IAS Privacy and Security Notice
Last updated: April 28, 2026
This Privacy and Security Notice is publicly available at https://chat.grovecare.co/policies/ias.
This notice constitutes Grove Technologies Co.’s Privacy and Security Notice for Individual Access Services (IAS), as required under the Trusted Exchange Framework and Common Agreement (TEFCA). This IAS Notice is intended to be a distinct and standalone description of Grove’s privacy and security practices specifically related to Individual Access Services. Note that our policies on privacy notice updates and affirmative efforts to notify users of revisions to our privacy notice, set out in our general Privacy Policy, apply to this IAS Privacy Policy as well.
Can I Access and Manage Health Data Through Individual Access Services (IAS)?
Grove provides functionality that allows individuals to request access to their own health information through national health information exchange networks, including those operating under the Trusted Exchange Framework and Common Agreement (“TEFCA”) via Qualified Health Information Networks (“QHINs”).
Request-Only IAS Provider Disclosure
Grove Technologies Co. does not provide bidirectional services. You will have the ability to request access to your health information via TEFCA exchange. You will not be able to use Grove to share your health information with other participants in TEFCA.
User-Directed Access and Authorization
When you choose to request your health information through Grove, you are explicitly directing Grove to retrieve your Individually Identifiable Information on your behalf from connected health information networks, providers, and electronic health record systems.
We will only access, exchange, use, or disclose your Individually Identifiable Information in connection with IAS based on your express, informed, and documented consent.
Identity Verification
To protect your information and prevent unauthorized access, Grove verifies your identity using industry-standard identity verification methods aligned with Identity Assurance Level 2 (IAL2) and Authenticator Assurance Level 2 (AAL2).
How Your Information May Be Used and Disclosed
Your Individually Identifiable Information may be:
- Accessed and retrieved from QHINs, health information exchanges, and healthcare providers
- Stored and displayed to you within the Grove platform
- Processed to generate summaries or insights for your personal use
We do not sell your Individually Identifiable Information.
We do not use your Individually Identifiable Information to assert claims against you, except for the collection of fees (if applicable in the future).
We may share information with service providers that help us operate our platform, subject to contractual obligations to protect your data.
All disclosures through TEFCA are conducted in accordance with the permitted and required uses and disclosures under the Common Agreement and applicable U.S. Department of Health and Human Services guidance. Where applicable, you will be provided with a choice regarding whether your Individually Identifiable Information may be disclosed in response to requests via TEFCA exchange, and we will honor your selection.
Third-Party Access
Your information may be accessed by:
- Health information networks (including QHINs)
- Healthcare providers and EHR systems
- Service providers supporting Grove infrastructure
Some disclosures may occur outside of Grove’s direct control once data is retrieved from external systems. We require third-party service providers to implement appropriate privacy and security safeguards consistent with this Notice and applicable law.
Grove maintains a list of key service providers and subprocessors that have access to Individually Identifiable Information in connection with Individual Access Services, and such information may be made available to individuals upon request.
Retention of Information
We retain your Individually Identifiable Information for as long as necessary to provide our Services or comply with legal obligations, unless you request deletion (subject to applicable law and technical feasibility).
De-Identification
We may de-identify your information. De-identified data may be used for analytics, product improvement, or research and may be shared in a manner that does not identify you.
Legal Requests and Law Enforcement
Unless prohibited by law, Grove will provide notice within three (3) business days if:
- We receive a subpoena, court order, or other compulsory request for your information
- We are required to disclose your information to law enforcement
You may have the right to object or seek legal remedies where permitted by law.
Security Practices
We use commercially reasonable efforts to protect your information, including:
- Encryption of data at rest and in transit
- Access controls and monitoring
- Secure infrastructure and vendor requirements
Grove is required to act in conformance with this Privacy and Security Notice and applies these practices to all Individually Identifiable Information we maintain. Our obligations under this Privacy and Security Notice continue for as long as we maintain your Individually Identifiable Information.
We maintain audit logs of access and activity related to your information.
If your information is reasonably believed to have been affected by a security incident, we will notify you as required by applicable law.
Consent Requirements
We obtain your express documented and informed consent before:
- Accessing your health data through IAS
- Using your data in new or materially different ways
Consent is recorded and maintained in secure, auditable logs.
Revoking Consent
You may revoke your consent at any time through available in-app controls or by contacting support@grovecare.co. Instructions for revocation are made available within the Grove platform and are designed to be easily accessible and not burdensome.
Revocation:
- Will not affect actions taken prior to revocation
- Will prevent future access to IAS services
- May limit your ability to use certain features
Your Rights (IAS-Specific)
You have the right to:
- Access your Individually Identifiable Information
- Request deletion (where legally and technically feasible)
- Obtain an export of your data in a machine-readable format
- Be notified of security incidents
We will honor your requests within a reasonable timeframe unless restricted by law.
Fees
Grove does not currently charge fees for Individual Access Services.
HIPAA Status
Grove Technologies Co. is not a HIPAA-covered entity or business associate in all circumstances when providing Individual Access Services. Instead, Individually Identifiable Information accessed through IAS is governed by the Trusted Exchange Framework and Common Agreement (TEFCA), applicable federal and state privacy and security laws governing consumer-directed health information, and the terms of this Privacy and Security Notice.
Grove implements safeguards consistent with healthcare data protection standards, including those required under TEFCA and applicable legal frameworks, to protect Individually Identifiable Information.
Contact for Privacy Questions or Complaints
You may contact us at:
support@grovecare.co
+1 (800) 495-2843
We maintain a process for reviewing and responding to privacy-related complaints.