Effective Date: July 27, 2026 · Last Updated: July 27, 2026
This Privacy Policy explains how Aquila Health PBC (“Aquila,” “we,” “us,” or “our”) processes information through the TREUE™ platform, TREUE APIs, patient-directed services, data-exchange services, and related platform functionality that link to this policy.
TREUE supports different customers, users, data sources, legal authorities, and deployment models. Aquila’s role and permitted processing therefore depend on the service and transaction involved.
This policy should be read together with any applicable:
- Customer agreement
- Business associate agreement
- Data processing agreement
- Data use agreement
- Participation agreement
- Patient authorization or consent
- Research consent
- Government contract
- Platform terms of use
- Feature-specific notice
If a written agreement or legally valid authorization imposes a more specific restriction on Aquila’s processing, the more specific restriction controls.
Aquila’s Different Privacy Roles
Aquila as a Service Provider, Processor, or Business Associate
Aquila often processes information on behalf of a health care provider, health plan, health information exchange, government agency, researcher, employer, customer, or another organization.
In that role, the organization determines the authorized purpose of the processing, and Aquila processes the information under the organization’s instructions, the applicable agreement, and law.
Requests concerning that information should ordinarily be submitted to the organization responsible for the information.
Aquila as the Provider of a Consumer-Directed Service
For a TREUE feature through which an individual creates and controls a direct account, retrieves information from multiple sources, selects recipients, or authorizes optional uses, Aquila may be directly responsible for some processing decisions.
The consumer-facing portions of this policy are designed to reflect relevant principles of the CARIN Alliance Code of Conduct, including transparency, proactive consent for optional disclosures, individual access, security, provenance, and accountability.
A reference to CARIN or NIST does not mean Aquila has received a certification, accreditation, or governmental approval. Aquila will identify any formal attestation or independent accreditation separately if and when it is obtained.
Aquila as an Independent Business
Aquila independently controls limited information used for account administration, service security, billing, relationship management, legal compliance, and the operation of Aquila’s business.
Information Processed Through TREUE
Depending on the service, customer, data source, and user authorization, TREUE may process the following categories of information.
Identity and Contact Information
This may include:
- Name
- Date of birth
- Address
- Email address
- Telephone number
- Sex or gender information
- Patient, member, medical-record, or account identifiers
- Government-issued or identity-verification attributes
- Authentication credentials or tokens
- Authorized representative or caregiver information
- Information used to resolve identity across systems
Aquila may use deterministic, probabilistic, or privacy-preserving methods to associate records with the correct person. Matching results may include confidence scores and supporting provenance.
Health and Health Care Information
This may include:
- Diagnoses and conditions
- Medications
- Allergies
- Immunizations
- Laboratory results
- Vital signs
- Procedures
- Encounters and admissions
- Clinical notes and documents
- Radiology or imaging reports
- Care plans
- Behavioral health information
- Substance use disorder information
- Reproductive health information
- Disability information
- Genetic or genomic information
- Family medical history
- Claims and billing information
- Insurance and eligibility information
- Provider and facility information
- Device, remote-monitoring, or wearable data
- Social determinants of health
- Public health and registry information
- Other health-related data selected by a user, customer, source, or legally authorized program
Not every TREUE deployment processes every category.
Account and Consent Information
This may include:
- User account information
- Identity-assurance status
- Authentication events
- Consent and authorization records
- Consent scope, purpose, recipient, and duration
- Revocation records
- Authorized caregiver designations
- Data-sharing preferences
- Notices presented to the user
- Records showing when a user accepted or declined an optional use
Technical and Usage Information
This may include:
- IP address
- Device and browser information
- API credentials and tokens
- API calls
- Log records
- Date and time information
- System events
- Configuration information
- Security alerts
- Data-source identifiers
- Transaction status
- Diagnostic information
Provenance, Quality, and Transformation Information
TREUE may maintain information showing:
- The source of a record
- When and how the record was received
- The original data format
- Normalization or transformation steps
- Terminology mappings
- Data-quality results
- Identity-matching methods
- Confidence indicators
- Consent and policy checks
- Authorized recipients
- System or model versions involved
- Human review or correction history
Sources of Information
TREUE may receive information from:
- The individual or an authorized caregiver
- Health care providers
- Health plans and payers
- Health information exchanges and health data utilities
- Pharmacies and laboratories
- Public health authorities
- Government agencies
- Clinical or claims systems
- Connected applications
- Wearable or medical-device providers
- Research organizations
- Customer files or databases
- Standards-based APIs, including FHIR APIs
- Health care messaging and document formats
- Authorized third parties
- Information derived from the operation of TREUE
Aquila processes information from a source only when supported by an applicable agreement, consent, authorization, legal permission, or other documented authority.
