/*-------------------------------- Amplitude Tag --------------------------------*/
Last Updated: September 15, 2026
We updated this Privacy Policy and added an Individual Access Services Privacy and Security Notice effective September 15, 2026. The changes clarify that Marble and SettLiT are names used by Medchart US Inc.; reorganize and clarify the categories of Personal Information we collect and how we use and disclose it; add information about identity verification, deidentified information, retention, security, and individual privacy rights; and add IAS-specific terms addressing consent, use and disclosure, deletion, access and export, legal process, incident notification, deidentification, and other applicable TEFCA requirements.
Your privacy is our first priority.
Medchart US Inc. dba Marble (“Marble”) is an information technology service provider that enables you, your Personal Representative, or customers acting with appropriate authorization to use electronic means to request, collect, access, maintain, organize, review, and share health information, medical records, and related data. Medchart US Inc. also does business as SettLiT. This Privacy Policy explains how Marble collects, uses, discloses, retains, and protects Personal Information in connection with its services in the United States. In this Privacy Policy, “Marble,” “we,” “us,” and “our” refer to Medchart US Inc. doing business as Marble.
The Individual Access Services Privacy and Security Notice below describes the additional requirements applicable when Individual Access Services are made available through Marble. Medchart US Inc., doing business as Marble, is the Individual Access Services Provider (“IAS Provider”) identified in the TEFCA Directory. The IAS Notice is part of and supplemental to this Marble Privacy Policy. Certain TEFCA requirements incorporate specified provisions of the Standards for Privacy of Individually Identifiable Health Information under the Health Insurance Portability and Accountability Act (the “HIPAA Privacy Rule”); those TEFCA-specific requirements are described in the IAS Notice below.
This Policy is effective as of the “Last Updated” date listed above. We reserve the right to change this Privacy Policy from time to time to ensure that it accurately reflects our services, practices, applicable law, and Marble policies. We will revise the “Last Updated” date above and provide additional notice or obtain consent if required by applicable law. Material changes to the Individual Access Services Privacy and Security Notice are subject to the IAS-specific consent requirements described below.
Personal Information
“Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with an individual or household, or that is otherwise treated as personal information, personal data, or a similar term under applicable law.
Health Information
“Health Information” means Personal Information that relates to an individual’s past, present, or future physical or mental health or condition, health care, payment for health care, or medical records. Depending on the context and applicable law, Health Information may be protected health information under HIPAA, consumer health data or sensitive personal information under state law, or Individually Identifiable Information under TEFCA. We use those more specific terms only where they apply.
Health Information Sources
“Health Information Sources” are health care providers, health plans and insurers, pharmacy networks, laboratory networks, insurance claims networks and clearinghouses, electronic medical record systems, state health information exchanges, national health data exchanges accessed through Marble’s Individual Access Services where applicable, medical record custodians, and other persons or organizations from which Marble obtains medical records or other Health Information at your direction, at the direction of a Marble customer acting with appropriate authorization, or as otherwise permitted by applicable law.
Deidentified Information
“Deidentified Information” means information that no longer constitutes Personal Information under applicable law because it has been deidentified in accordance with the applicable legal standard. Different laws and contracts may impose different deidentification requirements. The additional TEFCA requirements that may apply to deidentification of Individually Identifiable Information are described in the IAS Notice below.
Personal Representatives and Other Authorized Representatives
You may authorize another person, including a family member, advisor, lawyer, caregiver, or health care provider, as a Personal Representative to act on your behalf. Marble may require reasonable verification of that person’s identity and authority. Whether a parent, guardian, Personal Representative, executor, or other person may act for an individual, and the scope of that authority, is determined by applicable law and any valid authorization or other documentation.
Depending on how you interact with Marble, or how a Marble customer uses the services on your behalf, we may have collected the following categories of Personal Information. These categories may overlap.
Information You Provide Directly
When you register for or use a Marble service, we collect Personal Information that you, your Personal Representative, or a Marble customer acting with appropriate authorization provide directly, including your name, mailing address, email address, telephone number, date of birth, account identifiers, and other information described below.
Information We Collect at Your Direction
At your direction or the direction of a Marble customer, and with your consent or authorization where required, Marble collects medical records and other Health Information from Health Information Sources. If you designate a Personal Representative, you may also authorize that person to provide information to Marble and to access or direct the disclosure of information on your behalf, subject to the scope of that person’s authority.
