CareSwaps, LLC (the “Company,” “we,” “us,” or “our”) respects your privacy and are committed to protecting it through our compliance with this Privacy Policy (this “Privacy Policy”).
This Privacy Policy describes the types of information we may collect from you or that you may provide when you access and use www.careswaps.com (“CareSwaps”) or www.patientswaps.com (“PatientSwaps”) (collectively, the “Websites”), including any products or services offered on or through the Websites (collectively referred to as the “Services”), whether as a guest or a registered user, and our practices for collecting, using, maintaining, protecting, and disclosing that information.
The Company operates two related web-based platforms:
This Privacy Policy applies to information we collect from CareSwaps and PatientSwaps users:
It does not apply to information collected by:
Please read this Privacy Policy carefully to understand our policies and practices regarding your information and how we will treat it. If you do not agree with our policies and practices, your choice is not to use our Websites or the Services. By accessing or using the Websites and the Services, you agree to this Privacy Policy. This Privacy Policy may change from time to time (see Changes to This Policy in Section 10 below). Your continued use of the Websites or the Services after we make changes is deemed to be acceptance of those changes, so please check the Privacy Policy periodically for updates.
We collect several types of information from and about users of our Websites and Services, including information:
We collect this information:
The information we collect on or through our Websites and Services may include:
For CareSwaps users we may also collect:
For PatientSwaps users we may also collect:
As you navigate through and interact with our Websites and Services, we may use automatic data collection technologies to collect certain information about your equipment, browsing actions, and patterns, including:
The information we collect automatically may include personal information, or we may maintain it or associate it with personal information we collect in other ways or receive from third parties. It helps us to improve our Websites and to deliver a better and more personalized service, including by enabling us to:
The technologies we use for this automatic data collection may include, without limitation:
Some content or applications, on the Websites are served by third parties, including content providers and application providers. These third parties may use cookies alone or in conjunction with web beacons or other tracking technologies to collect information about you when you use our Websites. The information they collect may be associated with your personal information or they may collect information, including personal information, about your online activities over time and across different websites and other online services.
We do not control these third parties’ tracking technologies or how they may be used. If you have any questions about targeted content, you should contact the responsible provider directly.
The Company is a healthcare technology platform. We are not a healthcare provider, and we are not a “Covered Entity” as defined by the Health Insurance Portability and Accountability Act (“HIPAA”). When the Company processes Protected Health Information (“PHI”) on behalf of a participating facility, we do so as a Business Associate under a Business Associate Agreement (“BAA”). In that context, HIPAA individual rights (such as the right to access, amend, or receive an accounting of disclosures of PHI) should generally be exercised through the applicable healthcare facility (the “Covered Entity”), not directly through the Company. If you wish to exercise a HIPAA right relating to PHI that we have processed on behalf of a facility, please contact the applicable facility directly.
Information submitted directly by patients, families, and caregivers through CareSwaps before any facility relationship exists (e.g., through an intake form) is protected under this Privacy Policy and applicable federal and state privacy and security laws. We apply HIPAA-compliant administrative, technical, and physical safeguards to this information as a matter of best practice. If and when that information is later shared with a facility under a BAA, it becomes subject to the BAA terms.
The Company will cooperate with facility requests to fulfill individual rights obligations as required by the applicable BAA. If a breach involves PHI that the Company processes on behalf of a facility, we will notify the applicable Covered Entity as required by the BAA and HIPAA (45 CFR § 164.410). The Covered Entity is responsible for providing notification to affected individuals, HHS, and (where applicable) the media, unless that obligation is expressly delegated to the Company under the BAA.
The Company may also have independent state-law breach notification obligations for personal information it holds directly (i.e., not under a BAA).
We use information that we collect about you or that you provide to us, including any personal information:
We do not: (a) sell personal data or PHI; (b) use PHI for advertising, marketing, or targeted content; or (c) use health information to make or influence clinical decisions.
We may de-identify information in accordance with HIPAA (45 CFR § 164.514(b)) such that there is no reasonable basis to believe the information can identify an individual. Properly de-identified information is not PHI and is not subject to HIPAA restrictions.
The Company may use de-identified and aggregated information for lawful business purposes, including:
We will not attempt to re-identify de-identified information and will not use de-identified data to contact or identify specific individuals.
We may disclose aggregated information about our users, and information that does not identify any individual, without restriction.
We may disclose personal information that we collect or you provide as described in this Privacy Policy:
We may also disclose your personal information:
For CareSwaps users, when a family user affirmatively opts into the matching process, we may share relevant information with participating facilities as needed to facilitate transfer matching. PHI is shared only with facilities that have executed a BAA with the Company. De-identified operational signals (such as geographic demand information) may be shared more broadly to notify facilities of interest, but never in a form that identifies a specific patient or family.
For PatientSwaps users, transfer-related information may be shared between facilities as directed by the referring facility and as permitted under the applicable BAA.