Why Aquila Processes Information
Depending on Aquila’s role and the authorized service, Aquila may process information to:
- Authenticate users and verify identity
- Locate and retrieve authorized records
- Match records to the correct individual
- Transmit or exchange information
- Normalize formats, terminology, codes, and units
- Convert information between supported interoperability formats
- Identify duplicates, gaps, conflicts, or quality issues
- Assemble authorized longitudinal views
- Apply consent, access, segmentation, and disclosure rules
- Route information to a recipient selected by an authorized user or customer
- Support treatment, payment, or health care operations where legally authorized
- Support public health, research, quality, payment integrity, or other authorized programs
- Provide analytics or reports requested by a customer
- Maintain audit and provenance records
- Provide customer service and technical support
- Monitor performance and reliability
- Protect against security threats and fraud
- Comply with law and contractual requirements
- Establish, exercise, or defend legal claims
- Improve TREUE
- Develop or test authorized functionality
- Create aggregated or de-identified information
Aquila will not use PHI or consumer-directed personal health data for an unrelated purpose merely because the data is technically available.
Legal Authority, Consent, and Conditions of Service
Not all processing through TREUE relies on individual consent. Depending on the circumstances, processing may be authorized by:
- A user’s direction or individual right-of-access request
- A HIPAA authorization
- Treatment, payment, or health care operations
- A business associate agreement
- A data use or participation agreement
- Public health law
- Research consent, an IRB waiver, or another research authority
- A government contract or legal mandate
- Another permission under applicable law
- Aquila’s legitimate need to secure and administer the service
Required Processing
Some processing is necessary to provide the feature requested by the user or customer. Examples may include identity verification, authentication, record retrieval, data normalization, security logging, transmission to a selected recipient, or maintaining a legally required audit record.
A user may be unable to use a particular feature without permitting processing that is necessary to provide that feature.
Optional Processing
Aquila will provide a separate choice where an activity is optional and applicable law, a contract, or the CARIN principles call for affirmative consent.
Optional activities may include:
- Disclosing data to an additional recipient selected by the user
- Maintaining a persistent connection instead of a one-time retrieval
- Participating in an optional research project
- Using identifiable data for optional product research
- Using data for marketing
- Using data for targeted advertising
- Using data for automated decision-making that produces legal or similarly significant effects
A refusal to permit an optional activity will not prevent use of unrelated core functionality, unless the optional activity is the core functionality the user requested.
Consumer-Directed Data Sharing
When a user directs TREUE to retrieve or disclose personal health information:
- Aquila will identify the information or categories of information involved to the extent reasonably practicable
- Aquila will identify the intended recipient or allow the user to select the recipient
- Aquila will explain whether the connection is one-time or persistent
- Aquila will describe the purpose or functionality supported by the disclosure
- Aquila will obtain affirmative authorization where required
- Aquila will maintain a record of the direction, consent, or authorization
- Aquila will provide a reasonable mechanism to revoke an optional ongoing connection
A user should carefully evaluate a recipient before authorizing disclosure. After information has been disclosed to a recipient selected by the user, that recipient may control the information under its own privacy practices. Aquila may not be able to retrieve information already received, copied, or further disclosed by that recipient.
Revocation generally applies prospectively. It does not invalidate processing or disclosures that occurred lawfully before the revocation.
