1. INFORMATION WE COLLECT
2. HOW WE USE THE INFORMATION DESCRIBED IN THIS POLICY
3. HOW AND WHEN WE DISCLOSE USER INFORMATION TO THIRD PARTIES
4. ONLINE BEHAVIORAL ADVERTISING AND OPTIONS
5. A NOTE ABOUT CHILDREN
6. HOW WE PROTECT YOUR INFORMATION
7. CHANGES TO THIS POLICY
8. STATE SPECIFIC PRIVACY NOTICES
9. NOTICE TO USERS OUTSIDE OF THE UNITED STATES

ProxsysRx, Inc. (‘we’, or ‘us’ or ‘company’) provides this Privacy Policy to explain how we collect, use, share and protect the information you provide and that we collect on our Website (as defined in our Terms and Conditions located at www.ProxsysRx.com. BY USING ProxsysRx, OR OTHERWISE GIVING US YOUR INFORMATION, YOU AGREE TO THE TERMS OF THIS PRIVACY POLICY. Please review this Policy carefully to ensure your understanding of our privacy practices.

1. INFORMATION WE COLLECT

Information You Provide Directly. While using the ProxsysRx.com Website, we collect information that you provide us directly. This includes personal information, such as email addresses or information submitted via online forms.

Information We Collect Automatically.

General. In addition to any Personally or Non-Personally Identifiable Information that you choose to submit to us, we and our third-party service providers may use a variety of technologies that automatically (or passively) collect certain information whenever you visit the Website or access or use the Website. Non-Personally Identifiable Information may include the browser that you are using, the URL that referred you to our Website, and how and when you use the ProxsysRx Website. We may use Non-Personally Identifiable Information for various reasons, such as providing and enhancing ProxsysRx.com for you and other users. In addition, we may collect your IP address or other unique identifier that identifies the device from which you access the Website. This identifier is a number that is automatically assigned to your device and which our computers use to identify you and your device. This information may be non-identifying or

may be associated with you. If we associate any Non-Personally Identifiable Information or information that identifies your device with your Personally Identifiable Information, we will treat it as Personally Identifiable Information.

Geo-Location Information. We may collect information as you navigate our Website which may include geographic location.

Cookies. Cookies are small pieces of data containing text sent from a website to your computer or mobile device, where they are stored locally and can identify your internet browser or device to help enhance your experience. Cookies may be used for other purposes, including protection of your data, tracking your visits to our Website and storing preferences..

If you do not want information to be collected using cookies, your browser allows you to deny or accept the use of cookies. Cookies can be disabled or controlled by setting a preference within your web browser or on your device. If you choose to disable cookies on your device, some features of our Website may not function properly or may not be able to customize the delivery of information to you. You should be aware that we cannot control the use of cookies (or the resulting information) by third parties, and use of third-party cookies is not covered by our Privacy Policy.

Web Beacons. Web beacons are small graphic images or other web programming codes called web beacons (also known as GIFs) may be included in our web and mobile pages and messages. The web beacons are tiny graphics with a unique identifier, similar in function to cookies, and are used to track the online movements of web users. In contrast to cookies, which are stored in a user’s computer hard drive, web beacons are embedded invisibly on web pages and are about the size of the period at the end of this sentence. Web beacons or similar technologies help us better manage content on our Website by informing us what content is effective, count users, monitor how users navigate the Website, count how many emails we sent that were actually opened or to count how many particular articles or links were actually viewed.

Embedded Scripts. An embedded script is a programming code that is designed to collect information about your interactions with the Website, such as tracking links you click. The code is temporarily downloaded onto your device from our web server or a third party provider and is active only while you are connected to the Website and is deactivated or deleted thereafter.

Information Third Parties Provide About You. We may, from time to time, supplement the information we collect about you through our Website with outside records from third parties in order to provide service, enhance our ability to serve you, tailor content to you and offer opportunities to purchase products or Services that we believe may be of interest to you. For example, we may collect information from third party Providers that you visit when using the Website.

Our communications company may collect personal information when you interact with our digital property, including IP addresses, digital identifiers, information about your web browsing

and how you interact with our properties and ads for a variety of purposes, such as personalization of offers or advertisements, analytics about how you engage with websites or ads and other commercial purposes.

User Information. Unless otherwise noted elsewhere in this Policy, Personally Identifiable Information and Non-Personally Identifiable Information shall be collectively referred to as “User Information.”

