Client Services Privacy Policy
Last Updated: November 6, 2024
SCOPE OF THIS POLICY
Your privacy is extremely important to RXNT. This Client Services Privacy Policy (“Policy”) explains how we collect, use, disclose, and secure information about you or from you. This Policy pertains to your use of RXNT cloud-based desktop and mobile applications including RXNT Electronic Health Records, Practice Management (Billing and Scheduling), Electronic Prescribing, and RXNT Patient Portal (“MyRXNT”) (hereinafter, collectively referred to as either “our Products” or “RXNT Products”).
This Policy does not cover information RXNT may collect or receive through our website, https://www.rxnt.com, or any related services or applications (“Website”). For more information about the information collected or received through our Website, please see our Website Privacy Policy located here: https://www.rxnt.com/privacy-policy/.
This Policy does not cover the privacy policy of third parties. RXNT Products may include links to websites and/or applications operated and maintained by third parties. We encourage you to review the privacy policies of those third parties because we have no control over the privacy policies of website or applications owned by those third parties, and we cannot guarantee that such third parties will adhere to the same privacy practices that we do.
INFORMATION WE COLLECT
The types of information we collect about you depends on how you interact with our Products. Some of the information collected by RXNT is personal information. In general, the term “Personal Information” is information which identifies you, describes you, relates to you, or can be associated with you. RXNT sometimes combines non-personal information with other information in a way that makes the combined information Personal Information. RXNT treats this combined information as if it were all Personal Information. RXNT does not consider Personal Information to include information that has been anonymized so that it does not allow a third party to easily identify a specific individual. The following categories and types of Personal Information may be collected by us when you visit and use our Products:
Identifiers and Contact Information
When you use our Products, including creating an account, we collect basic identifying information about you, including your full name, email address, company name, mobile phone number, address, state of residence, and other similar identifiers.
Personal Information
We collect Personal Information from you when you use our products. Personal Information may include, but is not limited to, your social security number, NPI number, DEA number, medical license number, driver’s license number and other information.
Personal Information does not include publicly available information from government records, de-identified or aggregated user information, or information excluded from applicable laws, such as health or medical information covered by the Health Insurance Portability and Accountability Act of 1996 (HIPAA).
If you are a patient using our Products, the information you provide to us through the Product may be considered protected health information (PHI) and will be protected by RXNT as required by state and federal laws and regulations. Our processing of PHI on behalf of our healthcare provider users is governed by our agreements with our users, including our Business Associate Agreement as required by HIPAA. If you are a patient, your healthcare provider may also have its own privacy practices and policies that govern how your provider collects, uses, and shares your information. We encourage you to review these practices and policies.
Payment Information
When you use RXNT Products, we will collect your credit card or ACH information.
Commercial Information
When you purchase our Products and throughout your subscription, we collect information related to your company, including your company name, how many providers are in your organization, the company phone number, the state your company is located, and your company’s specialty.
Performance and Usage Information
RXNT collects data related to the use of our Products. This may include your interactions with our Products, error reports, and additional performance data.
Content Submission
RXNT collects reviews, testimonials, or any other content (“Content Submission”) submitted to RXNT.
Geolocation Data
RXNT may collect information that allows us to determine your general location. You may also manually provide location information when using our Products and their related functionalities. In accordance with applicable law requirements to the extent precise location-based information is considered sensitive information, we will ask for your permission before we collect or use precise location information.
Demographic Data
We may collect information related to your gender, race, and ethnicity when you use our Products. Some of this demographic data may include characteristics of protected classifications under state or federal law.
Audio and Visual Information
Some RXNT Products, and/or the implementation and support services we offer, may record your voice or likeness.
Device Information
RXNT collects data about your device when you use our Products. This may include cookies, beacons, pixel tags, browser type, device type, device identifiers, operating systems, and language settings.
METHODS OF COLLECTING INFORMATION
User-Provided Information
RXNT obtains personal information when you provide it to us when you create an account, contact us, and otherwise provide information to RXNT.
