care-management software, including the eCareMD platform for Chronic Care Management (CCM) and Remote Patient Monitoring (RPM), to health systems, hospitals, and physician practices. When we process Protected Health Information ("PHI") through those services, we do so as a Business Associate on behalf of, and under a written Business Associate Agreement ("BAA") with, the Covered Entity that provides your care. Your HIPAA rights with respect to that PHI, including access, amendment, and an accounting of disclosures, are described in your health care provider's Notice of Privacy Practices, and requests regarding PHI should be directed to your provider. Where this Privacy Policy conflicts with a BAA, the BAA controls with respect to PHI.
1.2 Scope
This Privacy Policy applies to visitors of our Website, prospective and current customers, and users of the Application. It does not replace the privacy notices of the Covered Entities we serve.
2. Information We Collect
There are three general categories of information we collect.
2.1 Information You Give to Us
We ask for and collect the following personal information about you when you use the Medarch Platform. This information is necessary for the adequate performance of the contract between you and us and to allow us to comply with our legal obligations.
- Account Information: When you sign up for a Medarch Account, we require certain information such as your first name, last name, email address, and date of birth.
- Profile and Offering Information: To use certain features, we may ask you to provide additional information, which may include your address, phone number, and a profile picture.
- Identity Verification Information: To help maintain a trusted environment, we may collect identity verification information (such as images of your government-issued ID, passport, national ID card, or driving license, as permitted by applicable laws) or other authentication information.
- Payment Information: To use certain features, we may require financial information (like your bank account or credit card information) to facilitate the processing of payments. Payment card data is processed by our PCI DSS compliant payment processor; Medarch does not store full payment card numbers.
- Communications: When you communicate with Medarch or use the Platform to communicate with other Users, we collect information about your communication and any information you choose to provide.
- Clinical and Device Data (PHI): When a health care provider enrolls you in a care-management program delivered through our Platform, we receive, on the provider's behalf, clinical information such as diagnoses, care plans, medications, clinical notes, and physiologic readings transmitted from connected monitoring devices (for example blood pressure, blood glucose, weight, and pulse oximetry). This information is PHI and is handled in accordance with HIPAA and our BAA with your provider, as described in Section 1.1.
2.2 Information We Automatically Collect
When you use the Platform we automatically collect personal information about the services you use and how you use them, including Geo-location Information (precise or approximate location via IP address or device GPS), Usage Information (pages or content you view, searches, and other actions), and Log Data and Device Information (IP address, access dates and times, hardware and software information, device information, unique identifiers, crash data, and cookie data).
Cookies and Similar Technologies. We use cookies, web beacons, pixels, browser analysis tools, server logs, and mobile identifiers when you use our platform, mobile app, or engage with our online ads or email communications. We use the following categories of cookies:
- Strictly necessary cookies, required for the Website and Application to function and to keep your session secure;
- Analytics cookies, which help us understand how visitors use the Website so we can improve it; and
- Advertising and marketing cookies, used to measure and personalize our marketing.
Analytics and advertising cookies are used only on the public Website, not within the clinical Application.
2.3 Your Cookie Choices
You can manage non-essential cookies through the cookie banner presented on your first visit and at any time via the "Cookie Settings" link in the Website footer. You can also block or delete cookies through your browser settings; doing so may affect some Website features. We honor Global Privacy Control ("GPC") browser signals as a valid request to opt out of the sale or sharing of personal information and of targeted advertising, where required by applicable law. Our Website does not currently respond to "Do Not Track" signals, for which no industry standard has been adopted.
2.4 Information We Collect from Third Parties
Medarch may collect information that others provide about you when they use the Platform, or obtain information from other sources and combine it with information we collect. For business contacts, these sources may include professional networking sites, data-enrichment providers, and industry event organizers.