2. HOW WE USE THE INFORMATION DESCRIBED IN THIS POLICY

IP Address. We use your Internet Protocol (“IP”) address to help diagnose problems with our computer server, and to administer our Website. Your IP address is used to help identify you but contains no User Information about you.

Messages. We will send you strictly ProxsysRx related announcements when it is necessary to do so. Generally, you may not opt out of these communications, which are not promotional in nature. If you do not wish to receive messages, you have the option to cancel your account.

Miscellaneous. In addition, we may utilize User Information in the following events:(i) to provide users with requested information or process transactions, provide special offers or promotional materials on behalf of us or third parties; (ii) to process user registration with the Website, including verifying information is active and valid; (iii) to improve the Website, to customize user experience with the Website, or serve specific content that is most relevant to a user; (iv) to contact users with regard to use of the Website and, in our discretion, make changes to the Website or our policies; (v) for internal business purposes; (vi) for inclusion in our data analytics; and (vii) for purposes disclosed at the time users provide us with their information, or as otherwise set forth in this Privacy Policy.

3. HOW AND WHEN WE DISCLOSE USER INFORMATION TO THIRD PARTIES

General. We do not sell, share, rent or trade the information we collect, including User Information other than as disclosed within this Privacy Policy or at the time you provide your information. We do not share your User Information with third parties for those third parties’ direct marketing purposes unless you consent to such use or sharing. We may share User Information, such as aggregated user statistics and log data, with third parties for industry analysis, demographic profiling, to deliver targeted advertising about other products or the ProxsysRx Website, or for other business purposes.

When You Agree to Receive Information From Third Parties. You may be presented with an opportunity provide your User Information in order to receive information and/or marketing offers directly from parties unrelated to us. If you do agree to have your User Information shared, your User Information will be disclosed to such third parties and all information you disclose will

be subject to those third parties’ privacy policies. We are not responsible for the privacy policies and practices of such third parties and, therefore, you should review the privacy policies and practices of such third parties prior to agreeing to receive such information from them. If you later decide that you no longer want to receive communication from a third party, you will need to contact that third party directly.

Third Parties Providing Services on Our Behalf. We use third party companies and individuals to facilitate our Website, provide or perform certain aspects of the Website on our behalf, and other third-parties to host the Website, design and/or operate the Website’s features, track analytics, process payments, engage in anti-fraud and security measures, provide customer support, provide geo-location information, which enable us to send you special offers, perform technical ProxsysRx Services (e.g., without limitation, maintenance ProxsysRx Services, database management, web analytics and improvement of the Website’s features), or perform other administrative Services. We may provide these vendors with access to User Information. This information sharing is limited to only the information needed by the vendor to carry out Services they are performing for you or for us. Each of these vendors are obligated not to disclose or use User Information for any other purpose and when required by law, ProxsysRx will enter into special contracts with the vendors strictly limiting the vendors’ ability to use and disclose User Information and requiring the use of certain security measures by the vendors.

Co-Branded ProxsysRx Services. Certain aspects of the Website may be provided to you in association with third parties that will be disclosed and identifiable to you, and we may disclose User Information to such parties in accordance with applicable law.

Administrative And Legal Reasons. If we receive requests for information from government and law enforcement officials and private parties in regard to enforcing and complying with the law and in connection with private lawsuits, we will disclose User Information to these parties as we reasonably determine is necessary to comply with applicable law. For example, we may disclose User Information: (a) to satisfy any applicable law, regulation, subpoenas, governmental requests or legal process; (b) to protect and/or defend our Terms and other policies; (c) to protect the safety, rights, property or security of the Company, our Website or any third party; (d) to protect the safety of the public for any reason; (e) to detect, prevent or otherwise address fraud, security or technical issues; and/or (f) to prevent or stop activity we may consider to be, or to pose a risk of being, an illegal, unethical, or legally actionable activity.

Business Transfer. We may, to the extent permitted by law, share all User Information with our parent, subsidiaries, and affiliates for internal, business related (non-marketing) purposes. We also reserve the right to disclose and transfer all User Information: (a) to a subsequent owner, co-owner or operator of ProxsysRx.com or applicable database; or (b) in connection with a corporate merger, consolidation, restructuring, the sale of substantially all of our interests and /or assets or other corporate change, including, during the course of any due diligence process.

4. ONLINE BEHAVIORAL ADVERTISING AND OPTIONS

General. Behavioral advertising uses information collected about an individual’s web or mobile browsing behavior such as the pages they have visited or the searches they have made. This information is then used to determine which advertisements should be displayed to a particular individual.

