In plain language. This website is not a place to send medical or patient information. If you are a patient, please contact your own provider, not us. Healthcare organizations that use Elysium remain responsible for their patients’ information, and Elysium handles it on their behalf only under a written business associate agreement, using it only to provide our services. We do not sell health information, use it for advertising, or use it to train AI models for our own purposes.
1. Purpose and scope
This notice explains how Elysium Innovative Labs LLC, operating as Elysium Ecosystem (“Elysium”, “we”, “us”), handles health-related information, and the roles we play under laws that protect it. It applies to:
- visitors to elysiumecosystem.com (the “Website”) and people who contact us;
- healthcare organizations, and other organizations that handle health information, that use or evaluate the Elysium platform and its solutions, such as clinics and medical practices (the “Services”); and
- individuals whose health information is processed through the Services by a healthcare organization that is our customer (“Patients”).
It should be read with our Privacy Policy, which covers all other personal information, and with our Messaging Terms, Email Policy and Terms of Use.
2. Elysium’s roles
- The Website. Elysium is not a healthcare provider, health plan or healthcare clearinghouse, and the Website is not designed to receive or store health information. Information you send us through the Website is handled under the Privacy Policy.
- The Services. When a healthcare organization that is a “covered entity” under the Health Insurance Portability and Accountability Act of 1996 and its regulations (“HIPAA”) uses the Services in a way that involves protected health information (“PHI”), Elysium acts as that organization’s business associate, or, if another business associate engages us, as its subcontractor. Elysium will act in that capacity only under a signed business associate agreement (“BAA”) and only for the Services and environments that the BAA covers. Until a BAA is signed, please do not submit PHI to us.
- Other health data laws. Where state laws protect consumer health data or sensitive health data outside HIPAA, Elysium acts as a processor or service provider for its customer, which decides why and how that data is used.
Elysium does not diagnose, treat, or give medical advice, and nothing about the Services replaces the judgment of a licensed professional.
3. What we mean by health information
- PHI is individually identifiable health information that a HIPAA covered entity or business associate creates, receives, maintains or transmits, including electronic PHI (“ePHI”).
- Consumer health data is personal information linked or reasonably linkable to a person that identifies their past, present or future physical or mental health status, as defined in laws such as Washington’s My Health My Data Act, Nevada’s consumer health data law and Connecticut’s consumer health data provisions. It can include, depending on the law, health conditions, treatment, medications, reproductive or sexual health information, gender-affirming care, biometric data, and data that identifies a person’s attempt to obtain health services.
- Sensitive health records include substance-use-disorder records protected by 42 C.F.R. Part 2, mental-health records, and other categories that state law protects specially, such as California’s Confidentiality of Medical Information Act.
4. What the Website does and does not collect
The Website collects the business contact details and messages described in the Privacy Policy. It does not ask for health information and it does not use advertising or analytics tools that would receive information about pages you view. Please do not enter patient, medical or diagnostic information in the contact form or in any email or text message to us. If you send such information, we will use it only as needed to direct you to the right resource and will delete it when we are able.
If you are a patient of a clinic or another healthcare organization that uses Elysium, contact that organization for questions about your health information or your rights. It is the organization, not Elysium, that decides how your health information is used.
5. How we handle PHI for our customers
Where Elysium is a business associate, we:
- use and disclose PHI only as the BAA permits, to provide the Services to the customer and for our own proper management and legal responsibilities, and not otherwise. We do not sell PHI, we do not use or disclose it for marketing, and we do not use it to train or improve AI models for anyone other than the customer, unless the BAA and the law expressly allow it;
- limit PHI to the minimum necessary for each purpose;
- maintain safeguards designed to support our obligations and our customers’ obligations under the HIPAA Security Rule. Those include administrative safeguards (risk analysis and management, workforce training and sanctions, access authorization and contingency planning), physical safeguards and technical safeguards (unique user identification, authentication, role-based access, logical isolation between customers, audit logging, integrity controls and encryption of data in transit and, as configured, at rest). Our approach is described on the Security page;
- require our subcontractors that handle PHI to sign business associate agreements that impose the same restrictions;
- report to the customer any use or disclosure of PHI not permitted by the BAA, any security incident, and any breach of unsecured PHI, without unreasonable delay and within the period in the BAA, which will not exceed the 60 days that HIPAA allows;
- help customers respond to individuals’ rights, including access, amendment and an accounting of disclosures, within the times the BAA sets;
- return or destroy PHI when the agreement ends, where feasible, and continue to protect anything we must retain; and
- make our practices, books and records available to the U.S. Department of Health and Human Services as required.
We do not claim that any product or service is “HIPAA certified”, because HIPAA has no certification, and we do not claim a security certification or attestation that we do not hold. HIPAA compliance depends on how a customer configures and uses the Services as well as on what we do, and each covered entity remains responsible for its own compliance.
