Macula Risk

Privacy & Genetic Information Notice

This notice explains the types of information Macula Risk may receive, why it is used, and the safeguards applied to sensitive patient information.

Effective date: October 1, 2026

This notice describes the Macula Risk service. Your ordering provider may also give you a separate Notice of Privacy Practices that applies to your care and medical record.

Information we may collect

Depending on the service requested, Macula Risk may receive:

  • Identity and contact details, such as name, date of birth, address, phone number, and email address.
  • Clinical information needed to order, process, and interpret the test.
  • Genetic test information, results, risk calculations, and related reports.
  • Uploaded documents, sample information, communications, and delivery details.
  • Account, billing, authentication, audit, and technical security information.

How information is used

Information is used as needed to receive and process orders, perform and report testing, communicate with authorized providers and patients, support billing, operate the service, protect accounts, investigate security events, and meet legal or contractual obligations.

Information should not be collected for unrelated purposes. Macula Risk does not use genetic results or biological samples for research, product improvement, or other secondary purposes.

Genetic information

Genetic information and genetic test results are treated as sensitive health information. Access is limited to authorized users and service providers who need the information to perform their assigned responsibilities.

Biological samples are discarded after testing and are not retained by Macula Risk. Genetic results are used to perform and report the ordered test and are not used for research, product improvement, or other secondary purposes.

Genetic information must not be used for employment decisions. Federal law also addresses discrimination involving genetic information; the EEOC GINA fact sheet provides general information.

Who may receive information

Information may be made available to the ordering provider, authorized care or laboratory personnel, contracted service providers supporting the service, payment processors when needed, and parties where disclosure is required or permitted by law. Access should be limited to the minimum necessary for the stated purpose.

Macula Risk does not use this notice to authorize a new disclosure or secondary use. The applicable consent, authorization, agreement, or law controls.

Security safeguards

The application includes controls intended to protect sensitive information, including authenticated access, role-based authorization, secured report and document downloads, account lockout protections, audit logging, denied-access monitoring, security headers, secure cookies, and controls intended to prevent sensitive responses from being cached.

Security also depends on the production hosting environment, database, storage, backups, integrations, personnel, and operating procedures. Those controls should be reviewed and verified separately; no website can promise absolute security.

Retention, deletion, and patient requests

Information is retained for the period needed for clinical, legal, contractual, billing, quality, security, and operational purposes. Retention and secure-deletion periods should be established in the applicable records-retention schedule.

To request access, correction, or information about a privacy concern, contact the ordering provider first or use the privacy/support contact provided by your organization. Requests may be subject to legal, clinical, identity-verification, and contractual requirements.

HIPAA and other notices

If your provider is a HIPAA-covered entity, the provider's Notice of Privacy Practices describes its permitted uses and disclosures, patient rights, complaints process, and privacy contact. Macula Risk may support a provider or other healthcare organization under separate agreements. This page does not replace any applicable Notice of Privacy Practices, consent form, authorization, or business associate agreement.

HHS provides guidance on Notices of Privacy Practices.

Questions or concerns

For a question about a specific test, report, consent decision, or medical record, contact the ordering provider. For a technical or privacy concern involving the Macula Risk service, contact the support or privacy representative provided by your organization.

This notice should be reviewed and approved by the organization's privacy and legal advisers before it is used as the final patient notice.