Lux Health, LLC d/b/a Health Convenience
Consumer Health Data Privacy Policy
Washington My Health My Data Act, Nevada SB 370, Connecticut Data Privacy Act, and other state consumer health data privacy laws
Effective Date: March 19, 2026
Lux Health, LLC, d/b/a Health Convenience ("Company," "we," "us," or "our") is committed to protecting your consumer health data. This Consumer Health Data Privacy Policy ("Policy") is provided in compliance with the Washington My Health My Data Act (RCW 19.373), Nevada SB 370, the Connecticut Data Privacy Act (health data provisions), and other applicable state consumer health data privacy laws. This Policy supplements our Privacy Policy and Notice of Privacy Practices and applies to consumer health data that may fall outside the scope of HIPAA.
This Policy applies to residents of states that have enacted specific consumer health data privacy laws, including but not limited to Washington, Nevada, and Connecticut. If you are not a resident of a covered state, this Policy is provided for your information and transparency.
1. What Is Consumer Health Data?
"Consumer health data" means personal information that is linked or reasonably linkable to a consumer and that identifies the consumer's past, present, or future physical or mental health status. This includes, but is not limited to:
- Individual health conditions, treatment, diseases, or diagnoses
- Social, psychological, behavioral, and medical interventions
- Health-related surgeries or procedures
- Use or purchase of prescribed medications
- Bodily functions, vital signs, measurements (e.g., heart rate, blood pressure, body temperature)
- Diagnoses or diagnostic testing, treatment, or medication
- Gender-affirming care information
- Reproductive or sexual health information
- Biometric data
- Genetic data
- Precise location information that could reasonably indicate a consumer's attempt to acquire or receive health services or supplies
- Data that identifies a consumer seeking healthcare services
Consumer health data does not include information used to engage in public or peer-reviewed scientific, historical, or statistical research that is in the public interest and that adheres to all applicable ethics and privacy laws.
2. Consumer Health Data We Collect
In connection with providing our Services, we may collect the following categories of consumer health data:
- Health conditions and symptoms you report through intake forms, questionnaires, or consultations
- Medication and prescription information
- Treatment plans and clinical notes
- Telehealth consultation records
- Laboratory and diagnostic test results
- Biometric identifiers (if collected as part of health assessments)
- Precise geolocation data (to verify you are in an authorized state for telehealth services)
3. How We Collect Consumer Health Data
- Directly from you when you complete intake forms, questionnaires, or participate in telehealth consultations
- From healthcare providers involved in your care
- From pharmacies and laboratories
- Through our Website and patient portal (e.g., location data, device information)
- From third-party sources authorized by you
4. Purposes for Collecting Consumer Health Data
We collect and use consumer health data for the following purposes:
- To provide healthcare services, including telehealth consultations, diagnosis, and treatment
- To fulfill prescriptions and coordinate with pharmacies
- To coordinate care with other healthcare providers, laboratories, and specialists
- To verify your geographic location for telehealth eligibility
- To process payments and manage billing
- To communicate with you about your care, appointments, and account
- To comply with legal and regulatory obligations
- To improve the quality and safety of our Services
- To conduct internal analytics and quality improvement
We will not collect consumer health data for purposes beyond those disclosed in this Policy without first obtaining your affirmative consent.
5. With Whom We Share Consumer Health Data
We may share your consumer health data with the following categories of recipients:
Healthcare Providers
Physicians, specialists, and other licensed healthcare providers involved in your treatment and care coordination.
Pharmacies
For the purpose of fulfilling prescriptions, verifying medication history, and checking drug interactions.
Laboratories
For the purpose of ordering, performing, and reporting clinical tests and results.
Payment Processors
For the purpose of processing payments for services rendered.
Business Associates/Service Providers
Third parties who perform services on our behalf under written agreements requiring them to protect your data.
Health Information Exchanges (HIEs)
To facilitate electronic sharing of health information among authorized providers involved in your care.
As Required by Law
In response to court orders, subpoenas, or other legal obligations.
We do not sell your consumer health data. We do not share your consumer health data for advertising or marketing purposes without your express opt-in consent.