6. Communications channels and health information
Email, text messages and standard voicemail are not inherently secure. Healthcare customers decide what they send to their Patients through the Services. We recommend, and the Messaging Terms and Email Policy require of customers, that they:
- send only the minimum necessary information and avoid clinical detail in text messages and unencrypted email;
- use secure portals, encrypted email or links that require authentication for anything more than reminders and administrative notices;
- rely on a Patient’s informed request to receive unencrypted communications only after warning of the risks and documenting the request;
- obtain the consents that the Telephone Consumer Protection Act and applicable state law require, including for calls made with artificial or prerecorded voices, and keep health-care communications free of marketing content that would change how those rules apply; and
- not use text, email or automated assistants for emergencies. In an emergency, call your local emergency number (911 in the United States and Canada, 112 in the European Union) or, in the U.S., call or text 988 for the Suicide & Crisis Lifeline.
7. Artificial intelligence in healthcare workflows
Elysium’s artificial-intelligence capabilities, such as automated assistants, voice agents and workflow automation, are designed for administrative and operational tasks such as scheduling, reminders, routing, summarizing and coordination. They are not medical devices, are not intended to diagnose or treat, and are not to be used as the basis for clinical decisions without qualified human review. Customers are responsible for the way they deploy them, including disclosing the use of AI to Patients where the law requires it (for example, California’s requirement for disclaimers on patient communications generated by generative AI), and for meeting nondiscrimination rules that apply to decision-support tools. Where Elysium operates an automated assistant, we tell people that it is not a human.
8. Consumer health data and state laws
Several U.S. states regulate health data that falls outside HIPAA, and many require opt-in consent to process sensitive health data. Washington’s law also requires a separate consumer health data privacy policy, consent for collection and sharing, separate authorization to sell, and it restricts geofencing around health facilities.
- Elysium does not collect consumer health data through the Website.
- When a customer uses the Services to process consumer health data, Elysium acts as its processor. We act only on the customer’s documented instructions, do not sell that data, do not use it for our own advertising or profiling, do not create geofences around health facilities, and help the customer honor consumer requests and its obligations under those laws.
- If Elysium ever becomes a regulated entity that collects consumer health data for its own purposes, we will publish a separate Consumer Health Data Privacy Policy, prominently linked from our homepage, before we collect it, and we will obtain the consents that the law requires.
9. Especially sensitive records
We apply heightened care to reproductive and sexual health, gender-affirming care, mental health, substance-use-disorder and other especially sensitive records, and to the state laws that protect them, including laws that limit disclosure in connection with legal process. Elysium does not accept records protected by 42 C.F.R. Part 2 unless the customer and Elysium have agreed in writing on the required terms first.
10. De-identified data
We do not create or use de-identified or aggregated data derived from PHI unless the BAA allows it, and any de-identification will follow the HIPAA standard (Expert Determination or Safe Harbor at 45 C.F.R. § 164.514). We do not attempt to re-identify de-identified data and require anyone who receives it to make the same commitment.
11. Your rights
- Patients. Under HIPAA and state law, you may have the right to access and receive a copy of your records, request amendments, receive an accounting of disclosures, request restrictions and confidential communications, and receive your provider’s Notice of Privacy Practices. Exercise these rights with your healthcare provider. If you contact us, we will direct your request to the relevant customer where we can identify it, and we will help the customer respond.
- Consumers. Depending on your state, you may have rights to access, delete and withdraw consent for consumer health data, to know who received it, and to appeal. Contact the organization that collected it. For information Elysium controls, use the process in Section 12 of the Privacy Policy.
- Complaints. If you believe that a covered entity or business associate has violated your HIPAA rights, you may file a complaint with the U.S. Department of Health and Human Services, Office for Civil Rights (hhs.gov/ocr/complaints), and with your state attorney general. You will not be retaliated against for filing a complaint.
12. Security incidents
We maintain an incident-response process that covers detection, containment, investigation, notification and remediation. We notify affected customers as described in Section 5 and cooperate with them so that they can meet their duties to notify Patients, regulators and, where required, the media and the U.S. Department of Health and Human Services. We monitor regulatory developments, including proposed updates to the HIPAA Security Rule, and adjust our practices as they become binding. To report a suspected security issue, write to security@elysiumecosystem.com.
13. Where health information is processed
The BAA and the customer’s Services Agreement identify the locations where PHI will be processed and stored and the subcontractors that may access it. We do not process PHI outside the locations and subcontractors identified to the customer in that agreement.
14. Changes and language
We may update this notice as our Services and the law change. The current version and its date appear at the top of this page. If a change materially affects how we handle PHI for a customer, we will tell the customer as the BAA requires. This notice is written in English, and if a translation conflicts with it, the English version controls except where the law requires otherwise.
15. Contact
Elysium Innovative Labs LLC, operating as Elysium Ecosystem 7901 4th St N, St Petersburg, FL 33702
- Health-information and privacy questions: privacy@elysiumecosystem.com
- Security incidents: security@elysiumecosystem.com
- Legal notices and business associate agreements: legal@elysiumecosystem.com