Privacy Policy
Introduction
At Kinnwell ("Company," "we," "us," or "our"), we respect your privacy and are committed to protecting it through our compliance with this policy. This policy describes the types of information we may collect from you or that you may provide when you visit the website Kinnwell.com or use our software applications (collectively, our "Services").
Please read this policy carefully to understand our policies and practices regarding your information and how we will treat it. If you do not agree with our policies and practices, your choice is not to use our Services.
Definitions
- "Client" refers to the senior living community, assisted living facility, or healthcare provider that has subscribed to our Services.
- "Authorized User" means an individual (e.g., staff member, nurse, administrator) authorized by the Client to access the Services.
- "Resident" means the individual receiving care from the Client, whose health data is processed by our Services.
- "Personal Information" means information that identifies, relates to, describes, or could reasonably be linked to a particular consumer or household.
HIPAA and Regulatory Compliance
Kinnwell provides software services to healthcare providers who are considered "Covered Entities" under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"). In this capacity, Kinnwell acts as a "Business Associate."
We process Protected Health Information (PHI) on behalf of our Clients in accordance with the Business Associate Agreement (BAA) executed with each Client. If there is any conflict between this Privacy Policy and the BAA regarding the handling of PHI, the BAA controls.
Information We Collect
Information Provided by Clients
We collect information that Clients enter into our system to provide care, including:
- Resident Health Data: Medical history, medication records (eMAR), vitals, allergies, assessments, and care plans.
- Administrative Data: Resident names, dates of birth, room numbers, and insurance information.
- Staff Information: Names, roles, contact details, and login credentials of Authorized Users.
Information Collected Automatically
When you access our Services, we may automatically collect:
- Usage Details: Traffic data, logs, and other communication data.
- Device Information: Information about your computer, tablet, or mobile device and internet connection, including IP address, operating system, and browser type.
How We Use Your Information
We use information that we collect about you or that you provide to us:
- To provide the Services and its contents to you (e.g., generating eMARs, processing billing).
- To provide you with information, products, or services that you request from us.
- To fulfill our obligations and enforce our rights arising from any contracts entered into between you and us, including for billing and collection.
- To notify you about changes to our Services or any products or services we offer or provide though it.
- To improve our Services, products, and services, including for testing, research, analysis, and product development.
- In any other way we may describe when you provide the information.
Data Security
We have implemented measures designed to secure your personal information from accidental loss and from unauthorized access, use, alteration, and disclosure. These include:
- Encryption: All data is encrypted both in transit (using TLS 1.2+) and at rest.
- Access Controls: Strict role-based access controls ensure that PHI is only accessible to authorized personnel.
- Audits: Regular security audits and vulnerability assessments.
The safety and security of your information also depends on you. Where we have given you (or where you have chosen) a password for access to certain parts of our Services, you are responsible for keeping this password confidential.
Data Retention
We retain Personal Information and PHI for as long as necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements. Health records are retained in strict accordance with state and federal health record retention laws, which typically require retention for a minimum number of years (e.g., 6-10 years) after the last date of service.
Your Rights
You may send us an email at privacy@kinnwell.com to request access to, correct, or delete any personal information that you have provided to us.
Available Rights for Residents: Because Kinnwell acts as a Business Associate, if you are a Resident (or a representative of a Resident) and wish to access or amend your health records, please direct your request to the Client (the facility) that provided your care. We will assist the Client in fulfilling such requests as required by law.
California Privacy Rights
California Civil Code Section § 1798.83 permits users of our Services that are California residents to request certain information regarding our disclosure of personal information to third parties for their direct marketing purposes. To make such a request, please send an email to privacy@kinnwell.com.
Contact Information
To ask questions or comment about this privacy policy and our privacy practices, contact us at:
Kinnwell Health Inc.
Attn: Privacy Officer
Email: privacy@kinnwell.com