QHIN Privacy Policy
MedAllies, Inc. and its affiliates (collectively, “MedAllies,” “we” or “us”)
respects the privacy of the individuals whose health information may pass through the network services we provide. This Privacy Policy explains, in plain language, how we handle health information in connection with our role as a Health Information Network (HIN) and as a Qualified Health Information Network (QHIN™) under the Trusted Exchange Framework and Common Agreement (“TEFCA”). This Policy is made publicly available in accordance with Section 11.2 of the Common Agreement for Nationwide Health Information Interoperability (the “Common Agreement”).
ABOUT MEDALLIES
MedAllies connects healthcare providers, health systems, health plans, and other organizations so they can securely exchange electronic health information (EHI) with one another — for example, to support treatment and care coordination. As a Designated QHIN under TEFCA, MedAllies also enables exchange between its network and other QHINs nationwide, under the terms of the Common Agreement.
Information we handle
In providing these services, MedAllies may access, transmit, or otherwise handle Protected Health Information (PHI) and other Individually Identifiable Information on behalf of the healthcare organizations, health plans, and other entities we serve, including information that MedAllies reasonably believes is “TEFCA Information” under the Common Agreement.
How we use and share information
MedAllies uses and discloses information only:
- In a manner that is not prohibited by applicable federal or state law;
- Consistent with our agreements with the healthcare organizations, health plans, and other entities we serve, including any applicable Business Associate Agreements;
- For permitted purposes recognized under TEFCA (“Exchange Purposes”), such as Treatment, and any other Exchange Purpose designated by ONC or the Recognized Coordinating Entity (RCE); and
- In accordance with the Privacy (Section 11) and Security (Section 12) provisions of the Common Agreement.
MedAllies does not sell health information and does not use the information that passes through our network for marketing purposes unrelated to the network services we provide.
Our privacy and security commitments
- We use and disclose health information lawfully, fairly, and in a transparent manner, consistent with this Policy.
- We maintain administrative, physical, and technical safeguards for the information in our care that are commensurate with the HIPAA Security Rule and applicable TEFCA security requirements, and that support our HITRUST CSF certification.
- We provide plain-language notice of our privacy practices and update that notice when our practices materially change.
- We limit our workforce’s access to health information to what is needed to perform their job responsibilities, and our workforce is trained on these obligations.
Your Rights
MedAllies is not an Individual Access Services (IAS) Provider — we do not offer patient portals or similar services that give individuals direct access to their records through MedAllies. If you have questions about your own health information, or wish to access, amend, or restrict it, please contact your healthcare provider, health plan, or the organization that originally collected your information; they remain responsible for responding to those requests. If your question relates specifically to how MedAllies operates its network, you may contact us using the information below.
Our participation in TEFCA
MedAllies is a Designated QHIN under TEFCA and a signatory to the Common Agreement. This Policy is maintained and made publicly available in accordance with Section 11.2 of the Common Agreement and applies to Individually Identifiable Information that MedAllies reasonably believes is TEFCA Information exchanged through the MedAllies network. More information about TEFCA and the Common Agreement is available at rce.sequoiaproject.org.
Changes to this policy
We may update this Policy from time to time to reflect changes in our practices, in applicable law, or in the Common Agreement. When we make changes, we will revise the “Last Updated” date above and post the updated Policy on this page.
Contact Us
If you have questions about this Policy or MedAllies’ privacy practices, please contact:
Attn: MedAllies QHIN Privacy Officer
Centauri Health Solutions
51 W. 3rd Street
Tempe, AZ 85281
845.896.0101