We use third-party service providers to operate our platforms. Each provider that processes PHI has executed a BAA with the Company. Providers that receive only de-identified or non-PHI data are bound by data processing agreements and confidentiality obligations. We use operational controls to segregate PHI from systems that do not require access to it. PHI is permitted only in systems covered by a BAA. Systems without a BAA receive only de-identified identifiers, operational data, or public business information, as currently designed. The Company periodically reviews its service provider arrangements to confirm compliance with these requirements.
We maintain a current list of service providers with PHI access. You may request this list any time by contacting privacy@careswaps.com.
The Company uses a minimal set of cookies and similar technologies on the Websites to:
These cookies include:
You can control cookies through your browser settings. Most browsers allow you to refuse or delete cookies. Disabling essential cookies may prevent you from using platform features that require authentication.
Depending on your jurisdiction and our relationship with you, you may have the right to:
To exercise any of these rights, contact privacy@careswaps.com. We will respond within 45 days (or such shorter period as applicable law requires).
Colorado residents may have additional rights under the Colorado Privacy Act (C.R.S. § 6-1-1301 et seq.) if the Company meets the applicable processing thresholds, including:
The Company does not sell personal data and does not engage in targeted advertising. If these practices change, we will update this Privacy Policy and provide opt-out mechanisms as required by the Colorado Privacy Act.
Residents of other states with comprehensive consumer privacy laws (such as California, Connecticut, Delaware, Florida, Indiana, Iowa, Montana, Oregon, Tennessee, Texas, Utah, and Virginia) may have similar rights under their respective statutes, including the rights to:
The exact scope of these rights may vary by state. To exercise any of these rights please send an email to: privacy@careswaps.com.
If your request relates to PHI that the Company processes on behalf of a healthcare facility under a BAA, HIPAA individual rights (including access, amendment, and accounting of disclosures) should be exercised through the applicable Covered Entity (the facility). Please contact the facility directly to exercise these rights. The Company will cooperate with the facility as required by the BAA.
If we deny a privacy rights request, we will explain the basis for the denial and you may appeal by responding to our denial communication. If we deny your appeal, you may file a complaint with the Colorado Attorney General (coag.gov) or, for PHI matters involving a Covered Entity, with the U.S. Department of Health and Human Services Office for Civil Rights (hhs.gov/ocr).
We have implemented measures designed to secure your personal information from accidental loss and from unauthorized access, use, alteration, and disclosure. The Company maintains administrative, physical, and technical safeguards designed to protect personal information and PHI, including:
PatientSwaps users may request integration with their existing Electronic Health Records (EHR) or healthcare information systems. The Company may support such integrations in the future and, if offered, will execute appropriate data sharing agreements with the facility’s vendor.
The safety and security of your information also depends on you. Where we have given you (or where you have chosen) a password for access to certain parts of our Websites or Services, you are responsible for keeping this password confidential. We ask you not to share your password with anyone.
Unfortunately, the transmission of information via the internet is not completely secure. Although we implement measures designed to protect your personal information, we cannot guarantee the security of your personal information transmitted to our Websites. Any transmission of personal information is at your own risk. We are not responsible for circumvention of any privacy settings or security measures contained on the Websites, except to the extent such circumvention results from our failure to maintain reasonable safeguards.
We retain information only as reasonably necessary to provide our services and comply with legal obligations:
When retention is no longer required, data is securely deleted or de-identified in accordance with applicable standards.
In the event of a security breach that results in the unauthorized access, acquisition, or disclosure of personal information, we will investigate the incident and take appropriate steps to mitigate any harm. Where required by applicable state or federal law (including, without limitation, breach notification requirements under Colorado law and any other state in which we operate) we will notify affected individuals and, where required, the appropriate state or federal authorities, in the manner and within the timeframes prescribed by law. Such notification will include, to the extent known, a description of the incident, the types of personal information involved, and the steps individuals may take to protect themselves. We maintain and regularly review our information security practices to minimize the risk of unauthorized access to personal information, and we will continue to update our security measures as necessary to address evolving threats.
The Services are designed for adult users (e.g., family members, caregivers, and healthcare facility staff arranging senior-care transfers). Our Services are not directed to children under 13, and we do not knowingly collect personal data from children.
Family and caregiver users may provide information about a loved one or resident as part of the intake and matching process. By submitting such information, you represent that you have the authority to do so on behalf of that individual (for example, as a legal guardian, power of attorney, or authorized family member).
If we become aware that any user has provided information through the Websites about a child, we will delete that information promptly. If you believe a child under 13 has submitted information to us, please contact privacy@careswaps.com and we will promptly delete it.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal obligations. When we make material changes, we will:
Continued use of CareSwaps or PatientSwaps after the effective date of an updated policy constitutes acceptance of the updated terms. We encourage you to review this policy periodically.
For privacy questions, rights requests, or to report a concern, contact us:
For regulatory complaints contact: