Long Health QHIO Privacy Policy

Effective Date: September 3, 2026 Last Reviewed: September 3, 2026 Version: 1.0

1. Purpose

Long Health, Inc. (“Long Health”) maintains and publishes this Qualified Health Information Organization Privacy Policy (“QHIO Privacy Policy”) in connection with its designation as a California Qualified Health Information Organization (“QHIO”) and its participation in the California Health and Human Services Data Exchange Framework (“DxF”).

Long Health facilitates the secure electronic exchange of Health and Social Services Information (“HSSI”) on behalf of healthcare providers, health plans, medical groups, hospitals, clinics, laboratories, social service organizations, and other authorized organizations (“Participants”).

This QHIO Privacy Policy describes how Long Health protects information exchanged or processed through its QHIO services and explains Long Health’s role with respect to participating organizations and individuals whose information may be exchanged.

This policy is intended to satisfy Long Health’s applicable QHIO privacy-policy requirements and is reviewed at least annually.

2. Long Health’s Role as a QHIO

Long Health provides interoperability infrastructure and related services that enable authorized organizations to request, receive, send, route, locate, match, and exchange HSSI.

Depending upon the service and relationship involved, Long Health may act as:

  • a Qualified Health Information Organization;
  • an Intermediary under the DxF;
  • a Business Associate under the Health Insurance Portability and Accountability Act (“HIPAA”);
  • an Implementer or service provider supporting participation in a nationwide interoperability network or framework; or
  • a technology and interoperability service provider to participating organizations.

Long Health does not provide medical treatment, diagnosis, healthcare services, or clinical decision-making directly to individuals.

The healthcare provider, health plan, or other organization responsible for an individual’s underlying medical or health record remains responsible for complying with its applicable legal obligations concerning that record.

Use of Long Health as a QHIO or Intermediary does not relieve a Participant of its obligations under Applicable Law, the DxF Data Sharing Agreement (“DSA”), or applicable DxF Policies and Procedures (“P&Ps”).

3. Relationship to the DxF DSA and Policies and Procedures

Long Health operates its QHIO services in accordance with Applicable Law and applicable requirements of the DxF DSA and P&Ps.

Terms used in this policy that are defined by the DxF DSA or DxF Glossary of Defined Terms are intended to have meanings consistent with those documents where applicable.

The DxF DSA and P&Ps may be amended from time to time. Long Health will review this policy and its applicable operational policies when material changes to the DxF requirements occur.

Nothing in this policy is intended to authorize Access, Use, Disclosure, or Exchange of HSSI that is prohibited by Applicable Law, the DxF DSA, applicable P&Ps, or Long Health’s contractual obligations.

4. Information Processed Through Long Health

In providing QHIO and interoperability services, Long Health may process information received from, maintained for, or exchanged on behalf of Participants.

Depending upon the applicable service, this information may include:

  • patient demographic information;
  • names, addresses, dates of birth, telephone numbers, and other person-matching information;
  • healthcare provider and facility information;
  • encounters and visit information;
  • admission, discharge, and transfer information;
  • diagnoses and medical conditions;
  • medications;
  • allergies;
  • immunizations;
  • laboratory and diagnostic information;
  • procedures;
  • clinical notes and clinical documents;
  • care plans;
  • referral information;
  • insurance or coverage information where applicable;
  • social services information where applicable;
  • clinical document attachments;
  • health information exchange requests and responses;
  • patient matching and record-location information;
  • exchange-related metadata; and
  • transaction and audit information.

The information available through Long Health varies according to the Participants involved, their source systems, applicable legal requirements, and the services they have elected to use.

Long Health does not represent that information available through its QHIO services constitutes a complete medical record for an individual.

5. Purposes for Which Information May Be Exchanged

Long Health facilitates Access to and Exchange of HSSI only for purposes permitted or required by Applicable Law, applicable agreements, and the DxF DSA and P&Ps.

Depending upon the circumstances, these purposes may include:

  • Treatment;
  • Payment;
  • Health Care Operations;
  • Public Health Activities;
  • Individual Access Services where applicable;
  • legally authorized social services purposes;
  • healthcare coordination;
  • referrals;
  • notifications and care transitions;
  • other Required Purposes or Permitted Purposes established under the DxF; and
  • other purposes permitted or required by Applicable Law.

