Effective Date: July 22, 2026
1. Introduction and Scope
This is a standalone Consumer Health Data Privacy Policy for Core Human Factors, Inc. (“Core,” “we,” “our,” or “us”). This policy is separate and distinct from Core’s General Privacy Policy and addresses only consumer health data as defined by Washington’s My Health My Data Act (RCW 19.373) and Nevada’s Consumer Health Data Privacy Law (SB 370 / NRS Chapter 603A).
This policy applies to all consumer health data collected, used, shared, or retained by Core in connection with our research studies, consulting services, and other business activities. It governs how we collect, use, disclose, retain, and protect consumer health data from Washington State and Nevada residents, as well as health data collected in Washington or Nevada regardless of where the individual resides.
This policy is designed to comply with:
Nevada’s Consumer Health Data Privacy Law (SB 370 / NRS Chapter 603A)
Washington’s My Health My Data Act (RCW 19.373)
2. Who This Policy Applies To
This policy applies to you if you are:
- A natural person who is a resident of Washington State or Nevada, or
- A natural person whose consumer health data is collected in Washington State or Nevada
This policy does not apply to:
- Individuals acting in an employment or contractor capacity (those individuals are covered under separate employment or contractor agreements)
- Individuals acting as agents of a government entity
- Consumer health data that is collected and governed under HIPAA as protected health information (PHI) by a HIPAA-covered entity or business associate (such data is exempt from this policy)
3. What Is Consumer Health Data
Consumer health data means personally identifiable information that is linked or reasonably linkable to a consumer and that Core collects and uses to identify the consumer’s past, present, or future physical or mental health status.
Consumer health data includes, but is not limited to:
- Health conditions and diagnoses: Any disease, condition, disorder, or diagnosis you have or have had
- Medical and surgical interventions: Surgeries, procedures, treatments, therapies, or other medical interventions
- Medications and medical devices: Information about any medications you use or have used, or any medical devices you use or inquire about
- Bodily functions, vital signs, and symptoms: Heart rate, blood pressure, respiratory rate, temperature, pain levels, symptoms, or other bodily measurements or functions
- Psychological and behavioral health: Mental health status, psychological conditions, behavioral health information, counseling, or therapy
- Reproductive and sexual health: Information related to pregnancy, contraception, fertility, reproductive health services, or sexual health
- Gender-affirming health care: Information related to gender-affirming medical services or treatments
- Biometric data related to health: Fingerprints, voice prints, retinal scans, facial recognition, or other biometric identifiers used to identify or authenticate health information
- Genetic data: Genetic tests, genetic markers, DNA information, or family health history
- Precise geolocation data: Location information that reveals or could reasonably indicate an attempt to obtain health care services or products (e.g., visits to healthcare facilities, pharmacies, mental health clinics, fertility clinics)
- Data derived or inferred from the above: Any data created through analysis, algorithms, machine learning, or other computational methods that infers or derives health status from the categories listed above
- Any other data used to identify health status: Any other personal information that Core uses to identify a consumer’s health status
4. Categories of Consumer Health Data We Collect
In the context of our research studies and consulting engagements, Core collects the following categories of consumer health data:
- Health conditions and medical histories: Self-reported health conditions, past and present medical diagnoses, medical history, and health-related information provided by study participants in the course of a research session
- Physical and cognitive functional assessments: Assessments of physical function, mobility, strength, cognitive abilities, memory, attention, and other functional capacities specific to the research session and participant’s interaction with the study subject
- Behavioral assessments: Behavioral assessments, which may include stress reactions, related specifically to a study subject
- Biometric measurements: Eye-tracking data, movement patterns, hand size, and other biometric data collected during research studies
- Medication use and medical device interaction data: Information about medications participants are taking, dosages, adherence, and data about interactions with medical devices relevant to study protocols
- Demographic health information: Age, disability status, gender identity, and other demographic information when relevant to study design or analysis
- Other health-related data: Any other health-related information voluntarily provided by participants in connection with our research or consulting services
5. Sources of Consumer Health Data
Core collects consumer health data from the following sources:
- Directly from you: Through study enrollment forms, intake questionnaires, interviews, clinical assessments, surveys, and other direct interactions where you voluntarily provide health information
- Through observational and measurement tools: Biometric sensors, eye-tracking equipment, video recordings, audio recordings, and other measurement devices used during study sessions
- From third-party platforms: Survey tools, video conferencing platforms, data collection software, and other third-party services used to facilitate research activities
Core does not purchase or obtain consumer health data from data brokers.
