Revised and effective as of December 5, 2023.
Welcome to Endeavor Health!
Endeavor Health is committed to protecting the individual privacy of our patients, team members and visitors. We care about your personal information, and we want you to be fully informed about our privacy practices.
The Endeavor Health Privacy Statement explains the types of information provided to us and how it is collected, used, shared, secured and stored when you use any of our services. Please review this Privacy Statement, as it contains information, terms and conditions that may affect your legal rights and ability to use our services. You can download and print a copy of this Privacy Statement here.
- About your protected health information (“PHI”)
- Acceptance of the Endeavor Health Privacy Statement
- Information we collect & how it is collected
- How we use & protect your information
- Choices regarding the collection & use of your PII
- Law applicable to this Privacy Statement
- Updates to this Privacy Statement
- Contact us
- “Endeavor Health”, “EH”, “We”, “Our” or “Us” — Endeavor Health includes our hospitals (Edward Hospital, Elmhurst Hospital, Evanston Hospital, Glenbrook Hospital, Highland Park Hospital, Linden Oaks Hospital, Northwest Community Hospital, Skokie Hospital and Swedish Hospital), our subsidiaries and affiliates.
- “Endeavor Health Services” — Collectively refers to all of the following services that are owned by, operated and/or managed by or for Endeavor Health:
- “Endeavor Health Websites” — Our websites include, but are not limited to, endeavorhealth.org, northshore.org, eehealth.org, nch.org and swedishcovenant.org.
- “Endeavor Health Patient Portals” — Our patient portals allow patients to access their medical records, schedule visits and more using a web browser or mobile app. Our patient portals include, but are not limited to:
- “Other EH Mobile Apps” — Separate from our patient portal’s mobile apps, Endeavor Health and/or other third parties’ may manage and/or offer additional mobile apps for our patients, team members and communities.
- “Endeavor Health Additional Services” — We also provide services, digital offerings and tools, including, but not limited to: customer service; technical support; QR codes; chatbots; search tools; employee recruitment tools; clinician profiles; location listings; digital signage; and subscriptions, reminders, alerts and marketing messages using direct mail, email and SMS (text messages).
- “You” or “Your” — You, regardless of being an individual, a group or an organization, and regardless of whether you are using Endeavor Health Services on behalf of yourself or someone else.
- “Your information” — Collectively refers to an individual’s personally identifiable information (“PII”), and/or protected health information (“PHI”).
- Personally identifiable information (“PII”) — An individual's first name or first initial and last name in combination with any one or more of the following data elements: Social Security number; driver's license or state identification card number; account number, credit card number or account information related to a financial account; medical information; health insurance information; and/or unique biometric data generated; OR, a username or email address, in combination with information that would permit access to an online account. See the Illinois Personal Information Protection Act for more information.
- Protected health information (“PHI”) — Any information regarding an individual's medical history, mental or physical condition, or medical treatment or diagnosis by a healthcare professional, including such information provided to a website or mobile application.
Unless otherwise specified, please note that this Privacy Statement only applies to personal information you provide through your use of the Endeavor Health Services. As otherwise not legally prohibited, Endeavor Health and third-parties may collect personally identifiable information (“PII”) that you choose to provide to the Endeavor Health Services. When necessary, you will be prompted to accept additional terms and conditions when using Endeavor Health Patient Portals via a web browser and/or mobile app (see “Endeavor Health Patient Portals and what we collect”).
This Privacy Statement does not apply to any protected health information (“PHI”) gathered via the Endeavor Health Services. Rather, Endeavor Health’s Notice of Privacy Practices will govern Endeavor Health’s use and disclosure of your PHI. The Notice of Privacy Practices describes how information about Endeavor Health’s patients may be used and disclosed. Please review it carefully.
For more information, including information about your rights under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations (collectively, “HIPAA”), please review Endeavor Health’s Notice of Privacy Practices.
By accessing the Endeavor Health Services and/or using any of the features or services provided on the Endeavor Health Services, you signify your acceptance of the Endeavor Health Privacy Statement and consent to the information collection and use practices described herein. If you do not consent or otherwise do not agree with the Endeavor Health Privacy Statement, please do not use or access the Endeavor Health Services.
Endeavor Health may collect your PII through the Endeavor Health Services. We may collect PII actively (i.e., by collecting information you voluntarily submit to Endeavor Health) and passively (i.e., by collecting information automatically gathered from your computer).