Long Health does not independently create the legal authority for a Participant to disclose HSSI.

Each Participant is responsible for determining that it has appropriate authority to Access, Use, Disclose, or Exchange HSSI, including obtaining an Authorization or consent when required by Applicable Law.

Long Health may rely on representations associated with an authorized exchange transaction unless Long Health has actual knowledge that the exchange is prohibited.

6. No Direct-to-Consumer Patient Record Service

Long Health does not currently operate a general direct-to-consumer patient portal or consumer medical-record repository through which individuals independently access, download, amend, delete, or manage their medical records.

Long Health’s QHIO services are primarily provided to participating healthcare and social services organizations.

An individual’s medical information may nevertheless be processed or maintained by Long Health on behalf of a Participant as necessary to provide contracted interoperability services.

The fact that information concerning an individual may pass through or be maintained within Long Health systems does not mean that Long Health is the healthcare provider responsible for that individual’s underlying medical record.

7. Individual Access to Health Information

Individuals have privacy and access rights established by Applicable Law and, where applicable, the DxF DSA and P&Ps.

Individuals seeking a copy of their medical records or access to health information maintained by their healthcare provider or health plan should ordinarily contact that healthcare provider, health plan, or other organization responsible for the underlying record.

Long Health does not routinely provide medical records directly to individuals as a consumer-facing service.

Where Long Health maintains information on behalf of a Participant and the Participant is responsible for fulfilling an applicable individual access request, Long Health will provide reasonable assistance to the Participant as required by Applicable Law, applicable contractual agreements, and the DxF DSA and P&Ps.

If an individual submits a record-access request directly to Long Health, Long Health may:

  • request sufficient information to identify the relevant Participant;
  • direct the individual to the healthcare provider, health plan, or other organization responsible for the record;
  • coordinate the request with the appropriate Participant; or
  • take other action required by Applicable Law or applicable DxF requirements.

Long Health will not ordinarily independently amend or alter a Participant’s source medical record.

8. Requests to Restrict Health Information Exchange or Opt Out

The DxF does not itself create a single centralized statewide patient opt-out mechanism.

Individuals may have rights under federal or California law to request restrictions on certain Uses, Disclosures, or Exchanges of their information. Participants that Maintain an individual’s HSSI are responsible for complying with those rights as applicable.

Individuals wishing to restrict information maintained by a healthcare provider, health plan, or other Participant should ordinarily submit the request to that organization through its established privacy process.

Requests Submitted Directly to Long Health

An individual may also contact Long Health concerning a requested restriction or opt-out relating to electronic exchange through Long Health.

Receipt of such a request does not constitute confirmation that Long Health maintains information concerning the individual.

Because Long Health generally provides services on behalf of Participants and does not maintain a direct patient-provider relationship, Long Health may need to:

  • verify the identity of the person making the request;
  • identify the healthcare provider, health plan, or other Participant associated with the information;
  • refer the individual to the appropriate Participant;
  • coordinate with the Participant concerning the scope and legal effect of the requested restriction; and/or
  • implement an applicable technical exchange restriction after receiving appropriate confirmation or instruction.

Long Health will implement applicable restrictions consistent with Applicable Law, the DxF DSA and P&Ps, Long Health’s contractual obligations, and applicable interoperability-network requirements.

A restriction implemented through Long Health applies only within the scope of Long Health’s systems and services and does not constitute a universal restriction applicable to independent healthcare providers, health plans, other HIEs, QHIOs, QHINs, or nationwide interoperability networks.

Individuals may need to contact other organizations separately regarding information those organizations independently Maintain or Exchange.

9. Consent and Authorization

Long Health does not interpret participation in the DxF as eliminating any consent or Authorization requirement imposed by federal or California law.

Where Applicable Law requires an individual’s consent or Authorization before information may be disclosed or exchanged, the applicable Participant is responsible for obtaining and managing that consent or Authorization.

If a Participant communicates an applicable consent restriction to Long Health, Long Health will apply the restriction to its services as required by Applicable Law, applicable agreements, and applicable exchange requirements.

Long Health does not use an individual’s request for information, restriction, or privacy assistance as authorization for any unrelated Disclosure of that individual’s HSSI.

10. Nationwide Networks and Other Interoperability Frameworks

Long Health may facilitate information exchange through nationwide networks, frameworks, health information exchanges, and other Intermediaries.

