VitaTrax, LLC (“VitaTrax,” “we,” “us,” or “our”) provides a software platform that healthcare practices use to deliver Remote Therapeutic Monitoring and related care management programs to their patients.
This Privacy Policy explains what information we collect, how we use it, who we share it with, and what choices you have. It applies to our websites, our patient mobile application, and our provider-facing platform.
1. Start Here: Which Rules Apply to Your Information
The rules that apply depend on why we have your information. There are three categories, and they are treated differently.
Category 1: Health information we handle for your healthcare provider
If you are a patient using the VitaTrax app, nearly all of your health information is Protected Health Information (“PHI”) that we process on behalf of your healthcare provider’s practice (your “Practice”).
For this information:
- Your Practice controls it. Your Practice is the HIPAA “covered entity.” Its Notice of Privacy Practices, not this Privacy Policy, governs how your health information may be used and disclosed.
- We act as a “business associate” under a signed Business Associate Agreement that limits us to using PHI only as needed to provide services to your Practice, or as required by law.
- To exercise your HIPAA rights, contact your Practice. This includes requests to access, obtain a copy of, amend, or restrict your health information, or to receive an accounting of disclosures. We assist your Practice in responding to those requests.
Category 2: Information we control directly
This includes account registration details, website visitor information, support communications, and business contact information for practice staff. This Privacy Policy governs that information.
Category 3: De-identified information
Information that has been stripped of identifiers in accordance with HIPAA’s de-identification standard. See Section 7.
2. Information We Collect
2.1 From patients using the app
| Category | Examples |
|---|---|
| Account information | Name, date of birth, email address, mobile number, login credentials, and the Practice you are enrolled with |
| Patient-reported health data | Pain scores and locations, symptom reports, functional status and activities of daily living, therapy and exercise adherence, medication adherence, journal and free-text entries, and responses to check-in prompts |
| Program and engagement data | Enrollment and disenrollment dates, dates and timestamps of data submissions, transmission days, check-in streaks, notification and reminder history |
| Communications | Messages exchanged with your care team through the app, and support requests you send to us |
| Optional connected health data | If, and only if, you turn it on, data from Apple Health on iOS or Android Health Connect on Android, such as step counts, activity, stand time, and sleep. You choose whether to connect this and can disconnect at any time in your device or app settings. |
| Technical and device data | Device type and operating system, app version, IP address, crash logs, and diagnostic information |
2.2 From practice personnel
Name, professional role and credentials, work email address and telephone number, employer, login credentials, and audit records of activity in the platform, including access events and time recorded on monitoring activities.
2.3 From website visitors
Pages viewed, referring source, approximate location derived from IP address, and information you submit through contact, demonstration request, or resource download forms. See Section 5 for the tools we use.
2.4 What we do not collect
We do not collect your search queries on other services, your browsing history outside our own properties, your precise GPS location, your contacts, your photos, or microphone or camera data, except where a specific app feature requires it and you have granted permission for that feature.
3. How We Use Information
Health information (PHI) is used only to:
- Deliver the monitoring program your Practice has enrolled you in
- Make your data available to your Practice and your care team
- Generate the documentation and Evidence of Care reports your Practice needs for its records and its billing
- Provide technical support, troubleshooting, and security monitoring
- Operate, maintain, and secure the platform
- Comply with law and respond to lawful requests
- Perform other functions permitted by our Business Associate Agreement with your Practice
Account, website, and business contact information is used to create and administer accounts, provide support, send service notifications, secure our systems, understand and improve how the platform is used, communicate about our products to practice contacts, and meet legal obligations.
3.1 Artificial intelligence features
The platform includes features that use artificial intelligence to help you describe what you are experiencing, to organize what you record, and to surface relevant information to your care team. We may add, change, or remove these features over time.
AI-assisted features do not practice medicine. They do not diagnose conditions, recommend or change treatment, interpret results clinically, triage you, or make any decision about your care. They do not monitor you and cannot detect or respond to an emergency. Information recorded through them is reviewed by qualified staff in the same way as information entered directly.
We do not use identifiable patient health information to train or fine-tune general-purpose artificial intelligence models. Where AI features process patient information to deliver the service, that processing is performed by vendors bound by written agreements, including Business Associate Agreements where required, that prohibit them from using the information for their own purposes, including model training.
You are never required to use a conversational feature to receive care. If you prefer not to, tell your Practice.
3.2 What we never do
- We do not sell personal information or health information. We have not sold personal information in the preceding twelve months.
- We do not share personal information for cross-context behavioral advertising.
- We do not serve advertising in the patient app, and we do not use health information to target advertising.
- We do not use patient content in marketing, promotional materials, or public demonstrations.
- We do not share information with data brokers.
6. Where Information Is Stored and How It Is Protected
We maintain administrative, physical, and technical safeguards designed to protect information against unauthorized access, use, alteration, and destruction, consistent with the HIPAA Security Rule. These include:
- Encryption of data in transit and at rest
- Role-based access controls and unique user credentials
- Audit logging of access to patient information
- Workforce training on privacy and security, and background screening of personnel with access to patient information where applicable
- Vendor security review, and written data protection and business associate agreements with vendors that handle PHI
- Documented incident response and breach notification procedures
Data location. Patient information is stored and processed in the United States.
Clinical personnel location. Clinical staff performing monitoring services under a Practice’s program are required to be located within the United States or its territories.
