Effective Date: September 3, 2026 Last Reviewed: September 3, 2026 Version: 1.0
Long Health, Inc. (“Long Health”) maintains and publishes this Qualified Health Information Organization Privacy Policy (“QHIO Privacy Policy”) in connection with its designation as a California Qualified Health Information Organization (“QHIO”) and its participation in the California Health and Human Services Data Exchange Framework (“DxF”).
Long Health facilitates the secure electronic exchange of Health and Social Services Information (“HSSI”) on behalf of healthcare providers, health plans, medical groups, hospitals, clinics, laboratories, social service organizations, and other authorized organizations (“Participants”).
This QHIO Privacy Policy describes how Long Health protects information exchanged or processed through its QHIO services and explains Long Health’s role with respect to participating organizations and individuals whose information may be exchanged.
This policy is intended to satisfy Long Health’s applicable QHIO privacy-policy requirements and is reviewed at least annually.
Long Health provides interoperability infrastructure and related services that enable authorized organizations to request, receive, send, route, locate, match, and exchange HSSI.
Depending upon the service and relationship involved, Long Health may act as:
Long Health does not provide medical treatment, diagnosis, healthcare services, or clinical decision-making directly to individuals.
The healthcare provider, health plan, or other organization responsible for an individual’s underlying medical or health record remains responsible for complying with its applicable legal obligations concerning that record.
Use of Long Health as a QHIO or Intermediary does not relieve a Participant of its obligations under Applicable Law, the DxF Data Sharing Agreement (“DSA”), or applicable DxF Policies and Procedures (“P&Ps”).
Long Health operates its QHIO services in accordance with Applicable Law and applicable requirements of the DxF DSA and P&Ps.
Terms used in this policy that are defined by the DxF DSA or DxF Glossary of Defined Terms are intended to have meanings consistent with those documents where applicable.
The DxF DSA and P&Ps may be amended from time to time. Long Health will review this policy and its applicable operational policies when material changes to the DxF requirements occur.
Nothing in this policy is intended to authorize Access, Use, Disclosure, or Exchange of HSSI that is prohibited by Applicable Law, the DxF DSA, applicable P&Ps, or Long Health’s contractual obligations.
In providing QHIO and interoperability services, Long Health may process information received from, maintained for, or exchanged on behalf of Participants.
Depending upon the applicable service, this information may include:
The information available through Long Health varies according to the Participants involved, their source systems, applicable legal requirements, and the services they have elected to use.
Long Health does not represent that information available through its QHIO services constitutes a complete medical record for an individual.
Long Health facilitates Access to and Exchange of HSSI only for purposes permitted or required by Applicable Law, applicable agreements, and the DxF DSA and P&Ps.
Depending upon the circumstances, these purposes may include:
Long Health does not independently create the legal authority for a Participant to disclose HSSI.
Each Participant is responsible for determining that it has appropriate authority to Access, Use, Disclose, or Exchange HSSI, including obtaining an Authorization or consent when required by Applicable Law.
Long Health may rely on representations associated with an authorized exchange transaction unless Long Health has actual knowledge that the exchange is prohibited.
Long Health does not currently operate a general direct-to-consumer patient portal or consumer medical-record repository through which individuals independently access, download, amend, delete, or manage their medical records.
Long Health’s QHIO services are primarily provided to participating healthcare and social services organizations.
An individual’s medical information may nevertheless be processed or maintained by Long Health on behalf of a Participant as necessary to provide contracted interoperability services.
The fact that information concerning an individual may pass through or be maintained within Long Health systems does not mean that Long Health is the healthcare provider responsible for that individual’s underlying medical record.
Individuals have privacy and access rights established by Applicable Law and, where applicable, the DxF DSA and P&Ps.
Individuals seeking a copy of their medical records or access to health information maintained by their healthcare provider or health plan should ordinarily contact that healthcare provider, health plan, or other organization responsible for the underlying record.
Long Health does not routinely provide medical records directly to individuals as a consumer-facing service.
Where Long Health maintains information on behalf of a Participant and the Participant is responsible for fulfilling an applicable individual access request, Long Health will provide reasonable assistance to the Participant as required by Applicable Law, applicable contractual agreements, and the DxF DSA and P&Ps.
If an individual submits a record-access request directly to Long Health, Long Health may:
Long Health will not ordinarily independently amend or alter a Participant’s source medical record.
