Privacy Policy
1. Introduction; Scope
1.1 Who We Are.
MedPathX, Inc. (“MedPathX”, “we”, “our”, or “us”) operates a technology platform that provides visibility into organ-transport flight availability and pricing and facilitates matching among transplant centers, organ procurement organizations, and other authorized participants (together with our websites, applications, and related services, the “Platform”).
1.2 Scope.
This Privacy Policy describes how we collect, use, and share information in connection with the Platform. It applies to personnel of our demand-side customers (“Customers”), personnel of the air carriers and other supply-side participants that list capacity on the Platform (“Providers” or “Operators”), and visitors to our websites.
1.3 Organizational Agreements Control.
We provide the Platform to organizations under agreements such as our Customer Terms of Service, Provider Terms of Service, Order Forms and Onboarding Terms, and business associate agreements (each, an “Organizational Agreement”). Data submitted to the Platform for an organization is owned and licensed as its Organizational Agreement provides, and the Organizational Agreement controls over this Privacy Policy in the event of a conflict. If your organization gave you access to the Platform, your organization controls its account and much of the information associated with your use, and this Policy does not limit its rights.
1.4 PHI.
Protected health information (“PHI”) is addressed in Section 3 (Protected Health Information) and is governed by HIPAA and the applicable business associate agreement (“BAA”), which control over this Policy as to PHI.
2. Information We Collect
2.1 Information You Provide.
We collect: account and registration information, such as your name, work email address, phone number, role and title, organization, and login credentials; provider onboarding and credentialing information for supply-side participants, such as certificates, operating authority, insurance information, aircraft and fleet details, and related documentation; listing and transaction information, such as availability, positioning, and pricing information and flight requests, quotes, acceptances, and status updates; case and logistics communications submitted through the Platform’s case-coordination and messaging features, which may include PHI (see Section 3); billing information for Platform fees, provided that payment card and bank details are collected and processed by our payment processor and we receive only limited billing metadata; and support communications and any other information you choose to submit.
2.2 Information Collected Automatically.
We collect log, device, and usage information, including IP address, browser and device type, pages viewed, features used, timestamps, and similar diagnostics, and we use cookies and similar technologies as described in Section 7 (Cookies and Similar Technologies).
2.3 Information from Other Sources.
We may receive information from third-party sources used to verify eligibility and credentials, including government registries and records (for example, FAA and DOT records), insurers and certificate holders, and other Platform participants (for example, a Customer that refers an affiliated carrier).
2.4 Payments for Transport Services.
We do not collect, hold, route, or process payments between Customers and Operators for transport services; those payments occur directly between them.
3. Protected Health Information
3.1 Our Role.
The Platform’s case-coordination and messaging features may transmit or store PHI. Where we create, receive, maintain, or transmit PHI for a customer that is a HIPAA covered entity, we act as a business associate and process that PHI in accordance with HIPAA and our BAA with that customer. As to PHI, the BAA and HIPAA control over this Policy.
3.2 Direction and Access.
Platform participants that receive PHI through the Platform, such as an Operator receiving case details for a flight, receive it at the direction of the customer that controls the case. Role-based access controls are designed to limit the case information visible to each participant consistent with the minimum-necessary standard.
3.3 Limits.
We do not use or disclose PHI except as the applicable BAA and HIPAA permit. We do not sell PHI, and we do not use or disclose PHI for marketing purposes. We may de-identify PHI in accordance with 45 CFR 164.514; de-identification is the sole pathway by which customer data may become data we use for our own purposes, and we do not attempt re-identification.
4. How We Use Information
We use information to: provide, operate, maintain, secure, and support the Platform; display availability, positioning, pricing, and related listing information to authorized participants; facilitate flight requests, matching, and case coordination; verify the eligibility, credentials, and compliance of Platform participants; bill and collect Platform fees; send transactional and service communications; monitor for and prevent fraud, abuse, and security incidents; comply with law and enforce our agreements; and improve and develop the Platform, including through De-Identified and Aggregated Data as described in Section 6. We use information processed for an organization only as its Organizational Agreement permits.
5. How We Share Information
5.1 With Other Platform Participants.
Listing information (availability, positioning, pricing, aircraft, and related details) is displayed to authorized demand-side participants so they can request and book flights. Case information is shared with the participants that the case-controlling customer selects. We do not make a provider’s non-public pricing visible to other supply-side participants.
5.2 With Your Organization.
Administrators of your organization’s account may see information about your use of the Platform.
5.3 Service Providers.
We share information with vendors that perform services for us, such as cloud hosting, communications and notifications, form and email handling, customer support, and payment processing, under contracts that restrict their use of the information and, where they handle PHI, under business associate agreements.
5.4 Affiliates.
We may share information with our corporate affiliates consistent with this Policy. We do not provide any MedPathX-affiliated managed-transport service with access to a provider’s non-public data, other than information generally visible to Platform participants or De-Identified and Aggregated Data (Section 6).
5.5 Legal; Safety.
We may disclose information to comply with law or legal process, to protect the rights, safety, or property of MedPathX, Platform participants, or others, and to enforce our agreements. Where legally permitted, we will use reasonable efforts to notify the affected organization before disclosing its data in response to legal process.
