Account Deletion, Data Deletion, and In-App Requests
If a Cognera Health mobile application or service allows users to create an account, Cognera Health will provide an in-app account deletion flow or a clearly accessible account deletion request process.
Users shall initiate account deletion from within HealConnect™ or HealScript™, and Cognera Health shall maintain this public web-based deletion request page for app store, privacy, and data safety compliance.
For account types, customer configurations, or enterprise deployments without in-app deletion for a particular account type, customer configuration, or enterprise deployment, users may submit a deletion request through this page or contact Privacy.
Data Covered by a Request
Deletion requests include deletion or deactivation of the user account, deletion of personal information that Cognera Health is not legally or contractually required to retain, and removal of app-accessible account data from active systems where permitted.
Account Access
Account closure, deactivation, credential removal, and removal of app-accessible profile data where permitted.
Personal Information
Deletion of personal information not required for legal, clinical, contractual, compliance, audit, continuity-of-care, or security purposes.
Request Support
Privacy request routing for mobile app, website, customer, provider, and service-related requests.
Information That May Need to Be Retained
Certain records shall be retained when required or permitted for HIPAA, HITECH, healthcare record retention, state healthcare laws, legal obligations, security, fraud prevention, audits, investigations, legal holds, customer contracts, continuity-of-care requirements, regulatory inquiries, dispute resolution, tax/accounting obligations, or other preservation purposes.
- Clinical, healthcare, PHI, ePHI, behavioral health, assessment, treatment, and care coordination records subject to healthcare retention obligations.
- Security, audit, authentication, fraud prevention, investigation, compliance, and governance records.
- Records preserved for legal holds, customer contracts, provider obligations, continuity-of-care, regulatory requirements, or enterprise backup schedules.
- Backup and disaster recovery copies retained according to approved backup lifecycle schedules before secure disposal.
Identity Verification
To protect privacy, security, and regulated healthcare information, Cognera Health shall require reasonable verification of identity, authority, organizational affiliation, account ownership, legal representative status, or provider/customer relationship before processing deletion requests.
Cognera Health shall request additional information only as needed to verify the request, locate relevant records, determine whether retention obligations apply, or route the request to the appropriate healthcare provider, Covered Entity, organization, or product workflow.
Request Processing Timeline
- Most verified requests are reviewed within 30 days.
- Complex requests, healthcare record reviews, enterprise customer routing, or legally sensitive requests can require additional time where permitted by law.
- When more time is needed, Cognera Health shall provide an update where required by applicable law or contract.
- Certain records shall be retained despite deletion requests when retention is legally, clinically, contractually, operationally, or security-related required.
How Cognera Health Reviews Requests
Cognera Health reviews deletion requests based on applicable privacy laws, healthcare record requirements, customer contracts, Business Associate Agreements, product configuration, provider instructions, and security requirements.
- Submit the request form, use the in-app deletion workflow, or email Privacy.
- Cognera Health reviews the request and verifies identity or authority where required.
- Eligible data is deleted, deactivated, restricted, de-identified, anonymized, or otherwise dispositioned where permitted.
- Where data must be retained, Cognera Health preserves only what is required or permitted and applies appropriate safeguards.
- Where Cognera Health acts as a Business Associate, requests may be routed to the applicable Covered Entity or healthcare provider.
Privacy Rights Request Workflow
Cognera Health processes data deletion and privacy rights requests through a documented workflow designed to support privacy, security, healthcare, legal, regulatory, contractual, and audit requirements.
Legal Hold and Preservation Requirements
Deletion requests may be delayed, restricted, partially fulfilled, or denied when information is subject to preservation obligations.
- Legal Holds
- Litigation Holds
- Investigations
- Regulatory Reviews
- Law Enforcement Requests
- Contractual Preservation Requirements
- Audit Requirements
- Healthcare Record Retention Requirements
- Continuity-of-Care Requirements
Deletion Request Denial Scenarios
A deletion request may be denied, limited, delayed, or only partially fulfilled when Cognera Health is required or permitted to retain information.
- Healthcare record retention laws apply.
- Continuity-of-care obligations apply.
- Legal hold requirements exist.
- Fraud prevention requirements exist.
- Security investigations are ongoing.
- Regulatory reviews are in progress.
- Contractual preservation requirements apply.