⚖ Patient Rights & Consent Policy — HIPAA · 21st Century Cures Act · ONC HTI-1 DOC-PATIENT-RIGHTS-001 · v1.0 · Effective 2026-04-19
Rx
MyRxWallet North America Corporation
Sovereign Health Infrastructure · Wyoming Corporation
Patient Rights & Consent Policy
A plain-language summary of every right you have over your health data — and exactly how to exercise each one within the MyRxWallet platform.
Document IDDOC-PATIENT-RIGHTS-001
Version1.0
Effective DateApril 19, 2026
BasisHIPAA · 21CC Act · ONC HTI-1
⚖ Your Data. Your Rights. Your Control.
Foundation
Core Principle: You Own Your Health Data
Patient Data Sovereignty

MyRxWallet was designed from day one around a single, non-negotiable principle: your health data belongs to you — not your insurance company, not your hospital, not MyRxWallet. We are a conduit that enables you to access, share, protect, and monetize your own health information on your own terms.

This document summarizes your rights under the HIPAA Privacy Rule (45 CFR Part 164), the 21st Century Cures Act, ONC Information Blocking Rules (45 CFR Part 171), and MyRxWallet's own Patient Data Ownership Policy. These rights are not abstract — every one of them can be exercised directly in your Patient Portal.

Section 02
Your 10 Patient Rights
Right 01 · 45 CFR §164.524
Right to Access Your Health Records

You have the right to inspect and receive a copy of your PHI in our designated record set. This includes your medical history, lab results, prescriptions, imaging reports, clinical notes, and all other health information we maintain about you.

Timeline: We must respond within 30 days. One 30-day extension is permitted with written notice.

Format: You may request records in electronic format (FHIR R4 JSON, PDF, CSV) at no charge for the first copy.

→ Patient Portal: Medical Records section → Any record → Download / Export
Right 02 · 45 CFR §164.526
Right to Request Amendment

If you believe your PHI is incorrect or incomplete, you may request that we amend the record. You must provide the reason for the requested amendment in writing.

Timeline: We will respond within 60 days. If we deny your request, you have the right to submit a statement of disagreement and request that it accompany future disclosures.

We may deny an amendment request if: the information was not created by us; the record is accurate and complete; the information would not be available for inspection; or it is not part of the designated record set.

→ Patient Portal: Profile → Edit / Request Amendment → Submit reason in writing
Right 03 · 45 CFR §164.522(a)
Right to Request Restrictions

You may request restrictions on how we use or disclose your PHI for Treatment, Payment, and Healthcare Operations purposes. While we are not required to agree to all restriction requests, we must agree to restrict disclosure to a health plan for services you paid for entirely out-of-pocket.

Once we agree to a restriction, we are bound by it except in emergency situations requiring treatment.

→ Patient Portal: Consents → Restrictions → Add Restriction Request
Right 04 · 45 CFR §164.528
Right to an Accounting of Disclosures

You have the right to a full accounting of disclosures of your PHI made for purposes other than Treatment, Payment, and Healthcare Operations, for the previous 6 years. This accounting must include the date, recipient, purpose, and description of each disclosure.

MyRxWallet's blockchain audit trail provides a real-time, tamper-proof accounting of every data access event anchored to our Hyperledger Fabric ledger.

→ Patient Portal: Blockchain tab → Full audit trail, exportable
Right 05 · 21st Century Cures Act · ONC HTI-1
Right to Data Portability (FHIR R4)

Under the 21st Century Cures Act and ONC HTI-1 Final Rule, you have the right to electronically access your complete health records in a standardized format. MyRxWallet supports full FHIR R4 export covering all USCDI data elements.

You may also authorize any SMART on FHIR-compatible third-party application to access your health records directly from our FHIR API. Revoke application access at any time from Consents.

FHIR Endpoint: https://ehr.myrxwallet.io/fhir/r4

MyRxWallet does not engage in information blocking as defined at 45 CFR Part 171. If you believe we have blocked your access to your information, you may report it to the ONC at info-blocking@hhs.gov.

