Privacy Policy
Last updated: August 5, 2026
1. Introduction and Scope
This Privacy Policy describes how Living Patterns Readings ("LPR," "we," "us," or "our") collects, uses, discloses, retains, and protects information in connection with the LPR Workflow Software platform and related websites and services (the "Platform").
LPR acts in two capacities: (a) as a service provider and Business Associate with respect to Protected Health Information ("PHI") that Customer clinics upload, generate, or maintain on the Platform for their patients; and (b) as a business with respect to commercial account, billing, support, and workforce contact data of clinic customers and prospective customers.
Patients access clinic workflows through Secure Patient Links that Customer authorizes (for example, for intake, document upload, package selection, policy acknowledgment, viewing a released report, browsing released care documents, or secure messaging with the clinic). Those links may require the patient to verify identity using information the clinic maintains, such as date of birth and last name. There is no passworded patient portal account; demographic updates are made by the clinic on request.
For patient-facing privacy matters relating to treatment and clinic health records, patients should contact their clinic (the Covered Entity). Clinic-authored privacy notices, notices of privacy practices, and consents govern those patient-facing matters. This Privacy Policy governs LPR's relationship with clinic customers and how LPR processes information as vendor and Business Associate.
This Privacy Policy was last updated on August 5, 2026 (version 2026-08-05.1).
2. Categories of Information We Collect
Depending on how the Platform is used, we may collect the following categories of information:
- Identifiers and contact data: name, email address, telephone number, account identifiers, and clinic legal and display names.
- Commercial and account data: role (for example, clinic owner or practitioner), subscription metadata, billing history references, and communications with support.
- Workforce authentication data: password hashes and multi-factor authentication secrets or device registrations for clinic users who create accounts (we do not store plaintext passwords).
- Secure patient-access data: tokens or identifiers associated with Secure Patient Links, identity-verification outcomes (for example, successful match of date of birth and last name), scoped session records for link-based tasks, and related access logs.
- Payment metadata: subscription status and invoices processed through our payment processor. Payment card data is entered on the processor's hosted pages; LPR does not store full card numbers or CVV.
- PHI and clinical workflow data: patient demographics and contact information; assessment responses (including Meridian Assessment Form and related questionnaires); laboratory documents and extracted lab values; clinical reports; uploaded documents; package and checklist status; notes; in-app secure message thread content between patients and clinic workforce (care-coordination messaging); and other health information Customer chooses to enter into the Platform, processed solely as a Business Associate.
- Internet and technical data: IP address, user agent, device/browser type, timestamps, referral URLs where applicable, and security and access logs.
- Audit and compliance data: records of legal acceptances, policy publications, access events, and administrative actions retained for security and regulatory purposes.
3. Sources of Information
- Information you provide directly when registering, inviting users (where team features are enabled), configuring a clinic, publishing patient policies, submitting support requests, or using Platform features.
- Information patients submit through Secure Patient Links, clinic policy acknowledgment flows, and secure messaging.
- Information workforce users submit through clinic accounts and practitioner workflows, including secure messages.
- Information generated by Platform use, including logs, workflow events, Secure Patient Link verification events, and acceptance records.
- Information from service providers that support hosting, email delivery, payments, and (where Customer enables them) laboratory or other integrations.
4. How We Use Information
- To provide, operate, maintain, secure, troubleshoot, and improve the Platform and customer support.
- To authenticate workforce users, operate Secure Patient Link identity checks and scoped sessions, enforce access controls (including multi-factor authentication for practitioner PHI access), detect fraud or abuse, and maintain audit trails.
- To process Subscriptions, invoices, and service, security, and billing communications to clinic customers.
- To process PHI only as permitted by the applicable Business Associate Agreement, Customer instructions, and applicable law.
- To host clinic-authored patient policies and record acceptances where the Platform provides that functionality, including via Secure Patient Links.
- To deliver clinic-authorized patient communications (for example, Secure Patient Link emails and notifications that a new secure message is available) using Customer-provided patient contact information. Message content for secure messaging remains in the Platform; such notices are designed not to include message bodies or other clinical content in email.
- To comply with law, respond to lawful requests, and establish, exercise, or defend legal claims.
- To analyze aggregated or de-identified usage for product improvement, capacity planning, and security, in a manner that does not identify individuals where required by the BAA or law.
5. PHI; Business Associate Role; No Sale of PHI
When we create, receive, maintain, or transmit PHI on behalf of a Customer clinic, we do so as a Business Associate under the HIPAA Privacy, Security, and Breach Notification Rules. Uses and disclosures of PHI are limited to those permitted by the BAA, the Customer's documented instructions, and applicable law.
We do not sell PHI. We do not use PHI for LPR's independent marketing to patients. Subcontractors that create, receive, maintain, or transmit PHI on our behalf are bound by written agreements imposing restrictions no less protective than those applicable to LPR with respect to such PHI. Categories of subprocessors may be provided to Customer clinics upon reasonable request.
