Steward Health Care System LLC Patient Portal Privacy Statement
Last Updated March 10, 2022
Steward Health Care System LLC, on behalf of ourselves and our affiliates (hereinafter “Steward” “we” “us” and “our”), are committed to protecting the privacy of our users. This Privacy Statement describes Steward’s privacy practices in relation to your use of our software, website, platforms, tools and applications associated with the Service (defined below), including any data that may be collected by Steward through your use of the Service. We do not use or disclose your information except as described in this Privacy Statement. This Privacy Statement is intended to be read in conjunction with the Steward Health Care System LLC End User License Agreement, which shall govern your use of the Service. This Privacy Statement does not apply to any third party applications, tools or services that are integrated in or support the Service.
Introduction
The Service is a health management software tool provided by Steward that lets you gather, edit, store and share health data online (“Service”). You may also be able to access information about other people (such as your family) with their consent and invitation, as we share your information with people to whom you invite and provide consent. Service accounts are not for use by healthcare providers or for any other commercial or non-personal purpose. The Service is capable of providing personalized health guidance for you and your family. It is important for you to understand how the information that you submit, review and edit in the Service is used by us.
The contents of the Service, such as text, graphics, images, personal health information, and other material contained in the Service and all information and data produced by the Service (“Content”) are for informational purposes only. The Content is not intended to be a substitute for professional medical advice, diagnosis, or treatment. The Content in your account may not always be accurate or up-to-date and should be considered by any health care provider as informational only. The Service does not hold records for healthcare providers or other medical or case management purposes. For example, Service records may not be designated record sets as defined under U.S. regulations. If a healthcare provider decides to include any data made available from the Service in its records, it should store a copy in its own system. If there is a co-custodian of a record in your account (because one of you invited the other), you acknowledge that the co-custodian has full control over that record and may cancel your access to the record, and manage how the record is used. The health information you will see comes from the Electronic Medical Record (“EMR”) and from you when you add information, including from connected devices. The health information guidance you will receive is automatically generated by the Service based on information that you enter into or make available to the Service through your Service account. This information may not be reviewed by a physician, nurse, or other health care provider for your treatment purposes. Always seek the advice of your physician or other qualified health provider with any questions you may have regarding a medical condition. You agree that the Service and the information and guidance provided by the Service do not constitute the practice of medicine or any medical, nursing, or other professional health care advice, diagnosis, or treatment. Never disregard professional medical advice or delay in seeking it because of something you have read when using the Service.
Signing in to the Service and Creating an Account
To sign in to the Service, the Service uses a built-in proprietary authentication service. If you close your Service account or lose your account credentials, you may not be able to access your data.
To create a new Service account, you must provide personal data such as name, date of birth, e-mail address, postal code, and country/region. Depending on which features you use, you may be asked for additional information. A Service account allows you to manage one or more health records, such as the ones you create for yourself and your family members. You can add or remove data to a health record you manage at any time.
Sharing Health Data
A key value of the Service is the ability you have to share your health data with people and services that can help you meet your health-related goals. By default, you are the custodian of any records you create. Custodians have the highest level of access to a health record. As a custodian, you can share data in a health record with another person by sending an e-mail invitation through the Service. You can specify what type of access they have (including custodian access), how long they have access, and whether they can modify the data in the record. When you grant someone access, that person can grant the same level of access to someone else (for example, someone with view-only access can grant another user view-only access). Because inappropriate granting of access could allow someone to violate your privacy or even revoke your access to your own records, you should be cautious about granting access to your records.
You can choose to share specific data (or all of the data) in a health record with other services, including participating third party services that you authorize (where available). No service has access to your data through the Service unless an authorized user grants it access through the Service. The Service allows you to control access by accepting or denying requests. For each service granted access, you choose what health information in a specific health record to share and what actions each service may perform on the health information.
A third party service that you authorize for a record will receive the full name associated with your Service account, the nickname of the authorized record(s), and your relationship to that record. The third party service will continue to have access through the Service until you revoke the permission. We can revoke a third-party service's access to the Service if it does not meet its privacy commitments to Steward. However, except for applying the access permissions you have granted to third-party services, we do not control or monitor third-party services, and their privacy practices will vary. You should review the privacy policy of all third-party services for which you have granted access. Steward exercises no authority over third party services and assumes no responsibility or liability for the independent methods or actions of third party services and is not responsible for the independent policies or procedures of any third party service.
Once your personal information leaves the Service, different privacy practices will apply to your data. For example, if your healthcare provider accesses your data, your healthcare provider could add your data to your EMR. The privacy practices of both the provider and the EMR will be different than the privacy practices of the Service. While we cannot control the privacy practices of your healthcare provider, your EMR may be owned and/or controlled by us. Therefore, if you have any questions or concerns about what happens to your data if your healthcare provider adds data that you enter into the Service into your EMR, you should contact us using the contact information contained in this Privacy Statement below.
Access and controls
You can review, edit, or delete your Service account data, or close your Service account at any time. Only custodians can permanently delete an item, however, we may be compelled by law to maintain a deleted item for our records. When you delete a heath record, it is also deleted for all users who had access to it.
When you close your Service account, except where we are compelled by law to maintain your information, we delete all records for which you are the sole custodian. If you share custodian access for a record, you can decide whether to delete the record. Except where we are compelled by law to maintain your information, we will wait a limited amount of time before permanently deleting your data in order to help avoid accidental or malicious removal of your health data.
The Service maintains a full history of each access, change or deletion by users and services, which includes the date, action, and name of the person or service. Custodians of records can examine the history of those records.
Email communications
We will use the email address you provide to share invitations you send through the Service, and to send you service notifications, such as email notifications that information is available to add to your Service records.