How Aquila Discloses Information
Aquila may disclose information to:
Recipients Selected or Authorized by the User
This may include a health care provider, caregiver, application, researcher, family member, or other recipient selected by the user.
Customers and Participating Organizations
Aquila may make information available to the provider, payer, HIE, agency, researcher, or other organization for which Aquila processes the information.
Data Sources and Exchange Participants
Limited information may be exchanged with a source or participant to authenticate a request, locate records, validate identity, resolve a data-quality issue, or complete an authorized transaction.
Service Providers and Subcontractors
Aquila may use providers for infrastructure, identity verification, communications, security, data processing, support, analytics, or other operational services.
Aquila will contractually restrict providers according to the nature of the information, Aquila’s role, and applicable law. Providers receiving PHI on Aquila’s behalf will be subject to a BAA where required.
Government, Legal, and Safety Recipients
Aquila may disclose information when required or expressly permitted by applicable law, including in response to valid legal process, health oversight, public health authority, or another legally authorized request.
Aquila may also disclose information when reasonably necessary to investigate fraud, address a security threat, protect a person, or establish, exercise, or defend a legal claim.
Additional restrictions will be applied to specially protected information when required by law.
Corporate Transactions
Information may be disclosed in connection with due diligence, financing, a merger, an acquisition, a sale of assets, a restructuring, bankruptcy, or a similar transaction.
Where Aquila directly controls a consumer account, Aquila will provide legally required notice and will take at least one of the following actions, as appropriate:
- Require the successor to honor applicable existing privacy commitments
- Give the user an opportunity to close the account
- Allow an available export or transfer
- Securely delete eligible information
- Obtain additional consent where required
Service Providers and Recipient Restrictions
Aquila requires service providers that process personal information for Aquila to use it only for authorized services and to maintain safeguards appropriate to the information.
Where Aquila permits a recipient to receive de-identified information, Aquila may require the recipient to:
- Maintain the information in de-identified form
- Take reasonable steps to prevent association with an individual
- Refrain from attempting re-identification
- Apply the same restrictions to downstream recipients
Aquila cannot control a third party that independently receives information at the direction of the individual, except to the extent Aquila has a contractual or legal right to impose restrictions.
De-Identified, Aggregated, and Pseudonymized Information
Where permitted by applicable law and agreement, Aquila may create, use, and disclose aggregated or de-identified information for:
- Analytics
- Benchmarking
- Data-quality improvement
- Platform development
- Research
- Public health
- Service planning
- Security
- Reliability analysis
- Other lawful purposes
Information derived from PHI will be de-identified using an applicable HIPAA method unless another legally permitted method is authorized. Aquila will not attempt to re-identify information maintained as de-identified except as permitted by law to test or validate the de-identification process.
Pseudonymized information is information that cannot be attributed to an individual without additional separately maintained information. Aquila will protect pseudonymized information as personal information when Aquila or another authorized party retains the ability to attribute it to an individual.
Artificial Intelligence and Automated Processing
TREUE may use rules, statistical methods, machine learning, or generative artificial intelligence to assist with functions such as:
- Data classification
- Format conversion
- Terminology mapping
- Record matching
- Data-quality review
- Duplicate identification
- Document extraction
- Summarization
- Anomaly detection
- Workflow routing
- Suggested remediation
Aquila may maintain confidence indicators, provenance, system versions, and human-review records for consequential transformations. TREUE is not intended to make an independent final diagnosis or replace professional judgment.
Unless Aquila provides a separate notice, TREUE will not use consumer-directed personal health data to make solely automated decisions that independently determine an individual’s eligibility for health care, insurance, employment, housing, credit, education, criminal justice, or another legally significant service.
Where an optional feature would involve automated decision-making producing legal or similarly significant effects, Aquila will provide any notice, consent, human-review mechanism, or opt-out required by applicable law.
Marketing and Targeted Advertising
Aquila does not sell personal health data for monetary consideration.
