How Your Consent and Information Are Handled
When you use Blackacre to retrieve your health information, you give consent for a single retrieval. That consent covers one request and is complete once the retrieval finishes. You decide whether a retrieval happens by giving or declining consent before it begins. Because each consent applies to a single retrieval and is fulfilled when that retrieval is complete, there is no ongoing consent to revoke afterward. Any withdrawal of consent applies going forward only and does not undo a retrieval already completed. Once a retrieval is complete, we automatically delete the information that was retrieved and do not keep your health information. We retain only limited records confirming that a consented retrieval occurred.
Questions?
Contact us at contact@blackacreservices.com or (312) 381-8824.
Blackacre Privacy and Security Notice
Individual Access Services (IAS)
Effective Date: July 24, 2026
Last Material Change Date: July 24, 2026
Version: 1.0
Quick Summary
This is a short, plain-language summary of how our service works. The full details, and the terms you consent to, are in the sections below.
What we do: You use our service to request your own health records through a nationwide health network. You tell us what you want and prove who you are, and we send those records to recipient identified in your consent. You do not need to log in to any patient portal or health system yourself.
What we keep: Almost nothing. We get your records, deliver them, and delete them in one continuous process. After that, we keep only a small set of records showing that a request took place, which the law and our health network require us to hold.
Your choices: Using our service is always your choice. You can say no before we start, and nothing will happen. We do not sell your information, and we do not use it for advertising.
Questions: If you have questions, you can reach us using the contact information at the end of this Notice.
1. Introduction
We value your privacy. This Privacy and Security Notice (“Notice”) explains how we collect, use, share, and protect your Individually Identifiable Information (“III”) when you use our Individual Access Services (“IAS”). III is any information that identifies you, or that could be used to identify you. It includes things like your name, address, date of birth, medical record number, and health records. In this Notice, we call it your Individually Identifiable Information, or “III.” This Notice also explains your rights and choices.
This Notice applies to our website and any other user-facing service we provide for accessing your health records. It follows the requirements of the Trusted Exchange Framework and Common Agreement (“TEFCA”).
To use our IAS, you give your consent and verify your identity. We then use that verified information to retrieve your records for you. You do not need to log in to any patient portal or health system yourself.
2. How We Use and Share Your Information
This section explains how we use and share your information. We may access, Use, exchange, and/or disclose your III:
-
For providing IAS: To help you access your health information and deliver it to the recipient identified in your consent, including through service providers acting on our behalf.
-
Categories of recipients: We may share your III with:
-
the Qualified Health Information Network (QHIN) that processes your request;
-
other QHINs, and their participants and subparticipants, that hold or transmit your health information within TEFCA;
-
our identity verification provider;
-
service providers and subcontractors that perform functions on our behalf; and
-
the recipient you name in your consent to receive your records.
-
-
Disclosures outside our control: Once your III is exchanged through TEFCA and delivered to the participants and recipients described above, those parties hold it. How they later use and share that information depends on their own legal duties and privacy practices. That use is outside our control.
-
-
With third parties: We may allow III to be accessed, exchanged, Used, and/or Disclosed by third parties only with your consent or as required by applicable law.
-
For required reporting: As permitted or required under TEFCA and applicable law.
We will not:
-
Sell or use for advertising: Sell your III (now or in the future) or use it for marketing or targeted advertising.
-
De-identify or make secondary use: De-identify the health information we retrieve for you or use or share it for research, analytics, or service improvement.
-
Use it against you: Assert any type of claim against you using your III, except for the collection of fees you owe.
Retention: As described in Section 8, retrieval, delivery, and deletion of your access token and your III all happen in one continuous process. After that, we keep only limited audit, consent, and transaction-log records (our “Compliance Records”). Our Compliance Records may include limited identifying information, such as your name and contact details. We keep them only as required or allowed under applicable law and the TEFCA Common Agreement, to verify your consent and support security and compliance. They show that a consented retrieval took place (for example, who requested it, when, and the details of the consent). They do not include the health information we retrieved.
All disclosures through TEFCA follow the uses and disclosures allowed or required by the Common Agreement and applicable U.S. Department of Health and Human Services guidance.