No system is perfectly secure. If we discover a breach of unsecured PHI, we notify the affected Practice without unreasonable delay and within the timeframe set out in the applicable Business Associate Agreement, and the Practice provides notice to affected individuals as required by law.
7. De-Identified Information
We may create de-identified information from data in the platform in accordance with the de-identification standard at 45 C.F.R. § 164.514.
De-identified information does not identify you and cannot reasonably be used to identify you. We use it to improve our products, understand how programs perform, and conduct research and analytics. We do not attempt to re-identify it, and we require anyone we share it with to agree not to attempt re-identification.
8. How Long We Keep Information
Health information is retained for as long as we provide services to your Practice, and afterward as set out in the Business Associate Agreement, which requires us to return or destroy PHI when it is no longer needed, retaining only what is necessary for our proper management and administration or to carry out legal responsibilities. Your Practice’s own record retention obligations apply independently to the copy in your medical record.
Account information is retained for the duration of the account and for a reasonable period afterward to handle support, audit, and legal matters.
Website and analytics information is retained for no longer than needed for the purposes in Section 5.
Business contact information is retained for as long as the relationship continues and afterward as needed for legal, tax, and audit requirements.
Specific retention periods by data category are available on request at info@vitatrax.co.
9. Your Choices and Rights
9.1 If you are a patient
- Health information rights. Contact your Practice to access, obtain a copy of, amend, or restrict your health information, or to request an accounting of disclosures. Your Practice’s Notice of Privacy Practices explains these rights.
- Withdraw from the program. Participation is voluntary. You may withdraw at any time by notifying your Practice, without affecting the care you receive. Deleting the app does not by itself end your enrollment.
- Connected health apps. Turn any optional health data connection on or off in your device or app settings.
- Notifications. Adjust reminder and notification preferences in the app, or opt out of non-essential messages. Discuss changes to care-related communications with your Practice first, since they may affect your program.
- Close your account. Contact your Practice, or write to us at info@vitatrax.co.
9.2 State privacy rights
Depending on where you live, you may have rights regarding personal information we control, including the rights to know what we collect, to request access or deletion, to request correction, to opt out of sale or targeted advertising, and to be free from discrimination for exercising those rights.
Note that information we hold as a business associate for a Practice is subject to HIPAA, and most state privacy laws exempt it. For that information, HIPAA rights apply and are exercised through your Practice.
To make a request about information we control, write to info@vitatrax.co with “Privacy Request” in the subject line. We will verify your identity before responding. You may use an authorized agent where state law allows.
Appeals. If we deny your request, you may appeal by writing to info@vitatrax.co with “Privacy Appeal” in the subject line. If your appeal is denied, you may contact your state Attorney General. You may also file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights.
9.3 California
The following describes the personal information we have collected in the preceding twelve months for individuals whose information we control. Information we hold as a business associate for a Practice is exempt from the California Consumer Privacy Act and is not included.
| Category | Collected | Source | Purpose | Disclosed to |
|---|---|---|---|---|
| Identifiers (name, email, phone, IP address, account identifier) | Yes | You, your Practice, your browser | Account administration, support, security, communications | Service providers |
| Professional or employment information | Yes | Practice personnel, practices | Account administration, platform access, business communications | Service providers |
| Internet or network activity | Yes | Your browser and device | Site and product operation, diagnostics, product improvement | Service providers |
| Geolocation (approximate, from IP address) | Yes | Your browser | Security and general analytics | Service providers |
| Commercial information (services purchased or considered) | Yes | Practices | Contract administration, billing | Service providers |
| Sensitive personal information | Account login credentials only | You | Authentication | Service providers |
We do not sell or share personal information as those terms are defined under California law, and we do not use sensitive personal information for any purpose other than those permitted without a right to limit. California residents may exercise the rights in Section 9.2.
9.4 Consumer health data
Some states, including Washington and Nevada, provide specific rights regarding consumer health data. Nearly all health information we hold is PHI processed on behalf of a Practice under HIPAA, which those laws exempt, and rights in that information are exercised through your Practice as described in Section 1.
For any consumer health data we control that is not PHI, we collect and use it only to provide the services described in this policy, we do not sell it, we do not use it for advertising, and we share it only with the service providers described in Section 4. You may request access to or deletion of that information, and withdraw any consent you have given, by writing to info@vitatrax.co. We will not condition the provision of services on your consent to collect consumer health data beyond what is necessary to deliver them.
10. Children
The platform is not directed to and may not be used by children under 13. A patient between 13 and 17 may be enrolled only by a Practice with the consent of a parent or legal guardian, in accordance with applicable law. We do not knowingly collect information from a child under 13 outside of a Practice-directed enrollment. If you believe we have, contact info@vitatrax.co and we will investigate and delete as appropriate.
11. Third-Party Services
The platform may link to or integrate with services operated by others, including your device’s health platform, your Practice’s electronic health record system, and scheduling tools on our website. Those services are governed by their own privacy policies. We are not responsible for their practices, and we encourage you to review them.
12. Where We Operate
Our services are intended for use in the United States. We do not offer them to individuals located outside the United States, and information is stored and processed in the United States.
13. Changes to This Policy
We may update this policy. We will revise the “Last Updated” date and, for material changes, provide notice through the app, by email, or by another reasonable method before the change takes effect. Changes to how we handle PHI remain subject to HIPAA and to our Business Associate Agreements with Practices.
14. Contact Us
For questions about your care, your enrollment, your bill, or your medical record, contact your healthcare provider’s office.
In an emergency, call 911.