Walrus
Notice of Privacy Practices

Last Updated: Mar 2, 2020

This Notice of Privacy Practices is incorporated in and incorporates the Walrus Health End User License Agreement.

A. The following Notice describes the personal information which may be obtained by Walrus Health about You in the course of Your use of the Walrus App, Walrus Website, Services and Licensed Content. This information will be referred to as “Protected Health Information” in this Notice and will include any information which could reasonably identify You and has to do with Your past, present or future health or health care, or payment for Your past, present or future health care. This Notice also describes the uses and disclosures Walrus Health may make of Your Protected Health Information, and Your rights with respect to such information.

B. Walrus Health manages and is responsible for the hardware and software platform used to implement the Walrus App, the Walrus Website, the Services and Licensed Content. Your Protected Health Information is created or provided:

C. Your Plan is a “Covered Entity” under a federal law called “HIPAA,” and Walrus Health is a “Business Associate” of Your Plan under HIPAA. Walrus Health’s  use and disclosure of Your Protected Health Information is therefore subject to regulation under HIPAA. It is also subject to the terms of a contract between Walrus Health and Your Plan called a Business Associate Contract, which also applies to Walrus Health’s use and disclosure of Your Protected Health Information.

  1. What Types of Information Does this Notice Cover?

    This information covered by this Notice includes the following types of Protected Health Information:

    • Account Information. This information includes Your contact and payment information, as well as Walrus Health’s administrative records for You, and communications between Walrus Health and You, and Walrus Health and Your Plan, its administrators and Sponsor.

    • Care Information. This information includes the records of Your use of the Walrus App, the Walrus Website and the Services and includes information about Your medications, prescriptions, communications with pharmacies and pharmacists and other health care providers, and related information about your health and health care.

    • Metadata. This information may include information about devices on which the Walrus App is installed, or from which the Walrus Website is accessed, including operating system, other installed apps, IP addresses, and Internet services and browser used; the Device(s) the Walrus App is used with or Walrus Website is accessed from; activities engaged in when using the Walrus App and Services, including how often the Walrus App or Website are used and Services and Licensed Content is opened, and activity involving those Services and Licensed Content.

  2. Subcontractors and Services Providers.

    In the ordinary course of business Walrus Health uses services providers and vendors to perform services or functions on Walrus Health’s behalf (“Subcontractors and Services Providers”), which Walrus Health may permit to obtain, create, maintain, use or disclose Your Protected Health Information. Walrus Health will not authorize Subcontractors and Services Providers to obtain, create, maintain, use or disclose Your Protected Health Information except for the purposes for which Walrus Health makes such information available to them, subject to the conditions of this Notice.

  3. How Does Walrus Health Use and Disclose Protected Health Information?

    The purposes for which Walrus Health may use and disclose Protected Health Information depends upon the type of information, as described below.

    1. Account Information.

      Walrus Health may use or disclose Patient Account Information to administer Your Account, for purposes of Walrus Health’s management and administration, and to fulfill Walrus Health’s legal responsibilities, subject to specific limitations as provided in HIPAA and the Business Associate Contract (as applicable). Walrus Health will not sell Your Account Information to any third party or use it for marketing purposes.

    2. Care Information.

      Walrus Health may store, process and transmit Your Care Information to provide You with the Services and Licensed Content.

    3. Metadata.

      Walrus Health may use or disclose Metadata to administer Your Account, for purposes of Walrus Health’s management and administration, and to fulfill Walrus Health’s legal responsibilities, to provide You with Services and Licensed Content, to improve the performance of the Walrus App and the Services, and to create records which do not include information which would identify You and is not Protected Health Information subject to this Notice (“Derived Information”), subject to  any limitations provided in HIPAA and the Business Associate Contract.  Walrus Health will not sell Your Metadata to any third party or use it for marketing purposes.

  4. May I Request Access to or a Copy of Walrus Health’s Records of My Protected Health Information?

    You may request a copy of or access to Your Protected Health Information which Walrus Health maintains in a Designated Record Set on behalf of Your Plan. Except as noted below, requests for access to Your Protected Information should be directed to Your Plan.

    1. Account Information.

      You may access and copy Your Account Information at any time during the Term of Your EULA from Your Account Page. Any request for other information must be directed to Your Plan.

    2. Care Information.

      Any request for Care Information must be directed to Your Plan.

    3. Metadata.

      Patient Metadata is not part of a Designated Record Set and is not available for copying or access.

  5. May I Request the Amendment of Walrus Health’s Records of My Protected Health Information?

    You may request amendment of Your Protected Health Information which Walrus Health maintains in a Designated Record Set on behalf of Your Plan. Except as noted below, requests for amendment of Your Protected Information should be directed to Your Plan.

    1. Account Information.

      You may amend Your Account Information at any time during the Term of Your EULA from Your Account Page. Any request to amend other information must be directed to Your Plan.

    2. Care Information.

      Any request to amend Care Information must be directed to Your Plan.

    3. Metadata.

      Metadata is not part of a Designated Record Set and is not available for amendment.

  6. May I Request an Accounting of Disclosures of Walrus Health’s Records of My Protected Health Information?

    Requests for an accounting of disclosures of Your Protected Information must be directed to Your Plan.

  7. What Are Walrus Health’s Obligations to Maintain the Security of Protected Health Information?

    Walrus Health complies with the HIPAA Security Rule and uses reasonable and appropriate safeguards to protect Protected Health Information.

  8. What Are Your Responsibilities?

    You are responsible for:

    • Providing complete and accurate contact information, and keeping it current, in case Walrus Health needs to notify You with respect to any issue concerning Your Protected Health Information.

    • Maintaining Your Device used with the Walrus App or Walrus Website in good working order with all current updates.

    • Keeping Your Device physically secure from access by any individual You do not wish to have potential access to Your Protected Health Information.

    • Keeping Your Device technically secure by maintaining a robust password or other authentication token, which You do not share with anyone else.

    • Notifying Walrus Health immediately if Your password or other authentication token has been obtained by someone else or Your Device has been stolen or lost.

    • Maintaining the administrative, physical and technical security of any mobile device or computer You use to access Your Account.

  9. Can Walrus Health Change the Terms of this Notice?

    Walrus Health reserves the right to change and update this Notice or publish a new notice as appropriate to address legal matters, user preferences, changes in technology, changes to the Walrus App, Walrus Website or Services or Account Page, or other matters affecting Walrus Health’s privacy practices, subject to the terms of the EULA. If Walrus Health does change this Notice, Walrus Health will notify You as provided in the EULA.

  10. When Does This Notice Apply?

    This Notice is effective as of the effective date stated above and replaces any prior privacy notices or policies Walrus Health may have published. It will remain in effect until it is replaced by a new or updated Notice published by Walrus Health.

  11. Can I Get More Information?

    If You have any questions or would like more information about this Notice please contact Walrus Health at: compliance@walrus.com