Research Participant Privacy Policy

Revised Date: October 11, 2023

BEESY, LLC is committed to protecting the privacy and security of your personal information. This comprehensive Privacy Policy explains how we collect, use, share, and protect personal information (PII) about you when you participate in our market research studies and how we handle Protected Health Information (PHI) as a business associate of covered entities under HIPAA regulations. We conduct various types of research, including pharmaceutical, medical device, and healthcare-related studies.

BEESY conducts healthcare primary market research globally, with a particular focus on the United States and European Union. We comply with all applicable data protection laws, including the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), the Health Insurance Portability and Accountability Act of 1996 (HIPAA), and all other relevant state and federal laws in the United States. We strive to conform our privacy practices to applicable laws and regulations, and the codes of standards of applicable market and opinion survey research associations, including, without limitation, Insights Association, ESOMAR, BHBIA, and EphMRA.

This Privacy Policy applies to all personal information collected during your participation in our research studies, whether online, by telephone, or in person. It does not cover information collected through other means or for other purposes.

Key Definitions: PII vs. PHI

It’s important to understand the difference between Personally Identifiable Information (PII) and Protected Health Information (PHI):

Personally Identifiable Information (PII):

This is any information that can be used to identify an individual. It can include direct identifiers like name and contact information, as well as indirect identifiers like demographic data and professional information when combined. Examples of PII include name, address, email, phone number, IP address, and online identifiers.

Protected Health Information (PHI):

This is a subset of PII and includes any individually identifiable health information that is created, received, used, or maintained by a covered entity (like a healthcare provider) or its business associate (like BEESY). PHI relates to an individual’s past, present, or future physical or mental health condition, the provision of healthcare, or the payment for healthcare. PHI is protected under the Health Insurance Portability and Accountability Act (HIPAA). PHI includes not just medical records but also billing information, insurance details, and conversations with healthcare providers. Removing the following 18 identifiers can result in “de-identified” data, which has different rules under HIPAA.

Information We Collect

We only collect the *minimum* amount of information necessary for research purposes. This includes:

Types of Personal Information (PII)

We may collect the following types of personal information about you:

For physicians and healthcare providers, this may include numbers such as a US Medical Education Number assigned by the American Medical Association (ME Number), state license numbers, or National ID numbers that immediately reveal your identity.

From time to time, we may also collect sensitive personal data, including health information (such as specific medical conditions, treatments, or genetic information) and financial information (such as bank account details used for incentives).

Protected Health Information (PHI)

PHI is personally identifiable health information in any form, including orally, written, and electronically. PHI includes the following 18 unique identifiers:

We will always collect your Personal Data and PHI by fair and lawful means.

How We Collect Information About You

When collecting personal information from you, BEESY will explain the purpose of collecting the information and will answer any questions you may have. Your participation is always voluntary, and you have the right to refuse or withdraw your consent at any time. BEESY, LLC and its employees collect data through a variety of means including but not necessarily limited to surveys, phone and in-person interviews. Some of your information may be collected from other sources such as third-party recruitment firms.

How We Use Your Information

When you participate in one of our surveys or other research programs, we combine the information you provide with the information of all other research participants and report aggregate responses. Individual responses are combined with those of other participants to create summary data, ensuring that no individual’s personal information is identifiable. Additionally, we may use data we collect in statistical modeling to better understand trends among the general population. When we conduct such statistical modeling, we never release your Personal Data. Data is only used for research purposes and not for marketing, sales, or other unrelated activities.

We use your personal information for the following purposes:

We only use your Personal Data for the conduct of research and for no other purpose. We do not use the contact information we receive about you for any direct marketing activities, nor do we share your contact information with third-party vendors for the purposes of marketing activities.

Please note that receiving email communications may be a requirement of your participation in our surveys or other research programs. You can opt out from receiving these emails by unsubscribing from the survey or other research program.

What We Do Not Do With Your Information