Cookies and Tracking Technologies
In some instances, RXNT may use cookies and similar technologies (e.g., pixels, pixel tags, ad tags, Software Development Kits (SDKs), clear GIFs, session replay scripts, and Javascript). Cookies are small text files placed on your device which help our Products work and help gather statistical information such as how visitors use our Products, how RXNT can improve the quality of our Products, authenticate users, and debug and maintain security. Our purpose in doing this is to provide you and other users with the best possible service. Cookies also help us deliver advertisements, some of which may be tailored to your behaviors on our Products.
Additional Methods
We may collect information about you from additional sources such as analytics providers, fraud prevention providers, vendors that we are contracting with, or publicly available sources.
USE AND SHARING OF YOUR INFORMATION
RXNT uses the information we collect from you for the following purposes:
- Communication: If you contact us through our Products or regarding your use of our Products, RXNT will use your personal information to respond to you, communicate with you in the future, and share updates regarding our products or other relevant information.
- Product Performance and Personalization. When you use our Products, we use your personal information to save user preferences, authenticate users, and debug and evaluate the performance of the RXNT Products.
- Additional Purposes. We may disclose other purposes for collecting information from you at the time of collection.
- As Required By Law. We may provide access to your personal information when we are legally required to do so, such as to comply with a subpoena, search warrant, court order, judicial proceeding, or similar legal process.
With regard to Personal Information, RXNT appreciates its sensitivity and the need to limit its disclosure. Accordingly, we limit our sharing of your Personal Information as follows:
- As Required By Law. We may provide access to your Personal Information when we are legally required to do so, such as to comply with a subpoena, search warrant, court order, judicial proceeding or similar legal process, or if your conduct violates our RXNT Terms of Service or the MyRXNT Terms of Service.
- Protection. When RXNT believes in good faith that disclosure is necessary to protect the RXNT Products and anything related to them, protect your safety or the safety of others, protect our rights and the rights of third parties, investigate fraud, or respond to a governmental agency or court order.
- Service Providers. When RXNT provides such information to trusted services providers who work on our behalf, do not have an independent use of the information we disclose to them, and have agreed to adhere to the rules set forth in this Policy and applicable law. Such information is provided to them subject to the terms of this Policy.
- Control Transfers. If RXNT is involved in a merger, acquisition, or sale of all or a portion of its assets, you will be notified via email and/or a prominent notice in our product or on our website of any change in ownership or uses of your personal information, as well as any choices you may have regarding such information.
CHILDREN’S PRIVACY
The RXNT Products are not intended for minors under the age of eighteen. RXNT does not wish to obtain any information from or about such minors through the RXNT Products without legal guardian or parental consent and under the supervision of such legal guardian and parent. If you are under eighteen years old, do not use the RXNT Products.
With regard to COPPA (Children’s Online Privacy Protection Act), we do not seek to collect any information from anyone under 13 years of age. Our Products are directed at people who are at least 13 years old or older.
RXNT does not knowingly collect personal information from children. If RXNT learns that it has obtained personal information from a child, RXNT will delete that information as soon as practicable. If you discover that your child has provided us with personal information without your consent, please contact RXNT immediately.
While observing any applicable provisions of COPPA, RXNT Products do not prevent persons above the age of 18 years—such as healthcare providers, parents and guardians—to provide, share and store personal information about others, including minors and children. Any user providing, storing, or submitting information on behalf of a child assumes full responsibility for the submission, use and transmission of such information.
As defined under the California Consumer Privacy Act, RXNT does not knowingly “sell” the personal information of minors under 16 years old who are California residents.
SAFETY AND SECURITY OF YOUR INFORMATION
Your Personal Information is maintained on RXNT’s and our service providers’ servers, and may be accessible by authorized employees, representatives, and agents as necessary for the purposes described in this Policy. RXNT utilizes and periodically evaluates the effectiveness of several technical, physical and administrative measures to prevent unauthorized access to its products, maintain data accuracy and ensure the appropriate use of your personal and non-personal information. These measures include encryption, firewalls, system alerts, and the use of industry-standard encryption technology. We also house such information in secure facilities that restrict physical and network access. RXNT applies what it regards as reasonable and accepted measures widely used in the IT industry to protect the confidentiality, integrity and availability of individually identifiable health information residing on and processed by the RXNT Products. No security system, however, can be expected to prevent all potential security breaches no matter what technology is used. Therefore, while we use reasonable and appropriate physical, electronic, and organizational safeguards to protect your personal information, we cannot guarantee absolute security in all circumstances.