3. HIPAA Status
We are not a “Covered Entity” under the Health Insurance Portability and Accountability Act (“HIPAA”). We are also not a “Business Associate” as HIPAA defines that term. We act as an IAS Provider under TEFCA’s Individual Access Services exchange purpose. Although HIPAA does not apply to us in this role, we are required to protect your III under TEFCA and other applicable laws.
4. Disclosures Required by Law
If we receive a subpoena (civil or criminal), court order, search warrant, or other legal demand for your III, we will give you written or electronic notice within three (3) business days. The one exception is where the applicable law does not allow that notice (for example, under the Patriot Act). You can object to us sharing the III, or ask a court to protect it, as applicable law allows. We will also notify you in writing or electronically (unless the law prohibits it) within three (3) business days if we make III available to law enforcement agencies, including through any sale of III. We do not sell III (see Section 2). We include this commitment because TEFCA requires us to tell you how we would handle any such disclosure, even one we do not make. If our practices change and we begin selling III, we will obtain your prior, express, and documented Consent to Sale, clearly labeled and separate from your consent to this Notice, before doing so.
If any of our Compliance Records are covered by a demand, we will share only the minimum the law requires and will notify you as described above where permitted.
5. Security Practices
We take the security of your information seriously. We use commercially reasonable efforts to protect your III from unauthorized or illegal access, modification, use, or destruction.
-
Access controls: Only authorized staff and partners have access, using role-based permissions and multi-factor authentication.
-
Encryption: We encrypt III both in transit and at rest.
-
Monitoring: We actively monitor for unauthorized access or security incidents, including 24/7 security monitoring and threat detection.
-
Vendor oversight: We require all vendors and third parties that handle III on our behalf to protect it. These parties must: maintain safeguards appropriate to the sensitivity of the III; use III only to perform services for us; limit access to authorized people; and notify us of any suspected or actual security incident.
-
Continued Obligations: Our obligations under this Notice will continue for as long as we keep your III.
6. Your Rights and Choices
This section explains your rights in the III we keep through our IAS. Retrieval and delivery happen in one continuous process, and at the end of that process we automatically delete your access token and your III (see Section 8). This means we hold your III only for the short time needed to complete a retrieval. After that, we keep only our Compliance Records (see Section 2).
You have the right to:
-
Deletion, access, and export. We honor your rights to delete, access, and export your III, where technically possible and permitted by law. See the instructions below for how to exercise each right.
-
Incident notification. Be notified if your III is reasonably believed to have been affected by an IAS Incident (a TEFCA Security Incident or a Breach of Unencrypted III).
-
Choice regarding TEFCA disclosure. Before a retrieval starts, you can decline to have your III shared in response to requests through TEFCA Exchange. Because we ask for your consent before each retrieval, you may decline at that time, and no retrieval will happen. If you decline, we will not be able to retrieve your information through the IAS.
REQUEST-ONLY IAS PROVIDER: Blackacre Marketing LLC does not provide bidirectional services. You will have the ability to request access to your health information via TEFCA Exchange. You will not be able to use Blackacre Marketing LLC to share your health information with other participants in TEFCA.
These rights apply to any III we hold when you make your request, other than our Compliance Records. If we are reasonably aware of any applicable law that would prevent us from deleting III we hold, we will notify you. To make a request, or to confirm deletion of your access token and your III, email support@blackacreservices.com. Use the subject line “Privacy Rights Request.” Please include your name, your contact information, and a description of your request. We may contact you to verify your identity before we process your request. Any III available for export will be provided in CSV format. We will respond within a reasonable time and as required by applicable law.
7. Requirements for Obtaining Express Documented Consent
We must get your express, documented and informed consent to the terms of this Notice before we access, exchange, Use, or Disclose your III. The only exception is Disclosures required by applicable law. This means that when we ask for your consent, we will give you enough information to understand what your choices mean.
-
When Consent is Required: We collect your consent before we start each retrieval request made on your behalf through our IAS. We will also ask for your consent again in two situations. The first is if we plan to use or share your III in a way that is materially different from what this Notice describes. The second is if we make Material Changes to this Notice that would change how your III is used or shared. In either case, we will get that consent before we act.