2.5 Children's Data
Our Website and marketing communications are not directed to children under 16, and we do not knowingly collect personal information directly from children under 16 or sell or share the personal information of consumers we know to be under 16. Where a health care provider enrolls a patient under 18 in a care-management program, we process that patient's PHI solely as a Business Associate on the provider's behalf and under the provider's authority and parental or guardian consent processes. If you believe we have collected information from a child in violation of this section, contact us at sales@medarch.com and we will delete it.
3. How We Use Information We Collect
We may use, store, and process personal information to (1) provide, understand, improve, and develop the Medarch Platform; (2) create and maintain a trusted and safer environment; and (3) provide, personalize, measure, and improve our advertising and marketing. We use PHI only as permitted by HIPAA and the applicable BAA; we do not use PHI for marketing or advertising.
3.1 Create and Maintain a Trusted and Safer Environment
We may use personal information to detect and prevent fraud, spam, abuse, and security incidents; conduct security investigations and risk assessments; verify or authenticate information; comply with our legal obligations; resolve disputes; and enforce our Terms of Service and other policies.
3.2 SMS Terms (U.S.)
By opting in to a Text Message Service, you authorize Medarch to send text messages (including marketing content, where you have opted in to marketing messages) to the cell phone number associated with your opt-in. Message and data rates may apply. Message frequency varies by program; care-program reminders are sent as scheduled by your health care provider. Consent is not a condition of purchase. Text STOP at any time to opt out; you will receive one final confirmation message and no further messages. Text HELP for help or email sales@medarch.com. We will not share or sell mobile opt-in information and consent with third parties for their own marketing purposes. Carriers are not liable for delayed or undelivered messages.
3.3 Your Choices
You can limit the communications Medarch sends to you. To opt out of marketing emails, click "unsubscribe" at the bottom of any marketing email or update your notification settings. To revoke permission for promotional texts, reply STOP. Even if you opt out of marketing, we may still send important transactional information.
3.4 Automated Decision-Making and Artificial Intelligence
Certain features of the Platform may use algorithms or artificial intelligence to assist clinicians, for example by flagging abnormal device readings, prioritizing patients for outreach, or drafting care-plan summaries for clinician review. These tools support, and do not replace, decisions made by licensed health care professionals. Medarch does not make solely automated decisions that produce legal or similarly significant effects about you. Where required by law, you may request information about the logic involved and may request human review of a decision. We do not use PHI to train models for purposes outside the services provided to your Covered Entity unless permitted by the applicable BAA and the data has been de-identified in accordance with 45 C.F.R. § 164.514.
4. Sharing & Disclosure
4.1 We Do Not Sell Your Personal Information
Medarch does not sell personal information and has not sold personal information in the preceding 12 months. We do not "share" personal information for cross-context behavioral advertising, except that advertising cookies on our public Website may be considered "sharing" under some state laws; you may opt out as described in Section 2.3.
4.2 When We Disclose Information
Sharing With Your Consent. Where you have provided consent, we share your information as described at the time of consent.
We will disclose your information when: you have given us consent; we need to provide a service you requested; we are complying with laws or lawful requests; we believe it is necessary to protect our rights and the security of our Platform; or in connection with a merger, financing, acquisition, or bankruptcy transaction.
When sharing information protected by HIPAA, we share your information with our HIPAA Covered Entity clients who provide you with services; with third parties you direct us to; and with third-party vendors and service providers with whom we contract as Business Associates under HIPAA. We may also share aggregated and de-identified information (de-identified in accordance with the HIPAA de-identification standard at 45 C.F.R. § 164.514) for regulatory compliance, research, and other business purposes.
4.3 Service Providers and Subprocessors
We use the following categories of service providers, each bound by contract (and, where PHI is involved, a BAA) to process information only on our instructions and to maintain appropriate safeguards:
- Cloud hosting and infrastructure (United States regions);
- SMS and communications delivery;
- Connected-device and data-integration partners;
- Customer support and ticketing;
- Website analytics and marketing tools; and
- Payment processing.
