CoreScripts policies
Privacy Policy
This policy covers information we collect through getcorescripts.com and the CoreScripts patient portal. Health information created in the course of your care is separately governed by our Notice of Privacy Practices.
In plain language
We do not sell your personal health information. We never have and we do not intend to.
Two sets of rules apply. Health information your clinician and pharmacy create is protected under HIPAA and covered by the Notice of Privacy Practices. Everything else — what you browse, your marketing preferences, your billing record — is covered here.
You can ask us for a copy of your data, ask us to correct or delete it, and opt out of marketing at any time.
1Who this policy covers
This Privacy Policy describes how MXS Suppliments LLC, a Delaware limited liability company doing business as CoreScripts (1309 Coffeen Ave, Ste 1200, Sheridan, WY 82801), handles information collected through getcorescripts.com, the patient portal, and related communications.
Two frameworks apply. Protected health information (“PHI”) created or received by CoreScripts Medical Group, P.A. and by dispensing pharmacies in the course of your treatment is governed by HIPAA and described in our Notice of Privacy Practices. This policy governs the other information we handle — website usage, account and billing records, marketing preferences, and support correspondence — and applies where HIPAA does not.
2Information we collect
Information you give us
- Account details — name, email address, phone number, date of birth, shipping and billing address, password.
- Intake and health information — symptoms, conditions, medications, allergies, height and weight, and the answers you provide in the medical intake, along with any photographs or laboratory results you upload.
- Payment information — processed by our PCI-DSS compliant payment processors. We do not store full card numbers on our systems. We retain a token, the card brand, the last four digits, and the expiration date.
- Correspondence — messages you send to support or to your care team.
Information collected automatically
- Device and browser type, operating system, IP address, and approximate location derived from it (used in part to confirm you are in the United States and in which state).
- Pages viewed, referring URL, time stamps, and interaction events.
- Cookies and similar technologies, described in section 7.
Information from others
- Dispensing pharmacies, laboratories, and shipping carriers, for order and tracking status.
- Identity- and address-verification services and fraud-prevention providers.
- Advertising partners, where permitted, for measurement and attribution.
3How we use information
- To provide the Services — route your intake to a licensed clinician, transmit an approved prescription to a pharmacy, arrange shipping, and support your care.
- To bill you — process the monthly membership charge, handle refunds, and prevent payment fraud.
- To communicate — transactional email and SMS about your order, shipment, renewal, and account, and, where you have not opted out, marketing messages.
- To operate and improve — analytics, troubleshooting, security monitoring, and product development.
- To comply with law — recordkeeping obligations, responses to lawful requests, adverse-event reporting, and enforcement of our terms.
We do not use protected health information for advertising or marketing purposes without your written authorization.
5Your privacy rights
Depending on where you live, you may have the right to:
- Know and access — request the categories and specific pieces of personal information we hold about you;
- Correct — ask us to fix inaccurate information;
- Delete — ask us to delete personal information, subject to legal and medical-record retention requirements;
- Portability — receive a copy in a portable format;
- Opt out — of sale or sharing (we do neither), and of targeted advertising;
- Limit — the use of sensitive personal information;
- Non-discrimination — we will not deny service, charge a different price, or provide a lesser quality of service because you exercised a right.
Residents of California (CCPA/CPRA), Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and other states with comprehensive privacy laws have these rights by statute. Residents of Canada have comparable rights under PIPEDA, and residents of the European Economic Area and the United Kingdom under the GDPR — note, however, that the Services are offered only to people physically located in the United States.
How to exercise a right
Email support@getCoreScripts.com with the subject line “Privacy Request” or call 1-888-888-8888. We will verify your identity before acting, respond within 45 days, and may extend once by another 45 days with notice. An authorized agent may submit a request with written proof of authorization.
Appeals. If we decline your request, you may appeal by replying to our decision with the subject line “Privacy Appeal.” If the appeal is denied you may contact your state attorney general.
Medical records. Requests to access or amend your medical record are handled under HIPAA through the Notice of Privacy Practices.
6Marketing choices
You can unsubscribe from marketing email using the link in any message, or by emailing support@getCoreScripts.com. You can stop marketing SMS by replying STOP to any message; reply HELP for help. Message and data rates may apply.
Transactional messages continue regardless. We will still send order confirmations, shipping notices, renewal reminders, clinical messages, and account and security notices, because they are necessary to deliver the Services you purchased.
8How we protect information
We maintain administrative, technical, and physical safeguards appropriate to the sensitivity of the information, including encryption of data in transit (TLS) and at rest, role-based access control, least-privilege administration, audit logging, background checks and periodic HIPAA training for workforce members with access to PHI, written business associate agreements with vendors that handle PHI, and a documented incident-response and breach-notification process.
No system is perfectly secure. We cannot guarantee absolute security, and you share information with us at your own risk. If a breach affecting your information occurs, we will notify you as required by HIPAA and applicable state law.
9How long we keep information
We keep information for as long as needed to provide the Services and to meet legal obligations. Medical records are retained for the period required by the law of the state in which care was delivered — commonly six to ten years from the last date of service, and longer for patients who were minors at the time of treatment. Financial and tax records are kept for at least seven years. Website analytics data is kept in identifiable form for no more than twenty-six months. When information is no longer needed we delete it or de-identify it.
10Children's privacy
The Services are intended only for adults 18 and older. We do not knowingly collect personal information from anyone under 18. If we learn that we have, we will delete it. A parent or guardian who believes a child has provided us information should contact us immediately.
11Changes to this policy
We may update this policy. The “Last updated” date above reflects the most recent revision. If we make a material change we will notify you by email or through the portal before the change takes effect. Continued use of the Services after the effective date constitutes acceptance.
Contact. Privacy Officer, MXS Suppliments LLC d/b/a CoreScripts, 1309 Coffeen Ave, Ste 1200, Sheridan, WY 82801 · support@getCoreScripts.com · 1-888-888-8888.
Questions about this page?
Email support@getCoreScripts.com or call 1-888-888-8888, Monday–Friday, 9am–6pm Eastern. Write to CoreScripts, 1309 Coffeen Ave, Ste 1200, Sheridan, WY 82801.