Armadillo Health Privacy Practices

Effective date: March 29, 2024

Overview

Want to know what you can do to keep your abortion private? Click here for tips.

Your Information. Your Rights. Our Responsibilities.

Please Read Carefully. Armadillo Health, LLC (“Armadillo,” “we,” “us,” or “our”) recognizes the importance of protecting the privacy of your personal information, and healthcare data (collectively, “Personal Information”) and we have prepared this Privacy Policy (“Policy”) to provide you with important information about the privacy practices applicable to ArmadilloClinic.org (the “Site”).  By accessing the Site, you agree to be bound by this Policy. 

Our policy does not apply to services offered by other companies or individuals, including products or sites that may be displayed to you. Our Policy also does not cover the information practices of other companies and organizations who host advertisements for our services, and who may use cookies, pixel tags, and other technologies on their sites or other third-party sites to serve and offer relevant ads.

Changes to this Policy. Each time you use the Site, the current version of this Policy will apply.  Accordingly, you should check the date of the Policy (which appears at the top) and review any changes since you last reviewed the Policy. 

Personal Information Armadillo Obtains. In connection with the Services, we may collect medical and health information from you. This may include information about your diagnosis, previous treatments, general health, laboratory and pathology test results and reports, social histories, any family history of illness. Armadillo is not a “covered entity” under the Health Insurance Portability and Accountability Act of 1996, Public Law 104-191, and its related regulations and amendments (collectively, “HIPAA”). However, health care providers involved in the delivery of the Services may be “covered entities” under HIPAA, and we may in some cases be a “business associate” of a healthcare provider network or a health care provider. HIPAA does not necessarily apply to us or to a provider due to the mere fact that health information is involved in our interactions, and HIPAA may not apply to your transactions or communications with us or the providers. Any medical or health information that you provide that is subject to specific protections under applicable state laws (collectively, with “protected health information,” as defined under HIPAA), will be used, and disclosed only in accordance with such applicable laws.

How We Use Personal Information. Armadillo may use your Personal Information for the following purposes: 

  • For the purposes for which you provided the information;

  • To contact you when necessary or requested;

  • To process your payments, communicate with you regarding your services from Site, or provide you with related customer service;

  • To provide, maintain, administer, improve, or expand the Services, perform business analyses, or for other internal purposes to support, improve or enhance our business, the Services, and other products and services we offer;

  • To prevent, detect, and investigate security breaches, fraud, and other potentially illegal or prohibited activities in accordance with our Terms of Use (which can be found here);

  • To enforce the legal terms that govern your use of the Services;

  • To protect Armadillo’s rights or property;

  • For any other purpose disclosed to you in connection with our Services.

How We Do Not Use Your Personal Information. Armadillo will not use your Personal Information for the following purposes: 

  • We do not use or share any data about you for advertising purposes.

  • We never share your information with other medical providers, unless you have specifically given verbal and written permission. The only exception would be a life-threatening medical emergency, if information-sharing would be important for you to receive life-saving care. That is extremely unlikely to happen. Medication abortion complications are extremely rare. When they happen, they require the same treatment as miscarriage.

How We Protect Personal Information. Armadillo maintains administrative, technical, and physical safeguards designed to protect the User's Personal Information and information against accidental, unlawful, or unauthorized destruction, loss, alteration, access, disclosure, or use. We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, considering technological reality, cost, the scope, context, and purposes of processing weighted against the severity and likelihood that the processing could threaten individual rights and freedoms. For example, we restrict access to personal information to our employees and medical providers, who need to know that information in order to operate, develop or improve our services. These individuals are bound by confidentiality obligations and may be subject to discipline, including termination and criminal prosecution, if they fail to meet these obligations. We use commercially reasonable security measures such as encryption, firewalls, and Secure Socket Layer software (SSL) or hypertext transfer protocol secure (HTTPS) to protect Personal Information. We only choose to work with vendors who offer encrypted services, meaning that these vendors do not have access to your personal information. Any information you send through secure chat is deleted within 2 days. Information sent in your medical intake is stored in a secure digital chart. 

Data Breach Notification. Unfortunately, no data transmission over the Internet can be guaranteed to be 100% secure. As a result, while we strive to protect your Personal Information, Armadillo cannot ensure or warrant the security of any information you transmit to us or from our online products or services, and you do so at your own risk. Armadillo strives to ensure that data breaches are responded to in an appropriate fashion, in accordance with the HIPAA breach notification rule and other applicable law. Individuals have the right to provide feedback on Armadillo’s compliance with the HIPAA Privacy Rule and its HIPAA privacy policies and procedures (“Privacy Complaints”). Individuals also have the right to provide feedback on the organization’s breach notification process and compliance with the Breach Notification Rule. To provide feedback on Armadillo HIPAA privacy policies and procedures, contact us through our website.

Vendors. We have relationships with these vendors for purposes of the provision of Services: Squarespace, Spruce andJotform. We chose technology vendors specifically to protect your data. These vendors do not have access to your private information — this is kept secure and encrypted, even from them.

Personal Information We Share. We do not share information with companies, organizations, and individuals outside of Armadillo unless one of the following circumstances applies:

  • With your consent. We may share information for any other purposes disclosed to you at the time we collect the information or pursuant to your consent or direction, only with your consent.