In some instances, Endeavor Health, through the Endeavor Health Services, and/or a third-party vendor or other third parties may collect PII (including but not limited to email address, Internet Protocol (IP) addresses, name, phone number, and other information as defined under the Illinois Personal Information Protection Act). This information may be collected when accessing the Endeavor Health Services or when volunteered by the user (e.g., when you create a patient portal account, when you schedule an appointment, when you submit a web form or when you answering a question prompt posed by a chatbot tool). If you send Endeavor Health an email request or participate in our forums, Endeavor Health may store that information as well, including any PII included in a post, message or email, as well as any PII included in any attachments you may include.
When applicable, you may also use the Endeavor Health Services to pay a bill, buy a gift from a gift shop or make a donation (collectively, “Transactions”). To process a Transaction, Endeavor Health or one of our third-party vendors (“Payment Processors”) may collect PII, such as your banking information, like your name, billing address, credit or debit card number, email address, telephone number and/or email address. We or Endeavor Health’s Payment Processors will process your credit card payment using established encryption techniques that protect your information.
Also, when you visit the Endeavor Health Services, Endeavor Health’s servers may automatically record certain information about the device (e.g., a computer, tablet, or mobile device) you used to access the Endeavor Health Services. If a third-party vendor collects your PII, such vendor may share and/or use all or part of your PII with Endeavor Health or another third party. In addition to other uses and disclosures in the Endeavor Health Privacy Statement, Endeavor Health may also disclose PII, as required or permitted by law.
When you visit Endeavor Health Services, Endeavor Health’s servers automatically record certain information about the device (e.g., a computer or mobile device) you used to access the Endeavor Health Services. Such information, often referred to as “log file” information, may include your device’s IP (“Internet Protocol”) address, operating system name and version, and browser name and version, as well as the referring URL, number of times your device has accessed the Endeavor Health Services, pages of the Endeavor Health Services you viewed, links you clicked, and other information about your visit to and use of the Endeavor Health Services. With your consent, Endeavor Health’s servers may also collect information about the precise location of your device. If you do not wish to provide location data, please consult your web browser and/or device support documentation for information on how to disable these features.
If you access the Endeavor Health Services from a smartphone or tablet, Endeavor Health’s servers may also collect information specific to your device. This information may include your mobile device’s hardware model, unique device identifier(s) and mobile network information. With your consent, Endeavor Health may also access and collect information from certain native applications on your device, such as your device’s camera, photo album, microphone, phonebook or calendar applications. If you do not wish to provide access to native applications, please consult your web browser and/or device’s support documentation for information on how to disable these features.
If you contact us in relation to your employment, fellowship, or grant prospects, we will use your personal information to consider you for current and future employment, fellowship, or grant opportunities and to contact you with respect to such opportunities at Endeavor Health that you have expressed an interest in. In connection with your application we may collect personal identifiers, such as your name, postal address, email address, or other similar identifiers; and professional or employment-related information about you, such as current or past job history or performance evaluations.
To provide patients and visitors with a useful and personalized patient experience, the Endeavor Health Patient Portals may require access to additional features and/or information stored on your web browser or smartphone. The following describes the ways Endeavor Health may access, collect, use and share your PII and/or PHI:
- Location: Endeavor Health Patient Portals do not collect or store your location data or share it with third parties without your consent. Location data can be used by mobile app features, such as sending notifications to Endeavor Health’s registration staff when you've arrived for an appointment or suggesting healthcare providers or locations that are nearby.
- Endeavor Health Patient Portals may offer location-based check-in for in-person appointments or allow you to find healthcare providers near you. The first time you try to use any features that use your location, you will be asked for your consent to share your device’s location information within the app. Your location information will be used only if you give your consent, and your consent can always be revoked by changing your privacy permissions. You do not have to provide consent if you do not want to allow the Endeavor Health Patient Portals to use your location.
- Camera and photo library: Endeavor Health Patient Portals may use your device’s camera feature, or require access to your photo library, to let you take and/or share photos or to capture and stream video for telehealth visits. If you choose to allow the Endeavor Health Patient Portals to interact with your photo library, you can upload photos to personalize an account or provide health record attachments and these photos may be accessed by the healthcare providers.