Opt Out. To opt out of this data collection process, click here to access the NAI Opt Out Page. Please note that this will opt you out of targeted ads from us and any other participating advertisers. If you opt out, you may continue to receive online advertising from us; however, these ads may not be as relevant to you.

Opting Out of Cookies. In order for behavioral advertising opt outs to work on your device, your browser must be set to accept cookies. If you delete cookies, buy a new device, access our ProxsysRx Services from a different device, login under a different screen name, or change web browsers, you will need to opt out again. If your browser has scripting disabled, you do not need to opt out, as online behavioral advertising technology does not work when scripting is disabled. Please check your browser’s security settings to validate whether scripting is active or disabled.

5. A NOTE ABOUT CHILDREN

The ProxsysRx Website is not directed to nor intended for minors. No one under eighteen (18) is allowed to register with or use the ProxsysRx Website. As such, we do not knowingly collect User Information from anyone under the age of 18. If we discover that we have collected User Information from a person under 18, we will delete that information immediately. If you are a parent or guardian of a minor under the age of 18 and believe he or she has disclosed User Information, you must notify ProxsysRx in writing of your request.

6. HOW WE PROTECT YOUR INFORMATION

User Identifiable Information is stored within our databases using standard, industry-wide, commercially reasonable security practices and procedures such as encryption, firewalls, and SSL (Secure Socket Layers). We also implement security measures required by law. However, as effective as such technology and efforts may be, no security system is infallible and impervious from attack or hacking. Therefore, we cannot guarantee the security of our databases, nor can we guarantee that User Information won’t be intercepted while being transmitted to us over the Internet or wireless communication or accessed when stored on our or our service providers’ servers and any information you transmit to us, you do at your own risk.

7. CHANGES TO THIS POLICY

From time to time, we may update this Privacy Policy to reflect changes to our information practices. We encourage you to periodically review this page for the latest information on our privacy practices.

8. STATE SPECIFIC PRIVACY NOTICES

Note To Illinois Consumers. The plans, although they are not insurance, are regulated by the Illinois Department of Insurance. You have the right to contact them regarding any complaint. We will provide contact information for the Illinois Department of Insurance upon request. You may make your request by contacting us at 866-959-7979 (RXRX).

Note To Louisiana Consumers. If you pay for any service and in the event you cancel your use of the Services within the first thirty (30) calendar days of use, we will refund to you all fees, dues, charges, or other financial consideration, except a nominal fee not toexceed$30,associatedwith the use of the Services. The 30-day period begins on the day after you enrolled in the Services or the day after you paid any fees, dues, charges, or other financial consideration, whichever is later.

The date of cancellation will be postage date of any notice appropriately mailed to us or the email date of any notice appropriately emailed to us.

We will return any fees, dues, charges, or other financial consideration charged or collected after you have notified us of your request to cancel.

If we cancel your use of the Services for any reason other than your failure to pay for such Services, we will make a pro rata refund to you for all fees, dues, charges, or other financial consideration within thirty (30) calendar days following the date of cancellation.

If, after following the Dispute Resolution process of this Member Agreement, you are not satisfied with the outcome of your dispute, you may contact the Louisiana Department of Insurance.

NOTE: If you are domiciled in Maryland please refer to the
following
for additional terms and
conditions for your state.

Note to Maryland Consumers:

Regulatory Addendum. In the event you cancel your use of the Services within the first thirty (30) calendar days of use, we will refund to you all fees, dues, charges, or other financial consideration, except a nominal fee, not to exceed any fees, dues, charges, or other financial consideration you have already paid associated with the use of the Services.

If we cancel your use of the Services for any reason other than your failure to pay for such Services, we will make a pro rata refund to you for all fees, dues, charges, or other financial consideration within thirty (30) calendar days following the date of cancellation.

Note To Oregon Consumers. In the event you cancel your use of the Services within the first thirty (30) calendar days of use, we will refund to you all fees, dues, charges, or other financial consideration, except a nominal fee not to exceed $30, associated with the use of the Services. The 30-day period begins on the day after you enrolled in the Services or the day after you paid any fees, dues, charges, or other financial consideration whichever is later.

Note To Rhode Island Consumers. These plans, although they are not insurance, are regulated by the Office of the Health Insurance Commissioner (‘OHIC’), 1151 Pontiac Avenue, Building 69-1, Cranston, RI 02920; for consumer complaints contact OHIC’s consumer assistance partner RIReach at: 855-747-3224 (toll free) or rireach.org.