Identity and Verification Information
When Marble services include identity verification, Marble or its service providers may collect information from you and from third-party identity and verification providers. Depending on the service and verification method, this may include information from a government-issued identification document, an image or selfie, identity-verification results, and similar information necessary to verify identity or authority.
Information from Marble Customers, Integrations, and Applications
Marble may receive information from customers, case management systems, integrations, APIs, or other applications, including client and case information that customers upload, import, or sync, as necessary to create or manage client profiles, present authorization requests, retrieve and organize records and related data, and provide the services requested or authorized by the customer or individual.
Website, Device, and Usage Information
When you visit our website or use our online services, Marble collects information about how and when you use our website and services, including information about pages or content viewed, browser and device type and settings, operating system, IP address, unique identifiers, system activity, crash reports, and the date, time, and referring URL associated with a request.
Cookies and Similar Technologies
The Site uses cookies and similar technologies to help personalize and support your online experience. Cookies are small amounts of data that often include unique identifiers that enable the Site to recognize you and keep track of your preferences. We use cookies and similar technologies for authentication, security, functionality, preferences, analytics and measurement, load balancing, and navigation. Cookies may include “session” cookies, which are not permanently stored and expire when your session ends, and “persistent” cookies, which remain on your device for a defined period or until deleted.
You have the ability to disable or manage cookies through your browser settings and any cookie or privacy controls Marble makes available. If cookies are disabled, some features or services of the Site may not be available or function as intended.
Marble uses Personal Information, including Health Information, for the following purposes:
Separate from the IAS-specific requirements described below, Marble may deidentify and/or aggregate Personal Information in accordance with applicable law and applicable contractual restrictions. Where required by applicable law, Marble will maintain and use deidentified information in deidentified form, will not attempt to reidentify it except as permitted by law to test or validate deidentification, and will require recipients to maintain the information in deidentified form and not attempt to reidentify it.
Marble may disclose Personal Information, including the categories described above, to the following categories of recipients for the purposes described in this Privacy Policy:
Marble does not authorize its service providers to use Personal Information received from Marble for their own marketing or other independent purposes unless separately permitted by applicable law and the governing agreement.
Marble does not sell or disclose medical records or other identifiable Health Information in exchange for direct or indirect remuneration except as permitted by applicable law and, where required, after obtaining the specific consent or authorization required by applicable law. Some state privacy laws use the terms “sale,” “sharing,” or “targeted advertising” to cover certain online disclosures that may not involve a traditional sale for money. Marble will provide any notices and honor any rights required by applicable law if Marble engages in a practice to which those requirements apply.
Marble will retain Personal Information for so long as reasonably necessary to provide our services and satisfy applicable legal, contractual, security, and business requirements. The retention period for a particular category of information depends on factors such as the duration of the account or service relationship, the nature and sensitivity of the information, the purpose for which it was collected, applicable authorization or consent requirements, and legal or contractual obligations. When Personal Information is no longer needed, Marble deletes, deidentifies, or otherwise disposes of it as appropriate, subject to applicable law and technical requirements such as backup or audit-log retention.
Your Personal Information may be processed and/or stored outside of the United States as necessary or appropriate to provide our services. Marble takes reasonable measures to protect your Personal Information regardless of where it is processed or stored. Information processed in another jurisdiction may be subject to the laws of that jurisdiction and may be disclosed as permitted or required by applicable law. Where applicable law requires additional safeguards for a transfer, Marble will implement the required safeguards.
Marble has deployed appropriate physical, administrative, and technical measures designed to safeguard your Personal Information against theft, loss, unauthorized access, copying, modification, use, disclosure, and disposal. These measures include appropriate security policies, employee training, confidentiality obligations, audits and compliance monitoring, access controls, monitoring, and encryption or other security technologies appropriate to the nature of the information and applicable requirements. No security measure can eliminate all risk.
Access to online accounts, medical records, and other client data is protected by account credentials and other security measures. Where available, we encourage you to use multi-factor authentication and to protect your account credentials from unauthorized use.
Marble does not knowingly collect Personal Information about minors without the consent or authorization of a parent, guardian, Personal Representative, or the minor, where required by applicable law.
