True Pill

Privacy Notice

The privacy of your personal and health information is of utmost importance to us.

Truepill understands the importance of keeping your personal and health information secure and private. Personal health information includes both medical information and personally identifiable information such as your name, address, telephone number, or social security number.

We are required by the applicable federal and state laws to maintain the privacy of your personal and health information. Under both the applicable laws and our company policy, Truepill has a responsibility to protect the privacy of your personal and health information (PHI).

  • •   We protect your privacy by limiting access to who may see your PHI
  • •   We inform you of our legal duties with respect to your PHI
  • •   We limit how we may use or disclose your PHI
  • •   We explain our privacy policies
  • •   We strictly adhere to the policies currently in effect

This is a notice of Truepill’s privacy practices, our legal duties, and your rights concerning your personal and health information. We follow the privacy practices that are described in this notice while it is in effect. This notice takes effect April 2nd, 2018 and will remain in effect until we replace it and provide you notice of such changes.

We reserve the right to make the modifications in our privacy practices and the new terms of our notice effective for all personal and health information that we maintain, including information we created or received before we made the changes. We reserve the right to change our privacy practices and the terms of this notice at any time, as allowed by applicable law, rules, and regulations. For more information about our privacy practices, or for additional copies of this notice, please contact us at the number listed below.

Uses and Disclosures of Your Personal and Health Information

As a customer of Truepill, we may use and disclose your personal and health information, without your consent/authorization, in the following ways:

Treatment - We may use and disclose your personal and health information to dispense prescription medications to you.

Payment - We may use and disclose your personal and health information for payment related functions. For example, we may contact your health insurer, pharmacy benefit manager, or other health care payer for payment and or co-payment determination. For billing purposes, the information on or accompanying the bill may include information that identifies you, as well as the prescriptions you are taking.

Health Care Operations - We may use and disclose your personal and health information for operational administrative and quality assurance activities. For example:

  • •   monitor the performance of the pharmacists providing treatment to you
  • •   assess the use or effectiveness of certain drugs

We are allowed to use and share your protected health information for the following reasons:

Wellness and Health Information - We may use and disclose your personal and health information to contact you with information about prescription refill reminders, or prescription medication alternatives that may be of interest to you.

Family and Friends - We may disclose your personal and health information to a family member, friend, or other person you identify to the extent necessary to help with the dispensing of your prescription medication or with payment for your medication expenses.

Serious Threat to Health or Safety - We may disclose your personal and health information to the extent necessary to avoid a serious and imminent threat to your health or safety or the health or safety of others.

Domestic Violence, Abuse, Neglect - We may disclose your personal and health information to appropriate authorities if we reasonably believe that you are a possible victim of abuse, neglect, domestic violence or other crimes.

Public Health - We may disclose your personal health information to public health or legal authorities charged with preventing or controlling diseases, injury, or disability.

Food and Drug Administration (FDA) - We may use and disclose to the Food and Drug Administration (FDA), or person under the jurisdiction of the FDA, protected health information relative to adverse events with respect to drugs, foods, supplements, products, and product defects, or post marketing surveillance information to enable product recalls, repairs, or replacement.

Where Required by Law - We must use or disclose your personal and health information when we are required to do so by Federal, State, or Local law.

Law Enforcement - We must disclose limited information to law enforcement officials concerning the personal and health information of a suspect, fugitive, material witness, crime victim, or missing person.

Judicial Proceedings - We may disclose your personal and health information in response to a court or administrative order, subpoena, discovery request, or other lawful process.

Correctional Institution - We may disclose the personal and health information of an inmate or other person in lawful custody to law enforcement official or correctional institution.

Health Oversight Activities - We may disclose your protected health information to an oversight agency for activities authorized by law. Examples of oversight activities include audits, investigations, inspections, and credentialing as subject to government programs and compliance with civil rights laws.

Workers’ Compensation - We may disclose your personal and health information to comply with Worker’s Compensation laws and other similar programs established by law.

Business Associates - We may disclose your personal and health information to contracted Business Associates if they need to receive this information to provide a service to us and will agree to abide by specific HIPAA rules relating to the protection of health information.

Military and Veterans - We may disclose to military authorities the personal and health information of armed forces personnel under certain circumstances.

