Privacy Policy & HIPAA Notice
1. Introduction & Scope
Carepak ("we," "our," or "us") operates the Carepak clinical workspace platform, helping laboratories, clinics, and medical practitioners coordinate patient scheduling, design clinical templates, deliver report notices, and process billing invoices.
This Privacy Policy describes how we handle, store, and safeguard data in connection with our services. By accessing or using the Carepak platform, you agree to the collection, transmission, and retention of data as detailed in this policy.
2. Our Role: Business Associate (HIPAA)
When Carepak acts as an operational platform handling patient information for healthcare organizations (our Customers), we do so as a "Business Associate" under the Health Insurance Portability and Accountability Act (HIPAA).
The healthcare provider or laboratory utilizing Carepak acts as the "Covered Entity" and retains primary responsibility for patient privacy consents. Carepak only processes Protected Health Information (PHI) to provide services on behalf of, and as instructed by, our Customers, in compliance with Business Associate Agreements (BAAs) executed with each customer organization.
3. What Information We Collect
Carepak collects and processes information necessary to coordinate modern medical logistics. This data includes:
- Clinician & Staff Profile Information: Professional credentials, organization details, emails, system action audit logs, and account access logs.
- Patient Demographic Information: Names, birthdates, biological sex, contact details (phone numbers, email addresses), and system patient identifiers.
- Clinical Diagnostic Data: Specimen barcode tracking identifiers, test request types, measured analyzer outputs, signed PDF medical reports, and referral physician names.
- Billing & Ledger Details: Invoice summaries, split-billing configurations, referral doctor bank accounts (for payout distribution), and transaction payment statuses.
4. How We Use Clinical Data
Carepak restricts all processing of clinical data to specific operational services, including:
- Workflow Automation: Scheduling slots, checking in patients, and directing analyzer data into clinical report designer workspaces.
- Patient Messaging: Delivering secure PIN-protected PDF report download links to patient phone numbers via WhatsApp or SMS.
- Billing Settlements: Calculating split payouts, generating invoices, and distributing commissions to medical partners.
- Regulatory Auditing: Recording immutable staff access history logs required to verify patient record confidentiality checks.
6. Security & PHI Retention
We implement robust administrative, physical, and technical safeguards. All patient files, demographics, and transaction records are encrypted at rest using AES-256 standards and in transit using TLS 1.3 encryption.
Data Retention: We store patient diagnostic information as instructed by the Covered Entity (our Customer). Because medical diagnostic records are subject to strict national legal retention guidelines, clinical logs are typically retained on Carepak databases for a minimum of 7 years or as required by applicable health provider record-keeping regulations.
7. Patient & User Rights
Under HIPAA (Right of Access) and applicable global regulations (such as GDPR), patients have the right to request copies of their medical diagnostic results.
If you are a patient seeking to access, correct, delete, or limit the processing of diagnostic information stored on Carepak, you must submit your request directly to the medical facility or clinical laboratory that performed your test (the Covered Entity). As a Business Associate, Carepak will coordinate with and assist our Customer to satisfy individual patient records requests.
8. Use by Minors
Carepak is an operational software platform designed for clinical institutions, medical practitioners, and adult users. It is not intended for use by individuals under eighteen (18) years of age without explicit guardian oversight.
If we discover that a minor under the age of 13 has submitted personal identifiers to us directly (outside of clinical data loaded by an authorized Covered Entity), we will take immediate measures to delete that information from our system servers in compliance with applicable children's privacy protections.
9. Relationship to HIPAA Notice of Privacy Practices
This Privacy Policy governs general website visitors, clinician system logins, pricing sandbox users, and marketing inquiries. It applies to data that is not classified as Protected Health Information (PHI) under HIPAA.
Patient diagnostic logs, diagnostic files, and report databases are governed by the respective healthcare provider's own Notice of Privacy Practices and the BAA executed between the healthcare provider and Carepak.