RXNT may notify you and inform you of potential countermeasures if RXNT learns of a security vulnerability or risk. RXNT strongly encourages you to be conscientious in using well-known and readily available technology to improve the security of your own system and devices. If you have questions about the security on our Products, please contact us at [email protected].
ACCESS LIMITED TO U.S. USERS
Access to the RXNT Products is administered in the United States and is intended solely for users within the United States, unless RXNT in advance and in writing authorizes specific users in specified locations outside of the United States who have executed such binding legal agreements and other documentation as RXNT may require. You should be aware that access by foreign nationals to systems located in the United States constitutes the exportation of technology under applicable U.S. law and may require compliance with U.S. export controls.
Under no circumstances are you to use the RXNT Products in any jurisdiction where accessing or using the RXNT Products would violate U.S. law or any other law. Any information that you submit to us while outside of the United States will be transferred to RXNT systems that reside in the United States unless RXNT notifies you that it intends to transfer such information to specific RXNT systems that reside in one or more location(s) outside of the United States pursuant to such binding legal agreements and other documentation as RXNT may require from you and third parties. You consent to any such transfer of non-personal and personal information when you use RXNT Products and provide us with such information.
Please be assured that RXNT will always employ appropriate measures to protect the privacy and security of your personal information, regardless of where it is processed or stored.
YOUR RIGHTS
Correcting, Updating and Deactivating Information
RXNT complies with all laws regarding access to and correction of your information. Depending on your state of residence, you may be able to exercise certain rights as described below.
You may have the right to request access, obtain details or a copy of, delete, update, or correct the personal information we maintain or have processed about you. You may also have the right to withdraw your consent to our processing of your personal information. Your rights depend on your state of residence, and may be limited by applicable law:
- Access to Your Personal Data. You have the right to request that we disclose certain information to you regarding our collection and use of your personal information over the prior twelve months. Upon receiving your request and confirming your identity, we will disclose to you:
- The categories of your personal information we collected and the source of such collection.
- RXNT’s business or commercial purpose for collecting or selling that personal information.
- If we sold or disclosed your personal information for a business purpose.
- The categories of third parties with whom we share that personal information.
- A data portability request, including the specific morsels of information we collected about you.
- Update and Correct Your Personal Information. You may update your information by contacting us at [email protected], or calling us at 800-943-7968.
- Delete Your Personal Information. You have the right to request that RXNT delete any of your personal information that we have collected and retained from you, subject to certain exceptions. Once you submit a deletion request, we will verify your identity by matching the information provided in your request with information we may have in our system. If we are unable to verify your identity, we will notify you. If an exception which allows us to retain the information does not apply and your identity is successfully verified, we will delete your information and inform you once completed. Your deletion request for your personal information may be denied if retaining the information is necessary for us or our service providers to:
- Detect any security incidents and protect against malicious, fraudulent, or illegal activity.
- Debug to identify and repair errors that impair our existing intended functionality.
- Complete the transaction for which your information was collected, provide goods or services you have requested, or to fullfil a contract you have entered into with RXNT.
- Comply with the California Electronic Communications Privacy Act pursuant to Chapter 3.6 (commencing with Section 1546) of Title 12 of Part 2 of the Penal Code.
- To enable solely internal uses that are reasonably aligned with the expectations of the consumer based on your relationship with us.
- Comply with a legal obligation.
- Exercise free speech, ensure the right of another consumer to exercise their right of free speech, or exercise another right provided by law.
- Help to ensure security and integrity to the extent the use of your personal information is reasonably necessary and proportionate for those purposes.
- Engage in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to all other applicable ethics and privacy laws.
- Make other internal and lawful uses of that information which are compatible with the context in which you provided it.
- Limiting the Use of Sensitive Personal Information. If you are a California resident, you have the right to limit the use of sensitive personal information. RXNT only collects sensitive personal information provided to us by you, such as your social security number, financial account information, and as otherwise defined by applicable law. RXNT only uses sensitive information for the use disclosed to you at the time you provide it to us. RXNT does not use sensitive information for inferring characteristics about you.