Collection of Personal and Usage Information
Any data that you enter into the Service is stored in a secure hosted environment. If You delete Your Service Account of Record, You may be permanently deleting Your Data. The Service uses the information that you authorize for access from your Service account to provide you with personalized health information. You can review information contained in your Service account using the patient portal.
The Service uses personal information collected from you, including personal health information, to provide the Service as described in this Privacy Statement. Steward does not access the personal health information that is stored in the secure hosted environment without your prior permission (for example, for maintenance or support purposes) and is not accessible by third parties without your secret login password information.
We may collect information about your interaction with the Service. For example, we may use web site analytics tools included in the Service to retrieve information from your browser, including the site you came from, the search engine(s) and the keywords you used to find the Service, the pages you view within the Service and your browser's width and height. We also may use technologies, such as cookies (described below), to collect information about the pages you view, the links you click and other actions you take on the Service. Additionally, we may collect certain standard information that your browser sends to every web site you visit, such as your IP address, browser type and language, access times, and referring web site addresses. This information is referred to as "Usage Information." Finally, we may collect information that is pushed to the Service from your EMR.
How Your Personal Information is Stored
The Service stores or "caches" your personal information as necessary to provide you the Service.
All of the personal information you enter, edit, delete or view in the Service is added to your Service account once you click on "Save" or another similar button.
When you click the "Save" button, the cache of information used by the Service is also updated with the new information you added or changed. When you select that link, the Service updates all the information in the cache with the most current information in the Service.
How Your Personal Information and Usage Information are Used and Shared
The Service uses Your personal information and Usage Information to provide you the Service and to personalize your user experience. We and our Service suppliers, as applicable, may also use some of this information to improve our respective products and services, including the Service. We may use aggregated information from the Service to improve the quality of the Service. This aggregated information is not associated with any individual account. Except as set forth in this Privacy Statement, we will not share your personal information and usage information in personally identifiable form with any other party without your consent, unless we are required to do so (1) to comply with the law; (2) in response to a judicial or other governmental subpoenas, warrants and court orders served on us in accordance with their terms; (3) to prevent, report or investigate illegal activity; or (4) to protect our rights or property (including the enforcement of our agreements).
Children’s Privacy Protection
The Service is not intended or targeted at children and is primarily for use by adults. We will not knowingly collect or maintain personal information from children thirteen (13) years of age or younger. In the event we discover that a child thirteen (13) years old or younger has disclosed any personal information through the Service, we will delete the child’s personal information from the Service to the extent possible in accordance with the Children’s Online Privacy Protection Act.
HIPAA and State Privacy Laws
Steward is committed to maintaining your privacy using all of the measures described in this Privacy Statement and by adhering to the HIPAA regulations, including but not limited to, the Privacy and Security Rules. Steward shall not retain, use, or disclose your personal data for any purpose other than for the specific purpose of performing the Service specified herein, which constitutes a business purpose, or as otherwise permitted by applicable state and federal law including, without limitation, HIPAA and the California Consumer Privacy Act. Steward will not sell your personal data. Each party certifies that they understand the requirements set forth herein and will comply with them.
Third Parties
The Service may contain links to web sites operated by third parties. We have no control over the privacy policies or practices of such third party sites, and you should review the privacy policies and terms of use of those sites for more information about the policies applicable to those sites. The choices you select in any third party sites which may be linked to the Service may allow other people, companies and applications to access the personal information that is stored in your Service account. Steward exercises no authority over third party sites and assumes no responsibility or liability for the independent methods or actions of third party sites and is not responsible for the independent policies or procedures of any third party sites.
How We Use Cookies
We may use cookies with this Service to enable you to sign in and to help personalize the Service. A cookie is a small text file that a web page server places on your hard disk. It is not possible to use cookies to run programs or deliver viruses to your computer. A web server assigns cookies uniquely to you and only a web server in the domain that issued the cookie to you can read the cookies. Like many other web services, the Service may use cookies to provide information relating to the sources of site traffic and to help you personalize your experience.
One of the primary purposes of cookies is to provide a convenience feature to save you time. For example, if you personalize a web page, or navigate within a site, a cookie helps the site to recall your specific information on subsequent visits. Using cookies simplifies the process of delivering relevant content, eases site navigation, and so on. When you return to the web site, you can retrieve the information you previously provided, so you can easily use the site's features that you customized.
You have the ability to accept all cookies or modify which cookies may be used. You may also decline cookies. If you choose to decline all cookies, you may still use the Service but it could adversely affect the functionality of the Service or the Service may be rendered inoperable.
Complaint Process
If you have a complaint or problem related to the Service, or any questions regarding our privacy practices, or you believe we have not adhered to the policies set forth in this Privacy Statement, you may contact a Privacy Officer. We suggest you review Steward’s general privacy policies before contacting a Privacy Officer. Steward’s privacy policies and Privacy Officer contact information may be found at the following address.
https://www.steward.org/privacy-policy
For specific contact options, please review the Questions and Complaints section.
We will make all commercially reasonable efforts to promptly address your concerns.
Changes to Our Privacy Statement
We may update this Privacy Statement from time to time. When we do, we will revise the "last updated" date at the top of the Privacy Statement. You will be responsible for reviewing this Privacy Statement prior to each use of the Service to ensure you are aware of any changes to our Privacy Statement. YOU ARE HEREBY ADVISED THAT YOUR CONTINUED USE OF THE SERVICE CONSTITUTES YOUR ACCEPTANCE OF ANY CHANGES TO AND THE MOST RECENT VERSION OF THIS PRIVACY STATEMENT.