The short version
The detail is below and none of it contradicts this. If you read only one part, read this one.
- Hold your record so you and the clinicians you choose can see it
- Log every access, and show you the log
- Encrypt everything, in transit and at rest
- Sign a BAA with every practice before any data moves
- Sell your information. To anyone. Ever
- Give it to advertisers, or use it for advertising
- Train models on it without separate written consent
- Share it with anyone you have not authorised, except your practice
Who this covers
Hylexa serves two kinds of person and the law treats them differently, so this policy says which is which throughout.
Patients and guardians. The record is about you. Your practice is the covered entity; Hylexa is its business associate, which means we handle your information on their instruction and under a signed agreement.
Practice staff and clinicians. We hold your work identity and what you did in the system. Your employer issues and removes your account.
What we collect
CategoryExamplesWhySource
CategoryIdentityExamplesName, date of birth, address, phone, email, licence detailsWhyTo know whose record this isSourceScanned at the desk, or entered by you
CategoryHealthExamplesHistory, medications, allergies, immunisations, vitals, screening responses, documentsWhyIt is the recordSourceYou, your practice, or your clinician
CategoryCoverageExamplesPayer, member and group ID, plan, benefits, eligibility responsesWhyTo verify cover before your visit rather than afterSourceYour card, and the clearinghouse
CategoryGuardian relationshipsExamplesWho may act for whom, and the basis of that authorityWhyBecause “who is allowed to consent for this child” must be recorded, not assumedSourceCaptured at registration
CategoryDocumentsExamplesCard images, uploads, signed consents and their certificatesWhyThe record, and proof of consentSourceYou, or your practice
CategoryMessagesExamplesWhat you send your care team through the appWhyTo let you ask without a phone queueSourceYou
CategoryAccess logsExamplesWho opened your record, when, and from whereWhySo the audit is real and so you can read itSourceGenerated automatically
CategoryTechnicalExamplesDevice type, app version, crash reports, interaction countsWhyTo keep the app workingSourceAutomatic
CategoryNot collectedExamplesLocation, contacts, browsing history, biometric templates, advertising identifiersWhyNothing in the product needs themSourceFace ID and Touch ID are verified by your device; we never receive the biometric itself
How we use it, and how we do not
We use your information to run the service: showing your record, moving it where you have authorised, verifying coverage, sending prescriptions, generating the work that follows, and keeping the whole thing secure and available.
- We do not sell personal information. Not under any definition, including the broad ones in state privacy law that count some disclosures as sales.
- We do not use it for advertising, and we do not disclose it to advertising networks. There is no advertising identifier in the app.
- We do not train artificial intelligence on your information without separate, specific, withdrawable written consent.
- Analytics carry no identifier. We count what happens; we do not attach who it happened to.
If any of these ever changesIt changes with notice and a choice, not in a policy update nobody was told about.
Who else sees it
RecipientWhat they getBasis
RecipientYour practiceWhat they getYour recordBasisThey are treating you. This is the service, not a disclosure
RecipientClinicians you inviteWhat they getOnly the categories you granted, only while the grant lastsBasisYour instruction, revocable at any moment
RecipientSubprocessorsWhat they getOnly what their function requiresBasisUnder contract, with equivalent obligations flowed down. Each is listed publicly
RecipientPayersWhat they getEligibility and authorisation requestsBasisTo confirm your cover, at your practice’s instruction
RecipientPharmaciesWhat they getPrescriptions your prescriber sendsBasisTo dispense them
RecipientLaw enforcementWhat they getOnly what a valid legal order compelsBasisWe require valid process, narrow the scope where we can, and tell you unless prohibited
RecipientAdvertisers, data brokers, manufacturersWhat they getNothingBasisNo basis exists and none is sought
Current subprocessors: cloud hosting and storage, identity and calendar, electronic signature, the eligibility clearinghouse, the prescribing network, and the drug knowledge base. The named, versioned list lives at trust.hylexa.net with notice before any addition.
Your rights
RightHow
RightSee your recordHowIt is the app. That is the whole product
RightCorrect itHowEdit what you supplied. For clinical values, ask your practice, who can amend the record
RightKnow who lookedHowThe access log, in plain language, in the app
RightWithdraw accessHowImmediately, from the app, no reason required
RightTake a copyHowExport in a standard format
RightDelete your accountHowIn the app. Removes the account, the credentials, and everything we are not legally required to keep
RightOpt out of sale or targeted advertisingHowNothing to opt out of. We do neither
RightComplainHowTo us, to your practice, to your state attorney general, or to the HHS Office for Civil Rights
The honest limit on deletionYour practice must keep treatment records for a period set by state law, typically several years, longer for a child. Deleting your Hylexa account does not and cannot delete their copy, and we would rather tell you that than let the word “delete” imply more than it does.
Children and guardians
A guardian may hold a child’s record and act for them. Two things follow that most policies leave out.
Access changes as a child grows. Many states let an adolescent consent independently to certain care, and where the law protects that confidentiality, those categories are withheld from the guardian’s view rather than shown. This is configured per state.
Guardian authority is recorded, not assumed. It is captured at registration and carried into any consent signed on the child’s behalf.
Minors’ data is a heightened-risk category, and California in particular applies elevated consent requirements and increased penalties for consumers under sixteen. Hylexa is not directed at children as a consumer product; the account holder is an adult.
How long we keep it
DataRetention
DataClinical recordRetentionWhile the account is active, then as the practice’s legal obligation and the BAA require
DataAccess and audit logsRetentionAt least six years, immutable. This is a HIPAA obligation and it is why they cannot be deleted on request
DataSigned consentsRetentionWith the record, plus their completion certificates
DataStaff account recordsRetentionWhile employed, plus the audit period
DataTechnical and crash dataRetentionThirteen months
DataBackupsRetentionRolling window, then overwritten. Deletion propagates within that window rather than instantly
Security
Encrypted in transit and at rest. Role-based access enforced on our servers rather than hidden in the interface. Single sign-on for staff through their organisation’s identity provider; biometrics for patients, verified by the device. Every record access logged immutably. Subprocessors bound by equivalent obligations.
What we will not claimNo system is impenetrable, and a policy that implies otherwise is both untrue and unhelpful. We say “designed for HIPAA compliance”, not “HIPAA compliant”, until an assessment has been completed and signed off. If a breach affects you, you and your practice are notified within the timeline the law requires, with what happened and what to do.