QuestConnect.app

Privacy Policy

HIPAA-grade controlsOAuth 2.0 patient authorizationEncrypted at rest

Overview

QuestConnect uses information to support remote patient monitoring workflows, care coordination, documentation, and billing readiness.

Information We May Collect

  • Account and contact information
  • Patient demographics
  • Insurance and eligibility information
  • RPM workflow information
  • Device setup and activation information
  • Patient-authorized retrospective CGM data and CGM-derived metrics from Dexcom, when production access is approved
  • Notes, tasks, time entries, and documentation records
  • Audit and security logs

Dexcom Data

The Dexcom API provides retrospective CGM data and CGM-derived metrics for use in software applications. QuestConnect uses Dexcom data only for retrospective RPM review, glucose trend review, patient follow-up, care coordination, documentation support, and billing readiness.

QuestConnect only accesses Dexcom data after the patient completes Dexcom's OAuth 2.0 authorization flow. Patients authenticate directly with Dexcom. QuestConnect does not collect or store Dexcom usernames or passwords.

QuestConnect has applied for Dexcom production credentials. Until Dexcom separately approves production access to actual patient CGM data, QuestConnect's Dexcom developer access remains sandbox-only. Sandbox data is simulated CGM data and does not include actual patient data.

How We Use Information

  • RPM review
  • Glucose trend review
  • Patient follow-up
  • Care coordination
  • Clinical documentation support
  • Billing readiness review
  • Compliance and audit support
  • Security monitoring

Patient Authorization and Revocation

Dexcom data sharing is opt-in. Patients may revoke Dexcom authorization through their Dexcom account permissions. If authorization is revoked, QuestConnect stops retrieving new Dexcom data unless the patient authorizes access again. Information already received before revocation remains subject to QuestConnect's retention, documentation, audit, and legal obligations.

Data Sharing

QuestConnect may share documentation or workflow information with approved healthcare systems used by an authorized healthcare organization when needed for care coordination, documentation, or billing workflow support.

QuestConnect does not currently share live Dexcom CGM readings directly with an EHR. QuestConnect does not share Dexcom data with advertising networks, third-party data aggregators, or non-care-team recipients.

What We Do Not Do

We do not sell patient information. We do not use Dexcom data for advertising. We do not collect Dexcom usernames or passwords. We do not use Dexcom data for insulin dosing recommendations or automated treatment decisions. We do not use Dexcom data for real-time emergency monitoring, immediate clinical action by patients or caregivers, or non-Dexcom glucose product promotion or comparison.

Data Protection

  • Role-based access
  • Secure backend processing
  • Server-side token storage
  • Encryption in transit
  • Audit logging
  • Access controls

Record Retention

QuestConnect keeps records only as long as needed to support RPM workflows, documentation, legal obligations, security review, and audit needs. Retention periods may vary based on the type of record, the healthcare organization using the platform, and applicable legal or contractual requirements.

When information is no longer needed, QuestConnect may delete, archive, or de-identify it according to approved retention rules. Security and audit logs may be retained separately to support compliance review and incident investigation.

Privacy Officer or DPO Contact

QuestConnect has a designated privacy contact for privacy questions, Dexcom data authorization questions, and data handling concerns.

Contact: support@questconnect.app

Please use the subject line: Privacy Request.

Contact