The DxF does not itself create a single centralized statewide patient opt-out mechanism.
Individuals may have rights under federal or California law to request restrictions on certain Uses, Disclosures, or Exchanges of their information. Participants that Maintain an individual’s HSSI are responsible for complying with those rights as applicable.
Individuals wishing to restrict information maintained by a healthcare provider, health plan, or other Participant should ordinarily submit the request to that organization through its established privacy process.
Requests Submitted Directly to Long Health
An individual may also contact Long Health concerning a requested restriction or opt-out relating to electronic exchange through Long Health.
Receipt of such a request does not constitute confirmation that Long Health maintains information concerning the individual.
Because Long Health generally provides services on behalf of Participants and does not maintain a direct patient-provider relationship, Long Health may need to:
Long Health will implement applicable restrictions consistent with Applicable Law, the DxF DSA and P&Ps, Long Health’s contractual obligations, and applicable interoperability-network requirements.
A restriction implemented through Long Health applies only within the scope of Long Health’s systems and services and does not constitute a universal restriction applicable to independent healthcare providers, health plans, other HIEs, QHIOs, QHINs, or nationwide interoperability networks.
Individuals may need to contact other organizations separately regarding information those organizations independently Maintain or Exchange.
Long Health does not interpret participation in the DxF as eliminating any consent or Authorization requirement imposed by federal or California law.
Where Applicable Law requires an individual’s consent or Authorization before information may be disclosed or exchanged, the applicable Participant is responsible for obtaining and managing that consent or Authorization.
If a Participant communicates an applicable consent restriction to Long Health, Long Health will apply the restriction to its services as required by Applicable Law, applicable agreements, and applicable exchange requirements.
Long Health does not use an individual’s request for information, restriction, or privacy assistance as authorization for any unrelated Disclosure of that individual’s HSSI.
Long Health may facilitate information exchange through nationwide networks, frameworks, health information exchanges, and other Intermediaries.
These may include Carequality and other authorized national or regional exchange arrangements.
Participation in such a framework does not mean that the framework itself maintains a centralized patient medical record.
Long Health follows applicable legal, security, technical, privacy, and participation requirements governing the networks and frameworks through which it exchanges information.
Where Long Health acts on behalf of a Participant, the Participant remains responsible for ensuring that its participation and requested Exchanges are permitted by Applicable Law and applicable participation requirements.
Long Health maintains administrative, technical, and physical safeguards designed to protect the confidentiality, integrity, and availability of HSSI and to protect against unauthorized Access, Use, Disclosure, modification, Exchange, loss, destruction, or disruption.
Long Health’s security program includes safeguards appropriate to the nature of its services and may include:
Long Health maintains security controls consistent with applicable QHIO Program requirements, including applicable HITRUST certification requirements.
No information technology environment can be guaranteed to eliminate every security risk. Long Health regularly evaluates its safeguards and updates its controls based on identified risks, legal requirements, and applicable industry standards.
Long Health does not store DxF Participants’ Protected Health Information (“PHI”) or Personally Identifiable Information (“PII”) outside the Continental United States where prohibited by applicable QHIO Program requirements.
Long Health requires applicable service providers and subcontractors involved in QHIO services to comply with contractual geographic restrictions applicable to the information they process.
Long Health may use demographic and other permitted information to identify and match records relating to the same individual across participating healthcare organizations.
Person matching is performed using information and technical processes consistent with applicable DxF Technical Requirements for Exchange and applicable nationwide network or framework requirements.
Long Health maintains controls intended to reduce inappropriate or inaccurate matching.
Because patient demographic information can change, contain errors, or differ between healthcare organizations, no person-matching system can eliminate every possibility of an incorrect or incomplete match.
Long Health may require additional demographic information or Participant assistance when necessary to investigate a potential matching issue.
Where the HIPAA minimum-necessary standard or another applicable data-minimization requirement applies, Long Health limits Access, Use, or Disclosure to information reasonably necessary to accomplish the authorized purpose.
The minimum-necessary standard does not apply in circumstances where HIPAA or other Applicable Law provides otherwise, including certain disclosures for Treatment.
Long Health also seeks to limit collection and use of identifying information for privacy, support, identity verification, and compliance activities to information reasonably necessary for the applicable purpose.