→ Patient Portal: Medical Records → Export FHIR R4 · Settings → Authorized Apps
Right 06 · 45 CFR §164.522(b)
Right to Confidential Communications

You may request that we communicate with you about health matters only through certain channels or at a specific location (e.g., "only contact me by email," "only use this phone number," "do not send mail to my home address"). We will accommodate reasonable requests without requiring an explanation.

→ Patient Portal: Settings → Communication Preferences → Confidential Communications
Right 07 · HIPAA · MyRxWallet Policy
Right to Revoke Consent

You may revoke any authorization you have provided — including access granted to providers, third-party applications, payer data connections, or data sharing agreements — at any time, in writing or electronically. Revocation takes effect immediately except to the extent action has already been taken in reliance on the authorization.

Revocation is recorded on the blockchain audit trail with a timestamp and is legally effective. The provider or application will be immediately unable to access new data; previously accessed data may remain with them per their own policies.

→ Patient Portal: Consents → Active Authorizations → Revoke (immediate)
Right 08 · 45 CFR §164.530(d)
Right to File a Complaint

If you believe your privacy rights have been violated, you have the right to file a complaint with MyRxWallet or directly with the HHS Office for Civil Rights (OCR). We will never retaliate against you for filing a complaint in good faith.

With MyRxWallet: Email info@myrxwallet.io or use the Help → Feedback form in the Patient Portal.

With HHS OCR: ocrportal.hhs.gov or 1-800-368-1019 (TDD: 1-800-537-7697).

Information Blocking Complaints: info-blocking@hhs.gov (ONC) or healthit.gov/topic/informationblocking.

→ Patient Portal: Help → Feedback → Select "Privacy Complaint"
Right 09 · HIPAA · ADA · Section 1557 ACA
Right to Non-Discrimination

You have the right to exercise any of the rights described in this document without being subjected to retaliation, discrimination, or any adverse action in your healthcare or access to Platform services. MyRxWallet complies with all applicable anti-discrimination laws including Section 1557 of the Affordable Care Act, which prohibits discrimination on the basis of race, color, national origin, sex, age, or disability in health programs.

→ Contact info@myrxwallet.io if you believe you experienced discrimination
Right 10 · 21st Century Cures Act · 45 CFR Part 171
Right Against Information Blocking

Under the 21st Century Cures Act, you have the right to access your electronic health information (EHI) without interference. Healthcare providers, EHR developers, and health information networks are prohibited from engaging in "information blocking" — practices that interfere with the access, exchange, or use of EHI.

MyRxWallet is committed to full compliance with ONC's Information Blocking Rules. Our FHIR R4 API is publicly accessible for all USCDI data elements. We do not charge excessive fees, impose unreasonable restrictions, or delay access to your data.

If any provider using MyRxWallet engages in information blocking against you, you may report it to ONC at healthit.gov/topic/informationblocking.

→ FHIR API: ehr.myrxwallet.io/fhir/r4 (public, standardized, no lock-in)
Section 03
Consent Framework

MyRxWallet operates a blockchain-anchored consent management system that gives you granular, auditable control over who can access your health data and for what purpose.

Consent TypeRequired ForHow to Grant/RevokeOn-Chain?
Treatment AuthorizationProvider access to your recordsPatient Portal → ConsentsYes
Third-Party App Access (SMART)FHIR app authorizationOAuth2 consent screen + Portal → AppsYes
Payer Data ConnectionCMS Blue Button, BCBS, etc.Patient Portal → Consents → Payer ConnectionsYes
Research AuthorizationPHI use for research (IRB required)Separate written authorization requiredYes
Data Royalty ParticipationOptional data monetization programMyRx-Royalty section → Opt-In requiredYes
42 CFR Part 2 ConsentAny SUD record disclosureSeparate patient-specific consent (stricter than HIPAA)Yes
Marketing AuthorizationAny marketing use of your PHISeparate written authorization required (we will not solicit)Yes

All consent events — grants, modifications, and revocations — are recorded as immutable SHA-256 hashes on the Hyperledger Fabric blockchain. You can view your complete consent history in the Blockchain tab of your Patient Portal at any time.