6. Your Rights
A. Washington Residents (My Health My Data Act)
If you are a Washington resident, you have the following rights under the Washington My Health My Data Act (RCW 19.373):
- Right to Know: You have the right to confirm whether we are collecting, sharing, or selling your consumer health data, and to know the specific consumer health data we have collected about you
- Right to Withdraw Consent: You have the right to withdraw your consent to the collection, sharing, or sale of your consumer health data at any time. Withdrawal of consent does not affect the lawfulness of processing performed prior to withdrawal
- Right to Deletion: You have the right to request that we delete your consumer health data, subject to legal exceptions
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your rights under this Act
An authorized agent may exercise these rights on your behalf with valid proof of authorization.
B. Nevada Residents (SB 370)
If you are a Nevada resident, you have the right to opt out of the sale of your personal information, including health-related data. To exercise this right, contact us at support@healthconvenience.com.
We do not currently sell consumer health data. If our practices change, we will update this Policy and provide you with the opportunity to opt out before any sale occurs.
C. Connecticut Residents
If you are a Connecticut resident, you have the following rights under the Connecticut Data Privacy Act (health data provisions):
- Right to Consent: We will obtain your consent before collecting or sharing your consumer health data for purposes beyond providing the Services you requested
- Right to Access: You have the right to access the consumer health data we maintain about you
- Right to Correct: You have the right to correct inaccurate consumer health data
- Right to Delete: You have the right to request deletion of your consumer health data
- Right to Data Portability: You have the right to obtain a copy of your consumer health data in a portable, machine-readable format
D. Other States
Residents of other states that have enacted or may enact consumer health data privacy laws (including but not limited to Colorado, Virginia, Oregon, and any future state legislation) may have similar rights. We will comply with all applicable consumer health data privacy laws. If you believe you have rights under your state's laws, please contact us and we will evaluate your request.
7. How to Exercise Your Rights
To exercise any of the rights described in this Policy, please contact us using one of the following methods:
- Email: support@healthconvenience.com
- Phone: 786-863-6314
- Through the "Your Privacy Choices" link on our Website
We will verify your identity before processing your request. Verification may require you to provide information that matches our records. We will respond to verified requests within the timeframes required by applicable law (generally within 45 days for Washington residents, or as otherwise required).
If we deny your request, we will provide you with a written explanation of the basis for the denial and instructions for how to appeal the decision.
8. Consent
Where required by applicable law, we obtain your affirmative consent before collecting, using, or sharing your consumer health data. Consent may be obtained through:
- Electronic signature or checkbox on intake forms
- Written consent forms
- Clear affirmative action (e.g., clicking "I Agree" or "Accept")
You may withdraw your consent at any time by contacting us using the methods described above. Withdrawal of consent will not affect the lawfulness of processing performed prior to your withdrawal. Withdrawal of consent may affect our ability to provide certain Services to you.
9. Data Security
We implement administrative, technical, and physical safeguards to protect your consumer health data from unauthorized access, use, disclosure, alteration, or destruction. These measures include encryption, access controls, employee training, and regular security assessments. Despite our efforts, no security measure is entirely foolproof, and we cannot guarantee the absolute security of your data.
10. Data Retention
We retain consumer health data only for as long as necessary to fulfill the purposes described in this Policy, comply with legal obligations, resolve disputes, and enforce our agreements. Medical records are retained in accordance with applicable federal and state law, including Florida medical records retention requirements (generally a minimum of seven (7) years from the last entry).
11. Geofencing Prohibition
In compliance with the Washington My Health My Data Act and similar laws, we do not use geofencing technology around healthcare facilities (including hospitals, clinics, mental health facilities, reproductive health clinics, or substance abuse treatment centers) for the purpose of identifying or tracking consumers seeking healthcare services, collecting consumer health data, or sending notifications, messages, or advertisements to consumers based on their proximity to such facilities.
12. Changes to This Policy
We reserve the right to update this Consumer Health Data Privacy Policy at any time. If we make material changes, we will notify you by posting the updated Policy on our Website and, where required by law, obtaining your consent to the material changes. Your continued use of our Services after the effective date of any changes constitutes acceptance of the revised Policy.
13. Contact Information
Lux Health, LLC, d/b/a Health Convenience
Email: support@healthconvenience.com
Phone: 786-863-6314
Website: healthconvenience.com
Questions? Contact Lux Health, LLC d/b/a Health Convenience at support@healthconvenience.com or (786) 863-6314. Website: healthconvenience.com