Zenth Health Sciences Privacy Policy

Effective: January 15, 2026 Last Updated: March 12, 2026 Applies To: All Patients, Clients & Care Partners
HIPAA Compliant GDPR Aligned HITECH Adherent SOC 2 Type II ISO 27001 Certified

1. Introduction & Scope

Aevum Zenth Conglomerate, through its Zenth Health Sciences division, is committed to protecting the confidentiality, integrity, and availability of your personal and health information. This Privacy Policy outlines how we collect, use, store, and safeguard your data when you interact with our healthcare services, digital health platforms, medical devices, and research initiatives.

Important Notice: This policy applies exclusively to health-related services and products. For privacy practices related to our financial, aerospace, or technology divisions, please refer to their respective divisional privacy notices.

By using Zenth Health Sciences services, you acknowledge that you have read and understood this policy. We comply with applicable global health data regulations, including HIPAA, GDPR, HITECH, and regional health privacy frameworks.

2. Information We Collect

We collect information necessary to deliver safe, effective, and personalized healthcare services. This includes:

2.1 Protected Health Information (PHI)

  • Medical history, diagnoses, treatment plans, and clinical notes
  • Prescription records, medication history, and allergy information
  • Diagnostic test results, imaging data, and lab reports
  • Insurance eligibility and billing information

2.2 Personal & Demographic Data

  • Full name, date of birth, contact details, and emergency contacts
  • Government-issued identification numbers (where legally permitted)
  • Employment information (for occupational health services)

2.3 Digital & Device Health Data

  • Biometric readings from connected wearables and medical IoT devices
  • App usage patterns, telemedicine session metadata, and consent records
  • Location data (only when explicitly enabled for emergency response or clinical trials)

3. How We Use Your Information

Your information is processed strictly for healthcare-related purposes:

  • Treatment: Coordinating care, prescribing medications, and managing therapeutic interventions
  • Payment & Billing: Processing insurance claims, invoicing, and revenue cycle management
  • Healthcare Operations: Quality assurance, staff training, compliance auditing, and service optimization
  • Research & Innovation: Participating in approved clinical studies, epidemiological modeling, and therapeutic R&D (with explicit informed consent)
  • Patient Communication: Sending appointment reminders, health alerts, and personalized wellness recommendations

We will never use your PHI for targeted advertising or sell your health data to third-party data brokers.

4. Data Sharing & Disclosure

We share information only when necessary, legally required, or explicitly authorized by you:

  • Healthcare Providers: Co-treating physicians, specialists, pharmacies, and emergency responders
  • Insurance & Payers: For claims processing, prior authorizations, and coverage verification
  • Business Associates: Vetted third-party vendors handling cloud hosting, billing, or analytics under strict Data Processing Agreements (DPAs)
  • Legal & Regulatory Bodies: When mandated by court order, subpoena, or public health reporting requirements
  • De-identified Research: Aggregated, anonymized datasets stripped of all direct and indirect identifiers for scientific advancement

Consent Control: You maintain full control over optional data sharing. You may withdraw consent for non-essential disclosures at any time through your patient portal or by contacting our Privacy Office.

5. Security & Safeguards

Zenth Health Sciences employs enterprise-grade security architectures to protect your health data:

  • Encryption: AES-256 encryption at rest and TLS 1.3 in transit across all data pipelines
  • Access Controls: Role-based access (RBAC), multi-factor authentication, and zero-trust network architecture
  • Audit Logging: Immutable records of all data access, modifications, and system events
  • Incident Response: 24/7 security operations center with mandatory breach notification within 72 hours per regulatory standards
  • Vendor Compliance: Annual third-party penetration testing and ISO 27001/SOC 2 certification audits

6. Your Rights & Choices

Depending on your jurisdiction, you may exercise the following rights:

  • Right to Access: Request a copy of your medical records and data processing logs
  • Right to Correction: Update inaccurate or incomplete personal/health information
  • Right to Deletion: Request erasure of non-mandatory data (subject to legal retention obligations)
  • Right to Portability: Export your health data in standardized, machine-readable formats (FHIR/HL7)
  • Right to Opt-Out: Decline marketing communications or non-essential data sharing
  • Right to Appeal: Challenge denial of a data request through our formal grievance process

Submissions are processed within 30 days. Extensions require written notice and are limited to complex requests.

7. Data Retention

We retain health information in compliance with statutory requirements and clinical best practices:

  • Medical Records: Minimum 7-10 years post-last interaction (varies by jurisdiction)
  • Billing & Insurance Data: 7 years for tax and audit compliance
  • Research Datasets: Retained per IRB protocol until study closure + 5 years
  • Deleted Requests: Permanently purged from active systems within 30 days; backups overwritten per lifecycle policies

8. International Data Transfers

As a global health enterprise, certain data may be processed across borders. We ensure adequate protection through:

  • EU Standard Contractual Clauses (SCCs) and UK International Data Transfer Agreements
  • Data localization options for regions with sovereignty requirements
  • Binding Corporate Rules (BCRs) approved for intra-group health data transfers

9. Children's Health Data

We treat pediatric health data with heightened safeguards. Parental/guardian consent is required for patients under 18, except where state law permits mature minor consent. We comply with COPPA and regional pediatric privacy statutes.

10. Policy Updates

This policy may be updated to reflect regulatory changes, service enhancements, or operational improvements. Material changes will be communicated via your patient portal, email, or facility notices. Continued use of our services constitutes acceptance of revised terms.

11. Contact Information

For privacy inquiries, data subject requests, or concerns regarding this policy, please contact our dedicated health privacy team:

Zenth Health Sciences Privacy Office

Privacy Officer
privacy.health@aezumzenth.global
Data Protection
dpo@aezumzenth.global
Secure Portal
portal.aevumzenth.health/privacy
Mailing Address
Zenth Health Tower, Floor 14
Neo Geneva, Sector 7, 08-2914
}