-
Consent Options: You can give consent by paper or electronic signature, as applicable law allows. We usually collect consent electronically. If you cannot give consent electronically, you may ask to give it on paper by contacting us at support@blackacreservices.com, and we will make reasonable arrangements to help.
-
Auditable Log: We keep all express, documented, and informed consents in a secure, auditable log so we can confirm and verify your consent.
-
Revocation of Consent and Automatic Termination
Your consent lets us retrieve your III one time, and it is used up once that retrieval is done. Retrieval and delivery happen in one continuous process. When that process ends, we automatically delete your access token and your III. We keep no access rights, no login credentials, and no way to make more requests for you.
If you do not want to proceed, you can decline consent when we ask for it, and no retrieval will happen. Declining before the retrieval starts is how you stop it. Any withdrawal of consent applies only going forward. It does not undo anything we already did while relying on your consent before the retrieval was complete. After a retrieval is done, you cannot get your information through our IAS again unless you give new consent for a new retrieval.
To make this clear and easy to control, we take these steps. First, before you consent, we clearly tell you that your consent is for one retrieval only. When the retrieval completes, your consent ends on its own, and we keep no standing permission to reach your data again. To get your information again, you will give new consent for a new retrieval. Second, we clearly post plain instructions on our website and within our service. These instructions explain that your consent is single-use, that you can decline before a retrieval begins, and that no consent remains after a retrieval is complete. Because each consent is single-use and ends on its own, there is nothing left to revoke after a retrieval is done.
9. IAS Incident Notification
We will notify you if we know, or reasonably believe, that your III was affected by an IAS Incident (a TEFCA Security Incident or a Breach of Unencrypted III). We will do this without unreasonable delay. In no case will we wait longer than sixty (60) days after we discover the IAS Incident. Where possible, our notice will include:
-
A short description of what happened, including the date of the IAS Incident and the date we discovered it, if known;
-
The types of III involved;
-
Steps you can take to protect yourself from possible harm;
-
What we are doing to investigate the IAS Incident, reduce harm to Individuals, and prevent further IAS Incidents; and
-
How to reach us with questions or to learn more about the IAS Incident. This will include a toll-free telephone number, an email address (support@blackacreservices.com), and our website, where this Notice and our contact information are posted.
We will also notify regulators and other parties about an IAS Incident when the law requires it. When we give these notices, we will follow the timing and methods required by applicable law.
10. Fees
We do not charge fees for our IAS or for exercising your rights described in this Notice.
11. Changes to This Notice and Notification of Material Changes
We may update this Notice from time to time. The Effective Date and Last Material Change Date at the top of this Notice will be updated accordingly.
A Material Change is a change in how we use or share your III. It means we would handle your III differently than we told you when we collected or obtained it.
Here's what we do when we make a Material Change to this Notice:
-
We will clearly post the updated Notice on our website and any user-facing service on the effective date of the change and keep it available there.
-
We will show Material Changes clearly, so you can easily see what changed in the updated version. We will do this by updating the “Last Material Change Date” and including a summary of Material Changes at the beginning of this Notice.
We will get your separate consent, in a documented and informed way, before we use your III in a way that is materially different from this Notice. This includes any later Material Change to this Notice. Because each retrieval requires its own new consent, any Material Change applies to future retrievals only. We keep a single version of this Notice: the copy on our website and the copy you see when you make a request come from the same source, so they always match and change at the same time an update is posted. When you request a new retrieval after a change, we will show you the current Notice and ask for your consent to it before we proceed. We do not need to reach earlier retrievals, because those are already complete and deleted.
Any contact information we keep is held within our Compliance Records. We use it only to verify consent and to send you required notices, such as notice of a security incident or breach affecting your III.
(Note: If there is ever a disagreement about whether we should have told you about a change, it is up to us to show the change was not material.)
12. Contact Us
If you have questions or complaints about this Notice, please contact our Client Services Department at:
-
Phone: (312)381-8824
We keep a record of each privacy complaint we receive, how we responded, and how it was resolved. We will handle your requests within a reasonable time.