National Security - We may disclose to authorized federal officials personal and health information required for lawful intelligence, counterintelligence, and other national security activities.

Other Uses and Disclosures

We will request written authorization from you to use your personal and health information or to disclose it to anyone for any purpose or situation not included in this document. You may revoke this authorization in writing at any time. Your revocation will not affect any use or disclosures permitted by your authorization while it was in effect.

Individual Rights

Access - You have the right to access and copy personal and health information about you contained in a designated record set for as long as the pharmacy maintains the personal and health information. The designated record set usually will include prescription and billing records. You may request that we provide copies in a format other than photocopies. You may submit this request in writing by obtaining a form from Truepill using the contact information listed at the end of this notice. If you request copies, we may charge you a fee for each page, and per hour for staff time to locate and copy your personal and health information, and postage.

Accounting of Disclosure - You have the right to receive a list of instances in which we or our subcontractors disclosed your personal and health information after April 2nd, 2018 for purposes other than payment, health care operations, and certain other activities. You may submit this request in writing by obtaining a form from Truepill using the contact information listed at the end of this notice. If you request this list more than once in a 12-month period, we may charge you a reasonable, cost based fee for responding to these additional requests.

Restriction Requests - You have the right to request that we place additional restrictions on our use or disclosure of your personal and health information. We are not required to agree to these additional restrictions, but if we do, we will abide by our agreement (except in a need for your emergency treatment). You also have the right to agree to or terminate a previous submitted restriction. You may submit this request in writing by obtaining a form from Truepill using the contact information listed at the end of this notice.

Alternate Communication - You have the right to request that we communicate with you in confidence about your personal and health information by alternative means or to an alternative location to avoid a life threatening situation. You must make your request in writing, and you must state that the information could endanger you if it is not communicated in confidence. We will accommodate all reasonable requests. Requests may be submitted in writing by obtaining a form from Truepill using the contact information listed at the end of this notice.

Amendment - You have the right to request that we amend your personal and health information. Your request must be in writing, and it must explain why the information should be amended. In certain cases, we may deny your request.

Right to Notice - You have the right to receive this notice in written form upon request at any time. Please contact us using the information listed at the end of this notice to obtain this notice in written form.

Right to File a Complaint - If you are concerned that we may have violated your privacy rights or you disagree with a decision we made about access to your personal and health information, you may file a complaint with us using the contact information listed at the end of this notice.

You also may submit a written complaint to the U.S. Department of Health and Human Services. We will provide you with the address to file your complaint with the U.S. Department of Health and Human Services upon request.

We support your right to protect the privacy of your personal and health information. We will not retaliate in any way if you choose to file a complaint with us or with the U.S. Department of Health and Human Services.

Privacy Rights

If you would like to request a privacy rights form or file a complaint regarding your privacy rights, you may telephone us at (650) 353-5495 at any time. You will be asked to provide information including your full name, date of birth, home address, mailing address, and other information deemed necessary to authenticate your identity. This information is necessary to process your request.

If you want more information regarding our privacy practices, have questions or concerns regarding your privacy rights, or would like to request a member’s rights form, you may contact us in the following ways:

Mail us at: Truepill Chief Privacy Officer, 3121 Diablo Ave, Hayward, CA 94545. For general questions, you can telephone us at 1-866-861-2762 during normal business hours.

Other Uses and Disclosures

We will request written authorization from you to use your personal and health information or to disclose it to anyone for any purpose or situation not included in this document. You may revoke this authorization in writing at any time. Your revocation will not affect any use or disclosures permitted by your authorization while it was in effect.

Use and Collection of Personal Information

Users of this website have the option to provide certain personal information. This personal information may be required in order to receive specific services. By providing such information, you are agreeing that Truepill may store, process, and review such information. And we may use this personal information for the purpose for which it was collected.

We collect certain personally identifiable information from our users at different places within this website. Our definition of personally identifiable information includes any information that may be used to specifically identify or contact you, such as your name, mail address, telephone number, cellular phone number, text message number, fax number, e-mail address, etc. Certain information may not be personally identifiable when standing alone (e.g., your age), but may become so when combined with other information (e.g., your address and age).

