Privacy at a glance: Patient Orbit uses personal and health information to provide secure prescription-management workflows. We do not sell personal information, and we do not use health information for targeted advertising.
01 Scope and who controls your information
This Privacy Policy describes how Patient Orbit (“Patient Orbit,” “we,” “us,” or “our”) handles personal information through the Patient Orbit website, patient portal, communications, and related services (the “Service”). It covers tools for consent forms, prior authorisations, copay support, payments, medication-price comparisons, pharmacy management, and care-team updates.
In some workflows, Patient Orbit processes information for a healthcare provider, pharmacy, health plan, manufacturer programme, or another healthcare organisation. That organisation may determine how your information is used and may provide its own privacy notice or Notice of Privacy Practices. In those cases, contact that organisation to exercise rights relating to the information it controls.
02 Information we collect
Name, date of birth, address, email, phone number, account credentials, verification details, and authorised-representative information.
Medications, prescribers, pharmacies, allergies or other form responses, consent records, prescription status, and care-team communications.
Insurance and member details, eligibility, prior-authorisation status, copay programme information, price options, and pharmacy preferences.
Amounts due, payment status, transaction identifiers, and limited billing details. Payment processors may collect full card or bank information directly.
Form contents, signatures, timestamps, audit trails, consent choices, and records showing how a document was presented and completed.
IP address, browser and device type, operating system, pages and features used, referring URLs, approximate location derived from IP, and diagnostic logs.
Support requests, feedback, email or text preferences, and messages exchanged through the Service.
Login events, authentication signals, suspected-fraud indicators, and records needed to protect accounts and systems.
Please do not submit information that is not requested or needed for your care journey.
03 Where information comes from
We may collect information:
- from you, when you register, complete forms, sign consents, select a pharmacy, make a payment, communicate, or use features;
- from participating healthcare organisations, including providers, pharmacies, health plans, benefit managers, manufacturers, patient-support programmes, laboratories, and their service providers;
- automatically, from your browser, device, cookies, logs, and similar technologies; and
- from vendors and public sources, such as identity-verification, security, address-validation, medication-pricing, eligibility, and fraud-prevention services.
04 How we use information
We use personal information as permitted by applicable law to:
- create and secure accounts, verify identity, and manage authorised representatives;
- display prescriptions, tasks, forms, signatures, statuses, prices, coverage information, savings options, balances, pharmacies, and care-team updates;
- route information and completed records to the appropriate participating organisation;
- support prior-authorisation, coverage, copay-support, payment, and pharmacy workflows;
- send authentication, security, transactional, service, and optional communications;
- provide support, troubleshoot, maintain, analyse, and improve the Service;
- detect fraud, misuse, security incidents, and technical problems;
- comply with law, enforce our terms, protect rights and safety, and respond to authorised requests; and
- create aggregated or de-identified information that does not reasonably identify you, where permitted by law.
Where a law requires consent or another specific legal basis, we will rely on that basis. We do not make eligibility or clinical decisions solely through automated processing that produces legal or similarly significant effects unless disclosed and permitted by law.
06 HIPAA and sensitive health information
Some information handled through Patient Orbit may be “protected health information” governed by the U.S. Health Insurance Portability and Accountability Act (“HIPAA”). When Patient Orbit acts as a business associate for a covered healthcare organisation, we use and disclose that information according to our agreement with that organisation, HIPAA, and the organisation’s Notice of Privacy Practices.
HIPAA does not cover every health-related service or every piece of health information. Where HIPAA does not apply, this Policy and other applicable consumer-health-data laws may govern. A “HIPAA-aligned” or security statement on the website does not mean every Patient Orbit interaction is subject to HIPAA.
We do not use or disclose protected health information for marketing, sale, or other purposes requiring HIPAA authorisation unless a valid authorisation or another lawful basis applies.
07 Cookies and communication choices
We may use strictly necessary cookies and similar technologies for sign-in, security, preferences, load balancing, and Service operation. We may also use limited analytics technologies to understand performance and improve usability, subject to applicable consent requirements. Browser controls can block or delete cookies, but doing so may prevent essential features from working.
You can opt out of optional promotional email using the unsubscribe link and manage optional texts as described in the message. You may still receive essential account, security, transaction, care-workflow, or legal notices. Message and data rates may apply.
Because we do not use personal information for cross-context behavioural advertising, the Service does not currently respond to browser “Do Not Track” signals. We will honour legally recognised opt-out preference signals where required.
08 Your privacy rights
Depending on where you live and which organisation controls the information, you may have rights to request access, correction, deletion, portability, restriction, or withdrawal of consent; to opt out of certain processing; or to appeal a denied request. HIPAA may also give you rights to inspect, copy, amend, restrict, or receive an accounting of certain protected health information.
To make a request about information Patient Orbit controls, email support@patientorbit.com. We may verify your identity and authority before responding. An authorised agent may submit a request where law permits, but we may require proof of authority. We will not discriminate against you for exercising privacy rights.
If a provider, pharmacy, health plan, or other organisation controls the relevant record, we may direct your request to that organisation. Certain information may be retained or excluded from a request where permitted or required for healthcare records, legal compliance, security, fraud prevention, transactions, or the rights of others. You may also complain to the appropriate privacy or data-protection regulator.
09 How we protect information
We use administrative, technical, and physical safeguards designed for the sensitivity of the information, including access controls, encryption in transit and where appropriate at rest, logging, monitoring, vendor controls, secure development practices, and incident-response processes. No system is completely secure, and we cannot guarantee absolute security.
Protect your password and verification codes, use a trusted device and network, sign out of shared devices, and contact us promptly if you suspect unauthorised access. If a legally reportable breach occurs, we will provide notice as required by applicable law.
10 Data retention
We retain information for as long as reasonably necessary for the purposes described in this Policy, including to provide the Service, maintain healthcare and transaction records, comply with legal or contractual obligations, resolve disputes, prevent fraud, and secure the Service. Retention periods vary by record type, the organisation controlling it, applicable healthcare rules, and jurisdiction. We then delete, de-identify, or securely isolate information as required.
Closing your Patient Orbit account may not delete records held by your provider, pharmacy, health plan, programme, or another organisation, or records we must retain by law.
11 Children and dependants
The Service is not directed to children under 13, and children may not create their own accounts. A parent, guardian, or authorised representative may manage a minor’s information when permitted by law and the participating healthcare organisation. State laws may give minors independent privacy rights for certain healthcare services; requests involving those records may be handled by the relevant provider or organisation.
If you believe a child submitted information without proper authorisation, contact us.
12 International use
Patient Orbit is designed primarily for users in the United States. If you access it elsewhere, information may be processed in the United States or other countries where our providers operate. Those countries may have different privacy laws. Where required, we use recognised safeguards for cross-border transfers. Do not use the Service where doing so would violate applicable law.
13 Changes to this Policy
We may update this Policy as our Service or legal obligations change. We will post the revised Policy, update the effective date, and provide additional notice or request consent when required. Material changes apply prospectively unless law permits otherwise.
14 Contact us
For privacy questions or requests, contact:
Email: support@patientorbit.com
Website: patientorbit.com
If your request concerns a medical record maintained by a provider, pharmacy, health plan, or patient-support programme, contacting that organisation directly may be the fastest route.
