NYU Langone Health MyChart App Privacy Policy

Last updated: 10/18/2024


This Privacy Policy applies to personal information obtained through the NYU Langone MyChart mobile application (“NYU MyChart”), which is operated by NYU Langone Health (“NYU Langone”, “we”, “us”, “our”). This Privacy Policy explains our practices and governs the use of personal information NYU Langone collects from you or about you through NYU MyChart.

This Privacy Policy does not apply to the NYU Langone MyChart website, mychart.nyulmc.org, which is governed by a separate privacy policy available on the website. Note that if you use access your NYU Langone MyChart account through the website, information collected through the app related to your app account and settings may not be synchronized between the app and the website.

By further downloading, using, creating an account, or registering through NYU MyChart you agree to this Privacy Policy and consent to the collection and use of your personal information as described in this Privacy Policy.

NYU MyChart is hosted through a service provider, Epic Systems Corporation (“Epic”), which processes patient information not collected through NYU MyChart, such as information contained in your electronic medical record at your doctor’s office. Such patient information may be viewable through NYU MyChart and may be considered protected health information, as governed by the Health Insurance Portability and Accountability Act and applicable state law. Please refer to our Notice of Privacy Practices, which shall govern as to protected health information in the event of a conflict with this Privacy Policy.

Note that because NYU MyChart is hosted through Epic, certain features on NYU MyChart may be subject to Epic’s privacy policies, which you should review separately to understand how Epic may process your personal information.

  1. Information We Collect

    1. Information You Submit

      We, and our vendors, may obtain personal information that you provide to us directly, for example, data you submit when you complete forms, fill out questionnaires, schedule in-person or telehealth video call appointments, request prescription refills, add or change pharmacies, add personal notes, enroll in research studies, send messages to your care team, or make payments through NYU MyChart. Personal information we, and our vendors, collect may include your nickname, account credentials, email address, phone number, insurance coverage information (including insurance card photos), vaccine documentation, health-related information, and payment processing information.

      If you submit the personal information of another person, you represent that you have obtained the authorization from that person to submit such personal information to us.

    2. Information We Collect Through Tracking Technologies

      In addition to any personal information or other information that you choose to submit through the NYU MyChart, we and our vendors use a variety of tracking technologies that collect certain information whenever you interact with NYU MyChart. This type of usage information may include the device you are using, your IP address, device ID, other unique identifier, geolocation, crash analytics, all of the areas within NYU MyChart that you visit, and the time of the visit.

      NYU MyChart may be personalized based on various information we may have about you to provide you with more location-relevant content. We may use GPS (global positioning systems) software, geo-filtering, and other location-aware technologies to locate you, sometimes precisely, for purposes such as verifying your location and delivering or restricting content based on your location. Our clinic location feature may access and use information about your device location to suggest appropriate clinic locations. Additionally, you may change your preferences regarding our “Appointment Arrival” feature, which uses your phone’s location to notify front desk staff when you’ve arrived. You may use your device settings to change your geolocation preferences.

      We may use 3rd party vendors to perform analytics services in order to facilitate the maintenance of the app and understand the use of app features in order to develop new features. The services these vendors provide to us are for the purposes of understanding how the app is used, whether the app is working, and what features and functions could be improved.

      We may combine certain information collected through tracking technologies with other information we obtain about you, which may include data we obtain from third parties.

      We or third parties, including our vendors, may collect personal information about your online activities over time and across different online services when you use NYU MyChart.

  2. App Permissions

    1. NYU MyChart may include features that require access to certain app permission settings. For example, for telehealth services, the NYU MyChart app may need access to your camera and microphone. By changing your app permission settings, you may affect your ability to access or use certain features on the app.