- Microphone: If you choose to allow the Endeavor Health Patient Portals to use your device’s microphone, you can use your microphone to navigate the Endeavor Health Patient Portals and/or can be used to capture audio for telehealth visits. The Endeavor Health Patient Portals do not store your audio data.
- Storage: Endeavor Health Patient Portals may store files you upload from your device's storage to your medical record. The Endeavor Health Patient Portals may access your device's storage to read and write files you select in the application. These files may be used as file attachments that are sent to your healthcare provider or they may be created from file attachments sent to you from your healthcare provider.
- Bluetooth: Endeavor Health Patient Portals may access your device's Bluetooth feature. Bluetooth may be used to detect other devices nearby that can help with your appointment arrival. The Endeavor Health Patient Portals do not store your Bluetooth data.
- Phone: Endeavor Health Patient Portals may use your smartphone to call phone numbers selected by you in the application. The Endeavor Health Patient Portals will not collect, store or share your call history or any other call data.
- Telehealth: Endeavor Health Patient Portals may allow you to conduct a telehealth appointment with your healthcare providers, such as a video visit or a phone appointment that may be subject to additional terms and conditions for you to review and accept. Always confirm with your provider if they provide telehealth services. The Endeavor Health Patient Portals only provide the technical capabilities for telehealth appointments to happen. Endeavor Health Patient Portals do not capture any health information about you that is discussed or exchanged with your provider during live telehealth appointment sessions.
In addition to giving you a notice of technology changes, if subsequent versions of Endeavor Health Patient Portals collect new types of PHI and/or PII, you may be notified by a pop-up message of these changes on Endeavor Health Patient Portals with an explanation of why new data is being collected.
Endeavor Health Patient Portals may interact with your PII or PHI to provide you with certain features, such as video visits or mobile appointment check-in. Please refer to Endeavor Health’s Notice of Privacy Practices to learn how Endeavor Health handles your PHI. The first time you try to use any of these features, you will be asked for your consent within the Patient Portal and you may only use a feature if you give your consent. You do not have to provide consent if you do not want to allow the Endeavor Health Patient Portals to interact with your data as requested.
The Endeavor Health Patient Portals were not created specifically for the COVID-19 pandemic. They existed before the COVID-19 pandemic to allow you to access your health information on file. We allow you to access COVID-19-related vaccination information, laboratory test results and documents with illness-related information using the Endeavor Health Patient Portals. You may choose if or how you want to access, display or use such information, just like you can make those decisions about health information relating to other conditions, services, tests or vaccinations.
Because Endeavor Health is committed to protecting the privacy of children, the Endeavor Health Services are not intended for use by or directed at children under the age of 13. We do not knowingly nor intentionally collect PII from anyone under 13 years of age via Endeavor Health Services. We encourage parents and guardians to take an active role in their children’s online and mobile activities and interests. If we are made aware that we have received such information, or any information in violation of our policy, we will use reasonable efforts to locate and remove that information from our records.
Cookies are small data files locally stored on the device used to access the Endeavor Health Services (e.g., computer, smartphone, tablet). Web beacons are electronic images that Endeavor Health or Endeavor Health’s third-party vendors may use in the Endeavor Health Services or in emails to deliver cookies, count visits, understand Endeavor Health Site usage, and/or evaluate the effectiveness of marketing campaigns.
Cookies have different durations and functions. Regarding the duration, there are two types: session cookies and persistent cookies. A session cookie only lasts for the specific duration of your visit to a website and is deleted when you close your browser. A persistent cookie remains in your device's data storage until it is deleted or it expires, which occurs thirteen months after being generated.
As for functionality, there are also two types of cookies: essential cookies and non-essential cookies. An essential cookie is a cookie that is either (i) used solely to carry out or facilitate a transmission to server hosting a website, or (ii) necessary to provide an online service you requested. A non-essential cookie, as the name suggests, is a cookie that may enhance the performance or functionality of a website, be required to access a portion of a website or be used for analytics or marketing (e.g., targeted advertising).
Endeavor Health and Endeavor Health’s third-party vendors may use one or more of the following types of cookies to facilitate access to various features of the Endeavor Health Services.
- Essential Cookies are required to enable the basic features of this site, such as providing secure log-in.
- Functional Cookies allows Endeavor Health to provide personalized features and/or enhance the performance of an experience, such saving a location, chat services and user preferences.
- Analytics Cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics such as the number of visitors, bounce rate, traffic source, etc.
