Plain-English summary
- QPR Capital Group LLC is a developer and problem-solving company for healthcare, and an AI-native enterprise ourselves. We build proof-of-concept platforms on synthetic data to test new ideas in healthcare operations. We are not a pharmacy or a provider. We do not collect, store, or process protected health information (PHI).
- We do not sell personal information. We do not run advertising. We do not use third-party advertising trackers.
- Text-message and voice programs are permission-based and non-marketing. Reply STOP to opt out at any time. Mobile numbers and consent records are never shared with third parties for their marketing.
- Data is stored and processed in the United States with vendors bound by contract.
Contents
- When this policy applies
- Our role: proof-of-concept work, demonstration data, and PHI
- Information we collect
- How we use information
- Text messaging, voice, and other communications
- AI in how we work
- How we share information
- Cookies and tracking
- How we protect information
- How long we keep information
- Your choices and rights
- Children
- Third-party websites and services
- Social Security number and payment-card protection
- United States only
- Changes to this policy
- Contact us
1. When this policy applies
This policy applies to the online services that QPR Capital Group LLC ("QPR," "we," "us," "our") owns or operates and that link to it: the My[Rx]Chart / RxPortal staff application, the My[Rx]Chart patient portal and secure order links, our text-messaging (SMS), fax, and voice programs, and the qprcapitalgroup.com website (together, the "Services"). It does not apply to information collected by other companies, or to websites and applications we link to but do not operate, even when you reach them from our Services.
By using the Services you agree to the collection, use, disclosure, and storage of information as described here. This policy does not create contractual rights for any party.
2. Our role: proof-of-concept work, demonstration data, and PHI
QPR Capital Group LLC is a developer and problem-solving company for healthcare: health systems and health-system-related customers bring us operational problems, and we build proof-of-concept platforms that show how they get solved. My[Rx]Chart is our proof-of-concept platform and test bed, used to try new ideas and demonstrate how AI-native pharmacy workflows could operate. It runs on demonstration data: fictional patients, prescriptions, payers, and cases created for testing, plus the accounts of the people evaluating it.
We do not collect, store, or process protected health information ("PHI") as defined by HIPAA. No real patient records are entered into My[Rx]Chart, no real prescriptions are filled through it, and no real patient is contacted by it. The people who receive its text messages are consenting staff and evaluators using their own numbers. QPR is not a HIPAA covered entity and does not currently act as a business associate for any customer.
If a customer ever chooses to pilot My[Rx]Chart with real patient data, that engagement would first require a written business associate agreement, a security review, and an updated privacy notice posted here before any PHI is handled.
3. Information we collect
Information you provide directly
- Account and identity information — name, username, work email, role, phone number, and the credentials you create. Passwords are stored only as salted one-way hashes, never in plain text.
- Demonstration data you enter — fictional patients, prescriptions, coverage, prior-authorization and financial-assistance cases, referral documents, and notes created to evaluate the platform. Evaluators are asked never to enter real patient information (Section 2).
- Demonstration portal and secure order links — the test identity details, delivery preferences, and order confirmations used to exercise the patient-facing flows. Payment flows use the processor's sandbox; card details entered there are handled by the processor (Square) and never touch our servers.
- Communications — text messages, faxes, voice-session transcripts, chat messages, call notes, and support requests you send us through the Services. Text messages go only to consenting staff and evaluator numbers; the fax line exchanges test documents only during the proof-of-concept phase (Section 5).
Information collected automatically
- Device and connection data — IP address, browser type and version, operating system, screen size, language, and referring page.
- Usage and log data — pages and features used, actions taken, timestamps, error reports, and request identifiers. In the staff application every action is written to an audit trail with the acting user and time.
- Cookies and similar technologies — see Section 8. We use only first-party cookies and browser storage needed to keep you signed in and remember your settings.
Information from other sources
- Our customers and their evaluators, when they create accounts or demonstration cases.
- Sandbox and test environments of healthcare systems the platform integrates with for demonstration (for example, electronic health record sandboxes, payer eligibility test services, and electronic prior-authorization test rails), which return synthetic data.
- Publicly available references such as DailyMed drug labeling and published payer and manufacturer program information.
4. How we use information
- To operate and demonstrate the Services for our customers: intake, benefits verification, prior authorization, financial assistance, order coordination, pharmacist verification, delivery scheduling, and patient communication — all on demonstration data.
- To authenticate users, secure accounts, and keep an audit trail.
- To communicate with you about the platform, your account, demonstrations, and support requests, and to respond to your messages.
- To exercise payment flows through our payment processor's sandbox and provide test receipts.
- To maintain, troubleshoot, secure, and improve the Services, including measuring performance and fixing errors.
- To comply with law, regulation, accreditation requirements, and legal process, and to protect the health, safety, and rights of patients, users, and others.
- To keep records of transactions and communications for business, security, and audit purposes.
We may combine information from the sources above for these purposes. We may use de-identified or aggregated data, which cannot reasonably identify you, to evaluate and improve the Services.
5. Text messaging, voice, and other communications
Program. My[Rx]Chart sends customer-care, non-marketing text messages from a U.S. business number about demonstration order status, refill reminders, delivery scheduling, account access, support requests, and replies to messages you send. During the proof-of-concept phase, messages go only to the numbers of consenting staff and evaluators, enforced by a server-side allowlist; no member of the public is messaged. Voice features let staff speak with the My[Rx]Chart assistant.
