Last Updated: July 28, 2026
Effective Date: August 1, 2026
1. Purpose and Scope
This TEFCA IAS Privacy and Security Notice (“Notice”) is provided in electronic form and describes how Greenlight Health Data Solutions, Inc. (“Greenlight” “we,” “us,” or “our”) may:
- Access, exchange, use, disclose, and store your individually identifiable information as an Individual Access Service (IAS) Provider in connection with our Trusted Exchange Framework and Common Agreement (“TEFCA”) connection; and your rights with respect to information Greenlight receives through the TEFCA network.
This Notice is written in accordance with Federal Plain Language Guidelines. The format is designed to be readable on mobile devices.
Greenlight will not use the TEFCA network to access your records without your consenting to this Notice and having the opportunity to read this Notice. Your acceptance of this Notice is your explicit, informed consent for Greenlight to use TEFCA IAS functions on your behalf, and to access your individually identifiable information through the TEFCA network.
We record, in an auditable log, your acceptance of this Notice prior to performing any TEFCA IAS functions related to you or to your data. Greenlight applications will check that we have your acceptance of this Notice on file before the applications allow any access via TEFCA IAS.
The following symbols indicate items of special interest:
🔒: security related item
👁: privacy related item
▶: item that changed since the last version of this Notice
👁 Individually identifiable information is information that identifies you or for which there is a reasonable basis to believe that it could identify you. Information that is de-identified is not individually identifiable information. This Notice is in addition to the Greenlight Terms of Service and Privacy Policy (see above), applicable to your use of our Service. In the event this Notice conflicts with the general Greenlight Terms of Service and Privacy Policy, this Notice controls with respect to the individually identifiable information we collect about you through the TEFCA network.
This Notice is intended to fulfill the requirements of the U.S. Department of Health and Human Services (HHS), Assistant Secretary for Technology Policy (ASTP) / Office of the National Coordinator for Health IT (ONC) and the Recognized Coordinating Entity (RCE) with respect to our participation in TEFCA as an Individual Access Service Provider (IAS Provider). This Notice is limited to our TEFCA participation as an IAS Provider. Other notices and policies may apply to how your individually identifiable information is processed by us outside of TEFCA or if we are processing your individually identifiable information on behalf of your health care provider, health plan, or other third party who also participates in TEFCA.
The most recent version of this Notice is publicly posted at all times on the Greenlight website home page and in user facing applications involved in TEFCA IAS or that display data accessed using TEFCA IAS.
2. Who We Are and What is TEFCA
Who is Greenlight?
Greenlight’s mission is to make healthcare more efficient through connected care and research. The Service allows you to track, retrieve, share, and manage your health information, often in connection with your healthcare provider or research study team.
What is TEFCA?
TEFCA is a “trusted” contractual framework for supporting nationwide health information exchange through Qualified Health Information Networks (QHINs) and their participants and subparticipants. A QHIN is generally a technology company that has been approved by a government-established process to provide the technical capabilities to support electronic health information exchange. Participants and subparticipants in TEFCA include health care providers, health plans, public health authorities and governmental agencies, individual access service providers and the individuals and entities who support them. To learn more about the types of individuals and entities that participate in TEFCA, read the Standard Operating Procedure (SOP): Types of Entities That Can Be a Participant or Subparticipant in TEFCA.
TEFCA permits QHINs, participants, and subparticipants to participate in different use cases that are called exchange purposes (XPs). One of those exchange purposes, which provides individuals with access to their health information, is called Individual Access Services (“IAS”). Organizations that have a direct contractual relationship with an individual, to support the right of access, are called Individual Access Services Providers (“IAS Providers”). Greenlight is a request-only IAS Provider as defined below in the IAS Provider Requirements SOP.
REQUEST-ONLY IAS PROVIDER: Greenlight Health Data Solutions, Inc, DOES NOT PROVIDE BIDIRECTIONAL SERVICES. YOU WILL HAVE THE ABILITY TO REQUEST ACCESS TO YOUR HEALTH INFORMATION VIA TEFCA EXCHANGE. YOU WILL NOT BE ABLE TO USE Greenlight Health Data Solutions, Inc, TO SHARE YOUR HEALTH INFORMATION WITH OTHER PARTICIPANTS IN TEFCA.
For more information about TEFCA, read this Fact Sheet about individual access of health information via TEFCA: https://rce.sequoiaproject.org/rce-tefca-for-individuals/.
