Last Update: January 2025
This notice describes how Personal Data (defined below) and/or medical information about you may be used and disclosed and how you can obtain access to this information. Please review it carefully.
We at Vitasigns, LLC., ("we", "us", "the Company", or "Vitasigns") value your privacy and are committed to keeping your personal data confidential. We use your data solely in the context of providing remote physiologic monitoring ("RPM") services, chronic care management ("CCM") services, and related healthcare services through our platform and mobile application (collectively, the "Services"). If you are reading this Patient User Privacy Policy, you are either currently receiving or considering receiving our Services.
Privacy Policy Applicability
This Patient User Privacy Policy applies to personal data that Vitasigns collects from patients using our Services ("Personal Data"). The term "Personal Data" includes any information that can be used on its own or with other information to identify or contact one of our users. Some of the Personal Data we collect and transmit may be considered "health data" (i.e., data related to your physical or mental health), "protected health information" or "PHI" (i.e., information that relates to your past, present, or future physical or mental health or condition(s); the provision of health care to you; or the past, present, or future payment for the provision of health care to you), and/or medical records as defined by state law.
We believe that privacy and transparency about the use of your Personal Data are of utmost importance. Therefore, our privacy practices are intended to comply with the Health Insurance Portability and Accountability Act ("HIPAA") and relevant state law related to the use and disclosure of medical records, where applicable. Additionally, in this Patient User Privacy Policy, we provide you detailed information about our collection, use, maintenance, and disclosure of your Personal Data. The Patient User Privacy Policy explains what kind of information we collect, when and how we might use your Personal Data, how we protect Personal Data, and your rights regarding your Personal Data.
For additional information related to how we use and disclose your Personal Data, health data, PHI, and/or medical records data, please contact our Privacy Officer at privacy@vitasigns.com.
Note regarding third-party sites: Our Services may contain links to other sites that are not operated by Vitasigns. If you click a third-party link, you will be directed to that third-party's site. We strongly advise you to review the privacy policies of every site you visit. Vitasigns has no control over and assumes no responsibility for the content, privacy policies, or practices of any third-party sites or services. This Patient User Privacy Policy does not apply to your use of or access to any third-party sites or services.
What Personal Information Do We Collect?
We collect Personal Information from you and certain devices that you use as part of our Services. This includes:
1. Information You Provide Directly
- Full name and demographic information
- Contact information (phone numbers, email addresses, physical addresses)
- Health insurance information
- Medical history and conditions
- Current symptoms and health status
- Communications with our Care Team
- Video consultation recordings (with your consent)
- Payment information (where applicable)
2. Medical Device Data
We collect health data through:
- Vitasigns-provided monitoring devices
- Your own compatible medical devices that you choose to connect to our service This may include:
- Blood pressure readings
- Blood glucose measurements
- Weight measurements
- Heart rate and other vital signs
- Other health metrics relevant to your care
3. Automatically Collected Technical Information
Our systems automatically collect:
- Device identifiers
- IP addresses
- Browser type and version
- Operating system information
- Usage patterns within our Services
- Location data (when enabled)
4. Information From Healthcare Providers
We may receive information from:
- Your primary care physician
- Other healthcare providers involved in your care
- Healthcare facilities
- Health information exchanges This may include:
- Medical records
- Treatment history
- Prescriptions
- Test results
- Other relevant health information
All collected information is protected under HIPAA regulations and applicable state laws. We maintain appropriate physical, technical, and administrative safeguards to protect your information.
How We Use Your Information
We use your Personal Information for the following purposes:
1. Providing Healthcare Services
- Delivering remote physiologic monitoring (RPM) services
- Managing chronic care conditions (CCM)
- Coordinating care with your healthcare providers
- Conducting telehealth consultations
- Monitoring your vital signs and health metrics
- Providing medical advice and support
- Managing your treatment plan
2. Healthcare Operations
- Creating and managing your patient account
- Processing insurance claims and payments
- Conducting quality assessment and improvement activities
- Performing business planning and development
- Conducting internal auditing and compliance programs
- Training our healthcare professionals and staff
- Resolving grievances
- Managing business operations
3. Communication Purposes
- Sending appointment reminders
- Providing treatment updates and recommendations
- Sharing important health information
- Responding to your questions and concerns
- Sending service-related announcements
- Providing technical support
- Alerting you to important system or service changes
4. Legal and Safety Purposes
- Complying with legal and regulatory requirements
- Responding to court orders or legal processes
- Preventing potential harm to your health and safety
- Protecting our legal rights and interests
- Detecting and preventing fraud
- Maintaining the security of our Services
5. Quality Improvement
- Evaluating and improving our Services
- Developing new features and capabilities
- Analyzing service performance and reliability
- Identifying technical issues
- Understanding user needs and preferences
- Enhancing patient care and experience
All use of your Personal Information complies with:
- HIPAA regulations
- State privacy laws
- Professional medical standards
- Our internal privacy and security policies
We maintain detailed records of how we use your information and regularly review our practices to ensure compliance with all applicable regulations.
