Our Commitment

Browser Extension Privacy Policy

What the extension reads, where it sends it, what it never does, and how to ask us about any of it.

Effective date: September 7, 2026

This policy covers the Grand Vision Practice Management browser extension only. Our website and client services are covered separately in our main privacy policy.

What the extension is for

The extension has one purpose: to move medication and member records a practice already has in its payer portal into that same practice's own practice-management system, without staff retyping them.

Clinical staff do this work today by opening each patient's record by hand and copying what they see. The extension performs the same reads, in the same browser session, and delivers the result to the practice's own system. It does not give anyone access to anything they could not already open themselves.

The two sites it works on

The extension is active on exactly two sites and nowhere else:

  • Your practice's own systemhub.gvpracticemanagement.com, operated by us on the practice's behalf.
  • The payer portalzephyr.leadingreach.com, run by Leading Reach for WellMed.

What it reads

A run reads from both sites. From your practice's own system, it reads the short list of patients currently awaiting pickup verification:

  • Personally identifiable information — patient name, date of birth and plan member identifiers, so it knows whose history to look up.
  • Health information — the medication each of those patients is being followed for.

Then, from the payer portal, for those patients only:

  • Health information — medication fill records, including drug name, fill dates, quantity and days supply.

It reads nothing else. It does not read browsing history, other tabs, form entries, keystrokes, location, or any site other than the two named above. It never reads a patient who is not already on that waiting list.

Where it sends it

Fill records go to one place: your practice's own system, and nowhere else.

The plan member identifier of each waiting patient is sent to the payer portal — that is simply how a record is looked up there, and the portal already holds it. Nothing else travels in that direction, and no third party receives anything at any point.

What it never does

  • It does not sell data, and it never will.
  • It does not transfer data to third parties — no advertising platforms, no data brokers, no information resellers.
  • It does not use data for advertising, personalized or otherwise.
  • It contains no analytics, tracking, telemetry, or usage measurement of any kind.
  • It does not use data for credit assessment or lending.
  • It does not send data to any artificial-intelligence service.
  • It does not store credentials or passwords. It asks for none, and never sees your password.
  • It does not keep you signed in. To talk to your practice's system it borrows the same short-lived access token that system's own web page uses, holds it in memory for the length of one run, and discards it. It cannot obtain one unless you are already signed in.

What it keeps

Nothing persistent. Records pass through the browser's memory during a transfer and are discarded when it completes. The extension writes no patient information to browser storage and keeps no local copy or history — it requests no storage permission at all, so it could not retain anything even by mistake.

Records that arrive in the practice's system are held there under that practice's own retention rules, described in our main privacy policy.

Who can use it

The extension is distributed to authorized staff at practices we serve. It performs no reads unless the person using it is already signed in to both systems with their own credentials, and it can reach only the records those credentials already permit. Installing it grants no access on its own.

Security

All traffic is encrypted with TLS. Access to the receiving system requires multi-factor authentication, is restricted to the people whose work requires it, and is logged. Reads performed through the extension are recorded the same way the equivalent manual reads would be.

Health information and HIPAA

The records handled here are protected health information. We handle them as a business associate of the practice under HIPAA, on that practice's instructions and under a business associate agreement. Patients seeking access to, correction of, or deletion of their records should contact their practice, which is the covering entity for those requests; we support the practice in fulfilling them.

Limited Use

Our use of information received through the extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Information is used only to provide the single purpose described above, and for directly related operational purposes such as keeping that feature secure and working.

Changes to this policy

If we change this policy, we'll post the updated version here with a new effective date.

Contact

Questions about the extension — including what it reads, how it's secured, or a request about specific information — are welcome:
security@gvpracticemanagement.com · (515) 400-3013