A current list of subprocessors is available to customers on request at sales@medarch.com. We provide customers with advance notice before a new subprocessor begins processing customer data, in accordance with the applicable customer agreement.
5. Other Important Information
5.1 Analyzing Your Communications
We may review, scan, or analyze your communications on the Platform for fraud prevention, risk assessment, regulatory compliance, investigation, product development, research, analytics, and customer support purposes.
5.2 Linking Third Party Accounts
You may link your Medarch Account with a third-party service and must comply with the terms of those sites.
5.3 Third Party Partners & Integrations
This Website may contain links to external websites or third-party content. Such links are provided for convenience only and do not imply endorsement or association. We do not sell, rent, or trade your personal information. We may share information with trusted service providers under strict confidentiality, or when required by law, and we remain accountable for how they handle it, including under HIPAA where applicable.
6. Your Rights
You may exercise any of the rights described in this section by emailing sales@medarch.com, calling +1 (404) 234-0521, or writing to us at the address in Section 10. We may ask you to verify your identity before taking further action. You may designate an authorized agent to make a request on your behalf; we will require proof of the agent's authority. We will respond within 45 days (extendable once by a further 45 days where reasonably necessary, with notice to you), or within any shorter period required by applicable law. We will not discriminate against you for exercising any of these rights.
6.1 Managing Your Information
You may access and update some of your information through your Account settings.
6.2 Rectification
You have the right to ask us to correct inaccurate or incomplete personal information about you.
6.3 Data Access and Portability
In some jurisdictions you may request copies of your personal information in a structured, commonly used, machine-readable format.
6.4 Data Retention and Erasure
We retain personal information only for as long as necessary for the purposes described in this Privacy Policy, and apply the following principles:
- PHI processed as a Business Associate is retained for the term of the applicable BAA and, at termination, is returned to the Covered Entity or destroyed in accordance with the BAA, except where retention is required by law;
- Documentation required by HIPAA (including policies, risk assessments, and BAAs) is retained for at least six (6) years from its creation or last effective date;
- Account and billing records are retained for seven (7) years after the end of the customer relationship to satisfy tax and audit obligations;
- Website analytics and marketing data are retained for no longer than 26 months; and
- Backups are retained for a limited rolling period and overwritten thereafter.
Where required by law you may request deletion of your personal information, subject to exceptions (for example, to complete a transaction, comply with a legal obligation, or as required by the BAA). Requests to delete PHI must be directed to your health care provider.
6.5 Withdrawing Consent
Where we process your personal information based on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
6.6 Objection to Processing and Lodging Complaints
In some jurisdictions you may object to certain processing and lodge complaints with our Privacy Officer or a supervisory authority.
6.7 U.S. State Privacy Rights
If you are a resident of California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, or another state with a comprehensive consumer privacy law, you may have the right to:
- confirm whether we process your personal information and access it;
- correct inaccuracies;
- delete personal information;
- obtain a portable copy;
- opt out of the sale of personal information, the sharing or processing of personal information for targeted advertising, and profiling in furtherance of decisions that produce legal or similarly significant effects; and
- limit the use of sensitive personal information.
To exercise these rights, use the contact methods above or the "Your Privacy Choices" link in the Website footer. If we deny your request, you may appeal by replying to our decision email with the subject "Privacy Appeal"; we will respond within 45 days and, if the appeal is denied, will provide a method for contacting your state Attorney General.
6.8 California Notice at Collection (CCPA/CPRA)
In the preceding 12 months we have collected the categories of personal information described in Section 2 (identifiers; customer records; commercial information; internet or network activity; geolocation; professional information; and inferences) for the purposes described in Section 3, from the sources described in Section 2, and disclosed them for business purposes to the service providers described in Section 4.3. We do not sell personal information and do not knowingly sell or share the personal information of consumers under 16. This Privacy Policy does not apply to PHI governed by HIPAA or medical information governed by the California Confidentiality of Medical Information Act, which are exempt from the CCPA; all other personal information we collect (including Website visitor, lead, and customer contact information) remains subject to the CCPA. California residents may also request, once per year and free of charge, a list of third parties to whom we have disclosed personal information for their direct marketing purposes ("Shine the Light").
