This Notice of Privacy Practices describes how we may use and disclose your personal identifiable information (PII) or protected health information (PHI) to carry out our operations that are permitted or required by law. It also describes your rights to access and control your PII and PHI. PII is any information that permits the identity of an individual to be directly or indirectly inferred. PHI is information about you, including demographic information, that may identify you and that relates to your past, present, or future physical or mental health or condition and related health care services.
We are required to abide by the terms of this Notice of Privacy Practices. We may change the terms of our notice at any time. Any new notice will be posted to the PayRx, Inc. (“PayRx”) website and be effective for PII and PHI that we maintain at that time. Upon your request, you may obtain any revised Notice of Privacy Practices by contacting us and requesting that a revised copy be sent to you in the mail.
1. Collection of PII and PHI
PayRx obtains PII and PHI from employers or health plan providers in the course of providing risk coverage and analytic solutions under a business contract. As such the employer or health plan provider is ultimately responsible for safeguarding the privacy and security of their memberships' data. PayRx signs a Business Associate Agreement with these employers or health plan providers that it contracts with which obliges PayRx to ensure the same or higher level of standards are in place to protect PII and PHI.
Additionally, PayRx obtains information through its website that includes PII such as name and contact information through its Learn More form. In this case, PayRx is ultimately responsible for safeguarding it's privacy and security.
Cookies
Cookies are text files placed on a computer to collect standard Internet log information and visitor behavior information. When you visit our websites, we may collect information from you automatically through cookies or similar technology.
We use cookies to keep users signed into our portal and to better understand how this and the portal site are used. Analytics cookies store information in an aggregated fashion and do not keep track of individual PII.
PayRx retains PII and PHI as long as necessary and if applicable in accordance with the Business Associate Agreement signed with the employer or health plan provider and as needed to comply with our data retention requirements as well as any legal and regulatory obligations.
2. Uses and Disclosures of PII and PHI
Set forth below are examples of the types of uses and disclosures of your PII and PHI that PayRx is permitted to make. These examples are not meant to be exhaustive, but rather to describe for you the types of uses and disclosures that may be made by PayRx.
- Risk Coverage Activities:
PayRx may use or disclose, as needed, your PHI and/or PII to support applicable coverage activities with your employer. This may include underwriting processes, verification, and coverage of eligible claims, quality management, compliance with regulations, and other business related activities.
-
Analytics and Trends:
We may use or disclose, as needed, your PHI and/or PII to identify trends and patterns to support analytics initiatives, corporate standards, and related controls.
We also may need to share your PHI and/or PII with service providers and business associates or other third parties that perform various activities on behalf of PayRx. Whenever an arrangement between PayRx and a business associate or third-party supplier involves the use or disclosure of your PHI and/or PII, we will have in place the legally required safeguards to protect the privacy of your information.
We also may use or share de-identified information that is not reasonably likely to identify you for commercially legitimate business purposes.
3. Your Rights
Set forth below is a statement of your rights with respect to your PII and/or PHI and a brief description of how you may exercise these rights.
- Right to receive a copy of our Notice of Privacy Practices. This Notice of Privacy Practices will be updated periodically and maintained on PayRx's website. You have the right to ask for a copy of this document whenever you may need to evaluate how PayRx uses and discloses your PII and/or PHI.
- Right to know about the PII and/or PHI we collect about you and how it is used and shared. This means you may request disclosure of the PII and/or PHI we have used, shared, or collected.
- Right to delete PII and/or PHI collected by PayRx. This means you may request deletion of specific information pursuant to certain qualifying factors, restrictions, and exceptions.
- Right to review or obtain a copy of PII and/or PHI. This means you may inspect and obtain a copy of records containing PII and PHI about you for as long as we maintain the underlying record in accordance with applicable laws and regulations.
- Right to request restrictions on the use or disclosure of PII and/or PHI. This means you may ask us not to use or disclose any part of your PII and/or PHI for specified purposes. Your request must state the specific restriction requested and to whom you want the restriction to apply. However, PayRx is not required to agree to a restriction that you request.
- Right to request amendments to PII and/or PHI, with certain limitations. This means you may request an amendment of PII and/or PHI about you in a record for as long as we maintain this information.
- Right to an accounting of certain disclosures of PII and/or PHI. This means you may request a copy of any log or ledger with applicable disclosures of your PII and/or PHI.
4. Exercising Rights
You may exercise your rights by sending your request via email, mail, or calling us using the contact information below. We may direct you to your employer or health plan provider for data for which they are legally responsible as they will need to initiate the procedure.
You may also contact your employer or health plan provider directly as appropriate using their Data Rights procedures. Please contact them for additional guidance on the best way to exercise your Data Rights.
5. Information Security
PayRx has implemented physical, electronic, and technical safeguards to protect your PII and/or PHI, consistent with applicable privacy and data security laws. However, we cannot completely guarantee security of your personal information. You can help safeguard your personal information by keeping confidential and private all usernames, logins, and passwords used to connect with PayRx Online Services.
6. Contact Us
You may contact us or an applicable federal or state regulatory agency if you believe your privacy rights have been violated by us. You may file a complaint with us by notifying our Privacy Officer about concerns or related issues and considerations. We will not retaliate against you for filing a complaint.
You may reach our Privacy Officer at:
PayRx, Inc
Attn: Privacy Officer
590 Madison Ave, 21st Floor
New York, NY 10022
privacy@payrxinc.com
(646) 777-7331
7. File a complaint
You may complain if you feel we have violated your rights by contacting us using the information above. In addition, you can file a formal complaint with the U.S. Department of Health and Human Services Office for Civil Rights by sending a letter to 200 Independence Avenue, S.W., Washington, D.C. 20201, calling 1-877-696-6775, or visiting www.hhs.gov/ocr/privacy/hipaa/complaints/. PayRx will not retaliate against you for filing a complaint.
8. Notice Effective Date
The effective date of this notice is June 09 2023.