PRIVACY POLICY FOR “LOGIN WITH ATHENAHEALTH” USER ACCOUNTS
(LWA USER PRIVACY POLICY)

Last Revision Date: June 20, 2019

Please read the following terms carefully as they relate to LOGIN WITH ATHENAHEALTH. If you do not wish to create a LOGIN WITH ATHENAHEALTH account, but still wish to access the Patient Portal, please contact athenahealth to obtain credentials that can be used to only access the Patient Portal at: athenaIdentityAccount@athenahealth.com. So that we can locate your account, in the body of the email, please provide your full name, date of birth, practice name of the portal you wish to access and your state of residence. This information will be used only for purposes of identification and to facilitate your request.

WHO WE ARE

We, athenahealth, Inc. and our subsidiaries and affiliates (collectively, “athenahealth”, "we", "us"), services providers and health systems throughout the United States to help deliver better care for all. We offer integrated health care solutions for our clients, including medical groups, practices, hospitals, health systems, and for physicians, specialists, staff and patients. We also offer a single sign on service "LOGIN WITH ATHENAHEALTH",("LWA") to make it easier for users to access various products and services offered separately by athenahealth as well as those of our clients and other third parties. We refer to all of our websites, applications, products, services, and solutions collectively as our "Services."

SCOPE AND PURPOSE:

This LWA User Privacy Policy focuses on information we collect in connection with your registration for an account with LWA and maintenance of that LWA account and any related LWA user profile. Our LWA Terms of Use also apply to your LWA account. Additional specific privacy policies, terms and agreements may also apply to any particular Services you use, whether through your LWA account or otherwise, including policies, terms and agreements for: our main website www.athenahealth.com; our athenahealth platforms (e.g., athenaCollector, athenaClinicals, athenaCommunicator, athenaCoordinator, athenaNet etc.); our athenahealth product offerings (e.g., athenaText or Epocrates®); our athenahealth Patient Portal; and any of our other websites, products, services, solutions or applications. If you use LWA to access or share data with any websites, applications, platforms, services, solutions or portals of any third parties (including any patient portals offered by any healthcare provider(s)) (each, a "Third Party Platform"), the privacy policies, terms and agreements of such Third Party Platforms will apply to your use of such Third Party Platform. We do not control and are not responsible for Third Party Platforms or any information you may share with, or access from, any Third Party Platforms, whether using LWA or otherwise.

LWA is not intended for use by anyone outside of the United States.

Any unauthorized registration for, access or use of LWA, our Services, client accounts or Third Party Platforms is strictly prohibited.

COLLECTION OF INFORMATION

We may collect the following types of information in connection with your LWA account:

In addition, we may collect other information as permitted under applicable law and any applicable contracts with our clients.

USE OF INFORMATION

We may use information collected in connection with your LWA account to:

In addition, we may use information in other ways as permitted under applicable law and any applicable contracts with our clients.

SHARING OF INFORMATION

We may share information regarding your LWA account:

We may also share information regarding your LWA account:

In addition, we may share information as permitted under applicable law and any applicable contracts with our clients.

COOKIES

We may use cookies and similar tracking technologies. A "cookie" is a unique numeric code that we transfer to your device so that we can keep track of your interests and/or preferences and recognize you as a return user of our Services. We may use cookies, log files, pixel tags, web bugs, web beacons, clear GIFs, Local Storage Objects (LSOs) such as HTML5 and Flash or other similar technologies to collect information related to your LWA account, to support and enhance features and functionality, to monitor performance, to personalize content and experiences, for marketing, advertising and analytics, and for other lawful purposes.

We may use the following types of cookies and similar technologies:

Most internet browsers accept cookies by default. You can block cookies by activating the setting on your browser that allows you to reject all or some cookies. The help and support area on your internet browser should have instructions on how to block or delete cookies. Some web browsers (including some mobile web browsers) provide settings that allow you to control or reject cookies or to alert you to when a cookie is placed on your computer, tablet or mobile device. Although you are not required to accept cookies, if you block or reject them, you may not have access to all of the features available through your LWA account. Your LWA account also may not recognize if your browser sends a "do not track" signal or similar mechanism to indicate you do not wish to be tracked or receive interest-based ads.

