Your privacy matters
GoPathDx APP (“we,” “our,” or “us”) is a mobile application designed exclusively for licensed clinical physicians to view pathology reports that have been signed and issued by pathologists. This statement explains how we collect, use, disclose, and safeguard your data.
Information we collect
Account information: Your account is provisioned by your affiliated healthcare institution. We process your name, email address, medical license number, institutional affiliation, and role. This information is managed by your institution’s system administrator and is used to authenticate your identity as a licensed clinical physician authorized to view pathology reports. GoPathDx APP does not support self-registration; only pre-approved users with valid institutional credentials may access the platform.
Pathology report data: Through GoPathDx APP, you access pathology reports—including diagnostic findings, specimen details, and clinical notes—that have been signed and issued by pathologists at your affiliated institution. All patient health information (PHI) contained in these reports is stored in HIPAA-compliant cloud infrastructure and encrypted both in transit and at rest.
Usage data: We record report-access events for security, compliance auditing, and to show whether an issued report has been viewed. We do not use this information for advertising or cross-app tracking.
Device data: To provide report alerts, Firebase Cloud Messaging processes an app-installation identifier, APNs and push-notification tokens, device model, language, time zone, operating-system version, app identifier, and app version. Our service registers the push token and device platform solely to deliver and manage those alerts. The app does not request or collect precise location and does not access the advertising identifier.
How we use your information
Your information is used exclusively for the following purposes:
- Authenticating your identity and maintaining secure access to the platform
- Providing access to signed pathology reports for clinical review and patient care
- Sending push notifications when new pathology reports are signed and available
- Maintaining security, compliance audit logs, and report-view status
- Complying with legal obligations under HIPAA, HITECH, and applicable state regulations
GoPathDx APP is a read-only viewer for issued pathology reports. The app does not create, modify, or sign pathology reports. All diagnostic interpretations are performed by pathologists at your affiliated institution.
Data sharing and disclosure
We do not sell, rent, or trade your personal information. We may share data only under the following circumstances:
- With your institution: Activity logs may be shared with your affiliated hospital or laboratory for compliance auditing and access verification.
- Service providers: Cloud hosting and notification services that operate under strict data processing agreements and BAAs.
- Legal requirements: When required by subpoena, court order, or applicable law.
GoPathDx APP does not sell personal information, display advertising, combine app data with third-party data for advertising or advertising measurement, share data with data brokers, or track users across apps or websites owned by other companies.
Data security
We implement industry-standard security measures including AES-256 encryption for data at rest, TLS 1.3 for data in transit, multi-factor authentication, role-based access controls, and comprehensive audit logging of all pathology report access events.
All patient health information in pathology reports is stored and transmitted in accordance with HIPAA Security Rule requirements (45 CFR Part 160 and Part 164, Subparts A and C).
Your rights
You have the right to access, correct, or delete your account information at any time through the Account tab in the application. You may also request a data export or account deletion by contacting our privacy office.
How to request deletion of your data
You may request deletion of your personal data at any time. Send an email to our privacy office with the subject “Data Deletion Request.” Include your full name, the email address linked to your account, your medical license number, and your affiliated institution so we can locate and verify your record.
Identity verification: To protect your information, we verify every deletion request before acting. We may contact you via the email on file or through your institution to confirm the request.
Processing time: Once verified, we will delete your account information within 30 days and notify you when deletion is complete. If we cannot honor part of your request, we will explain the reason in writing.
What is deleted and retained: We remove your account information and associated usage and device data from active systems. Pathology report data (PHI) you viewed is not deleted at the user level; it remains part of the permanent medical record held by your affiliated institution and is retained according to its policies and applicable legal requirements. We will disconnect your account from those records and disable further access.
Withdrawal: You may withdraw a deletion request at any time before it is completed by contacting our privacy office.
Data retention
Account information is retained for the duration of your active relationship with GoPathDx APP. Upon account termination, personal data is deleted within 30 days.
Pathology report data retention follows your institution’s records retention policies and applicable regulatory requirements.
Changes to this statement
This privacy statement may be updated periodically. We will notify you of material changes through the application and via email. Continued use of the app after changes constitutes acceptance of the updated policy.