      Depending on your device or app permission settings, which you set, the NYU MyChart may have access to the following information from your device:

      1. Location: Location data may include your precise or approximate location. This enables your access to certain features, such as being able to notify the front desk staff of your arrival for appointments for easy check-in.
      2. Photos/Media/Files: The app may be able to read, modify, or delete the contents of your USB storage, including files and photos. This enables your access to certain features, such as being able to upload files and photos to the app in order to personalize your account, send or download attachments in your messages to healthcare providers, or upload your insurance card information.
      3. Camera: Your camera may allow the app to take photos and videos. This enables your access to certain features, such as video visits and taking photos to submit to the app to personalize your account, send as attachments in messages to your healthcare providers, or upload your insurance card information.
      4. Microphone: The app may record audio. This enables your access to certain features, such as video visits.
      5. Bluetooth: The app may use your Bluetooth to connect to health devices. This enables your access to certain features, such as using Bluetooth to notify front desk staff when you arrive for an appointment for easy check-in, and sending data from a connected device, such as smart watches or medical devices, which your healthcare provider invites you to submit.
      6. Other information: The app may be able to receive data from the Internet, prevent your device from sleeping, control vibration of your device (such as to prevent a text you are receiving to interrupt a telehealth session), and view your network connections and obtain network information, including at startup of your device.

      Additionally, you may be able to log into NYU MyChart using your device’s log in features such as using a passcode or your fingerprint. These device log in features are facilitated through your device and not NYU Langone and we have no control over such features, which you can change by accessing your device settings and preferences.

  3. How We Use The Information We Collect

    We use your information for many purposes, such as to: (i) provide various products or services to you, including by processing your payments; (ii) analyze trends and conduct research about improving our products and services; (iii) provide support and respond to questions from customers and NYU MyChart users; (iv) improve NYU MyChart, products, or services; (v) learn about users’ needs; (vi) contact users for research, informational, and marketing purposes; (vii) track traffic patterns and NYU MyChart usage; (viii) provide customer service; (ix) correlate information with other commercially available information to identify demographics and preferences to assist us in our marketing efforts; (x) provide specific relevant marketing, promotional, or other information to you; (xi) address information security and/or privacy issues, network functioning, and troubleshooting; (xii) investigate claims and/or legal actions, violations of our policies and procedures, and compliance with relevant applicable laws and legal process; (xiii) comply with applicable laws, regulations, or legal process as well as industry standards and our company policies; or (xiv) prevent, investigate, identify, or take any other action with regard to suspected or actual fraudulent or illegal activity, or any activity that violates our policies.

    We use vaccination documentation and/or diagnosis information (including information related to COVID-19) to support epidemic and pandemic-related efforts, epidemiological and pandemic research, and to provide healthcare services, including telehealth services.

    We will store your personal information for no longer than is necessary for the performance of our obligations or to achieve the purposes for which the information was collected, or as may be permitted under applicable law.

  4. Sharing Of Your Information

    Personal information submitted to NYU MyChart, such as your communications with your health providers, may be shared with our service provider, Epic, and added to your medical record. Once part of your medical record, this personal information may be considered protected health information, as governed by the Health Insurance Portability and Accountability Act and applicable state law. For more information on such protected health information, please refer to our Notice of Privacy Practices.

    We may share your personal information in the event we sell or transfer all or a portion of our business assets (e.g., further to a merger, reorganization, liquidation, or any other business transaction), including negotiations of such transactions.

    We may also share your personal information at your direction. For example, you may share your information with friends, family, other individuals, or other healthcare organizations. You may adjust your sharing preferences through NYU MyChart. Note that if you choose to provide access to your information to friends or family through the proxy access feature, they may obtain full access to all the information you have access to yourself on NYU MyChart. If you choose to provide access to any individual (e.g., nurse, social worker), those individuals may view a subsection of your information. You may also choose to link your NYU MyChart account to other healthcare system.

    We may also share certain information to other devices or applications as per your preferences. Connecting to other devices or applications, such as Apple HealthKit or Google Fit, may entail sharing information between NYU MyChart and such devices related to the device’s technologies or features (e.g., thermometers, blood pressure calculators, weight measuring).

