Consumer Health Data Privacy Policy
Most of what OwnIt Health holds about you is protected health information under HIPAA, and our Notice of Privacy Practices governs it. Some states — including Washington, Nevada, and Connecticut — regulate "consumer health data" more broadly than HIPAA does, covering health-related information collected outside a treatment relationship. This policy covers that narrower category.
What consumer health data we collect
Very little, deliberately.
- Before you become a patient: if you start signing up, we collect your name, date of birth, email address and phone number. The fact that you approached a healthcare provider is itself health-related information, and we treat it that way.
- Technical data: your IP address at sign-up, used only to assess whether a sign-up is fraudulent, and only through a vendor bound by a business associate agreement.
- What we do not collect: we do not use advertising trackers, analytics that profile you, or third-party marketing pixels anywhere on this website or in the app. There is no advertising identifier to link you to.
How we use it
To let you sign up, to reach you about your care, and to prevent fraudulent accounts. Nothing else.
We do not sell it
OwnIt Health does not sell consumer health data, and does not share it for anyone's advertising. We have never done so and have no arrangement that would allow it.
Who else sees it
Only companies that help us run the practice, each under a written agreement requiring them to protect it and forbidding them from using it for their own purposes:
- Our hosting provider, which runs the servers your record sits on
- Our email and text message providers, which carry appointment reminders — those messages deliberately contain no clinical detail
- Our payment processor, which receives an amount and an account reference, never anything clinical
- Our fax and clearinghouse providers, when a record must be sent to another provider or a claim filed
We may also disclose information where the law requires it, such as a court order or a public health reporting obligation.
Your rights
Wherever you live, we will honor these:
- Know what consumer health data we hold about you and who we have shared it with
- Get a copy of it
- Correct it if it is wrong
- Withdraw consent to our collecting or sharing it
- Delete it — with one limit, stated plainly: once you have had a visit, your chart is a medical record we are legally required to retain. See our Account Deletion Policy.
To exercise any of these, write to admin@ehr.ownithealthcare.com or call 302-615-6105. We respond within 45 days and will not charge you or treat you differently for asking.
How long we keep it
If you never become a patient, we delete sign-up data we are not required to keep. Once you are a patient, retention follows the medical record rules in our Notice of Privacy Practices.
Security
Your information is encrypted in transit and at rest, access is limited to people who need it for your care, and every look at a record is logged. Backups are encrypted before they leave our servers.
Changes and contact
We will post any change here with a new effective date, and tell you directly if it materially affects you. Questions to our Privacy Officer: admin@ehr.ownithealthcare.com.