QuestConnect.app

Privacy Policy

QuestConnect is a workflow platform used by healthcare organizations to run remote patient monitoring. This policy explains what information the platform handles, why, who can see it, and how long it is kept.

HIPAA-grade controlsOAuth 2.0 patient authorizationEncrypted at rest
Our role
Business Associate
Your provider is the Covered Entity and holds the patient relationship
Patient data sold
Never
No sale, no advertising, no data brokers
Dexcom sharing
Opt-in, revocable
Authorized by the patient directly with Dexcom
Audit retention
6 years
Access history retained per HIPAA

Our Role and Who This Applies To

QuestConnect operates as a HIPAA Business Associate. The healthcare organization that uses the platform — for QuestConnect, Quest Health Solutions — is the Covered Entity. That organization holds the direct relationship with the patient and is responsible for its own notice of privacy practices.

In practice this means QuestConnect handles patient information on behalf of, and under the instructions of, that healthcare organization, under a Business Associate Agreement. QuestConnect does not use patient information for its own purposes.

Information We Handle

  • Staff account and contact information
  • Patient demographics and contact details
  • Insurance, eligibility, and coverage information
  • Enrollment, clinical, and encounter form submissions
  • Device setup, activation, and shipping information
  • Device readings and monitoring metrics
  • Patient-authorized retrospective CGM data from Dexcom, when production access is approved
  • Care-management notes, tasks, time entries, and documentation
  • Billing and claim records
  • Audit and security logs

How Information Is Used

Information is used to operate the remote patient monitoring program for the healthcare organization — and for nothing else:

  • Patient enrollment and eligibility review
  • Retrospective monitoring and glucose trend review
  • Patient follow-up and care coordination
  • Clinical documentation support
  • Billing readiness and claim preparation
  • Compliance, audit, and security monitoring

Who Can See Patient Information

Access is limited to authorized members of the care team, and it is enforced by role on the server for every action — not merely hidden in the interface. Identifiable patient fields are encrypted with AES-256-GCM before they are stored, and every access to or change of patient information is written to an append-only audit log.

Exports that could contain patient information require a written justification, a permission check, and an elevated role above a bulk threshold, and each one is recorded. See the Security page for the full control set.

Dexcom Data

The Dexcom API provides retrospective CGM data and CGM-derived metrics. QuestConnect uses Dexcom data only for retrospective monitoring review, glucose trend review, patient follow-up, care coordination, documentation support, and billing readiness.

QuestConnect accesses Dexcom data only after the patient completes Dexcom's OAuth 2.0 authorization flow. Patients authenticate directly with Dexcom; QuestConnect never collects or stores Dexcom usernames or passwords, and access tokens are held server-side and encrypted at rest.

QuestConnect has applied for Dexcom production credentials. Until Dexcom separately approves production access, QuestConnect's Dexcom developer access remains sandbox-only, and sandbox data is simulated rather than real patient data.

Patient Authorization and Revocation

Dexcom data sharing is opt-in and can be withdrawn at any time through Dexcom account permissions. On revocation, QuestConnect stops retrieving new Dexcom data unless the patient authorizes access again.

Data already received before revocation remains subject to clinical documentation, retention, audit, and legal obligations — a treatment record that has already been created cannot simply be withdrawn.

Patient Rights

Patients have the right to obtain a copy of their health information, to request a correction, and to receive an accounting of disclosures. Because QuestConnect is a Business Associate, these requests are made to and answered by the healthcare organization providing your care, not by QuestConnect directly.

QuestConnect's role is to make the record producible and to log the production, so your provider can respond within the timeframe HIPAA requires and can demonstrate that it did. If you contact us directly, we will route your request to your provider's privacy contact.

Data Sharing

QuestConnect shares documentation and workflow information with the clinical, insurance, and billing systems the healthcare organization uses, where needed for care coordination, documentation, or claim submission. Vendors that may handle patient information are covered by Business Associate Agreements.

QuestConnect does not currently share live Dexcom CGM readings directly with an EHR. QuestConnect does not share Dexcom data with advertising networks, third-party data aggregators, or anyone outside the care team.

Record Retention and Disposal

Retention is governed by a per-record-type register rather than left to discretion. Clinical and billing records are retained for the applicable medical-record and claims retention periods. Audit and security logs are retained for six years in line with HIPAA and are suspended from disposal while a legal hold applies.

Patient records are never automatically purged. Where information is no longer needed, it is archived or de-identified under the approved retention rules rather than deleted ad hoc.

What We Do Not Do

We do not sell patient information. We do not use patient or Dexcom data for advertising or share it with data brokers. We do not collect Dexcom usernames or passwords. We do not use Dexcom data for insulin dosing recommendations or automated treatment decisions, for real-time emergency monitoring or immediate clinical action by patients or caregivers, or for promoting or comparing non-Dexcom glucose products.

Privacy Officer or DPO Contact

QuestConnect maintains a designated privacy contact for privacy questions, Dexcom authorization questions, and data-handling concerns.

Contact support@questconnect.app with the subject line Privacy Request. Please do not include health information in your first message — we will tell you how to send anything sensitive securely.

For a request about your own health record, contact your healthcare provider directly, as described under Patient Rights above.