1. Purpose
This Data Rights & Privacy Addendum describes how QwikCare, a service of Lemur PBC, collects, uses, shares, and protects personal and health information when you use the QwikCare iOS app to complete a 10 USD encounter for a one-year COVID vaccine prescription. It supplements (and should be read together with) the QwikCare User Agreement and Lemur PBC's HIPAA Notice of Privacy Practices (NOPP).
In the event of a conflict between this page and the HIPAA NOPP, the HIPAA NOPP controls how Lemur PBC uses and discloses protected health information (PHI) under applicable law.
2. Information We Collect
Depending on how you use QwikCare, Lemur PBC may collect the following categories of information:
- Account and contact information. Name, email address, phone number, state or jurisdiction, and limited device metadata (such as device model and operating system) needed to operate the app, send appointment-related communications, and verify your account.
- Demographic information. Date of birth, age group, and similar fields needed to determine eligibility and appropriate vaccine formulations.
- Health information related to COVID vaccination. Medical history, allergies, prior vaccine history, and responses to pre-screening questions that you provide so that Lemur providers can evaluate whether a COVID vaccine prescription is appropriate.
- Encounter and prescription information. Information about your QwikCare encounter, such as dates, provider notes, and the fact that a prescription was issued, as part of your medical record.
- Device and usage information. Log data, approximate location (such as state), and app interaction data used to maintain security, troubleshoot, and improve the service.
- Support and communications. Messages you send to Lemur support or your provider, including attachments such as screenshots or documents you choose to upload.
- Optional data sources. If you choose, QwikCare may access or receive limited information from:
- Apple Health, to help you track COVID vaccinations and other relevant immunizations on your device; and
- Insurance cards or identity documents that you scan or upload to support coverage verification, pharmacy billing, or identity verification.
3. How Your Information Is Used
Lemur PBC uses your information primarily to provide clinical services and operate QwikCare safely. This includes:
- Clinical evaluation and prescribing. Providers use your health information and screening responses to determine whether a COVID vaccine prescription is medically appropriate and to issue a one-year prescription when indicated.
- Care coordination with pharmacies. Your prescription and related information may be used to help ensure that pharmacies can verify that a valid prescription exists, when you present it.
- Operations and quality improvement. We use aggregated and de-identified data to understand how QwikCare is used, improve workflows, and monitor quality and safety.
- Security, fraud prevention, and abuse monitoring. We use device, usage, and identity information to help prevent fraud, abuse, and misuse of medical credentials.
- Regulatory and legal compliance. We may use your information to comply with record-keeping requirements, respond to lawful requests, and support public-health reporting where required by law.
- Communications with you. We use contact information to send you appointment reminders, prescription updates, and important notices about your care or the app.
4. How Your Information Is Shared
Lemur PBC does not sell or rent patient data. We do not share your personal health information with third parties for their independent advertising or marketing.
We may share your information in the following ways, consistent with our HIPAA obligations and this addendum:
- Lemur PBC clinical teams. Doctors, nurse practitioners, and authorized clinical staff access your information to provide care, review encounters, and manage prescriptions.
- Your pharmacies and other providers. When you choose to show or share your prescription or related records, those recipients may use the information for treatment, payment, and health-care operations under their own policies and legal obligations.
- Service providers and business associates. Vendors that provide hosting, secure messaging, analytics, e-signature, or similar services may process data on our behalf under contracts or business associate agreements that limit their use of your information.
- Payers and insurers. If you choose to submit claims or otherwise involve an insurance plan, we may share the minimum necessary information with that plan, subject to your authorization and applicable law.
- Regulators and legal authorities. We may share information when required by law, court order, subpoena, or public-health reporting obligations.
- De-identified or aggregated data. We may share or publish de-identified or aggregated information that does not reasonably identify you, for purposes such as research, analytics, or public reporting.
5. Storage and Control
QwikCare is designed so that patients have strong control over their prescriptions and key records, particularly on their own iOS devices:
- Prescription PDFs on your device. Signed prescriptions are delivered into the app on your device. You may show, print, or share them. We do not maintain separate public copies of your prescription PDFs outside of secure clinical systems required for care and compliance.
- Apple Health storage. When you choose to sync vaccine information with Apple Health, the data is stored and controlled under Apple's HealthKit framework, and subject to Apple's policies. You can revoke access at any time.
- Encryption. We use reasonable technical and organizational measures, including encryption in transit and at rest, to protect data we store on our systems.
- Device loss or replacement. If you lose your device, you may need to re-authenticate, restore from an Apple backup, or contact Lemur support to help re-establish access where permitted by law and internal policy.
6. Your Rights
Your rights under HIPAA and applicable privacy laws are described in more detail in Lemur PBC's HIPAA Notice of Privacy Practices. In general, and subject to legal and clinical limits, you may have rights to:
- Access. Request access to certain information in your medical record.
- Correction. Request corrections to incomplete or inaccurate information.
- Restriction. Request certain limits on how your information is used or disclosed, where the law allows.
- Confidential communications. Request that we contact you in a specific way (for example, at a particular email address or phone number).
- Accounting of disclosures. Request a list of certain disclosures we have made of your information.
- Copy or export. Obtain copies of certain records, including electronic copies where required.
Some requests may be limited or denied when allowed by law (for example, when records relate to quality review or legal matters), but we will explain the reason and describe any available appeals process.
7. Retention
Lemur PBC maintains medical records, encounter data, and related documentation for as long as required by applicable law, clinical standards, or contractual obligations. Retention periods may vary by state and by record type.
We may retain de-identified or aggregated data that no longer identifies you for analytics, research, or reporting, and this data may be kept for longer periods.
8. Contact
If you have questions about this Data Rights & Privacy Addendum, or if you wish to exercise your privacy rights, you may contact us at:
- Email (privacy): privacy@lemurpbc.com
- Email (prescriptions/support): prescriptions@lemurpbc.com
Our HIPAA Notice of Privacy Practices is available in the app and on our website under HIPAA NOPP.
9. Acknowledgment
- Your personal and health data will be used to deliver QwikCare encounters, prescriptions, and related services.
- Lemur PBC will protect your information under HIPAA and applicable privacy laws.
- Lemur PBC will not sell or rent your patient data to third parties or share it for their independent marketing campaigns.
- You control when and how your prescription PDFs and vaccine records are shared from your device and, if you choose to use it, from Apple Health.