- Performance Cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
- Marketing Cookies are used to provide visitors with customized advertisement based on previous actions, such as a website visit or viewing a marketing email, and used to analyze the effectiveness of an advertising campaign.
- Other Cookies are cookies that are being analyzed and may have not been classified into a category.
Endeavor Health may use third-party services, such as Google Analytics, that provide Endeavor Health with usage analytics. Such analytics may help Endeavor Health track usage of the Endeavor Health Services, identify popular features, provide advertising, share content specific to your use of the Endeavor Health Services, and better understand the online activity of Endeavor Health’s patients and visitors of the Endeavor Health Services.
You may still use the Endeavor Health Services if you reject, block and/or delete Endeavor Health’s own or third-party vendors’ cookies, but please note that you may not be able to access some areas or features of the Endeavor Health Services. For additional information on cookies and tracking technologies, including how to block cookies, please see “How to manage cookies” or refer to your web browser and/or device’s support documentation.
The following information below provides you with other privacy information related to the Endeavor Health Services and describes other ways how Endeavor Health, through its Endeavor Health Services, and third parties may store, use and disclose your PII.
Unless legally prohibited, Endeavor Health, through the Endeavor Health Services, may use, store, disclose and/or share PII as set forth in this Privacy Statement. Endeavor Health may also use the PII you provide to the Endeavor Health Services in the following way:
- to provide you with services you request through the Endeavor Health Services and maintain your account with us;
- to register you to use the Endeavor Health Services;
- to contact you about your use of the Endeavor Health Services or about Endeavor Health’s programs, services, products, activities, special events or other news that may be of interest to you;
- to provide, maintain or improve the Endeavor Health Services;
- to provide you with customer service;
- to process financial transactions, such bill payments, gift purchase or donations;
- to detect, investigate and prevent fraudulent credit card transactions;
- for general security monitoring;
- to publish in annual reports or other public documents that include donors’ names and information relating to the amount of their respective donations (e.g., by indicating a donation level or tier)
- to schedule appointments or place you in contact with one of Endeavor Health’s healthcare providers;
- to provide medical advice from your providers through telemedicine services or through Endeavor Health Services;
- to manage and host telemedicine services;
- for internal and external marketing, promotional, informational and fundraising purposes;
- to provide you with technical notices, updates, alerts and support or administrative messages;
- to process employment, fellowship or grant applications;
- to monitor and analyze usage of the Endeavor Health Services; and
- to maintain administrative records.
We may use Your email address to deliver newsletters, as well as for other promotional purposes (e.g., new service offerings, upcoming events or new location opening). We may send email messages that contains code that enables Endeavor Health’s database to track your usage of the emails; such usage includes, but is not limited to, whether the email was opened and what links (if any) were clicked.
If you do not want to receive informational communications from Endeavor Health, such as email communications informing you of programs, services or products, please see “Choices you have regarding the use of your PII” regarding your options to opt-out of receiving such communications.
Communication you send to Endeavor Health via email or form submission on Endeavor Health Services may be shared with the appropriate Endeavor Health staff member and/or third-party vendors. Email does not provide a completely secure and confidential means of communication. Please do not send any PHI via unsecured email. For more information about sharing PHI with Endeavor Health via email, please see the Notice of Privacy Practices.
Endeavor Health is committed to processing your PII in accordance with applicable data privacy laws and with transparency and fairness. We will only process your PII if:
- We have your consent to process and use your PII;
- We need to process your PII in order to complete a transaction with you or to fulfill a contractual obligation owed to you;
- We have a legitimate business purpose for processing your PII, such as to improve and develop the Endeavor Health Services or services offered on or through the Endeavor Health Services, to prevent fraud or provide general security monitoring, or to improve user experience; or
- We are required to process your PII in order to comply with an applicable law or regulation.
Endeavor Health will not sell, share, trade, or rent any PII to others in ways different from what is disclosed in the Endeavor Health Privacy Statement without first obtaining your authorization and consent.
In addition to other uses of PII as described in the Privacy Statement, Endeavor Health may allow third-party vendors and/or other third parties to collect, use and disclose your PII.