- Opt Out of the Sharing of Your Personal Data. RXNT’s use of online tracking technologies may be considered a sale or sharing under applicable law.
If you are a California, Connecticut, Utah, or Virginia resident, we will not discriminate or retaliate against you for exercising any of the rights provided above.
Identity Verification
For security purposes, we may request additional information from you to verify your identity when you request to exercise your rights. This information will be used solely to verify your identity in connection with your request and will not be retained. Once you submit a request to exercise your rights, we will verify your identity by matching the information provided in your request with information we may have in our system. Upon successfully verifying your identity, we will provide you with your requested information in a secure, password-protected format if necessary. If we are unable to verify your identity, we will notify you.
Authorized Agent
If you are a resident of California, Colorado, or Connecticut, you may designate an authorized agent to submit a request on your behalf to exercise your privacy rights described herein. To authorize an agent to do so, you must: (i) provide such agent your signed permission to submit such request; and (ii) verify your own identity directly with us. RXNT may deny a request from an authorized agent if the agent does not provide adequate proof that they have been authorized by you to act on your behalf.
Appealing Requests
If you are a Colorado, Connecticut, or Virginia resident, you may appeal our decision to your request regarding your personal information. To do so, please contact us in ways described in this Policy, and we will respond to all appeal requests as soon as reasonably possible, and no later than legally required.
Responding to Requests
Upon receipt of your request, RXNT will respond within the time frame permitted by applicable law.
Exercising Your Rights
If you need assistance updating your personal information, or you would like further information regarding your legal rights under applicable law or would like to exercise any of them, please contact us via email addressed to [email protected].
YOUR RIGHTS WITH RESPECT TO HEALTH AND MEDICAL INFORMATION WE COLLECT OR PROCESS
If you are a patient of healthcare provider who uses our Products, we may collect or process information about you at the direction of your healthcare provider. If your healthcare provider is a Covered Entity under HIPAA, your rights with respect to your PHI are governed by HIPAA as well as our Business Associate Agreement with your healthcare provider. If you would no longer like to be contacted by the healthcare provider via our Products, please contact your healthcare provider directly. If you would like to access or delete personal information, or to correct or update inaccurate personal information, please contact your healthcare provider directly to do so.
We will retain personal information we process on behalf of our Covered Entity users for as long as needed to provide services to our users. RXNT will retain this personal information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.
DATA AGGREGATION SERVICES AND DE-IDENTIFIED DATA
RXNT receives PHI from our Covered Entity users under HIPAA, we may use such information to provide data aggregation services (as defined by HIPAA) and to create de-identified data in accordance with 45 CFR 164.514(a)-(c) retaining all ownership claims relating to the de-identified data RXNT creates from PHI. RXNT may use, during and after this agreement, all aggregate non-identifiable information for purposes of enhancing RXNT Products, technical support, and other business purposes, all in compliance with the HIPAA Privacy Standards, including without limitation the limited data set and de-identification of information regulations.
TRUEDEPTH API
Our app makes use of automatically collected information using the device camera and the TrueDepth API provided by Apple. This information is used to track the user's head and face so that we can detect any kind of image or video spoofing thus making LiveID scan feature more robust. None of the information collected by the TrueDepth API ever leaves the user's device nor is it persistently stored on the device.
UPDATES AND REVISIONS TO THIS POLICY
RXNT may update and otherwise revise this Policy from time to time as it deems necessary. The most current version of this Policy will be posted on this site along with the new effective date, and you will be notified via email if in RXNT’s sole judgment, the changes will materially affect the way we use or disclose previously collected personal information. However, it is your responsibility to review this Policy periodically on our website to see if there have been any changes that affect you. Your use of the RXNT Products, including the continued storage of your information on RXNT systems, following any such change constitutes your agreement that all information collected from or about you through RXNT Products will be subject to the terms of the revised Policy.
QUESTIONS
If you have any questions about this Policy or information security, please contact us at:
RXNT
1449 Whitehall RD
Annapolis, MD 21409
Email: [email protected]