Consent. You receive texts only after you opt in — by asking to be added as an evaluator, by texting us first, or by verbally agreeing, which we record. Consent to receive texts is not a condition of purchasing any goods or services.
Frequency and cost. Message frequency varies with your care activity. Message and data rates may apply. Carriers are not liable for delayed or undelivered messages.
Opting out and help. Reply STOP to any message to stop receiving texts; you will receive one confirmation and no further messages unless you opt in again. Reply HELP for help, or contact us using Section 17.
No sharing for marketing. Mobile phone numbers, opt-in and consent records, and the content of text messages collected through our texting program are never sold, rented, or shared with third parties or affiliates for their own marketing or promotional purposes. They are shared only with the service providers needed to deliver the messages (our messaging platform and mobile carriers).
Fax. My[Rx]Chart can send and receive faxes — for example, prescription renewal requests to a prescriber's office and documents that arrive on our fax line — through a fax service provider under contract. During the proof-of-concept phase only test documents are exchanged. If a real prescriber or patient ever sends a real health document to our fax line by mistake, we treat it as misdirected information: we do not use it, we delete it, and we notify the sender. Before any customer used the fax line with real patient documents, the safeguards in Section 2 (business associate agreement, security review, updated notice) would be in place first.
Security of messages. Text messages and standard email travel over networks we do not control and may be intercepted. We keep message content to what your care requires and avoid including sensitive details such as diagnoses, dates of birth, or Social Security numbers.
6. AI in how we work
AI in how we work. QPR runs as an AI-native enterprise: AI agents also help us research, build, test, document, and operate the Services. They work under human direction, within the same role-based access controls as our staff, and their changes are reviewed and recorded. They are never given personal information to train on.
7. How we share information
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We share information only as follows:
- With the customer whose evaluation you are part of and the people it authorizes.
- With service providers that host, secure, and operate the Services on our behalf and are bound by contract, including providers of cloud hosting, communications, payment processing, AI services, monitoring, and error reporting.
- With integration partners' test environments (electronic health record sandboxes, payer eligibility test services, electronic prior-authorization test rails) using synthetic data only, to demonstrate workflows.
- For legal reasons: to comply with law, regulation, subpoena, court order, or a lawful government request; to enforce our terms; or to protect the rights, property, or safety of patients, users, QPR, or others.
- With your consent or at your direction.
De-identified or aggregated data that cannot reasonably identify you may be used and shared for any lawful purpose.
8. Cookies and tracking
The Services use first-party cookies and browser storage to keep you signed in, protect against fraud and cross-site request forgery, remember display settings, and measure basic performance. We do not use third-party advertising cookies, tracking pixels, or social-media plug-ins. Our web server keeps standard access logs (IP address, request path, time, response code) for security and troubleshooting. You can block or delete cookies in your browser; if you do, sign-in and some features may not work.
9. How we protect information
We use administrative, technical, and physical safeguards appropriate to the sensitivity of the information, including encryption in transit (TLS) and at rest, role-based access so users see only what their role requires, multi-factor authentication for staff accounts, salted one-way password hashing, rate limiting and lockout on sign-in, a server-side allowlist for text-message recipients, audit logging of every action, and least-privilege access for our own personnel. The platform is built so that real PHI could be protected to HIPAA standards, but today it holds none. No method of transmission or storage is completely secure; if we learn of a breach affecting your personal information we will notify you as applicable state law requires.
10. How long we keep information
We keep information for as long as needed to provide and demonstrate the Services and as the law requires. Account information is kept while the account is active. Demonstration data may be reset or deleted at any time. Audit logs are retained to meet security requirements. Text-message consent records are kept for as long as you are opted in and for a reasonable period afterward to document consent. Website access logs are kept for a limited period for security. When information is no longer needed we delete it or de-identify it.
11. Your choices and rights
- Access, correction, and deletion. Users can view and update their profile in the application. Anyone may ask to see, correct, or delete personal information we hold by contacting us (Section 17).
- Communication preferences. Reply STOP to end text messages, or contact us to change how you are contacted. Some communications, such as account security notices, may continue because they are necessary to provide the Services.
- Cookies. Manage them in your browser settings (Section 8).
We respond to verified requests within 30 days, or sooner where the law requires. We will never discriminate against you for exercising a privacy right.
12. Children
The Services are intended for adults evaluating healthcare software and are not directed to children under 13. We do not knowingly collect personal information from children under 13.
13. Third-party websites and services
The Services may link to or work alongside third-party websites and applications. Those services have their own privacy policies, which govern your use of them. A link does not mean we endorse or monitor the third party's practices.
14. Social Security number and payment-card protection
We do not collect Social Security numbers and ask users never to enter them anywhere in the Services. Payment-card numbers are entered directly with our payment processor and are never stored by us. Our AI assistant is built to refuse to type into password, Social Security number, or card-number fields.
15. United States only
The Services are intended for a United States audience. Information you provide is transferred to, stored, and processed on servers in the United States. If you use the Services from outside the United States, you consent to that transfer and processing.
16. Changes to this policy
We may update this policy as the Services and the law change. We will post the updated policy here with a new effective date, and for material changes we will give notice in the application or by email to account holders. Your continued use of the Services after a change means you accept the updated policy.
17. Contact us
QPR Capital Group LLC
1883 W Royal Hunte Dr, Ste 200A
Cedar City, UT 84720, USA
Phone: (440) 328-6563
Email: fcampogni2012@gmail.com · fcampogni@qprcapitalgroup.com (subject line "Privacy request" for privacy matters, "Security" for security concerns)
Web: qprcapitalgroup.com