Depending on where you live, the Personal Information involved, and applicable law, you may have some or all of the following rights:
How to Exercise Your Rights
To submit a privacy request, email privacy@medchart.com or call 1-833-603-0407. Please provide enough information for Marble to identify the request and respond. We may need to ask for additional information to verify your identity. Where a request is made by a Personal Representative or authorized agent, Marble may also need to verify that person’s authority. Where applicable law gives you a right to appeal Marble’s decision on a privacy request, you may request an appeal by replying to the decision or contacting privacy@medchart.com and identifying the request as a privacy appeal. Where Marble processes Personal Information on behalf of a customer, such as a law firm, that customer may be responsible for responding to your request under applicable law. In those circumstances, Marble may direct your request to the customer or assist the customer in responding.
For more information about Marble’s privacy practices, or to raise a question or concern, please contact:
Juliana Doxey
Chief Privacy Officer, Medchart US Inc.
215 S. Denton Tap Rd., Suite 290
Coppell, TX 75019
Email: privacy@medchart.com
Toll-free: 1-833-603-0407
Fax: 1-888-929-2687
IAS Notice Effective Date: September 15, 2026
Marble makes Individual Access Services (“IAS”) available through Medchart US Inc., the legal entity doing business as Marble. Medchart US Inc. provides IAS in conformance with the Trusted Exchange Framework and Common Agreement (“TEFCA”) issued by the U.S. Department of Health and Human Services. This IAS Notice is part of and supplemental to the Marble Privacy Policy above. For purposes of this IAS Notice, the “IAS Provider” is Medchart US Inc. doing business as Marble. Marble is listed as the Individual Access Services Provider identified in the TEFCA Directory. Medchart US Inc. also does business as SettLiT. The scope of Marble services, datasets, or processing activities subject to IAS or HIPAA requirements is determined by the applicable TEFCA Framework Agreements, standard operating procedures, and applicable law.
This IAS Notice explains the additional privacy and security practices applicable to Individually Identifiable Information (“III”) maintained by Medchart US Inc. where TEFCA requirements apply, including rights that apply specifically to III maintained by Medchart US Inc. in connection with IAS (“IAS Data”). For purposes of TEFCA, where the Framework Agreements or applicable standard operating procedures refer to “III” generally, the requirement applies to all III maintained by Medchart US Inc. as the IAS Provider legal entity, regardless of source. Where they refer specifically to “III maintained by the IAS Provider in connection with IAS,” that term applies to information accessed by an individual using the TEFCA Exchange.
Relationship with Other Agreements
Once information retrieved through Individual Access Services is available to you in the Individual Access Services App, the Individual Access Services App’s terms of service and privacy notice apply to that information. Those terms do not displace any TEFCA obligations that continue to apply while the III remains within Medchart US Inc.'s stewardship.
If there is a conflict between this IAS Notice and the Individual Access Services App's terms or privacy notice, this IAS Notice controls to the extent necessary to satisfy Medchart US Inc.'s obligations as the IAS Provider under TEFCA.
How IAS Data is Accessed, Exchanged, Used, and/or Disclosed
In general, we only share your information with you or your Personal Representative(s), any person or organization authorized by you or your Personal Representative(s), and our third-party service providers. We may also share your information when required by law or court order, or in connection with business transfers (such as a merger or acquisition).
We share the minimum information necessary to search for, locate and retrieve information. If authorized by you or your Personal Representative(s), we can also share information with organizations that you designate or their participating organizations.
We share the minimum necessary information with our sub-processors to help us provide the Individual Access Services. These companies are acting on our behalf and are required, by contract with us, to keep your information confidential, and are only authorized to use it for specified purposes, consistent with our contractual commitments, applicable law and other requirements.
All disclosures through TEFCA are made in accordance with the permitted and required Uses and Disclosures specified in the Common Agreement and applicable U.S. Department of Health and Human Services guidance.
We closely scrutinize law enforcement and regulatory requests. We disclose information to law enforcement or regulatory authorities only when we determine disclosure is required or permitted by applicable law, including in response to a valid court order, subpoena, civil investigative demand, search warrant, or other valid legal process. Where appropriate, we use reasonable efforts to limit the information disclosed.
If we are not prohibited from doing so, we will provide written or electronic notice to you within three (3) business days of receiving any such legal process, and within three (3) business days of making your III available to law enforcement. You may object to the production of your III or seek a protective order or other appropriate remedy consistent with applicable law.