These may include Carequality and other authorized national or regional exchange arrangements.

Participation in such a framework does not mean that the framework itself maintains a centralized patient medical record.

Long Health follows applicable legal, security, technical, privacy, and participation requirements governing the networks and frameworks through which it exchanges information.

Where Long Health acts on behalf of a Participant, the Participant remains responsible for ensuring that its participation and requested Exchanges are permitted by Applicable Law and applicable participation requirements.

11. Privacy and Security Safeguards

Long Health maintains administrative, technical, and physical safeguards designed to protect the confidentiality, integrity, and availability of HSSI and to protect against unauthorized Access, Use, Disclosure, modification, Exchange, loss, destruction, or disruption.

Long Health’s security program includes safeguards appropriate to the nature of its services and may include:

  • identity and access management;
  • role-based access controls;
  • multifactor authentication;
  • encryption of information in transit and at rest where appropriate;
  • network security controls;
  • endpoint security;
  • vulnerability management;
  • security monitoring;
  • audit logging;
  • workforce security;
  • privacy and security training;
  • incident response procedures;
  • business continuity and disaster recovery controls;
  • risk assessments;
  • penetration testing; and
  • vendor and subcontractor oversight.

Long Health maintains security controls consistent with applicable QHIO Program requirements, including applicable HITRUST certification requirements.

No information technology environment can be guaranteed to eliminate every security risk. Long Health regularly evaluates its safeguards and updates its controls based on identified risks, legal requirements, and applicable industry standards.

12. Geographic Location of DxF Information

Long Health does not store DxF Participants’ Protected Health Information (“PHI”) or Personally Identifiable Information (“PII”) outside the Continental United States where prohibited by applicable QHIO Program requirements.

Long Health requires applicable service providers and subcontractors involved in QHIO services to comply with contractual geographic restrictions applicable to the information they process.

13. Person Matching

Long Health may use demographic and other permitted information to identify and match records relating to the same individual across participating healthcare organizations.

Person matching is performed using information and technical processes consistent with applicable DxF Technical Requirements for Exchange and applicable nationwide network or framework requirements.

Long Health maintains controls intended to reduce inappropriate or inaccurate matching.

Because patient demographic information can change, contain errors, or differ between healthcare organizations, no person-matching system can eliminate every possibility of an incorrect or incomplete match.

Long Health may require additional demographic information or Participant assistance when necessary to investigate a potential matching issue.

14. Minimum Necessary and Data Minimization

Where the HIPAA minimum-necessary standard or another applicable data-minimization requirement applies, Long Health limits Access, Use, or Disclosure to information reasonably necessary to accomplish the authorized purpose.

The minimum-necessary standard does not apply in circumstances where HIPAA or other Applicable Law provides otherwise, including certain disclosures for Treatment.

Long Health also seeks to limit collection and use of identifying information for privacy, support, identity verification, and compliance activities to information reasonably necessary for the applicable purpose.

15. Sale, Advertising, and Prohibited Use of HSSI

Long Health does not sell HSSI received through the DxF.

Long Health does not use PHI or HSSI received through its QHIO services for consumer advertising or targeted behavioral advertising.

Long Health does not Access HSSI through the DxF for the purpose of selling that information.

Long Health will not re-use, re-disclose, aggregate, de-identify, or re-identify information received through the DxF for Long Health’s independent financial benefit except where expressly permitted by Applicable Law, the DxF DSA and P&Ps, and an applicable legally enforceable agreement.

Where Long Health creates or uses De-Identified information, it will do so only as permitted by Applicable Law and applicable DxF requirements.

16. Workforce Access

Access to HSSI within Long Health is limited to authorized workforce members and contractors who require access for legitimate business, technical, privacy, security, compliance, or support purposes.

Long Health maintains policies governing confidentiality and appropriate information use and provides privacy and security training to applicable personnel.

Unauthorized Access, Use, or Disclosure of HSSI is prohibited and may result in disciplinary action, termination of access, contractual remedies, or other appropriate action.

17. Service Providers and Subcontractors

Long Health may use third-party service providers and subcontractors to support infrastructure, hosting, security, communications, software, monitoring, and other functions necessary to provide QHIO services.

Where a service provider or subcontractor receives PHI, PII, or other protected HSSI, Long Health requires appropriate contractual safeguards and, where required, Business Associate Agreements or equivalent contractual protections.