Information Sharing and Disclosure
We share your Personal Information only as necessary to provide our Services and as permitted or required by law. Here's how we share your information:
1. Healthcare Providers and Treatment
We share your information with:
- Your primary care physician
- Other healthcare providers involved in your care
- Specialists when referred
- Healthcare facilities as needed for your care
- Other providers in your care network
This sharing is done to:
- Coordinate your care
- Ensure proper treatment
- Maintain continuity of care
- Support medical decisions
- Enable emergency care when needed
2. Healthcare Operations
We share information with:
- Health insurance companies for claims processing
- Medical device suppliers
- Healthcare billing services
- Quality assurance reviewers
- Professional consultants
All third-party service providers must:
- Sign HIPAA-compliant Business Associate Agreements
- Maintain appropriate security measures
- Use information only for specified purposes
- Return or destroy information when no longer needed
3. Legal Requirements
We may disclose information when:
- Required by federal, state, or local laws
- Necessary for public health activities
- Requested by law enforcement with proper authorization
- Ordered by a court or administrative body
- Necessary to prevent serious health or safety threats
- Required for workers' compensation cases
4. Business Transitions
If Vitasigns is involved in a merger, acquisition, or sale of assets, we will:
- Ensure continued protection of your Personal Information
- Notify you of any change in ownership or privacy policy
- Ensure the new entity maintains similar privacy protections
5. Your Authorization
We will obtain your written authorization before sharing your information for any purpose not described in this policy or required by law.
You may revoke any authorization at any time by:
- Submitting a written request
- Contacting our Privacy Officer
- Following the instructions in our authorization form
Important Notes About Information Sharing
- We never sell your Personal Information
- We do not share your information for marketing purposes
- We maintain records of all disclosures
- We limit sharing to the minimum necessary information
- We require confidentiality agreements with all recipients
- We verify the identity and authority of requestors
Your Rights and Choices
Your Rights Under HIPAA
As our patient, you have the following rights regarding your health information:
- Right to Inspect and Copy
- You can request to see and receive copies of your health records
- We will provide access within 30 days of your request
- We may charge a reasonable, cost-based fee for copies
- Records will be provided in the format you request (if readily producible)
- Right to Amend
- You can request corrections to your health information
- We will respond to your request within 60 days
- If we deny your request, we'll explain why in writing
- You have the right to submit a statement of disagreement
- Right to an Accounting of Disclosures
- You can request a list of when and to whom we've disclosed your information
- This covers disclosures made in the last six years
- Does not include disclosures for treatment, payment, or healthcare operations
- The first request in 12 months is free
- Right to Request Restrictions
- You can ask us to limit how we use and share your information
- We aren't required to agree to all restrictions
- We will honor restrictions related to disclosure to health plans if you pay for a service in full
- Right to Confidential Communications
- You can request we contact you in a specific way
- We will accommodate reasonable requests
- You can specify preferred contact methods and locations
Your Choices
- Communications Preferences
- You can choose how we communicate with you
- You can opt out of certain non-essential communications
- You will continue to receive important service-related and treatment communications
- Mobile App Settings
- You can control app permissions through your device settings
- You can choose which device features our app can access
- You can manage notification preferences
- Data Sharing Options
- You can choose whether to share data with other healthcare providers
- You can control integration with other health monitoring devices
- You can manage authorizations for information sharing
How to Exercise Your Rights
To exercise any of these rights, you may:
- Contact our Privacy Officer at Privacy@vitasigns.com
- Call us at (949) 200-6840
- Mail your request to: Vitasigns LLC c/o Privacy Officer P.O. Box 8592 Newport Beach, CA 92658
We will respond to all requests within the timeframes required by applicable laws.