Section 04
Special Protections for Sensitive Information

Certain categories of health information receive enhanced legal protections beyond standard HIPAA. MyRxWallet implements these protections automatically:

  • Substance Use Disorder (SUD) Records — 42 CFR Part 2: Records related to substance use disorder assessment or treatment require your patient-specific written consent before disclosure to any party, including your own treating physicians. This is stricter than HIPAA and cannot be overridden by a court order without special procedures. Our platform flags all ICD-10 F10-F19 codes and MAT medications (buprenorphine, methadone, naltrexone) under Part 2 protection.
  • Mental Health Records: State laws typically provide enhanced protections for mental health records, including psychotherapy notes. Psychotherapy notes require separate HIPAA authorization even for treatment purposes. Our platform maintains these as a separate record set.
  • Reproductive Health — HIPAA 2024 Final Rule: Health information related to lawful reproductive healthcare receives additional protections against disclosure to law enforcement for purposes of investigating lawful reproductive health activities.
  • HIV/AIDS Status: State-specific consent requirements apply to HIV/AIDS testing and status disclosure. Many states require separate written consent.
  • Genetic Information (GINA): Genetic information cannot be used for insurance underwriting. GINA prohibits health insurers from using genetic information for coverage decisions.
  • Minor's Confidential Services: Depending on state law, minors receiving certain services (family planning, SUD treatment, STI testing) may have the right to keep those records confidential from parents or guardians.
Section 05
Blockchain-Verified Audit Trail
Tamper-Proof Consent History

Every consent event on MyRxWallet is anchored to our Hyperledger Fabric 2.5 blockchain as a SHA-256 cryptographic hash. This creates an immutable, timestamped, independently verifiable record of every grant, revocation, data access, and disclosure — something no traditional EHR system provides.

What is stored on-chain (as SHA-256 hash only — no PHI):

  • Consent grant events (who, when, purpose, expiration)
  • Consent revocation events (timestamp, reason)
  • PHI access events (provider/app ID, timestamp, data category)
  • Amendment requests and dispositions
  • Data export events (FHIR exports, portability requests)
  • Security incident events (Sentinel flags)

You can view your complete blockchain audit trail at any time in the Patient Portal → Blockchain tab. The audit trail can be exported in CSV or JSON format for personal records or legal purposes.

Section 06
How to Exercise Your Rights
ActionHowTimeline
Access your recordsPatient Portal → Medical Records → DownloadImmediate (digital) / 30 days (formal)
Request record amendmentPatient Portal → Profile → Request Amendment60 days response
Revoke provider accessPatient Portal → Consents → RevokeImmediate
Revoke app accessPatient Portal → Settings → Authorized Apps → RevokeImmediate
Request restrictionsPatient Portal → Consents → Add Restriction10 business days
Request accountingPatient Portal → Blockchain tab (real-time) or written requestImmediate / 60 days formal
Export FHIR dataPatient Portal → Medical Records → Export FHIR R4Immediate
Request account deletionEmail info@myrxwallet.io with subject: DELETE MY ACCOUNT30 days
File a privacy complaintPatient Portal → Help → Feedback / Email info@myrxwallet.io10 days acknowledgment
Report information blockinginfo-blocking@hhs.gov or healthit.gov/topic/informationblockingONC jurisdiction

Privacy Officer Contact

For any questions, concerns, or formal requests regarding your patient rights:

  • Name: Olivia Trinh, Chairman & CEO / Privacy Officer
  • Email: info@myrxwallet.io
  • Phone: 702.546.8686
  • Response Commitment: All formal rights requests acknowledged within 3 business days; substantive response within applicable HIPAA timelines.