    Information, including personal information, may also be shared: (i) as permitted by law; (ii) where we determine that disclosure of specific information is necessary to comply with the request of a law enforcement or regulatory agency or other legal process; or (iii) to enforce our policies, or to protect legal rights, property, or safety.

    From time to time we may enter into an arrangement with another company that is not owned by or affiliated with us to provide additional features on NYU MyChart. These arrangements may include business partners, sponsors, and co-branded online services (referred to here as “co-branded services”). Any information, including personal information, that you provide on one of these co-branded services may be shared with these partners. By participating in activities or providing your information on these co-branded services, you consent to our providing your information to those partners. Separate privacy policies may apply to these partners’ uses of your personal information.

    We may use vendors and share information with them to help us operate our business and NYU MyChart, or administer activities on our behalf, such as NYU MyChart maintenance, payment processing, and facilitating telehealth video services.

  5. Links And Features

    NYU MyChart may contain links to, or features facilitated by, other online services, some of which NYU Langone may control. This Privacy Policy does not apply to other online services, even if they are controlled by us. Please note that other online services may have their own privacy policies. We are not responsible for the privacy practices, advertising, products, or content of online services that NYU Langone does not control.

  6. Personal Information From Children

    NYU MyChart is intended for a general audience and not directed to children under 12 years of age. Some portions of NYU MyChart, however, may be intended, as appropriate, for a mixed audience that may include users under 12. For example, NYU MyChart allows minors aged 12 – 17 to create an NYU MyChart account (“Minor NYU MyChart Account”), which provides the minor access to all of NYU MyChart’s features (for example, the ability to communicate with health providers). As a non-profit organization, NYU Langone’s collection of children’s personal information is not governed by the U.S. Children’s Privacy Protection Act (“COPPA”).

    A Minor NYU MyChart Account user may choose to share their information with a parent or guardian through the “Share MyChart Access” feature. If a Minor NYU MyChart Account user provides proxy access, the parent or guardian will have access to information on the Minor NYU MyChart Account. Please note that the minor may choose to restrict or withdraw such proxy access at any time.

  7. Your Choices

    You may log in to NYU MyChart and visit the update certain preferences or personal information details. You may also download and send records accessible through NYU MyChart or change sharing and device/app access preferences.

    You may change your preferences regarding our “Appointment Arrival” feature, which uses your phone’s location to notify front desk staff when you’ve arrived. You may use your device settings to change your geolocation preferences. You can also manage appp communications that you receive from NYU Langone in the “Notifications” settings on the app.

    As discussed above, NYU MyChart is hosted through Epic, a service provider that processes patient information not collected through NYU MyChart. Accordingly, there may be certain personal information that you may be able to view through NYU MyChart, but you will not be able to update or delete this information through NYU MyChart. This information is contained in your electronic medical record at your doctor’s office and may be protected health information. Please refer to our Notice of Privacy Practices for more information.

    Note that in some cases patient information contained in your medical records may not be viewable through NYU MyChart. For example, certain laboratory tests of a sensitive nature are not released to NYU MyChart at your provider’s discretion. If you do not see an expected test result, please contact your physician’s office to request that these results be released to your NYU MyChart account. Similarly, if you are unable to edit certain personal information through NYU MyChart, this may be because the information is contained in your electronic medical record and requests to amend the information should be directed to your healthcare provider.

    If you elected to receive marketing emails from us and prefer to no longer receive such emails, you may opt out at any time by using the unsubscribe link located at the bottom of the email.

  8. Security

    We maintain appropriate administrative, technical, and physical safeguards designed to help protect personal information collected or received through NYU MyChart. Although we use reasonable efforts to safeguard information, transmission via the Internet is not completely secure and we cannot guarantee the security of your information collected through NYU MyChart.

  9. Questions / Changes In Policy

    If you have questions or concerns with respect to our Privacy Policy, please contact us at compliancehelp@nyulangone.org. We may change this Privacy Policy from time to time. If we make changes, we will notify you by revising the date at the top of this Privacy Policy.