For more information, visit the help page for your web browser or see http://www.allaboutcookies.org or visit www.youronlinechoices.com which has further information about behavioral advertising and online privacy.

We may use third party analytics such as Google Analytics or similar analytics services. For information on how Google processes and collects your information regarding Google Analytics and how you can opt-out, please see https://tools.google.com/dlpage/gaoptout.

DATA RETENTION

To the extent permitted by applicable law and any applicable client agreements (if any are applicable), we may retain your information for as long as needed to comply with our legal obligations (including to you, to our clients or to any third parties), to resolve disputes, to enforce our legal rights, policies, terms and agreements, for marketing or analytic purposes, for security purposes, or for as long as is reasonably necessary for other lawful purposes.

SECURITY OF INFORMATION

Security is of the utmost importance for athenahealth. athenahealth uses technical and physical safeguards to protect the security of your information from unauthorized disclosure. However, security cannot be guaranteed against all threats.

You may not assign or transfer your LWA account or share your LWA login, password or any other credentials with any other person without our consent. Please notify us immediately if you believe the security of your LWA account may have been compromised.

ACCESSING AND UPDATING YOUR INFORMATION

NOTICE REGARDING CHILDREN

athenahealth recognizes the importance of protecting the privacy and safety of children. LWA accounts are not intended for users under the age of thirteen (13) years old, and such users are not authorized to have LWA accounts. If you believe we have collected data from a user under thireen (13) years old without the consent of their parent or legal guardian, please let us know immediately by contacting us as indicated below and provide sufficient information so we can act appropriately on your request.

CALIFORNIA PRIVACY RIGHTS NOTICE

California residents may request certain information regarding our disclosure (if any) of personal information to third parties for their direct marketing purposes, pursuant to California Civil Code Section 1798.83. To make such a request, please contact us as listed below, identify yourself as a California resident, and provide sufficient information so we can take appropriate action, such as your name, email address, and LWA account.

TELEPHONE CONSUMER PROTECTION ACT (TCPA) NOTICE

In connection with your LWA account, athenahealth may need to send business, informational, support and security related messages (whether texts, alerts or calls) to all telephone numbers, including cellular numbers or mobile devices, you choose to provide on your LWA account. You agree such texts or calls may be pre-recorded messages or placed with an automatic telephone dialing system. In addition, you agree that athenahealth may send service or account related text messages to cellular phone numbers you provide to athenahealth, and you agree to accept and pay all carrier message and data rates that apply to such text messages. If you choose to provide an e-mail or other electronic address on your LWA account, you acknowledge and consent to receive business and informational messages relating to your LWA account at the address, and you represent and warrant that such address is your correct address and is not accessible or viewable by any other person.

DISPUTES

Unless otherwise required by applicable law, or otherwise specified in other athenahealth terms applicable to the specific Services you are accessing or using through your LWA account (and then only to the extent that the dispute relates solely to such specific Services), you agree that all provisions regarding disputes set forth in our LWA Terms of Use also apply to any disputes related to this LWA User Privacy Policy, including without limitation, choice of law, forum, service of process, mediation or arbitration, waiver of rights to trial by jury and agreement not to assert any claims in a consolidated or class action.

QUESTIONS/UPDATES TO THIS LWA USER PRIVACY POLICY

This LWA User Privacy Policy may change from time to time. Your registration or maintenance of your LWA account or any related LWA user profile after we make changes is deemed to be acceptance of those changes. Please check periodically for updates. To the extent required by applicable law, athenahealth will also attempt to notify you when we make material changes to this LWA User Privacy Policy.

CONTACT

If you have any questions about this LWA User Privacy Policy or any other aspects of your privacy with respect to athenahealth, please contact us at: athenahealth, Inc., Attn: Chief Compliance Officer, 311 Arsenal Street, Watertown, MA 02472.