If we are a party to a legal proceeding with you, we will not disclose information retrieved from Individual Access Services for purposes of resolving a civil dispute. If we are not a party to a legal proceeding but receive a valid subpoena, discovery request or other lawful process, we will provide notice as described above and use reasonable efforts to limit disclosures of your IAS Data to the minimum necessary to accomplish their intended purpose.
If we enter into a merger, acquisition, or the sale of all or part of our assets, Individual Access Services will likely be part of the assets transferred. If a successor makes a Material Change to this IAS Notice that would result in use or disclosure of III in a materially different manner, your express, documented, and informed consent will be obtained before that use or disclosure.
We will never use information retrieved from Individual Access Services to make claims against you, except (if applicable) to collect fees or costs for services you requested.
We use your IAS Data to:
We retain III until you decide to delete it, subject to applicable legal, contractual, audit-log, technical, and deletion requirements.
For III subject to an applicable TEFCA requirement that incorporates the HIPAA de-identification standards, we may deidentify and/or aggregate that III in accordance with 45 C.F.R. § 164.514. Once such III has been deidentified in accordance with those standards and is no longer III under the applicable TEFCA requirement, the resulting deidentified information may be used or disclosed for analytics, research, product development, market research, and other lawful purposes, including disclosure to third parties, subject to applicable law and contractual restrictions, including any applicable no-reidentification requirements. We will complete the required deidentification before any use or disclosure that relies on treatment of the information as deidentified. Recipients may use or disclose the deidentified information only as permitted by applicable law and the terms governing the transfer. Usage data reflects general patterns and trends about how users interact with the Individual Access Services (for example, feature utilization, navigation flows, and performance metrics) but does not identify any individual user. We use usage data to analyze, maintain, and improve the functionality, performance, and user experience in Individual Access Services and related services, and to generate reports, which we may share with customers and the public.
We collect and use only the amount of Personal Information reasonably necessary for the permitted purposes described in this Privacy Policy and Individual Access Services Privacy and Security Notice, subject to applicable TEFCA requirements and applicable law.
Medchart US Inc. is not a “covered entity” or a “business associate” under HIPAA. To the extent required by the applicable TEFCA Framework Agreements, Medchart US Inc. doing business as Marble complies with the HIPAA Privacy Rule provisions incorporated by those agreements with respect to III subject to those requirements. When Medchart US Inc. is a Non-HIPAA Entity under the applicable TEFCA Framework Agreements, it also complies with the HIPAA Security Rule provisions required by those agreements with respect to III as if the III were protected health information and Medchart US Inc. were a covered entity or business associate. Nothing in this IAS Notice is intended to extend HIPAA or TEFCA requirements beyond the scope imposed by applicable law, the applicable TEFCA Framework Agreements, or standard operating procedures.
Required Conformance with the Privacy and Security Notice and TEFCA
Marble is required to act in conformance with this IAS Notice and uses commercially reasonable efforts, including administrative, physical, and technical safeguards, to protect III, including IAS Data, from unauthorized or illegal access, modification, use, or destruction in accordance with the applicable TEFCA Framework Agreements.
Marble encrypts all III it holds, both in transit and at rest, regardless of whether the data is TEFCA Information. Our sub-processors are required to meet applicable privacy and information security requirements consistent with our contractual commitments and applicable law.
Marble’s obligations under the Individual Access Services Privacy and Security Notice and TEFCA will continue for as long as it maintains III subject to those obligations.
While we implement reasonable privacy controls and information security measures to safeguard Personal Information from unauthorized access, disclosure, use, modification, and loss, no security measure can eliminate all risk. We maintain protocols to provide required notifications and take appropriate response measures if information is compromised.
Opt-In Consent
We will not launch Individual Access Services without your affirmative opt-in consent.
We will obtain your express, documented, and informed consent to this IAS Notice before accessing, exchanging, using, or disclosing III in connection with IAS, other than disclosures required by applicable law. If we make a Material Change to this IAS Notice, including by adding new uses or disclosures of III, we will obtain your express, documented, and informed consent before using the information in the materially different manner described in the updated IAS Notice.
How to Revoke Consent for Individual Access Services
You can withdraw your consent at any time through the Individual Access Services App, and we will honor the withdrawal upon receipt. Step-by-step instructions for revoking consent are available in the app and on our website.