9. NOTICE TO USERS OUTSIDE OF THE UNITED STATES

If you are located outside of the United States, please note that information we collect, including Personally Identifiable Information, will be transferred, processed, and stored in the United States. The data protection laws in the United States may differ from those of the country or jurisdiction in which you are located, and your Personally Identifiable Information may be subject to access requests from governments, courts, or law enforcement in the United States according to laws of the United States. By using the Website or providing us with any information, you expressly and unambiguously consent to the transfer, processing, and storage of your information in the United States.

International Users. This Website is hosted and operated by ProxsysRx, Inc. in the United States. If you are accessing or providing information to our Website from a location outside of the United States, the privacy and data security laws of the United States shall govern, and as such, the laws of your jurisdiction will not apply. By visiting this Website or providing your information, you understand and unambiguously agree to the collection, storage, and processing of your information in the United States.

PROXSYSRX NOTICE OF PRIVACY PRACTICES

May 2024

THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT.

 

As part of the federal Health Insurance Portability and Accountability Act of 1996, known as HIPAA, the pharmacy has created this Notice of Privacy Practices (Notice). This Notice describes the pharmacy’s privacy practices and the rights you, the individual, have as they relate to the privacy of your Protected Health Information (PHI). Your PHI is information about you or could be used to identify you related to your past and present physical and mental health care services. The HIPAA regulations require that the pharmacy protect your PHI’s privacy that the pharmacy has received or created.

 

This pharmacy will abide by the terms presented within this Notice. For any uses or disclosures that are not listed below (including marketing and selling of PHI), the pharmacy will obtain a written authorization from you for that use or disclosure, with the right to revoke at any time, as explained in more detail below.

 

The pharmacy reserves the right to change the pharmacy’s privacy practices and this Notice.


HOW THE PHARMACY MAY USE AND DISCLOSE YOUR PHI

The following are ways that the pharmacy is permitted, by law, to use and disclose your PHI:

Uses and Disclosures of PHI for Treatment – We will use the PHI that we receive to fill your prescription and coordinate or manage your health care.

Uses and Disclosures of PHI for Payment – The pharmacy will disclose your PHI to obtain payment or reimbursement from insurers for your health care services.

Uses and Disclosures of PHI for Health Care Operations – The pharmacy may use the minimum necessary amount of your PHI to conduct quality assessments, improvement activities, and evaluate the pharmacy workforce.

 

The following are additional ways in which the pharmacy is permitted, or required, to use or disclose PHI about you without your written authorization:

Uses and Disclosures as Required by Law – The pharmacy is required to use or disclose PHI about you as required and as limited by law.

Uses and Disclosure for Public Health Activities – The pharmacy may use or disclose PHI about you to a public health authority authorized by law to collect to prevent or control disease, injury, or disability. This includes the FDA monitoring any adverse effects of drugs, foods, nutritional supplements, and other products as required by law.

Uses and Disclosure about Victims of Abuse, Neglect, or Domestic Violence – The pharmacy may use or disclose PHI about you to a government authority if it is reasonably believed you are a victim of abuse, neglect, or domestic violence.

Uses and Disclosures for Health Oversight Activities – The pharmacy may use or disclose PHI to a health agency for certain oversight activities. This may include audits, investigations, inspections as necessary for licensure, compliance with civil laws, or other activities the health agency is authorized by law to conduct.

Disclosures to Individuals Involved in Your Care The pharmacy may disclose PHI about you to individuals involved in your care.

Disclosures for Judicial and Administrative Proceedings The pharmacy may disclose PHI about you in the course of any judicial or administrative proceedings, provided that proper documentation is presented to the pharmacy.

Disclosures for Law Enforcement Purposes The pharmacy may disclose PHI about you to law enforcement officials for authorized purposes as required by law or in response to a court order or subpoena.

Uses and Disclosures About the DeceasedThe pharmacy may disclose PHI about a deceased, or before and in reasonable anticipation of individual’s death, to coroners, medical examiners, and funeral director.