6. Purposes for Collecting, Using, and Processing Consumer Health Data
Core collects, uses, and processes consumer health data for the following specific purposes:
- Conducting human factors research studies: To conduct research studies as requested by you or by client organizations on whose behalf you are participating
- Categories of Client Organizations: Pharmaceutical companies, medical device companies, or other organizations as may be more specifically identified in a consent form for a specific study
- Analyzing study results: To analyze data and generate research findings and reports for and on behalf of our clients. Information may also be used for publications, but only deidentified, unlinked information.
- Improving research methodologies: To improve our research methodologies, study designs, and data collection processes
- Complying with legal and regulatory obligations: To comply with legal, regulatory, and contractual obligations, including institutional review board (IRB) requirements and research regulations
- Safety monitoring: To monitor participant safety during study protocols and to detect and respond to any adverse events or safety concerns
- No other purposes without separate consent: Core will not use consumer health data for any other purposes without obtaining your separate, affirmative consent
7. Categories of Consumer Health Data We Share and With Whom
Core shares consumer health data in the following circumstances and with the following categories of recipients:
- With client organizations: Core deidentifies consumer health data before sharing research results or reports with the client organizations who commissioned the research study. Clients receive deidentified, aggregated findings such as statistical summaries and group-level results and typically do not receive individually identifiable consumer health data. Deidentification is performed in accordance with applicable standards prior to disclosure to a client. Where a study protocol requires disclosure of individually identifiable data to a client (for example, sharing of audio-visual files of study sessions), that disclosure is governed by the applicable study-specific research protocol and consent form, including the category of client who will receive such information.
- With service providers and processors: Core shares consumer health data with service providers and data processors (such as data analysis platforms, secure cloud storage vendors, IRB administrators, and research support services) who are contractually bound to use the data only as directed and for the purposes specified in the study protocol.
- With regulatory authorities and IRBs: Core may share consumer health data with institutional review boards, regulatory authorities, and government agencies as required by law or research protocol.
- Core does NOT sell consumer health data: Core does not sell consumer health data to any third party under any circumstances. This prohibition applies regardless of the jurisdiction in which you reside and is an absolute organizational policy, not merely a legal compliance requirement.
- Strictly Necessary Processing: Core limits its processing of consumer health data to what is strictly necessary to provide the service requested, conduct the research activity for or on behalf of our client, or fulfill a legal or regulatory obligation. Consumer health data is not processed for any purpose beyond those for which it was originally collected without your explicit consent.
- Data Minimization: Core collects only the consumer health data that is necessary for the specific, identified purpose of the research study or service engagement. We do not collect health data beyond what is required by the applicable study protocol or service scope.
- Core does NOT share with advertising networks, data brokers, or social media platforms: Core does not share consumer health data with advertising networks, data brokers, social media platforms, or other commercial entities for marketing or profiling purposes.
- Core does NOT use health data for cross-context behavioral advertising: Core does not share or use consumer health data for cross-context behavioral advertising or targeted advertising purposes.
8. How Consumer Health Data Is Processed
Consumer health data is collected, processed, and managed as follows:
- De-identification for client reports: Unless otherwise disclosed and consented to by study participants for research session purposes (including sharing of audio-visual recorded study sessions), Consumer health data is deidentified before being shared with client organizations. Core applies recognized deidentification standards to ensure that research outputs shared with clients cannot reasonably be used to identify any individual. Deidentified data is not ‘consumer health data’ under applicable law and is not subject to the same consent and disclosure requirements. Core also deidentifies data before inclusion in any research reports, publications, or other external disclosures, unless specifically disclosed to the study participant during the consent process of the specific study.