Be advised, withdrawing consent does not affect actions we took in reliance on your consent before we received the withdrawal. After withdrawal, we may continue processing only to the extent required by applicable law or supported by a separate valid authorization or other applicable TEFCA basis.
After revocation, you will no longer be able to access Individual Access Services unless you provide a new opt-in consent.
Individual’s Rights with respect to IAS Data
With respect to IAS Data, and subject to applicable law and technical feasibility, you have the right to require deletion of III maintained by Marble in connection with IAS with respect to future uses and disclosures, except for III contained in audit logs or where deletion is prohibited by applicable law; access that III; obtain an export of that III in a machine-readable format, including the means to interpret that format; and be notified if the III is reasonably believed to have been affected by an IAS Incident. You may exercise these rights through the Individual Access Services App or by contacting our Privacy Office. If Marble is reasonably aware of applicable law that prohibits it from honoring a deletion request, we will inform you.
To access or export your IAS Data, follow the instructions to log-into the consumer portal sent to your email from Medchart US Inc. during your Individual Access Services identity verification and authorization process. Then use the download function within the portal for each element of IAS Data you wish to export. Available export format(s): ZIP files containing IAS Data elements selected. Each IAS Data element may be stored as a unique data format and is only available in the format in which it is natively stored within Marble. These may include JSON, FHIR, HTML, XML, CSV, PDF, TIFF, TXT, or other formats.
Incident Reporting
We will notify you if III is reasonably believed to have been affected by an IAS Incident, as required by TEFCA and applicable law.
Fees and Consent to Sale
We do not charge individuals fees or costs for IAS or for exercising the rights described in this IAS Notice. We get paid by customers for services we provide. We will not sell III or receive remuneration in exchange for III unless the transaction is permitted by applicable law and we have obtained your prior, express, and documented Consent to Sale, together with any other consent or authorization required by applicable law. Any Consent to Sale will be conspicuously labeled and separate from your consent to this Notice. As described above, we may use, disclose, license, or sell information after we have deidentified it in accordance with the standards described above.
To access and use Individual Access Services, you will need access at your own expense to the internet, a computer, cell phone number, smartphone or similar handheld device, and an acceptable digital identity credential from a recognized organization. We are not responsible for the fees that you incur from these third parties.
We may use III to provide you with better access to services through targeted marketing or advertising only if the use or disclosure is permitted by applicable law and we have obtained your prior, express, and documented Consent to Sale, together with any separate permission or authorization required by applicable law for the marketing or advertising.
Required Disclosures
CommonWell Health Alliance (https://www.commonwellalliance.org/):
Any information retrieved through CommonWell is provided to you on an as-is, as available basis, with no warranty of any kind, and for information purposes only. You disclaim any claim that CommonWell’s services or any information retrieved through CommonWell is medical advice.
The Trusted Exchange Framework and Common Agreement (https://rce.sequoiaproject.org/tefca/)
U.S. Centers for Medicare & Medicaid Services (CMS)
Be advised, CMS does not certify or endorse the Individual Access Services functionality. CMS disclaims any warranty relating to its services for facilitating the retrieval of information from CMS, or to the information itself.
U.S. Department of Veterans Affairs
Marble is an independent application and is not created or endorsed by the U.S. Department of Veterans Affairs. If you authorize the IAS Provider through Marble to retrieve information from VA, our collection, use, disclosure, and protection of that information is governed by this Privacy Policy, this IAS Notice, applicable law, and any applicable VA terms.
Request-Only IAS Provider
MEDCHART US INC., OPERATING AS MARBLE, DOES NOT PROVIDE BIDIRECTIONAL SERVICES. YOU WILL HAVE THE ABILITY TO REQUEST ACCESS TO YOUR HEALTH INFORMATION VIA TEFCA EXCHANGE. YOU WILL NOT BE ABLE TO USE MARBLE TO SHARE YOUR HEALTH INFORMATION WITH OTHER PARTICIPANTS IN TEFCA.
Complaints and Questions
For more information about our privacy protection practices, or to raise a concern you may have about our practices, please contact:
Juliana Doxey
Chief Privacy Officer, Medchart US Inc.
215 S. Denton Tap Rd., Suite 290
Coppell, TX, 75019
Email: privacy@medchart.com
Toll-free: 1-833-603-0407
Fax: 1-888-929-2687