6.9 EU / UK Residents
If you are in the European Economic Area, the United Kingdom, or Switzerland, we process your personal information on the following legal bases: performance of a contract, compliance with legal obligations, our legitimate interests (such as securing and improving the Platform and marketing to business customers), and consent where required. You have the rights described in Sections 6.1 to 6.6 and may lodge a complaint with your local supervisory authority. Our customers may request a Data Processing Addendum compliant with the GDPR and UK GDPR, incorporating the Standard Contractual Clauses and the UK International Data Transfer Addendum, by emailing sales@medarch.com.
7. International and Business Transfers
To facilitate our operations, Medarch may transfer, store, and process your information within our family of companies, partners, and service providers. Laws may differ from the laws in your residence. Our Platform is hosted in data centers located in the United States. Where we transfer personal information from the EEA, UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) or another lawful transfer mechanism, and apply supplementary technical measures such as encryption in transit and at rest. PHI is stored and processed in the United States unless otherwise agreed in the applicable BAA.
7.1 Business Transfers
In connection with a merger, acquisition, financing, reorganization, or sale of assets, personal information may be transferred to the successor entity, which will be bound by this Privacy Policy and, for PHI, by the applicable BAA. We will notify affected customers before their information becomes subject to a materially different privacy policy.
7.2 California & Vermont Residents
Medarch will not share information it collects about you with its affiliates or third parties (both financial and non-financial), except as required or permitted by your state's law.
8. Security
We continuously implement and update administrative, technical, and physical security measures to help protect your information against unauthorized access, loss, destruction, or alteration. Safeguards include firewalls, data encryption, and information access controls. Data is encrypted in transit using TLS 1.2 or higher and at rest using industry-standard encryption; access is governed by role-based permissions and multi-factor authentication; and systems are logged and monitored. Our security controls are periodically assessed by independent third parties. These safeguards are intended to meet our obligations under the HIPAA Security Rule. If you believe your account credentials have been compromised, please contact us immediately at sales@medarch.com. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8.1 Breach Notification
In the event of a breach of unsecured PHI, we will notify the affected Covered Entity without unreasonable delay and in no case later than the period specified in the applicable BAA (and in any event within 60 days of discovery, as required by the HIPAA Breach Notification Rule), and will cooperate with the Covered Entity in notifying affected individuals, the Secretary of Health and Human Services, and, where required, the media. For personal information that is not PHI, we will notify affected individuals and regulators as required by applicable state breach-notification laws.
9. Changes to This Privacy Policy
Medarch reserves the right to modify this Privacy Policy at any time. If we make changes, we will post the revised Privacy Policy and update the "Last Updated" date. For material changes we will provide additional notice, such as an email to registered account holders or a prominent notice on the Website, at least 30 days before the changes take effect. Your continued access to or use of the Platform after the revised Privacy Policy becomes effective will be subject to the revised Privacy Policy. Prior versions are available on request. This Privacy Policy is reviewed at least annually.
10. Contact Us
If you have any questions or complaints about this Privacy Policy or Medarch's information handling practices, you may contact us as follows:
Email (privacy inquiries, rights requests, and security concerns):
sales@medarch.com, Attn: Privacy Officer
Phone: +1 (404) 234-0521
Mail: Medarch, Inc., Attn: Privacy Officer, 8735 Dunwoody Place #4178, Atlanta, GA 30350,
United States
If you need this Privacy Policy in an alternative format for accessibility reasons, please contact us using the details above.
Need a DPA?
EU/UK customers can request a Data Processing Addendum compliant with GDPR, UK GDPR, and Standard Contractual Clauses by emailing sales@medarch.com