TELEXY Privacy Policy
Your privacy is important to Telexy Healthcare. This privacy policy provides information about the personal information that Telexy Healthcare collects and the ways in which Telexy Healthcare uses that personal information ("PHI").
Personal Infromation Collection
Telexy Healthcare may collect and use the following kinds of personal information:
- information about your use of this website (including interest in products and services, request for information, reporting product issues, request for product features, request for new products, request for product demos, and use of the forum);
- information that you provide us for the purpose of registering with the website (including interest in products and services, request for information, reporting product issues,request for product features, request for new products, request for product demos, and questions about the forum);
- information that you provide for the purpose of subscribing to the website services (including website forum and news updates);
- and any other information that you send to Telexy Healthcare
Using personal information
Telexy Healthcare may use your personal information to:
- administer this website
- personalize the website for you
- enable your access to and use of the website services
- send you information about our products and services
- respond and schedule product demos per your request
- respond to feedback regarding product issues
- respond to requests for new product features
- respond to requests for new products and services
- provide support for products you purchased
- send you marketing and corporate communications
- respond to any other requests you made
Where Telexy Healthcare discloses your personal information to its agents or sub-contractors for these purposes, the agent or sub-contractor in question will be obligated to use that personal information in accordance with the terms of this privacy policy. In addition to the disclosures reasonably necessary for the purposes identified elsewhere above, Telexy Healthcare may disclose your personal information to the extent that it is required to do so by law, in connection with any legal proceedings or prospective legal proceedings, and in order to establish, exercise or defend its legal rights
Securing Your Data
Telexy Healthcare uses administrative, technical, and organizational safeguards designed to protect personal information and protected health information (“PHI”) against unauthorized access, use, disclosure, alteration, loss, or destruction.
Qpath Cloud Security
Telexy-hosted Qpath environments operate on Microsoft Azure. Qpath uses Azure services for application hosting, database services, file storage, backup, redundancy, and disaster recovery.
Security safeguards for Telexy-hosted Qpath environments include:
- encryption of stored data using the encryption capabilities provided by Microsoft Azure, including encryption for Qpath databases and storage;
- encryption of data transmitted through the Qpath Cloud Connector using TLS 1.2 over HTTPS;
- separate databases and storage accounts for individual Qpath customers;
- controlled access and multifactor authentication for authorized administrative access;
- backup, replication, and disaster-recovery capabilities intended to maintain availability and support restoration following an outage;
- audit logging to support monitoring, troubleshooting, and security incident investigations; and
- secure deletion and storage-media sanitization procedures when data reaches the end of its applicable retention period.
Microsoft Azure maintains security and compliance programs covering widely recognized standards and frameworks. The availability and applicability of particular Azure certifications may depend on the services, configuration, and region used.
Access to PHI
Telexy Healthcare restricts access to customer PHI to designated, authorized personnel who require access for legitimate technical support, service, maintenance, or training purposes. Access must use an approved method and, where applicable, must be authorized by the responsible customer.
Personnel authorized to access PHI receive security and confidentiality training. Telexy personnel are prohibited from downloading or storing customer PHI on local computers or removable storage devices unless specifically authorized and protected under an approved procedure.
Security Incident Response
Telexy Healthcare maintains procedures for investigating and responding to suspected security incidents involving Qpath or customer PHI. When Telexy determines that an incident may have compromised customer PHI, Telexy will notify and cooperate with the affected customer in accordance with the applicable agreement and legal requirements. Relevant Qpath audit records may be made available to assist with an authorized investigation.
Customer-Managed Qpath Environments
When Qpath is installed in an environment hosted or managed by a customer or its designated service provider, the customer is responsible for securing the underlying network, servers, databases, storage, backups, user accounts, and physical environment. Telexy Healthcare secures the components and access methods under its control and provides reasonable security assistance as specified in the applicable customer agreement.
Although Telexy Healthcare applies safeguards designed to protect information, no system, network, or transmission method can be guaranteed to be completely secure. Information is retained and securely disposed of as described in the Data Retention and Deletion section below.
Data Retention and Deletion
Telexy Healthcare retains personal information and protected health information (“PHI”) only for as long as reasonably necessary to provide its products and services, fulfill contractual obligations, comply with applicable legal and regulatory requirements, resolve disputes, and enforce its agreements.
Qpath Data Retention
Unless a customer agreement, applicable law, regulatory requirement, or documented customer instruction requires a different retention period, PHI stored in Telexy-hosted Qpath environments is retained as follows:
- training examinations may be retained for up to four years;
- clinical examinations successfully archived to a customer-designated PACS or VNA may be retained for up to one year;
- clinical examinations that have not been archived to a PACS or VNA may be retained for up to seven years; and
- following the expiration or termination of a Qpath subscription, customer data may remain available for retrieval for up to 30 days, after which it is scheduled for deletion.
Customers remain responsible for determining whether these retention periods meet their legal, regulatory, clinical, and organizational requirements. Different retention arrangements may be established in the applicable customer agreement.
Deletion and Secure Disposal
When information reaches the end of its applicable retention period, or when Telexy Healthcare receives an authorized and valid deletion request, the information is securely deleted or rendered inaccessible in accordance with Telexy Healthcare’s security procedures and the capabilities of the applicable hosting platform.
Deleted information may remain temporarily in encrypted backups, system replicas, or disaster-recovery systems until those copies are overwritten or expire through the normal backup lifecycle. Such information remains protected from ordinary access and is not restored except when required for legitimate disaster recovery or business continuity purposes.
Deletion may be delayed when retention is required by applicable law, a legal hold, an investigation, a regulatory obligation, a contractual requirement, or a documented instruction from the customer responsible for the information.
Customer-Managed Environments
For Qpath installations hosted or managed by a customer or its designated service provider, the customer is responsible for establishing and carrying out its own retention, backup, deletion, and media-disposal procedures. Telexy Healthcare will provide reasonable assistance where required by the applicable customer agreement.
Deletion Requests
Individuals may request the deletion of personal information submitted directly to Telexy Healthcare by submitting a support ticket through Telexy's Support System. This process is required to verify the requester's identity before the deletion request can be processed.
Requests concerning PHI contained in Qpath should normally be directed to the healthcare organization that collected or controls the information. Telexy Healthcare processes such PHI on behalf of its healthcare customers and will assist the responsible organization as required by the applicable agreement and law.
Updating this statement
Telexy Healthcare may update this privacy policy by posting a new version on this website. You should check this page occasionally to ensure you are familiar with any changes
Other websites
This website may contain links to other websites. Telexy Healthcare is not responsible for the privacy policies or practices of any third party
Contact
If you have any questions about this privacy policy or Telexy Healthcare’s treatment of your personal information, please contact us
Contact Telexy