Aquila does not use or disclose personal health data for targeted advertising.
Aquila will not use or disclose personal health data for third-party marketing without separate, informed, affirmative consent where required by applicable law or the CARIN principles.
Consent concerning one individual does not authorize Aquila to use another person’s health information for marketing merely because the other person is referenced in the first individual’s records.
Aquila may communicate with users about TREUE functionality, account security, service changes, requested services, or Aquila’s own related products, subject to applicable law and available communication preferences.
Access and Portability
Where Aquila directly maintains a consumer-controlled TREUE account, a user may request access to personal information maintained in that account, subject to identity verification, technical feasibility, applicable law, and exceptions.
Available functionality may allow a user to:
- View information
- Download information
- Transmit information to a selected recipient
- Review consent status
- Review connected sources
- Review authorized recipients
- Obtain information concerning prior activity
When Aquila processes information solely for a customer or HIPAA covered entity, the request should ordinarily be submitted to that organization. Aquila will assist the organization as required by contract or law.
Nothing in this policy expands the HIPAA designated record set or requires Aquila to create a record that Aquila does not maintain.
Corrections and Data Quality
Health information displayed through TREUE may originate from another organization. Aquila generally cannot change the source organization’s official medical, claims, or administrative record.
A user may report suspected inaccurate or incomplete information through [Correction or Support Process].
Aquila may:
- Determine whether the issue originated with Aquila or a source
- Correct an error introduced by Aquila
- Add an annotation or quality indicator
- Notify or route the issue to the source
- Provide information about contacting the source
- Reprocess information after the source corrects it
- Explain why the information cannot be changed
Aquila does not guarantee that information received from another organization is complete or error-free.
Deletion and Account Closure
Where Aquila directly controls a consumer account, a user may request closure of the account and deletion of eligible personal information.
Aquila may retain information when reasonably necessary to:
- Comply with law
- Fulfill a customer or contractual obligation
- Maintain an audit, provenance, consent, or transaction record
- Protect security or prevent fraud
- Document prior lawful processing
- Resolve disputes
- Establish, exercise, or defend legal claims
- Protect another person’s rights
- Complete a backup or disaster-recovery cycle
A deletion request generally does not require Aquila to delete:
- Information held by an independent source or recipient
- A covered entity’s designated record set
- Information Aquila processes solely on another organization’s instructions
- Information that must be preserved by law or contract
- Properly de-identified information
- Information already disclosed at the user’s direction
When information cannot be deleted, Aquila may restrict further use to the purpose requiring retention.
Retention and Dormant Accounts
TREUE retention periods vary based on the deployment, transaction, information type, legal authority, and applicable agreement.
Some information may be processed transiently. Other information may be retained to provide longitudinal functionality, maintain consent and audit history, meet customer requirements, comply with law, or preserve provenance.
Aquila may designate a consumer account as dormant after [Dormancy Period] without activity.
Before closing a dormant consumer account, Aquila will provide notice when reasonably practicable and legally required.
A dormant or closed account may remain subject to limited security, audit, legal, and backup retention.
Provenance
Where reasonably possible, Aquila maintains information identifying:
- The original source of information
- The date and method of receipt
- Transformations performed
- Data-quality or normalization actions
- Material annotations
- The source of a correction
- The recipient of an authorized disclosure
- The consent or policy authority supporting a transaction
Provenance information may be retained even when associated content is deleted if the provenance record is reasonably necessary for security, compliance, accountability, or legal purposes.
Information Concerning Other People
A person’s health information may contain information about relatives, caregivers, dependents, or other individuals. Genetic and family-history information can reveal information about biologically related people.
A user should consider these effects before downloading or disclosing records. A user’s authority over their own record does not necessarily grant authority to independently use another person’s information for marketing, public posting, or another unrelated purpose.
Aquila may restrict or segment information concerning another person when required by law, contract, or applicable technical standards.
Authorized Representatives and Caregivers
An authorized representative or caregiver may use TREUE only within the scope of legally valid authority.