Long Health does not sell HSSI received through the DxF.
Long Health does not use PHI or HSSI received through its QHIO services for consumer advertising or targeted behavioral advertising.
Long Health does not Access HSSI through the DxF for the purpose of selling that information.
Long Health will not re-use, re-disclose, aggregate, de-identify, or re-identify information received through the DxF for Long Health’s independent financial benefit except where expressly permitted by Applicable Law, the DxF DSA and P&Ps, and an applicable legally enforceable agreement.
Where Long Health creates or uses De-Identified information, it will do so only as permitted by Applicable Law and applicable DxF requirements.
Access to HSSI within Long Health is limited to authorized workforce members and contractors who require access for legitimate business, technical, privacy, security, compliance, or support purposes.
Long Health maintains policies governing confidentiality and appropriate information use and provides privacy and security training to applicable personnel.
Unauthorized Access, Use, or Disclosure of HSSI is prohibited and may result in disciplinary action, termination of access, contractual remedies, or other appropriate action.
Long Health may use third-party service providers and subcontractors to support infrastructure, hosting, security, communications, software, monitoring, and other functions necessary to provide QHIO services.
Where a service provider or subcontractor receives PHI, PII, or other protected HSSI, Long Health requires appropriate contractual safeguards and, where required, Business Associate Agreements or equivalent contractual protections.
Long Health requires applicable subcontractors to protect information consistently with Long Health’s legal, contractual, security, and QHIO obligations.
Long Health maintains audit trails and/or transaction logs relating to QHIO exchange activities.
Such information may include:
Long Health maintains applicable QHIO audit trails and transaction logs for at least six years or for a longer period where required by Applicable Law or contractual obligations.
Audit and transaction information is protected against unauthorized Access or modification.
Long Health retains HSSI and other information only as necessary to:
Retention periods may vary based upon the information involved and the services being provided.
Long Health does not independently delete information maintained on behalf of a Participant solely because an individual contacts Long Health requesting deletion when the Participant or Applicable Law requires the information to be retained.
Requests concerning deletion or amendment of a Participant’s underlying medical record should be directed to that Participant.
Long Health maintains processes for identifying, investigating, mitigating, documenting, and responding to suspected privacy and security incidents.
Long Health will provide notifications concerning breaches or other reportable incidents in accordance with Applicable Law, contractual requirements, and applicable DxF Breach Notification requirements.
Long Health cooperates with affected Participants and appropriate authorities when required in connection with privacy or security investigations.
Individuals may contact Long Health with questions concerning Long Health’s privacy practices or information exchange services.
Before disclosing patient-specific information, confirming whether a particular individual is represented in Long Health systems, or taking a patient-specific action, Long Health may require reasonable identity verification.
Long Health will request only information reasonably necessary to evaluate the request.
Individuals should not transmit Social Security numbers, complete medical records, or other unnecessary sensitive information through ordinary email.
Long Health may provide a secure process when additional information is required.
Questions or complaints regarding Long Health’s QHIO privacy practices may be directed to:
Long Health, Inc. Privacy / QHIO Compliance
Email: contact@longhealth.io
Phone: 408-673-8215
Website: www.longhealth.io
Individuals may also have the right to submit privacy complaints to applicable federal or state authorities.
Nothing in this policy restricts an individual from exercising rights available under Applicable Law or from filing a complaint with an appropriate regulatory authority.
Long Health prohibits retaliation for making a good-faith privacy complaint or exercising a legally protected privacy right.
Long Health may amend this policy to reflect:
Material revisions will be reflected by updating the Effective Date, Last Reviewed date, and version information displayed at the beginning of this policy.
Superseded versions may be retained internally in accordance with Long Health’s document-retention and compliance processes.
Long Health reviews this QHIO Privacy Policy at least annually and more frequently when material regulatory, operational, or technical changes warrant review.
The review includes consideration of applicable:
The “Last Reviewed” date at the beginning of this policy reflects the most recent completed review, whether or not that review resulted in changes to the text.
This QHIO Privacy Policy is maintained under the oversight of Long Health’s privacy, security, and compliance functions.
Questions regarding interpretation or application of this policy should be directed to Long Health’s Privacy / QHIO Compliance function.
Version 1.0 — September 3, 2026 Initial publication of the dedicated Long Health QHIO Privacy Policy.