1. Introduction & Overview
MoveFitRx, Inc. ("MoveFitRx," "we," "us," or "our") operates a clinical technology platform facilitating remote therapeutic monitoring (RTM), exercise prescription fulfillment, and connected medical exercise infrastructure. This Privacy Policy describes how we collect, use, protect, and disclose information when you access or use the MoveFitRx web platform, mobile applications, connected equipment integrations, and associated clinical services (collectively, the "Platform").
By accessing or using the Platform, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our data practices, please do not use the Platform.
2. Information We Collect
We collect several types of information to deliver, maintain, and secure our clinical exercise prescription and monitoring services:
- Personal Account Information: Name, email address, and enrollment identifiers provided during patient onboarding or clinician referral. Clinician accounts may additionally include a phone number.
- Protected Health Information (PHI) & Clinical Data: Clinical diagnoses (e.g., hypertension, osteoporosis, Type 2 diabetes), medical parameters provided by your treating clinician, prescribed exercise protocols, and clinical adherence records.
- Telemetry & Remote Therapeutic Monitoring (RTM) Data: Session duration, equipment type, resistance levels, repetitions, sets, distance, estimated calories, average and maximum heart rate (where compatible heart rate monitors are connected), facility name, equipment integration source, and metrics collected via commercial gym equipment or mobile applications.
- Device & Technical Data: IP addresses, device identifiers, operating system versions, browser types, log files, and cryptographic execution timestamps required for platform security and HIPAA audit logs.
3. HIPAA Safeguards & Encryption Standards
As a software platform handling health-related telemetry and clinical data, MoveFitRx maintains technical, administrative, and physical safeguards consistent with the HIPAA Security Rule (45 C.F.R. Part 164, Subpart C):
- Federal Encryption Standards: All data in transit is encrypted using Transport Layer Security (TLS) 1.2 or higher, following NIST Special Publication 800-52 Rev. 2 guidelines. Data at rest is encrypted using AES-256 cryptographic standards consistent with NIST FIPS 140-2 guidelines.
- Access & Audit Controls: Role-based authorization controls and row-level security policies restrict access to patient data. Detailed audit logging records access and modifications to protected health information.
- Third-Party Cloud Infrastructure: MoveFitRx utilizes SOC 2 Type II certified cloud infrastructure providers operating under executed HIPAA Business Associate Agreements (BAAs).
4. How We Use Information
MoveFitRx uses collected information exclusively for clinical coordination, RTM fulfillment, and platform security:
- Delivering Exercise Prescriptions: Translating clinical parameters into individualized exercise programs designed by qualified Exercise Physiologists or Physical Therapists.
- Remote Therapeutic Monitoring (RTM): Transmitting exercise adherence telemetry to your treating clinician to support remote clinical evaluation and CPT billing support (CPT 98975–98981).
- Equipment Integration: Interfacing with commercial gym equipment and connected fitness devices via Bluetooth, ANT+, or API integrations.
- Regulatory & Compliance Reporting: Maintaining HIPAA audit trails, processing FSA/HSA billing documentation, and fulfilling legal obligations.
5. Data Sharing & Disclosures
MoveFitRx does not sell, rent, or trade your personal or health data to advertisers or third parties. We share information only under the following limited circumstances:
- Treating Clinicians & Practices: Sharing RTM compliance logs, exercise completion data, and telemetry metrics with the licensed clinician who issued your exercise prescription.
- Payment Processing: Transmitting your name, email address, and an opaque account identifier to our PCI-compliant payment processor solely to process enrollment payments. No diagnosis, clinical, or telemetry data is shared with the payment processor.
- HIPAA Business Associates: Securely transferring data to audited technology infrastructure partners operating under signed BAAs.
- Legal Obligations: Disclosing information if required by law, subpoena, court order, or applicable federal or state regulations.
6. User Rights & Data Retention
In accordance with applicable privacy laws and HIPAA regulations, you have the right to request access to, correction of, or copies of your personal health data processed through the Platform.
You may request deletion of your MoveFitRx account at any time by contacting our Privacy Officer at the address below. Upon request we will close your account and delete personal account information that we are not required to retain. Clinical records, telemetry audit logs, and executed agreement records are retained for the statutory period described below, as required by healthcare record retention and HIPAA obligations, and are then securely archived or sanitized.
MoveFitRx retains patient records, telemetry audit logs, and executed agreement records for a minimum of seven (7) years to comply with healthcare record retention mandates and HIPAA requirements. After the applicable retention period, records are securely archived or sanitized.
7. Updates to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements, technical capabilities, or our clinical workflows. When updates are made, we will update the "Effective Date" at the top of this Policy and make the updated Policy available on the Platform.
8. Contact & Privacy Inquiries
If you have questions, concerns, or requests regarding this Privacy Policy or MoveFitRx data protection practices, please contact our Privacy Officer at:
MoveFitRx, Inc. · Email: privacy@movefitrx.com · Reference: MFRx-PRIVACY-v1.1