1. Introduction
This Provider Privacy Policy ("Policy") supplements the general ActiPatch® Privacy Policy and describes how Electrome Corporation ("Electrome," "we," "us") collects, uses, discloses, and protects information when you use the ActiPatch® provider portal and related tools (collectively, the "Provider Services"). To the extent this Policy conflicts with the general Privacy Policy, this Policy controls with respect to the Provider Services.
2. Information We Collect from Providers
Registration and Credentialing Data
- Full legal name, email address, phone number, and practice address
- National Provider Identifier (NPI), verified against the NPPES NPI Registry
- State license number(s), license type, and jurisdiction(s) of practice
- DEA registration number (if prescribing controlled substances)
- Practice legal name, tax identification number, and specialty
- Account credentials and multi‑factor authentication identifiers
Clinical and Platform Data
- Care plans, clinical notes, and treatment documentation you create for your patients
- Prescriptions issued through the Provider Services for RecoveryRx®
- Patient panel information and care‑team assignments
- Platform usage data, feature interactions, and session logs
- Communications with Electrome support, clinical operations, or compliance teams
Billing Data
- Payment method tokens (we do not store full card numbers; payments are processed by Stripe)
- Invoice and payment history
3. Legal Bases for Processing
We process provider data under the following legal bases:
- Contract Performance: To provide and maintain the Provider Services under these Provider Terms of Service.
- Legal Obligation: To comply with HIPAA, state licensing laws, FDA reporting requirements, tax regulations, and other applicable laws.
- Legitimate Interest: To improve the Provider Services, detect fraud, and maintain platform security, balanced against your privacy interests.
- Consent: Where required by law, including for optional analytics, marketing communications, and participation in research programs.
4. How We Use Provider Data
- Verify and maintain your clinical credentials (NPI, license status, DEA)
- Operate, maintain, and improve the Provider Services
- Process RecoveryRx® prescriptions and route them to licensed pharmacy partners
- Generate outcomes reports, clinical analytics, and care‑quality metrics
- Manage your billing and account administration
- Provide technical support and respond to your inquiries
- Comply with FDA adverse‑event reporting and HIPAA breach‑notification requirements
- Create de‑identified and aggregated datasets for research and service improvement consistent with HIPAA §164.514
5. How We Share Provider Data
We do not sell provider data. We share information only as needed to deliver the Provider Services:
- NPI Verification: We transmit your NPI to the CMS NPPES system for identity and credentialing verification.
- Pharmacy and Fulfillment Partners: Prescription routing data for RecoveryRx® is shared with licensed pharmacy partners under Business Associate Agreements.
- Payment Processor: Billing data is processed by Stripe under its services agreement and PCI DSS compliance program.
- Infrastructure Providers: Hosting, email, and cloud services operating under written confidentiality agreements and (where PHI is involved) Business Associate Agreements.
- Legal and Regulatory: When required by law, subpoena, court order, or to respond to a licensing board inquiry or FDA investigation.
- Business Transfers: In connection with a merger, acquisition, or asset sale, with notice consistent with applicable law.
6. Protected Health Information (PHI)
When you use the Provider Services to create, receive, maintain, or transmit Protected Health Information on behalf of your patients, Electrome acts as a Business Associate under HIPAA. Our obligations regarding PHI are set forth in the HIPAA Compliance page and any executed Business Associate Agreement between you and Electrome.
Provider Data vs. Patient PHI. Your credentialing data (NPI, license information, practice details) is not PHI. Patient information created or managed through the Provider Services is PHI and is governed by both this Policy and the HIPAA regulations.
7. Data Security
We protect provider data and PHI using:
- AES‑256 encryption at rest and TLS 1.2+ encryption in transit
- Role‑based access controls with least‑privilege principles
- Multi‑factor authentication for all provider accounts
- Comprehensive audit logging of all access to clinical data
- Regular vulnerability assessments and penetration testing
- Formal incident‑response and breach‑notification procedures
For detailed information about our security program, see our HIPAA Compliance page.
8. Data Retention
- Account Data: Retained for as long as your provider account is active, plus two (2) years following account closure for audit and compliance purposes.
- Clinical Records (PHI): Retained for the longer of (a) seven (7) years from the last service date, or (b) any longer period required by applicable state medical‑records retention law.
- Billing Records: Retained for seven (7) years in accordance with IRS record‑keeping requirements.
- De‑identified Data: May be retained indefinitely for research and analytics purposes.
9. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access and receive a copy of your provider account data
- Correct inaccurate credentialing or profile information
- Request deletion of your account, subject to our legal and regulatory retention obligations
- Receive a machine‑readable export of your Provider Data within thirty (30) days of written request
- Opt out of non‑essential marketing communications
- Appeal a denial of any privacy rights request
To exercise your rights, contact our Privacy team (mention "Provider Privacy Request").
10. Cookies and Analytics
We use strictly necessary cookies for authentication and session management. Limited analytics cookies measure platform performance and usage patterns. We do not use cross‑site behavioral advertising trackers within the Provider Services. You can manage cookie preferences through your browser settings.
11. Changes to This Policy
We may update this Provider Privacy Policy from time to time. Material changes will be communicated by email and through the provider portal at least fourteen (14) days before they take effect. The "Last updated" date above reflects the most recent revision.
12. Contact
Electrome Corporation
Privacy Officer
200 N Vineyard Blvd
Ste. A325 # 5743
Honolulu, HI 96817
Phone: (808) 300-5703
Privacy: contact our Privacy team · Provider Relations: contact Provider Relations