- Secure collection: Data is collected through secure digital and physical means, with appropriate safeguards to prevent unauthorized access or interception
- Encrypted storage: Consumer health data is stored in encrypted, access-controlled systems with technical and administrative safeguards
- Limited access: Access to consumer health data is restricted to Core personnel and authorized service providers who have a legitimate need to access the data to fulfill the study protocol or provide services
- Research analysis: Data is analyzed using statistical and qualitative research methods appropriate to the study design
- Retention: Consumer health data is retained only for the period specified in the study consent form or as required by law, research regulations, or IRB protocol
9. Consent
Affirmative Opt-In Consent
Core obtains affirmative, voluntary opt-in consent before collecting consumer health data. Consent is obtained through a study-specific informed consent form provided at the time of enrollment.
Separate Consents
- Effect of withdrawal: Withdrawal of consent does not affect the lawfulness of collection or processing that occurred before your withdrawal
- Collection consent is separate from sharing consent: Your consent to allow Core to collect your consumer health data is separate from your consent to allow Core to share that data with others
- Withdrawal of consent: You may withdraw your consent for collection or sharing of consumer health data at any time by contacting Core using the information in Section 11 below
10. Your Rights
You have the following rights regarding your consumer health data:
Right to Confirm
You may request confirmation of whether Core is collecting, sharing, or selling your consumer health data. Core will confirm or deny collection, sharing, or sale of your consumer health data.
Right to Access
You may request a list of all third parties and affiliates with whom your consumer health data has been shared or sold. Core will provide you with a list of all recipients of your individually identifiable consumer health data. Please note that client organizations who commissioned research studies and received only de-identified, aggregated research findings are not recipients of individually identifiable consumer health data; accordingly, they will not be included in such list. Service providers and processors who handle individually identifiable consumer health data on Core’s behalf (if any on the research study) will be included.
Right to Withdraw Consent
You may withdraw your consent for the collection or sharing of consumer health data at any time. Upon withdrawal, Core will cease collection and sharing of your health data, except where continued processing is required by law or research regulations.
Right to Delete
You may request deletion of your consumer health data from Core’s systems. Core will delete your consumer health data from active systems, backup systems, and archived systems, subject to legal retention obligations and research regulations that may require retention of certain data.
Right to Appeal
If Core denies your request to access, delete, or withdraw consent regarding your consumer health data, you have the right to appeal that decision. Core will provide you with information on how to submit an appeal.
Right to Non-Discrimination
Core will not discriminate against you for exercising any of your rights under this policy.
11. How to Exercise Your Rights
To exercise any of your rights regarding consumer health data, please submit a written request to Core’s Privacy Officer:
By Email:
By Mail:
Core Human Factors, Inc.
1 Belmont Ave., Suite 704
Bala Cynwyd, Pennsylvania 19004
USA
What to Include in Your Request
Please include the following information in your request:
- Your full name
- Your contact information (email address and/or phone number)
- A clear description of the right you wish to exercise (e.g., “I request access to my consumer health data” or “I wish to withdraw my consent for sharing of my health data”)
- Any additional information that will help Core locate your data
Response Timeline
Core will acknowledge receipt of your request and will respond to your request within 45 days of authenticating your identity. (Note: Under Nevada law, the response timeline begins upon authentication of your identity, not from the date of receipt of your request.)
Core may extend the response period by an additional 45 days if your request is complex or requires additional time to locate and compile your data.
Verification of Identity
Core will take steps to verify your identity before processing your request. You may be asked to provide additional information such as your date of birth, study participation details, or other identifying information.
Fees
Core will not charge a fee for most requests. However, if your request is manifestly unfounded or excessive, Core may charge a reasonable fee to cover the cost of processing your request. Core will inform you of any fee before processing your request.
12. Appeals Process
If Core denies your request to access, delete, or withdraw consent regarding your consumer health data, you will receive a written explanation of the reasons for the denial.
How to Appeal
You may appeal Core’s denial by submitting a written appeal to:
Email:
[email protected] (Legal Department of Core’s parent company)
Mail:
Core Human Factors, Inc.
c/o Rimkus Consulting Group, Inc.
[INSERT]
Attn: Legal Department
Please include:
- Your name and contact information
- A copy of Core’s denial letter
- An explanation of why you believe the denial was incorrect
- Any additional information supporting your appeal
Appeal Response
Core will respond to your appeal within 45 days of receipt. If your appeal is denied, Core will provide a written explanation.
