This is a separate, standalone policy required by the Washington My Health My Data Act (RCW 19.373) and the Nevada consumer health data law (SB 370, NRS 603A). It is published in addition to, and does not replace, our general Privacy Policy. Where the two describe the same practice, they are intended to say the same thing; if they ever conflict, this policy governs consumer health data for Washington and Nevada consumers.
It applies to you if you are a Washington resident, a Nevada resident, or a person whose consumer health data is collected in Washington or Nevada. It does not apply to individuals acting in an employment context. Healthvocate is operated by DYS Global Macro Trading Corp, 5830 E 2nd St, Ste 7000, Casper, WY 82609.
Both laws define consumer health data broadly: personal information that is linked, or reasonably linkable, to you and that identifies your past, present, or future physical or mental health status. It is wider than the medical-records definition most people have in mind, and it covers things like the medications you take, the conditions you have, and the care you are seeking or paying for.
Healthvocate is not a HIPAA covered entity, and we do not claim to be. That is precisely the gap these two state laws were written to close, which is why this policy exists.
We collect only what a given tool needs in order to do the job you asked it to do. You choose which tools to use, and unused tools collect nothing.
How it is used. Solely to deliver the tools you requested, to show you your own results, and to prepare documents that you review and sign before anything is sent. We do not use consumer health data for advertising, for profiling unrelated to the service, or to build audiences.
We do not buy consumer health data, obtain it from data brokers, receive it from your insurer or provider, or gather it from third-party tracking. Every piece of it originates with you.
We do not share consumer health data with third parties. Under both statutes, disclosure to a processor acting on our instructions — and consistent with the purpose the data was collected for — is not "sharing," and a processor is not a "third party." We nonetheless describe those processors in section 5, because we would rather over-disclose than have you discover a data flow you did not expect.
We have never sold consumer health data, we do not sell it, and we will not sell it without first obtaining the separate written authorization both laws require. We have no such authorizations on file.
Third parties with whom we share consumer health data: none.
Specific affiliates with whom we share consumer health data: none. Healthvocate has no corporate affiliates, parents, or subsidiaries with which any data is shared.
The processors that handle consumer health data on our behalf, by category:
Two further categories of outbound query carry health-related terms but nothing that identifies you, which is why they do not constitute sharing of consumer health data:
Both laws permit collection and sharing of consumer health data, without separate consent, to the extent necessary to provide a product or service you requested. That is the basis Healthvocate operates on: we collect what a tool needs to produce the result you asked for, and nothing beyond it.
If we ever want to collect additional categories of consumer health data, or use it for a purpose not described in this policy, we will disclose that and obtain your affirmative, opt-in consent first — separately for collection and for sharing, as the statutes require. Continuing to use the service, or accepting our general terms, does not count as that consent and we will not treat it as such.
If you are covered by this policy, you have the right to:
How to submit a request. Signed-in users can use Account & Data Rights, which is the fastest route because your identity is already established. Anyone else can email support@healthvocate.com with the subject line Consumer Health Data Request. You do not need to create an account to make a request.
Verification. We will take reasonable steps to confirm the request is really from you, and may ask for additional information if we cannot. If we are unable to authenticate you, we may decline to act, and we will say so.
Timing. We respond within 45 days. If a request is complex we may extend once by a further 45 days, and we will tell you within the first 45 days that we are doing so, and why. Requests are free up to twice a year; we may charge a reasonable fee, or decline, only for requests that are manifestly unfounded, excessive, or repetitive — and the burden of showing that is ours.
If we refuse. You may appeal by replying to our decision, or by emailing support@healthvocate.com with the subject line Consumer Health Data Appeal. We will respond in writing within 45 days, explaining the reasons for the decision. If we deny the appeal, you may complain to your state Attorney General using the links in sections 9 and 10.
This policy is our consumer health data privacy policy for purposes of RCW 19.373.020, and the rights in section 8 are those provided by RCW 19.373.040.
Washington's My Health My Data Act is enforceable through the Washington Consumer Protection Act (chapter 19.86 RCW). If we deny your appeal, you may submit a complaint to the Washington State Attorney General at atg.wa.gov/file-complaint.
This policy is our consumer health data privacy policy for purposes of NRS 603A.495, and states its effective date at the top of this page as that section requires.
Nevada's law is enforced by the Nevada Attorney General as a deceptive trade practice; it does not provide a private right of action. If we deny your appeal, you may submit a complaint to the Nevada Attorney General's Bureau of Consumer Protection at ag.nv.gov/Complaints/File_Complaint.
Access to consumer health data is restricted to those who need it to deliver the service you requested. We maintain administrative, technical, and physical safeguards appropriate to the volume and sensitivity of the data, including encryption in transit, encryption at rest for sensitive fields, hashed credentials, optional two-factor authentication, and audit logging of sensitive actions. Any processor handling this data does so under a binding contract that limits it to our instructions.
If we change the categories of consumer health data we collect, the purposes we use it for, or who receives it, we will update this policy and bump the dates above before the change takes effect — and where the law requires affirmative consent for the change, we will ask for it first rather than relying on this notice.
DYS Global Macro Trading Corp
5830 E 2nd St, Ste 7000, Casper, WY 82609
support@healthvocate.com