  • Research and advocacy partners. We may share your anonymized information with our research and advocacy partners to conduct health-related research and advocacy as permitted by law. We will never share your name, date of birth, contact information, or any identifiable data..

  • Help with public health and safety issues. We will only share personal information about you in certain situations, when we have no alternatives, such as: 

·       Documenting who received particular medications in the event of a medication recall (extremely rare — these medications have been used safely for over 20 years).

·       Reporting suspected abuse, neglect, or domestic violence, only if this information is shared with us. We do not ask questions other than those required for you to get an abortion.

·       Preventing or reducing a serious threat to anyone’s health or safety, only if we are alerted by phone or chat that there is this type of threat.

  • Legal purposes. We may disclose information with companies, organizations or individuals outside of Armadillo if we have a good-faith belief that access, use, preservation or disclosure of the information is reasonably necessary to:

    • Medical examiner. We may be required to release a chart in the extremely rare case of a patient's death. (Note: Death from childbirth is 35 times more likely than death from abortion).

    • Meet any applicable law, regulation, legal process or enforceable governmental request. Note: Armadillo is protected by state shield laws and may not be required to release data as part of an investigation by a state that bans abortion practice.

    • Enforce applicable Terms of Use, including investigation of potential violations.

    • Detect, prevent, or otherwise address fraud, security or technical issues.

    • Protect against harm to the rights, property or safety of Armadillo, our Users or the public as required or permitted by law.

      • We attempt to notify Users about legal demands for their Personal Information when appropriate in our judgment, unless prohibited by law or court order or when the request is an emergency. We may dispute such demands when we believe, in our discretion, that the requests are overbroad, vague or lack proper authority.

Your Rights to Your Personal Information. When it comes to your health information, you have certain rights. This section explains your rights and some of our responsibilities to help you.

  • You have the right to file a complaint against Armadillo Health LLC (see the Terms of Use for our Dispute Resolution proceedings)

  • You have the right to receive a copy of an electronic or paper copy of your medical record:

    • You can ask to see or get an electronic or paper copy of your medical record and other health information we have about you. We will provide a copy or a summary of your health information, usually within 30 days of your request. 

  • You have the right to request confidential communications

·       We communicate with all patients through secure, online chat, or a phone conversation. To protect your privacy, we do not communicate by email or unsecured text messages.

Sale of Information. We have never sold, and never will sell, information.

‍Our Retention of Your Personal Information. We may retain your Personal Information for a period of time consistent with the original purpose for collection.  For example, we keep your Personal Information for no longer than reasonably necessary for your use of our Services and for a reasonable period of time afterward. We also may retain your Personal Information during the period of time needed for us to pursue our legitimate business interests, conduct audits, comply with our legal obligations, resolve disputes and enforce our agreements. The data from your intake form and any on-line chats are deleted within 48 hours. Your private electronic medical record will be kept for 7 years, in a secure location.

Devices. If you use our phone service, your cellular carrier will have a record that you called our phone number or received a call from our phone number. 

Links to Other Websites. You should know that websites/pages (other than Armadillo’s webpage) referred to or linked from our Website are not under the control, ownership, or operation of the Armadillo. Accordingly, we can make no representation concerning the content of these sites to you, and we make no endorsement of the sites or any information or further links contained on those sites. We are providing these links only as a convenience to you, and you should know that Armadillo has not reviewed these sites and therefore cannot make any representations regarding the quality or reliability of any information found on these sites. We have no control over the content, operations, policies, terms, or other elements of Third-Party Sites, and we do not assume any obligation to review any Third-Party Sites. Company does not necessarily endorse, approve, or sponsor any Third-Party Sites, or any third-party content, advertising, information, materials, products, services, or other items. Furthermore, we are not responsible for the quality or delivery of the products or services offered, accessed, obtained by or advertised at such Third-Party Sites. Finally, we will under no circumstances be liable for any direct, indirect, incidental or special loss or other damage, whether arising from negligence, breach of contract, defamation, infringement of copyright or other intellectual property rights, caused by the exhibition, distribution or exploitation of any information or content contained within these Third-Party Sites.

Privacy Rights for Users Based in California. Under the California Consumer Privacy Act (“CCPA”), California residents have certain rights regarding their Personal Information. If you would like to exercise these rights, please contact us. For your own privacy and security we may require you to prove your identity before providing the requested information, as provided for by the CCPA. We will respond within the requirements of the CCPA. This Policy describes the Personal Information we collect from you and the purposes for doing so. The CCPA grants you specific rights, including the following:

  • Upon a verifiable request, we will disclose to you the items listed below, one or more of which may be provided by this Policy:

    • The categories of Personal Information we have collected about you.

    • The categories of sources from which the Personal Information was collected.

    • The business purpose behind collecting the Personal Information.

    • The categories of third-parties with whom we have shared the information.

    • The specific pieces of Personal Information we have collected about you.

    • The right to request deletion: upon a verifiable request, made through the “Contact Information” section below, we will delete Personal Information we have regarding you and direct our service providers to delete your Personal Information from their records, to the extent provided by the CCPA.

    • The right to be free from discrimination: we will not discriminate against you for exercising any of your rights under the CCPA. If you are a job applicant, you may provide certain Personal Information to us, including email address, phone number, name, SSN and government issued identification numbers.

  • We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to facilitate our response.

  • We will respond to all legitimate requests within forty-five days, or as required by the CCPA.