Consumer Health Data Privacy Notice

Effective Date: May 31, 2024

This Consumer Health Data Privacy Policy supplements Simply Medical's existing Privacy Notice. This supplemental notice explains your rights and how we handle your personal data that may be considered “Consumer Health Data” under Washington’s My Health My Data Act.

Certain terms in this supplemental notice are defined by applicable state law and their meanings may differ from the meanings applied elsewhere on our website.  We may periodically update this Privacy Policy.  If we make material changes, we will post a notice of the material changes on our website.  We encourage you to periodically review this Privacy Policy for the latest information on our privacy practices.  

Sources of Personal Data

We collect personal data from the following categories of sources:

  • Directly from you when you provide information
  • Our affiliates and business partners
  • Data verification services & data brokers
  • Marketing vendors and advertising networks
  • Social media
  • Healthcare providers

Personal Data We May Collect

We collect or process the following categories of personal data:

  • Identifiers, such as real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, signature, physical characteristic or description, telephone number, insurance policy numbers, employment status, or employment history
  • Characteristics of protected classifications, such as race, sex, disability, national origin, marital status
  • Commercial information, including records of personal property, products or services purchased, obtained, or considered or other purchasing histories or tendencies
  • Biometric information
  • Internet or other electronic network activity, including, but not limited to, browsing history, search history, and information regarding interactions with the site
  • Geolocation data
  • Audio, electronic, visual, thermal, olfactory, or similar information
  • Professional or employment-related information
  • Education information
  • Inferences drawn from any of the information identified above to create a profile about you that reflects your preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligences, abilities, and aptitudes.

We collect or process the following categories of sensitive personal data:

  • Social security number
  • Driver’s license number
  • Passport number
  • State identification card
  • Medical information
  • Health insurance information
  • Financial information such as, bank account information, credit or debit card number, account log-in, account numbers, required security or access code, password, or credential(s) allowing access to the account
  • Precise geolocation
  • Racial or ethnic origin, religious or philosophical beliefs, or union membership
  • Genetic data
  • Biometric information, such as audio, electronic, visual, thermal, olfactory, or similar information
  • Personal information collected and analyzed concerning your sex life or sexual orientation
  • Personal information collected and analyzed concerning your health

Processing, Disclosure, and Retention of Personal Data

The categories of data collected and listed above will be processed, disclosed, sold, shared, and retained as described below:

PROCESSING PURPOSE

Business Purposes:

  • To perform the business services you have requested and/or to provide reasonably expected goods
  • To develop new products and services
  • To provide personalized and non-personalized offers and services based on your interactions with our site/product or affiliated vendors utilizing your browsing history, search history, and interactions with our site products, or services
  • To detect security incidents that compromise the availability, integrity, authenticity, and confidentiality of stored or transmitted personal information
  • To prevent malicious, deceptive, fraudulent, or illegal actions and to prosecute those responsible for those actions
  • To protect our rights, property, and safety or the rights, property, and safety of others
  • To perform services, such as maintaining or servicing accounts, providing customer service, processing, or fulfilling orders and transactions, verifying information, processing payments, providing financing, providing analytic services, or providing storage
  • To verify, analyze, maintain, or enhance the quality or safety of our products and services
  • To offer or provide employee benefits and services
  • To comply with legal obligations

COMMERCIAL PURPOSES

  • For targeted advertising. We utilize cookies, pixels, and other advertising technology to provide users personalized ads
  • For profiling in furtherance of decisions that produce legal or similarly significant effects concerning a consumer

CATEGORIES OF THIRD PARTIES TO WHICH WE DISCLOSE THAT PERSONAL DATA 

  • Our vendors and service providers
  • Healthcare providers
  • Advertising networks, who may use your browsing history, search history, and information regarding your interaction with the site
  • Our affiliates and business partners
  • Law enforcement, when required by law

CATEGORIES OF THIRD PARTIES TO WHICH WE “SOLD” OR “SHARED” THAT PERSONAL DATA 

  • Our vendors and service providers
  • Healthcare providers
  • Advertising networks, who may use your browsing history, search history, and information regarding your interaction with the site
  • Our affiliates and business partners

We do not knowingly sell or share personal data of residents under the age of 16.

We sell or share de-identified information. De-identified information is data that is no longer considered individually identifiable, cannot be reasonably linked to an identified or identifiable person or a device linked to that individual, and has been deidentified in compliance with either the HIPAA expert determination method or the HIPAA safe harbor method as described in Sections 164.514(b)(1) and (2) of the Code of Federal Regulations.

Retention

We retain your data in accordance with applicable contracts, Terms of Service, regulatory/legal obligations, or as otherwise allowed.

There are times when personal data is disclosed externally with other companies, organizations, or individuals when we have a good faith belief that access, use, preservation, or disclosure of that data is reasonably necessary to:

  • Meet applicable laws, regulations, legal processes, or enforceable governmental requests
  • Enforce applicable Terms of Service, including investigation of potential violations
  • Detect, prevent, or otherwise address fraud, security, or technical issues
  • Protect against harm to the rights, property or safety of our users, McKesson, or the public as required or permitted by law
  • Engage in a merger, acquisition, reorganization, or sale of all or a portion of the business’s assets
  • Or fulfill other lawful purposes

How to exercise your rights related to Consumer Health Data

You are afforded the following rights. If you or your authorized representative would like to exercise one of your rights, please use the applicable link below. Should you exercise one of your rights, we may require certain identifying data from you or your authorized representative to verify your request. We will honor your request if it complies with applicable state privacy laws.  Please note that these rights may not be absolute and exceptions to these rights may apply.  Questions and concerns can be emailed to Privacy@McKesson.com.

You will not be discriminated against in any way by virtue of your exercise of the rights listed in this Privacy Notice which means, for example, we will not deny goods or services to you, provide different prices or rates for goods or services to you, or provide a different level or quality of goods or services to you. 

WASHINGTON

The right to confirm whether we are processing your personal data and access such data. You can exercise this right by clicking HERE.

The right to delete personal data provided by or obtained about you. You may ask that we delete certain personal data we have collected about you. You can exercise your right to delete by clicking HERE.

Contact Information

If required, we will provide you the opportunity to appeal certain decisions made by us related to your rights. For each request you submit, we will inform you of the action we have taken in response to your request. If your state requires it, you will be provided the opportunity to appeal our decision by following the instructions in our response.

If you have questions or concerns about this Privacy Notice, you may contact us at Privacy@McKesson.com.