Regulatory Complaints
If your appeal is denied or if you are dissatisfied with Core’s response, you may file a complaint with the appropriate regulatory authority:
Nevada residents: Nevada Attorney General’s Office at ag.nv.gov
Washington residents: Washington State Attorney General’s Office at washingtonag.gov
13. Prohibition on Geofencing
Core does not implement, use, or deploy geofencing technology around healthcare facilities or any other location for the purpose of identifying, tracking, or collecting consumer health data from individuals seeking in-person health care services or products.
14. Third-Party Tracking Across Websites and Services
Core’s websites may use third-party analytics tools (such as Google Analytics) that collect device and usage information. However, Core does not permit third parties to collect consumer health data across websites or services for purposes other than those disclosed in this policy or in Core’s General Privacy Policy.
Third parties may not use consumer health data collected on Core’s websites or services for cross-context behavioral advertising, profiling, or other purposes beyond those explicitly authorized by Core or required by law.
Back to Top
15. Security
Core maintains comprehensive administrative, technical, and physical safeguards to protect consumer health data against unauthorized access, use, disclosure, alteration, and destruction. These safeguards include:
- Encryption: Consumer health data is encrypted in transit (using SSL/TLS protocols) and at rest using industry-standard encryption
- Access controls: Access to consumer health data is restricted to Core personnel and authorized service providers who have a legitimate need to access the data
- Employee training: All Core employees are trained on the importance of protecting consumer health data and on proper data handling practices
- Incident response: Core maintains procedures to detect, investigate, and respond to security incidents involving consumer health data
- Physical security: Consumer health data is protected through physical security measures at Core’s facilities
Despite these safeguards, no security system is 100% secure. Core cannot guarantee that all unauthorized access attempts will be prevented.
16. Retention
Consumer health data is retained only as long as necessary to fulfill the purposes described in this policy and in the applicable study consent form, or as required by law or research regulations.
Typical retention periods are:
- Research study data: Retained for the period specified in the study consent form, typically 3–7 years or longer if required by the IRB protocol, sponsor agreement, or applicable research regulations
- Backup and archived systems: Consumer health data in backup and archived systems is retained for the same period as active data, unless a shorter retention period is specified
Upon expiration of the retention period, consumer health data is securely deleted or de-identified in accordance with applicable law and research standards.
17. Relationship to Study-Specific Consent Forms
If you are a research study participant, your participation is governed by a study-specific informed consent form provided to you at the time of enrollment. That consent form contains important information about how your consumer health data will be collected, used, retained, and shared.
To the extent of any conflict between this Consumer Health Data Privacy Policy and your study-specific consent form, the consent form controls with respect to data collected in that study.
If you have questions about how your consumer health data is handled in a specific study, please refer to the consent document you signed or contact the principal investigator or study coordinator listed in that document.
18. Contact Information
For questions about this Consumer Health Data Privacy Policy or to exercise your rights regarding consumer health data, please contact:
Core’s Privacy Officer at:
Email:
Mailing Address:
Core Human Factors, Inc.
1 Belmont Ave., Suite 704
Bala Cynwyd, Pennsylvania 19004
USA
Back to Top
19. Regulatory Complaints
If you believe Core has violated your consumer health data rights or this policy, you may file a complaint with the appropriate regulatory authority:
Washington State Attorney General’s Office:
- Website: washingtonag.gov
- The Washington My Health My Data Act provides a private right of action, which means you may also pursue legal action against Core
Nevada Attorney General’s Office:
Note: Nevada SB 370 does not provide a private right of action; enforcement is by the Nevada Attorney General
Website: ag.nv.gov
Back to Top
20. Policy Updates
Core will notify you of material changes to this Consumer Health Data Privacy Policy before those changes take effect. Notifications will be provided by:
- Posting the updated policy on our website with a new effective date
- Providing notice at the time of your next interaction with Core
The effective date of the current version of this policy is shown at the top of this document. Your continued use of Core’s services or participation in Core’s research studies after notification of changes constitutes your acceptance of the updated policy.
Last Updated: July 20, 2026
Back to Top
We are always happy to help.