3. Privacy Commitments
👁 Greenlight adheres to applicable federal and state privacy laws and TEFCA privacy and security requirements when we process your individually identifiable information through the TEFCA network. We commit to the following:
- Consent: Before we perform patient-directed data access or sharing through the TEFCA network, we will ask you for your express, written and informed consent. We may collect this consent electronically or in paper form. You can revoke this consent at any time; see Section 9 for an explanation. If you revoke your consent, you will no longer have access to our IAS services or to your data through the TEFCA network, unless you sign a new consent. We also obtain your express, documented consent to this Privacy and Security Notice prior to accessing, using, exchanging, or disclosing your Individually Identifiable Information.
- Confidentiality: We use commercially reasonable efforts to protect individually identifiable information from unauthorized or illegal access, modification, use, or destruction.
- Data Minimization: We collect and use the minimum necessary amount of individually identifiable information necessary to fulfill the permitted uses described in this Notice.
- Exchange Purpose Limitation: When individually identifiable information is accessed, used, or disclosed through TEFCA it is done only for permitted TEFCA exchange purposes.
- Individual Rights: TEFCA IAS users can access, request correction, or request deletion of their individually identifiable information. See Section 9, below on Individual Rights and Contact Information, as well as our Greenlight Terms of Service and Privacy Policy, above.
- Transparency: We communicate our practices and responsibilities through policies, agreements, and user notifications.
Our full Greenlight Terms of Service and Privacy Policy can be found on our website.
4. Security Measures and Compliance
🔒 👁 Greenlight implements security safeguards aligned with industry standards and HITRUST controls to protect individually identifiable information, including:
- Access Controls: We require role-based access, least privilege, and multi-factor authentication (MFA) for all systems with individually identifiable information.
- Encryption: We encrypt all individually identifiable information, in transit and at rest, using industry standard encryption measures. We do this for all individually identifiable information, regardless of how it was accessed (from TEFCA network or from other sources).
- Security Testing: We conduct annual third-party penetration testing.
- System Monitoring: We continuously monitor our systems for anomalies using infrastructure monitoring tools and intrusion detection systems (IDS).
- Incident Response: We maintain a formal incident response plan, including 24/7 on-call escalation procedures and post-incident review processes.
- Business Continuity: We review and test our documented disaster recovery plans at least annually.
- Standards: Greenlight meets or exceeds the requirements of the following security and compliance standards. HITRUST CSF v11.5.1 e1; NIST SP 800-53a moderate; TEFCA security and privacy principles as defined in the Participant/Subparticipant Terms of Participation (ToPs) and the Standard Operation Procedure (SOP): Individual Access Service (IAS) Provider Requirements. All Greenlight employees undergo background checks, complete annual privacy and security awareness training, and sign confidentiality agreements.
5. Our Use and Disclosure of Your Individually Identifiable Information as an IAS Provider
- Permitted Uses and Disclosures on TEFCA:
👁 When providing Individual Access Services on TEFCA, Greenlight uses and discloses your individually identifiable information to QHINs, their participants and subparticipants, and other individuals and entities only when allowed under TEFCA, applicable law, applicable HHS guidance and by you. As your IAS Provider, we may use and disclose your individually identifiable information to other individuals and entities that participate in TEFCA or that may request it for the following exchange purposes, ONLY with your consent:- Treatment
- Payment
- Health Care Operations, including without limitation care coordination / case management, HEDIS reporting, and quality measure reporting
- Public Health, including electronic case reporting and lab reporting
- Individual Access Services (IAS)
- Government Benefits Determinations
- Any other exchange purposes approved by ASTP/ONC and RCE as permitted or required by the Participant/Subparticipant Terms of Participation (ToPs).
- 👁 As a Request-Only IAS Provider, Greenlight’s primary exchange purpose is Individual Access Services (IAS). Under the IAS exchange purpose, with your consent, we request your individually identifiable information for you to access or to transmit a copy of your information as you direct us. If in the future we decide to participate bi-directionally on the TEFCA network, or to support other exchange purposes, we will update this policy accordingly. If those updates materially change how we use or disclose your individually identifiable information, we will notify you before doing so.
- You can learn more about the TEFCA exchange purposes by reading this Standard Operating Procedure (SOP): Exchange Purposes (XPs). If the government decides to change these SOP documents at any time, we will follow the most current version of these documents.
- Be aware that once an individual or entity receives your individually identifiable information for one of these purposes (such as another TEFCA participant or subparticipant) they may keep, use, and redisclose your individually identifiable information for purposes that are allowed by the laws, contracts, and policies that apply to them. We don’t have the ability to control how people (who are not our employees or contractors) who receive your individually identifiable information decide to use and disclose it.