Long Health requires applicable subcontractors to protect information consistently with Long Health’s legal, contractual, security, and QHIO obligations.

18. Audit Trails and Transaction Logs

Long Health maintains audit trails and/or transaction logs relating to QHIO exchange activities.

Such information may include:

  • transaction dates and times;
  • requesting and responding organizations;
  • transaction type;
  • permitted-purpose information;
  • user or system identifiers;
  • technical status information; and
  • other information needed for security, compliance, troubleshooting, or audit purposes.

Long Health maintains applicable QHIO audit trails and transaction logs for at least six years or for a longer period where required by Applicable Law or contractual obligations.

Audit and transaction information is protected against unauthorized Access or modification.

19. Information Retention

Long Health retains HSSI and other information only as necessary to:

  • provide contracted services;
  • facilitate authorized information exchange;
  • meet Participant requirements;
  • maintain required transaction and audit records;
  • comply with Applicable Law;
  • comply with the DxF DSA and P&Ps;
  • comply with nationwide network or framework requirements;
  • investigate privacy or security matters;
  • resolve disputes; and
  • meet contractual or regulatory obligations.

Retention periods may vary based upon the information involved and the services being provided.

Long Health does not independently delete information maintained on behalf of a Participant solely because an individual contacts Long Health requesting deletion when the Participant or Applicable Law requires the information to be retained.

Requests concerning deletion or amendment of a Participant’s underlying medical record should be directed to that Participant.

20. Privacy and Security Incidents

Long Health maintains processes for identifying, investigating, mitigating, documenting, and responding to suspected privacy and security incidents.

Long Health will provide notifications concerning breaches or other reportable incidents in accordance with Applicable Law, contractual requirements, and applicable DxF Breach Notification requirements.

Long Health cooperates with affected Participants and appropriate authorities when required in connection with privacy or security investigations.

21. Individual Privacy Inquiries

Individuals may contact Long Health with questions concerning Long Health’s privacy practices or information exchange services.

Before disclosing patient-specific information, confirming whether a particular individual is represented in Long Health systems, or taking a patient-specific action, Long Health may require reasonable identity verification.

Long Health will request only information reasonably necessary to evaluate the request.

Individuals should not transmit Social Security numbers, complete medical records, or other unnecessary sensitive information through ordinary email.

Long Health may provide a secure process when additional information is required.

22. Complaints

Questions or complaints regarding Long Health’s QHIO privacy practices may be directed to:

Long Health, Inc. Privacy / QHIO Compliance

Email: contact@longhealth.io

Phone: 408-673-8215

Website: www.longhealth.io

Individuals may also have the right to submit privacy complaints to applicable federal or state authorities.

Nothing in this policy restricts an individual from exercising rights available under Applicable Law or from filing a complaint with an appropriate regulatory authority.

Long Health prohibits retaliation for making a good-faith privacy complaint or exercising a legally protected privacy right.

23. Changes to This QHIO Privacy Policy

Long Health may amend this policy to reflect:

  • changes in Applicable Law;
  • changes to the DxF DSA or P&Ps;
  • changes to QHIO Program requirements;
  • changes to nationwide network or framework requirements;
  • changes in Long Health’s services or technology; or
  • changes to Long Health’s privacy and security practices.

Material revisions will be reflected by updating the Effective Date, Last Reviewed date, and version information displayed at the beginning of this policy.

Superseded versions may be retained internally in accordance with Long Health’s document-retention and compliance processes.

24. Annual Review

Long Health reviews this QHIO Privacy Policy at least annually and more frequently when material regulatory, operational, or technical changes warrant review.

The review includes consideration of applicable:

  • QHIO Program requirements;
  • DxF DSA requirements;
  • DxF Policies and Procedures;
  • federal and California privacy laws;
  • nationwide interoperability requirements; and
  • Long Health operational practices.

The “Last Reviewed” date at the beginning of this policy reflects the most recent completed review, whether or not that review resulted in changes to the text.

25. Policy Governance

This QHIO Privacy Policy is maintained under the oversight of Long Health’s privacy, security, and compliance functions.

Questions regarding interpretation or application of this policy should be directed to Long Health’s Privacy / QHIO Compliance function.

Version History

Version 1.0 — September 3, 2026 Initial publication of the dedicated Long Health QHIO Privacy Policy.