Data Security and Privacy Policy
Introduction
IMPOWR by Continual Care Solutions (IMPOWR) recognizes that privacy is important to you, your patients, and your caregivers. We want you to be familiar with how we collect, use and disclose data. This Data Security and Privacy Policy describes our privacy practices.
-
Data Protection: IMPOWR implements appropriate technical and organizational measures to protect Customer Data, including data encryption both in transit and at rest, isolated storage accounts and isolated databases.
-
Compliance: IMPOWR complies with applicable laws and regulatory frameworks. We provide HIPAA compliant tools and sign Business Associate Agreements (BAAs). We can function as a GDPR processor.
-
Breach Notification: Parties in breach will notify the HIPAA business associate as required by covered statute upon discovering data breach affecting Customer data in the most expedient time possible, no later than 45 days after discovery.
Information We Collect
The IMPOWR platform collects information you provide directly, and information we derive from the use of the platform, including the following types of information, dependent on the Customer’s usage:
-
Personal Information: Name, email address, phone number, and other contact details.
-
Health Information: Medical history, treatment plans, and other health-related data.
-
Usage Data: Information on the use of the platform, including device, IP addresses, browser types, and access times.
Lawful Basis for Processing Personal Data
-
In processing your Personal Data in connection with the purposes described in this Privacy Policy, we rely on the legal basis of Legitimate Interest.
-
We collect Personal Data that is necessary for managing and promoting our business, maintaining a product supplier to customer business relationship which includes but is not limited to; product information and marketing communication, maintaining data and network security, improving website and product performance and customer experience, and preventing fraud and malicious acts.
How Information May be Used
-
We use the information we collect from our services to provide, maintain, protect and improve them, to develop new ones, and to protect the Company and our users.
Information may be used for the following purposes: -
Service Delivery: To provide and improve services.
-
Communication: To communicate about care and our services, including support.
-
Compliance: To comply with legal and regulatory requirements.
Data Security
-
We implement a variety of security measures to protect personal data, including:
-
Encryption: All data is encrypted both in transit and at rest.
-
Access Controls: Only authorized personnel have access to your data.
-
Regular Audits: We conduct regular security audits to identify and address potential vulnerabilities.
Data Sharing
-
We do not sell or rent personal data. We require opt-in consent for the sharing of any sensitive personal information. Our team and Customers who use the IMPOWR platform, with appropriate consent and data sharing agreements, may share information with:
-
Organization Administrators: Your organization administrator and those that provide user support to your organization may have access to your Account information.
-
Providers: To coordinate care.
-
Legal Authorities: When required by law.
-
Service Providers: Who assist us in delivering our services, under strict confidentiality agreements.
-
If the Company is involved in a merger, acquisition or asset sale, we will continue to ensure the confidentiality of any personal information and give notice before personal information is transferred or becomes subject to a different privacy policy.
Your Rights
-
You have the following rights regarding personal data:
-
Access: Request access to your data.
-
Correction: Corrections to your data.
-
Deletion: Deletion of your data.
-
Objection: Object to the processing of your data.
Changes to This Policy
We may update this policy from time to time. We will notify you of any significant changes by posting the new policy on our website and updating the effective date.
Contact Us
If you have any questions or concerns about this policy, please contact us at:
Continual Care Solutions:
-
Physical address: 140 Office Park Way, Pittsford, NY 14534
-
Mailing address: P.O. Box 27, Pittsford, NY,
-
Phone: 585-485-0011
References
-
IMPOWR website: Security | IMPOWR
-
System > Regulatory Compliance in IMPOWR platform, including Operational Security, Technology Infrastructure Security, Data Security, Privacy & Compliance, Compliance Resources & Support, Security Alerts