- 👁 Once we receive your individually identifiable information through TEFCA, or from other third parties, we may use and disclose your individually identifiable information outside of TEFCA for the other permitted uses and disclosures described in this Notice.
- 👁 Permitted Uses and Disclosures through other Health Information Networks/Exchanges (HIN/HIEs):
We may participate in other HIN/HIEs that support use cases similar to the TEFCA exchange purposes described above. If we do, we will follow the policies and procedures of those HIN/HIEs about use and disclosure of your individually identifiable information in connection with those HIN/HIEs. - 👁 Other Permitted Uses and Disclosures:
Beyond TEFCA and other HIN/HIEs, Greenlight will only use or disclose your individually identifiable information that was accessed through the TEFCA network:- to deliver the services that we provide to you;
- to manage and administer our business and our legal responsibilities, such as providing, operating, maintaining and securing our Platform and the Service;
- to communicate with you about the Service, including sending you announcements, updates, security alerts, and support and administrative messages, and to respond to your requests, questions and feedback;
- as required by law and in response to legal process, such as subpoenas, court orders and law enforcement demands as further described in this Notice (see Section 10);
- to certain sub-processors that assist us in the services and the proper management and administration of our business and legal obligations, as further described and listed in this Notice (see Section 7);
- with your written or verbal consent or otherwise at your direction, to other third parties you have explicitly authorized.
- 👁 No Marketing or Profiling:
We do not use or disclose the individually identifiable information we access through the TEFCA network for advertising, profiling, or any other unauthorized purpose. We will ask for your consent before using your individually identifiable information for such purposes. - 👁 No Sale:
We do not intend to sell the individually identifiable information we access through the TEFCA network to third parties. We will ask for your consent before selling your individually identifiable information. - 👁 IAS Provision not regulated under HIPAA, but aligned:
You have probably heard of HIPAA. The Health Information Portability and Accountability Act (HIPAA) is a U.S. federal law protecting health information maintained by certain “covered” entities and their “business associates” that act on their behalf. Greenlight is not a “covered” entity under HIPAA, and as an IAS Provider Greenlight is not acting on behalf of a “covered” entity; as an IAS Provider, Greenlight is acting on your behalf, as an individual. But while Greenlight’s IAS provision may not be regulated by HIPAA, Greenlight follows TEFCA’s strict privacy and security requirements, which meet or exceed HIPAA’s privacy and security protections. - 👁 De-Identified Data:
We may de-identify and/or aggregate individually identifiable information, including protected health information, in accordance with the HIPAA de-identification standards at 45 CFR 164.514(b), to support our services or for our internal business purposes, such as creating application usage data. Application usage data reflects general patterns and trends about how users interact with the Service (for example, feature utilization, navigation flows, and performance metrics) but does not identify any individual user. We use usage data to analyze, maintain, and improve the functionality, performance, and user experience of our Platform and related services, as well as to promote our business.
We may also create, use and disclose de-identified data if: (1) required to do so by applicable law; or (2) as may be permitted by applicable law, if you consent to it and in accordance with our Privacy Policy. - No Use Against You:
Greenlight will never use your information to make claims against you, except (if applicable) to collect fees or costs for services you requested.
6. Fees and Costs
Greenlight supports an individual’s right to access their health information. As an IAS Provider, Greenlight allows individuals to access their health records, and to exercise the rights listed in this Notice, at no cost to the individual. If we decide in future to charge individuals fees or costs for our IAS services, those fees or costs will be listed on our website (www.greenlighthealth.com). We reserve the right to charge fees and costs to businesses for services provided to them or on their behalf or for other work we may do for them around education, identity verification, consent management and data delivery.
7. Vendors, Subcontractors, Third-Party Service Providers and Subprocessors
🔒 👁 We use trusted vendors such as Amazon Web Services (AWS) for infrastructure and hosting. Any vendors with access to individually identifiable information have undergone industry standard security certification. We may also contract with other types of vendors, subcontractors, third-party service providers and subservice organizations to assist us in providing the services and supporting the proper management and administration of our business and legal responsibilities. Our contracts with them require them to protect the confidentiality of individually identifiable information. Greenlight conducts vendor risk assessments and subprocessor reviews at least annually.
Here is a list of current Greenlight sub-processors: https://greenlighthealth.com/legal/sub-processors-list/
8. Data Retention and Disposal
👁 We retain individually identifiable information accessed through the TEFCA network as long as your account remains active or as needed to provide you with the services you have requested. We also keep your data for up to seven years in compliance with federal and state laws for disclosure reporting. You may ask us to delete your account at any time by contacting us at cancelmyaccount@greenlighthealth.com. When asked, we will cease any further authorized sharing of your individually identifiable information and will delete your individually identifiable information. This deletion requirement does not apply to any individually identifiable information that may be contained in our audit logs or which is technically infeasible for us to completely delete.