Uses and Disclosures for Cadaveric Organ, Eye, or Tissue Donation Purposes – The pharmacy may use and disclose PHI for procurement, banking, or transplantation of cadaveric organs, eyes, or tissues for donation purposes.
Uses and Disclosures for Research Purposes – The pharmacy may use and disclose PHI about you for research purposes with a valid waiver of authorization approved by an institutional review board or a privacy board. Otherwise, the pharmacy will request signed permission by the individual for all other research purposes.
Uses and Disclosures to Avert a Serious Threat to Health or Safety – The pharmacy may use or disclose PHI about you, if believed in good faith, and is consistent with any applicable law and standards of ethical conduct avert a serious threat to health or safety.
Uses and Disclosures for Specialized Government Functions – The pharmacy may use or disclose PHI for specialized government functions, including military and veteran’s activities, national security and intelligence, protective services, department of state functions, and correctional institutions, and law enforcement custodial situations.
Disclosure for Workers’ Compensation – The pharmacy may disclose PHI about you as authorized by, and to the extent necessary to comply with, workers’ compensation laws or programs established by law.
Disclosures for Disaster Relief Purposes – The pharmacy may disclose PHI as authorized by law to a public or private entity to assist in disaster relief efforts and for family and personal representative notification.
Disclosures to Business Associates – The pharmacy may disclose PHI about you to the pharmacy’s business associates for services they may provide to or assist the pharmacy in delivering quality health care. To ensure your PHI’s privacy, we require all business associates to apply appropriate safeguards to any PHI they receive or create.

 

OTHER USES AND DISCLOSURES

The pharmacy may contact you for the following purposes:
Information About Treatment Alternatives – The pharmacy may contact you to notify you of alternative treatments and products.
Health-Related Benefits or Services – The pharmacy may use your PHI to notify you of the benefits and services the pharmacy provides.

FOR ALL OTHER USES AND DISCLOSURES

The pharmacy will obtain a written authorization from you for all other uses and disclosures of PHI. The pharmacy will only use or disclose PHI according to such an authorization. In addition, you may revoke such an authorization in writing at any time. To revoke a previously authorized use or disclosure, request a Request for Restriction of Uses and Disclosures Form from the pharmacy.

YOUR HEALTH INFORMATION RIGHTS

The following are a list of your rights in respect to your PHI:
To Request Restrictions on Certain Uses and Disclosures of Your PHI – You have the right to request further uses and disclosures of your PHI; however, the pharmacy is not required to accommodate a request. This includes the right to restrict disclosures to Insurances for those products and services you for pay out‐of‐pocket.
To Have Your PHI Communicated to You by Alternate Means or Locations – You have the right to request that the pharmacy communicate confidentially with you using an address or phone number other than your residence. However, state and federal laws require the pharmacy to have an accurate address and home phone number in emergencies. The pharmacy will consider all reasonable requests.
To Inspect or Obtain A Copy of Your PHI – You have the right to request access or obtain a copy of your PHI that is contained in the pharmacy for the duration the pharmacy maintains PHI about you. There may be a reasonable cost‐based charge for photocopying documents. You will be notified in advance of incurring such costs if any.
To Amend Your PHI – You have the right to request an amendment of the PHI the pharmacy maintains about you if you feel that the PHI is incorrect or otherwise incomplete. Under certain circumstances, we may deny your request for an amendment. If we deny the request, you will have the right to have the denial reviewed by someone we designate who was not involved in the initial review. You may also ask the Secretary of the United States Department of Health and Human Services (“HHS”), or their appropriate designee, to review such a denial.
The Right to Receive an Accounting of Disclosures of Your PHI – You have the right to receive an accounting of certain disclosures of your PHI made by the pharmacy.
To Receive Additional Copies of The Pharmacy’s Notice of Privacy Practices – You have the right to receive additional paper copies of this Notice upon request, even if you initially agreed to receive the Notice electronically.
To Notification of Breaches – You will be notified of any breaches that have compromised the privacy of your PHI.

REVISIONS TO THE NOTICE OF PRIVACY PRACTICES

The pharmacy reserves the right to change or revise this Notice and make the new revised version applicable to all PHI received before its effective date. The pharmacy will also post the revised version of the Notice in the pharmacy.

COMPLAINTS

If you believe your privacy rights have been violated, you may file a complaint with ProxsysRx or HHS. If you wish to file a complaint with the pharmacy, please contact the Privacy Officer at (866) 959-7979 or email Compliance@proxsysrx.com. If you wish to file a complaint with HHS, visit www.hhs.gov/hipaa. The pharmacy will not take any adverse action against you as a result of your filing a complaint.

CONTACT INFORMATION

If you have any questions on the pharmacy’s privacy practices or for clarification on anything contained within the Notice, please contact:

ProxsysRx, Inc.
Attn: Privacy Officer
1500 Urban Center Dr, Ste 325
Birmingham, AL 35242
Tel: (866) 959-7979

Email: Compliance@proxsysrx.com

Website: ProxsysRx.com