This is PatientPower's Model Privacy Notice (MPN) โ a standardized, plain-language snapshot based on the format published by the U.S. Office of the National Coordinator for Health IT (ONC). It is a quick-reference summary; our full commitments are in our Privacy Policy & Disclosure and CARIN Code of Conduct attestation.
Yes โ only what you authorize: health records you connect from a health plan or health system (labs, medications, conditions, allergies, immunizations, claims/coverage, demographics), information you enter or upload yourself, and your account email. We practice data minimization โ only what is needed to provide the Service.
We do not collect your precise location, and we do not track you across other apps or websites for advertising. Basic technical/security logs (e.g., sign-in and audit events) are kept to operate and secure the Service.
You must sign in and connect or enter data for the app to be useful, but connecting any specific health source is always your choice.
No. Never.
Only in these limited ways: with people you choose (such as a clinician or caregiver you share with), with service providers under contract solely to operate the Service for you, and when required by law. We do not share your data for third-party advertising or marketing.
No.
No. Your individual data is not used to train or improve AI models.
To consolidate your records in one patient-owned place, present them to you in plain language for education and visit preparation, and to provide, maintain, secure, and support the Service. When a healthcare practitioner uses PatientPower's Case Manager for your care plan, PatientPower acts as their business associate under a BAA, and information from one practitioner is never shared with another.
Yes โ in transit (TLS 1.2+) and at rest (AES-256).
Role-based access controls, audit logging, and server-side token handling so credentials and secrets are never exposed to your browser. Protected health information is held in a dedicated, access-controlled environment.
As long as your account is active or as needed to provide the Service. When you delete your data or account, we remove it from active systems within a reasonable period, except where retention is required by law.
Yes โ we work to notify affected users of a material breach as required by law.
Yes โ you may view and export your information at any time.
Yes โ you may delete your account and information at any time.
Yes โ disconnect a source in PatientPower, and you can also revoke access at the source (your provider's or health plan's portal). We honor source-side revocation promptly.
Yes โ you authenticate at your provider or health plan and explicitly authorize the specific information before anything is accessed.
PatientPower's Privacy Officer is accountable for these practices. Questions or requests: contact us through beyondmychart.com. Our practices support oversight by the FTC, state attorneys general, and other applicable authorities.
Yes โ material changes are reflected by the "Last updated" date above and, where appropriate, by notice in the Service.
Full details: Privacy Policy & Disclosure ยท CARIN Code of Conduct attestation ยท Terms & Conditions.