In addition, once you have shared your individually identifiable information with a third party in connection with your use of the Service, deletion of your Greenlight account does not obligate that third party to delete the individually identifiable information you provided directly to them, shared with them via the Service, or that is governed by their separate relationship with you. Nor does Greenlight have any obligation to inform that third party of the deletion of your individually identifiable information at Greenlight.
If Greenlight is unable, by law, to honor your request for deletion, we will inform you.
9. Individual Rights and Contact Information
The following rights may be available to you immediately, through the Greenlight Service, or are available within a few business days by contacting Greenlight support.
You have the right to:
- Access your individually identifiable information anytime through our services or by writing to us as described below.
- Download your individually identifiable information in a machine-readable format. For example, we enable you to download an electronic copy (PDF) of your records when you use the Service.
- Request corrections to your individually identifiable information by writing to us at the address(es) listed below.
- Request deletion of your individually identifiable information (except audit logs), unless prohibited by law. You can delete your full clinical record by emailing us at cancelmyaccount@greenlighthealth.com or by contacting our support team through the communication methods below.
- 👁 Revoke your consent at any time via the Record Finder application’s “Done” page, by “deleting the connection.” This is simple, electronic, and automatically deletes the data associated with that connection within minutes. Within Record Finder, the “Done” screen always displays at the end of any process. The screen shows your current connections with healthcare facilities. For each connection there is a menu that allows you to delete the connection. Simply select to delete and confirm, and the connection will be disabled (consent revoked) and the data accessed for that facility will be deleted.
- These instructions are also posted on the Greenlight website.
- You can also revoke your consent by contacting Greenlight support. Revoking your consent stops future disclosure of your individually identifiable information but does not recall previously authorized disclosures. It also does not stop any uses or disclosures that are either required by law or that are otherwise permitted by applicable law.
- 🔒 Be notified if your data is involved in an IAS Incident. An “IAS Incident” is one of the following: (a) an unauthorized acquisition, access, disclosure, or use of unencrypted individually identifiable information that does not qualify for an exception; and (b) other security events that are set forth in the Standard Operating Procedure (SOP): TEFCA Security Incident Reporting. Any such notification to you will contain a description of the incident, the discovery date, the time frame affected, what types of individually identifiable information were involved, steps being taken to mitigate the effects of the incident, and steps you should take to protect yourself.
- Greenlight will report an IAS Incident, no more than 72 hours after discovery, as required in the Standard Operating Procedure (SOP): TEFCA Security Incident Reporting. We will provide the details required in section 4.6 of the SOP.
- You may file a privacy or security complaint with us, contact us with questions, or submit requests to access, correct, or delete your individually identifiable information, by contacting us at:
Email: support@greenlighthealth.com
Mailing Address:
Greenlight Health Data Solutions,
801 Corporate Center Dr., Suite 320
Raleigh, NC 27607Phone (toll free to the Greenlight support team): 844-877-7827
- Our support team processes consent and deletion requests quickly, typically within one or two business days. There may be instances where we need more information from you to process your request in accordance with applicable law and some laws might prohibit us from honoring a request to delete individually identifiable information. If this is the case, we will contact you with details.
- We document and track all privacy-related concerns, including final result, according to our incident response procedure.
10. Legal Proceedings and Law Enforcement
👁 If we receive a civil or criminal subpoena, court order, search warrant, or other demand for compulsory disclosure or law enforcement request for your individually identifiable information that we obtained via the TEFCA network, we will notify you within three (3) business days, unless we are prohibited by law from doing so (e.g., Patriot Act). Written or electronic notice will also be provided to affected Individual(s) (unless prohibited by Applicable Law) within three (3) business days of us making Individually Identifiable Information available to law enforcement agencies, including through sale of Individually Identifiable data.
To the extent permitted by applicable law, you will have an opportunity to object or to seek a protective order.
11. Changes to This Notice
- If we make material changes, we will update this Notice and let you know using the communication methods you have on file at Greenlight.
- All changes to this Notice will also be posted to our website at https://greenlighthealth.com/greenlight-terms-of-service/. Changes within this Notice will be flagged.
- Changes take place 14 days after the changes are posted to the Greenlight website. Posted copies of the Notice will always display an effective date, which also serves to identify the version.
- As the IAS Provider, Greenlight bears the burden of proof in disputes about the materiality of any change to the Notice.
- This Notice remains in effect as long as we hold your individually identifiable information that we accessed through the TEFCA network.