Individuals (patients), medical providers and pharmacists have the ability to register for access to the secured area of this website. To access the secured area, you may need to provide additional information such as name, address, health plan id, and tax identification number. The purpose of the registration process is to verify and validate who is requesting access to the secured area of the website. Registration also enables us to tailor the information you receive.

We may use the voluntarily provided contact information to notify website users of updates to existing products and services, new products and services, or upcoming events. Website users who do not wish to receive such notifications via e-mail can choose to opt-out of receiving such information. Website users who do not wish to receive such notifications via e-mail or SMS (text) can choose to opt-out of receiving such information. It is our policy that e-mail and SMS (text) messages will contain an "unsubscribe" and "STOP" function, along with instructions on how to execute the opt-out function.

Some website users may have the ability to opt-out of receiving e-mail and SMS (text) messages by updating their communications preferences within the secured area of the website.

After completing the log in process, website users have the option to change their password, e-mail address and security question and response. If the website user forgets or misplaces their password, Truepill will use the security question and response to identify the website user and grant access to the website. To change personally identifiable information, registered patients must contact us at the number located below.

We understand that when website users choose to provide personal information, they trust that we will protect their privacy and will provide them with choices about how that information is to be shared. Truepill will not sell, trade, rent or disclose the personal information that you provide unless you authorize us to do so or required to do so by law.

There are instances in which Truepill may disclose website user’s personal information to our agents, third-party partners, affiliates, and subsidiaries to enable them to perform business functions on our behalf. These companies are only permitted to share, store and/or use personal information for contracted business purposes.

We may share your personal information when we believe that such action is necessary to: 1) fulfill an enforceable government request; 2) conform with the requirements of the law or legal process; 3) protect or defend our legal rights or property, this website, or other users; or 4) protect your health and safety or the health and safety of this website’s users or the general public.

Use of Technology On This Website

Information about you and your use of this website is collected through the use of session and persistent cookies. Session cookies are small text files that are stored within your computer’s memory. These files are used to facilitate your navigation throughout this website.

Persistent cookies are small computer files that are transferred to your computer’s hard drive. Persistent cookies are used to grant you access to both public and private areas and are used for session tracking. Information stored within both session and persistent cookies are not tied to your Personally Identifiable Information.

If you are concerned about the storage and use of cookies, you may be able to direct your Internet browser to notify you and seek approval whenever a cookie is being sent to your hard drive. You may also delete a cookie manually from your hard drive through your Internet browser or other programs. You can also set your browser to refuse all cookies. Please note that some parts of this website may not function properly or be available to you if you refuse to accept a cookie or choose to disable the acceptance of cookies.

To gauge the effectiveness of this website, we may collect non-personal information about our website users. This information may include, among other things, your: IP address, browser type, internet service provider (ISP), domain names, referring/exit pages, operating system, date/time stamp, and clickstream data. We use this information, which does not identify individual users, to analyze trends, to administer the website, to track users’ movements around the site and to gather demographic information about our user base as a whole. We do not link this automatically collected data to personal information.

Internal security procedures

Information that you share on the website is kept strictly confidential and fully secure. Your encrypted (encoded) information is protected using "Secure Socket Layers (SSL)" as it passes between your browser and this website. We follow generally accepted industry standards to protect the personal information submitted to us, both during transmission and once we receive it.

No method of transmission over the Internet, or method of electronic storage, is 100% secure. Therefore, while we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security. Only authorized persons are permitted to access your personal information. All authorized persons must abide by security, privacy, and confidentiality agreements.

E-mail

If you send questions or comments to an e-mail address listed within this website or via a contact form located within this website, we will share your correspondence with an associate most capable of addressing your questions and concerns. We will retain your communications until we have done our very best to provide you with a complete and satisfactory response. Ultimately, we will either discard your communication or, in some cases, archive it. All information and correspondence you share with us will be handled in the strictest confidence.

For communications concerning confidential information, please contact Truepill at the number located below. Please do not email us confidential HIPAA-protected information.

This website is not intended for use by children under the age of 18.

Privacy Notice

This Privacy Notice is effective as of April 2nd, 2018 and is not intended to and does not create any contractual or other legal rights with or on behalf of any party.