Security of Your Information
Our Security Measures
Vitasigns maintains comprehensive security measures to protect your Personal Information and PHI:
- Technical Safeguards
- Encryption of data in transit and at rest
- Multi-factor authentication
- Secure firewalls and access controls
- Regular security updates and patches
- Intrusion detection systems
- Continuous system monitoring
- Secure backup systems
- Administrative Safeguards
- Regular staff training on privacy and security
- Background checks for employees
- Access controls based on job role
- Written policies and procedures
- Regular security assessments
- Incident response planning
- Business associate agreements
- Documentation of security practices
- Physical Safeguards
- Secure facility access controls
- Locked server locations
- Surveillance systems
- Device and media controls
- Clean desk policies
- Secure disposal of physical records
Data Breach Procedures
In the event of a data breach, we will:
- Investigate the incident promptly
- Take necessary steps to contain the breach
- Notify affected individuals as required by law
- Provide information about steps you can take
- Implement measures to prevent future incidents
Your Security Responsibilities
To help protect your information, we recommend:
- Keeping your login credentials confidential
- Using strong, unique passwords
- Not sharing your account access
- Logging out after each session
- Notifying us of suspected unauthorized access
- Keeping your device security updated
Important Security Notes
- No method of transmission over the Internet or electronic storage is 100% secure
- We cannot guarantee absolute security of your information
- You use our Services at your own risk
- We are not responsible for security breaches resulting from third-party actions or your failure to maintain security measures on your devices
We regularly review and update our security measures to maintain the safety and integrity of your information.
Special Provisions for California Residents
If you are a California resident, you have specific rights under California privacy laws, including the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA). Please note that these rights may not apply to Personal Information collected and used as part of providing healthcare services, which is governed by HIPAA and other healthcare privacy laws.
Your California Privacy Rights
- Right to Know
- You can request details about the personal information we collect
- You can learn how we use and share your information
- You can receive specific pieces of personal information we have collected
- Right to Delete
- You can request the deletion of personal information we have collected
- Some exceptions apply, particularly for healthcare-related information
- We will inform you if we cannot delete certain information due to legal requirements
- Right to Correct
- You can request corrections to inaccurate personal information
- We will process these requests within the timeframes required by law
- Right to Limit Use of Sensitive Personal Information
- You can limit how we use certain sensitive personal information
- Healthcare-related information may be exempt from this right
- Right to Opt-Out of Sharing
- You can opt out of certain types of information sharing
- This right may be limited for healthcare-related information
- Right to Non-Discrimination
- We will not discriminate against you for exercising your rights
- Your healthcare services will not be affected by privacy choices
How to Exercise Your California Privacy Rights
To exercise these rights:
- Email: Privacy@vitasigns.com
- Call: (949) 200-6840
- Mail: Vitasigns LLC c/o Privacy Officer P.O. Box 8592 Newport Beach, CA 92658
We will verify your identity before processing any requests to protect your privacy.
Response Timing
We will respond to privacy rights requests within:
- 45 days of receiving your request
- 90 days if we need additional time (we will notify you)
Annual Disclosure
As required by California law, we disclose:
- Categories of personal information collected
- Business purposes for collection
- Categories of sources
- Categories of third parties with whom we share information
- Categories of information disclosed for business purposes
Changes to This Privacy Policy
Updates and Modifications
We may update this Privacy Policy from time to time. When we make changes:
- We will post the updated policy on our website and in our mobile application
- We will update the "Last Updated" date at the top of this Privacy Policy
- We will notify you of material changes via email or through our Services
- Changes will become effective when posted
If you continue using our Services after changes become effective, you accept the updated Privacy Policy. If you disagree with any changes, you must stop using our Services and contact us to close your account.
Children's Privacy
We do not knowingly collect Personal Information from anyone under the age of 18 without parental consent. Our Services are not directed to minors under 18. If we learn we have collected or received Personal Information from a child under 18 without verification of parental consent, we will delete that information.
If you believe we might have any information from or about a child under 18, please contact us at:
- Email: Privacy@vitasigns.com
- Phone: (949) 200-6840
Contact Information
For questions or concerns about this Privacy Policy or our privacy practices, please contact:
Vitasigns LLC Privacy Officer P.O. Box 8592 Newport Beach, CA 92658
Phone: (949) 200-6840 Email: Privacy@vitasigns.com
We will respond to your privacy concerns promptly and in accordance with applicable laws and regulations.
This Privacy Policy was last updated on December24, 2024.