5.6 Corporate Transactions.
If MedPathX is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, information may be transferred as part of that transaction. We will provide notice before your information becomes subject to a materially different privacy policy.
5.7 With Consent.
We may share information for other purposes with your consent or at your direction.
5.8 No Sale; No Targeted Advertising.
We do not sell personal information, and we do not share personal information for targeted or cross-context behavioral advertising.
6. De-Identified and Aggregated Data
We may create, use, and share de-identified and aggregated data that does not identify, and cannot reasonably be used to identify, any individual or organization (“De-Identified and Aggregated Data”) for lawful purposes, including Platform operations and improvement, product development, benchmarking, analytics, and reporting. With respect to PHI, de-identification follows 45 CFR 164.514. De-Identified and Aggregated Data is not personal information, and we will not attempt to re-identify it.
7. Cookies and Similar Technologies
We use a limited set of cookies and similar technologies necessary to operate the Platform, including session cookies for authentication and security and persistent cookies for authentication continuity and basic functionality. We do not use third-party advertising cookies, and we do not engage in cross-context behavioral advertising. We do not currently use third-party analytics tools. Because there is no industry consensus on responses to “Do Not Track” signals, the Platform does not respond to DNT signals.
8. Data Security
We implement administrative, technical, and physical safeguards designed to protect information, appropriate to the nature and sensitivity of the information we process. No system is perfectly secure, and we cannot guarantee the security of information transmitted to or through the Platform. If you become aware of a security issue affecting your account, please notify us at support@medpathx.com.
9. Data Retention
We retain information for as long as necessary for the purposes described in this Policy, including to provide the Platform, comply with legal, regulatory, and contractual obligations, resolve disputes, and enforce agreements. When information is no longer needed for those purposes, we delete or de-identify it. Case and transaction records are retained as the applicable Organizational Agreement (including any data-export window) and applicable law require, and billing and payment records are retained as required for tax, accounting, and audit purposes. PHI is retained, returned, or destroyed as the applicable BAA provides. De-Identified and Aggregated Data may be retained indefinitely.
10. Your Choices
You may access and update your account information through your account settings or by contacting us. You may request deletion of your account information by contacting us; where information is controlled by an organization or must be retained under Section 9 or applicable law, we may route the request to the organization or retain the information as permitted. Because we provide the Platform to organizations, we may direct requests concerning organization-controlled data to the relevant organization and assist it in responding. You may opt out of non-transactional marketing emails using the unsubscribe link in those messages. We send transactional and service messages as part of operating the Platform.
11. State Privacy Rights
11.1 Scope; Exemptions.
The Platform is a business-to-business service, and much of the information we process is regulated by HIPAA or processed on behalf of our customers. Information governed by HIPAA and de-identified information are generally exempt from state consumer privacy laws.
11.2 California.
If you are a California resident, this Section describes our practices under the California Consumer Privacy Act. We collect the following categories of personal information: identifiers (such as name, work email, phone number, and IP address); professional or employment-related information (such as employer, role, and credentials); commercial information (such as transactions and billing metadata); internet or other electronic network activity information (such as usage and log data); general geolocation derived from IP address; and inferences drawn from the foregoing to operate and improve the Platform. We collect these categories from the sources described in Section 2, use them for the purposes described in Section 4, and disclose them for business purposes as described in Section 5. We do not sell personal information and do not share it for cross-context behavioral advertising, and we have no actual knowledge of selling or sharing personal information of consumers under sixteen (16). California residents may request access to, deletion of, or correction of their personal information, and will not be discriminated against for exercising those rights. Submit requests, directly or through an authorized agent, to support@medpathx.com; we will verify requests using account and contact information.
11.3 Other States.
Residents of states with comprehensive consumer privacy laws (including Virginia, Colorado, Connecticut, Texas, Oregon, and others) may have rights to confirm processing, access, correct, delete, and obtain a copy of their personal data, to opt out of certain processing, and to appeal a refusal to act on a request. Exercise these rights at support@medpathx.com.
11.4 Consumer Health Data.
Information governed by HIPAA is exempt from state consumer health data laws such as the Washington My Health My Data Act and the Nevada consumer health data law. To the extent we process any non-exempt consumer health data of residents of applicable states, we process it only as described in this Policy and with any legally required consent, and those residents may exercise applicable rights at support@medpathx.com.
12. Children
The Platform is a professional service that is not directed to individuals under eighteen (18), and we do not knowingly collect personal information from anyone under eighteen (18). This Section addresses users of the Platform; it does not limit the processing of patient information, including pediatric patient information, that health care organizations and the participants they select handle through the Platform, which is governed by Section 3 (Protected Health Information) and the applicable BAA.
13. International Users
MedPathX is based in the United States, and the Platform is intended for use in the United States. Information we collect is processed and stored in the United States.
14. Changes to This Policy
We may update this Policy from time to time. We will post the updated Policy with a new effective date and, for material changes, provide notice through the Platform or by email. We encourage you to review this Policy periodically.
15. Contact
Questions or requests about this Policy or our privacy practices may be directed to: MedPathX, Inc., Attn: Privacy, 210 Delburg Street, Davidson, NC 28036, or support@medpathx.com.