6. How We Disclose Information
- To Customer's authorized workforce for that clinic's patients and clinic administration, according to roles Customer configures (including the clinic owner and practitioners).
- To subprocessors under appropriate agreements (for example: cloud hosting, email delivery, payment processing for clinic Subscriptions, and laboratory or other integrations Customer enables).
- To professional advisors under confidentiality obligations where reasonably necessary.
- As required by law, regulation, legal process, or governmental request, or to protect the rights, safety, and security of LPR, our users, patients, or the public.
- In connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, subject to continued protections for PHI under HIPAA and comparable contractual protections for other personal information.
7. California Commercial Privacy (CCPA/CPRA) — Clinic Customer Data
For personal information of clinic owners and workforce that is not PHI maintained by LPR as a Business Associate, California residents may have rights under the California Consumer Privacy Act, as amended by the CPRA, including rights to know/access, delete, correct, and opt out of certain sharing, subject to exceptions and verification.
PHI that LPR maintains as a Business Associate is generally exempt from CCPA to the extent it is protected health information collected by a covered entity or business associate governed by HIPAA. Clinic customers may submit commercial-data privacy requests to the contact below. We will respond within applicable statutory timeframes (typically forty-five (45) days, subject to permitted extensions).
We do not sell personal information of clinic customers as "sale" is commonly understood, and we do not knowingly sell or share personal information of consumers under sixteen (16) years of age. If we engage in "sharing" for cross-context behavioral advertising within the meaning of CPRA with respect to non-PHI commercial data, we will provide a required opt-out mechanism; the authenticated Platform does not use advertising trackers for that purpose.
8. Patient Rights Requests
Patients seeking access, amendment, restriction, confidential communications, or an accounting of disclosures regarding their health information should contact their clinic (the Covered Entity). LPR will assist the clinic as required under the BAA and HIPAA. LPR does not independently fulfill patient rights requests directed solely to LPR except as Required by Law or as directed by the Covered Entity in accordance with the BAA.
9. Security
We implement administrative, physical, and technical safeguards designed to protect information, including measures appropriate to our role as a Business Associate with respect to ePHI. Safeguards include, without limitation:
- Encryption of data in transit using TLS, with HSTS enforced where configured.
- Password hashing using industry-standard algorithms for account holders; secrets encrypted at rest using strong cryptography.
- Session controls for workforce accounts and for scoped Secure Patient Link sessions; account lockout after repeated failed workforce logins; multi-factor authentication required for practitioner access to PHI, subject to a short initial enrollment grace period of seven (7) days from account creation (or such other period as documented in-product).
- Identity verification steps for Secure Patient Links as configured for the task (for example, date of birth and last name matching), including links used for secure messaging sessions.
- Role-based access within clinics and audit logging of relevant PHI access and administrative events (including secure messaging access and send events where logged).
- Workforce and vendor controls appropriate to the Services.
No method of transmission or storage is completely secure. Customer remains responsible for safeguarding workforce credentials, authorizing Secure Patient Links only to intended recipients, maintaining accurate patient identity data used for verification, and securing Customer-controlled systems used to access the Platform.
10. Retention
We retain clinic account, billing, and audit information for as long as needed to provide the Platform, meet legal and contractual obligations, resolve disputes, and enforce agreements. HIPAA-related audit and security logs are retained for at least six (6) years or as otherwise required by law or contract. PHI retention, return, and destruction after termination of services are governed by the BAA, including limited carve-outs for encrypted rolling backups (up to seven (7) days), mandatory audit archives, and a clinic-owner export or offboarding window of thirty (30) days after subscription termination or inactivation.
11. Cookies and Similar Technologies
We use cookies and similar technologies necessary for authentication, Secure Patient Link and workforce session management, security, and basic Platform operation (including httpOnly, Secure, and SameSite attributes as configured). We do not use advertising cookies or third-party marketing pixels on authenticated or patient-access portions of the Platform. Disabling necessary cookies may prevent account login, Secure Patient Link sessions, or other core functionality.
12. Children
The Platform is directed to clinics and adult practitioners. LPR does not knowingly collect commercial personal information directly from children under thirteen (13) for LPR's own purposes. Patient information concerning minors may be processed solely as a Business Associate when submitted by or at the direction of a Customer clinic in connection with care.
13. International Users
The Platform is operated primarily for Customers in the United States. If you access the Platform from outside the United States, you acknowledge that information may be processed and stored in the United States, where laws may differ from those of your jurisdiction.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Material changes may require clinic re-acceptance before continued PHI-related use. The version and last-updated date identify the operative text. Continued use after the effective date of non-material changes constitutes acceptance where permitted by law.
15. Contact
Privacy inquiries from clinic customers may be directed to Living Patterns Readings at support@livingpatternsreadings.com, or via https://app.livingpatternsreadings.com. Complaints regarding HIPAA may also be filed with the U.S. Department of Health and Human Services Office for Civil Rights.