Aquila may require documentation or verification of:
- Guardianship
- Parental authority
- Personal representation
- Power of attorney
- Caregiver designation
- Proxy access
- Individual authorization
- Other lawful authority
Aquila may suspend representative access if the authority expires, is revoked, is disputed, cannot be verified, or appears inconsistent with law or the individual’s interests.
Minors
TREUE is not intended for independent use by a child under 13 unless the service is specifically designed for that use and appropriate parental, guardian, customer, or legal authorization has been established.
Rules governing minors’ health information vary by state, type of care, parental authority, and the minor’s legal ability to consent to treatment. Aquila may rely on instructions from the responsible provider, payer, customer, or legally authorized representative.
Security
Aquila maintains administrative, technical, and physical safeguards selected through a risk-based program informed by recognized NIST standards and applicable health-information security requirements.
Controls may include:
- Identity verification
- Multifactor authentication
- Role- and attribute-based access
- Least privilege
- Encryption in transit and at rest
- Segmentation
- Logging and monitoring
- Provenance and audit controls
- Secure development
- Vulnerability and patch management
- Incident response
- Workforce training
- Vendor risk management
- Backup and recovery controls
- Security testing or independent assessment
Safeguards vary by deployment and risk. No technology or security program can eliminate all risk.
Users must protect credentials, review recipients carefully, use approved devices and networks, and promptly report suspected unauthorized activity.
Breach and Incident Notification
Aquila investigates suspected unauthorized access, acquisition, use, or disclosure.
Aquila will notify customers, covered entities, individuals, regulators, or other parties when and as required by applicable law or contract. Depending on Aquila’s role, the responsible customer or covered entity may provide the notice to affected individuals.
For consumer-directed health information outside HIPAA, an incident may be subject to the FTC Health Breach Notification Rule or applicable state consumer-health laws.
Nothing in this policy creates a notice obligation beyond the applicable law or written agreement.
HIPAA and Other Health Privacy Laws
When Aquila acts as a HIPAA business associate, Aquila’s handling of PHI is governed by HIPAA provisions applicable to business associates and the applicable BAA.
This policy is not a HIPAA Notice of Privacy Practices and does not replace the notice issued by a covered entity.
Certain information may be subject to additional legal restrictions, including restrictions applicable to:
- Substance use disorder records
- Reproductive health information
- Genetic information
- Mental or behavioral health information
- HIV or communicable-disease information
- Minor-consented care
- Public health records
- Research records
Aquila applies such restrictions when they are legally applicable to Aquila’s role and the transaction.
State Privacy Rights
Depending on your state, Aquila’s role, and the applicable law, you may have rights to:
- Confirm processing
- Access information
- Correct information
- Delete information
- Obtain portable information
- Obtain information about disclosures
- Withdraw consent
- Opt out of targeted advertising, sale, or qualifying profiling
- Restrict certain consumer-health-data processing
- Appeal a denied request
Rights are subject to verification, exemptions, legal thresholds, and Aquila’s role. Where Aquila acts solely for a customer, Aquila may direct the request to that customer. Submit requests through privacy@aquilahealth.com.
Complaints and Accountability
Questions or complaints may be submitted to Aquila’s Privacy Office.
Aquila may:
- Request information necessary to investigate
- Refer a customer-controlled issue to the responsible customer
- Correct an Aquila-controlled error
- Explain applicable limitations
- Document the complaint and response
- Take remedial action appropriate to the circumstances
Aquila trains relevant personnel on privacy and security responsibilities and periodically evaluates applicable controls and practices. Aquila has designated [Responsible Executive Title] as the executive responsible for oversight of Aquila’s privacy program.
Changes to This Policy
Aquila may update this policy to reflect changes in services, technology, law, or privacy practices.
Aquila will provide clear notice of a material change before applying the change to previously collected consumer-directed personal health information where required.
When a material change would permit a materially different optional use or disclosure, Aquila will obtain renewed consent where required or allow the user to withdraw the applicable consent or close the account.
Nonmaterial changes become effective when posted.