We may disclose your PII you provide Endeavor Health to third parties (e.g., independent contractors, volunteers, vendors, service providers or consultants) who are engaged by or working with Endeavor Health and who need access to such information to carry out their programs or services. Such services include but are not limited to billing, payment processing, providing medical advice for telemedicine services, management and hosting of telemedicine services, customer service, email deployment, business analytics, talent acquisition services, marketing (i.e., advertising, attribution, deep-linking, direct mail, mobile marketing, optimization, performance monitoring, hosting, and data processing) (collectively “Specialized Services”). These third-party vendors and service providers may not use your information for purposes other than those related to the Specialized Services they are providing to Endeavor Health.
We may also provide aggregate information (i.e., information collected from you that does not allow you to be personally identified or contacted) to third parties without your authorization, such as information about your access and use of the Endeavor Health Services.
We may also disclose Your Information your PII that Endeavor Health has collected if required to do so by law or if, in Endeavor Health’s good faith judgment, such action is reasonably necessary to comply with a legal process, to provide general security monitoring, to respond to any claims or to protect the rights of Endeavor Health and/or Endeavor Health’s patients, physicians, healthcare providers, partners, vendors and/or its constituents and the public.
Protecting your PII is of the utmost importance to Endeavor Health. Thus, We use security measures to protect your information and continuously monitor activity across Endeavor Health’s technology infrastructure. We implement technical and organization security measures, including physical, administrative, and technical safeguards to protect your PII from unauthorized access, use and disclosure.
We take steps, to the most reasonable extent, to ensure that your personal information is treated securely. No data transmission over the Internet can be guaranteed to be 100% secure. While Endeavor Health strives to protect your PII, Endeavor Health cannot ensure the security of any information you provide to Endeavor Health, and you do so at your own risk. Once Endeavor Health receives your information, a reasonable effort is made to ensure its security on Endeavor Health’s systems.
If you are a Endeavor Health patient, you may access, verify, modify, and/or update limited account information using a Endeavor Health Patient Portal. If you do not have Endeavor Health Patient Portal account, you can either create an account or you can contact Endeavor Health to verify, correct or modify any personal information.
For PII, you can contact Endeavor Health to have that information updated and/or modified.
To request the deactivation of a patient portal account or to update and/or modify other PII, please contact Endeavor Health. We will make every attempt to update and/or modify your PII as you request, provided that such PII is not necessary to complete any service or transaction and is not otherwise prohibited by law. If you wish to deactivate an account(s) you have with Endeavor Health, please note that Endeavor Health may retain some information from or about you in accordance with applicable law, including for various legal, operational, accounting and auditing purposes.
There are several ways to manage cookies. You can configure your browser to refuse all cookies or to indicate when a cookie is being sent. The “Help” feature on most browsers provides information on how to accept cookies, disable cookies or to notify you when receiving a new cookie. Please note, however, that many of the cookies Endeavor Health uses are "strictly necessary" cookies. By blocking or deleting them, you will not be able to access certain features of the Endeavor Health Services.
As described in the Endeavor Health Privacy Statement, third-party advertisers that may collect information from you or about you on the Endeavor Health Services to provide you with more relevant advertising on websites you visit. Such third-party advertisers may provide you with the option to opt out of their services.
Some third-party advertisers participate in the Digital Advertising Alliance Self-Regulatory Program for Online Behavioral Advertising. This program offers a centralized location where users can make choices about the use of their information for online behavioral advertising. To learn more and to make choices about the use of your information for online behavioral advertising on websites, please visit the Digital Advertising Alliance website. Please note that if you opt out of online behavioral advertising using this method, this opt-out will only apply to the specific browser or device from which you opt out.
In addition, some third-party advertisers, advertising technology companies, and service providers that perform advertising-related services for Endeavor Health’s business partners and Endeavor Health may be members of the Network Advertising Initiative (“NAI”), a cooperative of online marketing companies that offers a centralized tool for opting out of interest-based advertising delivered by each of its member companies. If you would like to obtain more information about interest-based advertising and the NAI and make choices about their members’ use of information from or about you on websites, please visit the Network Advertising Initiative website. Please note that if you opt out of interest-based advertising using this method, this opt-out will only apply to the specific browser or device from which you opt out.
We want to communicate with you on your terms. Endeavor Health Patient Portals can help connect you with your healthcare provider and/or other Endeavor Health staff members (e.g., nurses, pharmacists, HIM etc.…) by sending you messages or notifications to your email, phone and mail regarding appointments, test results and more. You can set communications preferences on how you would like to be contacted by Endeavor Health healthcare. Log in to a Endeavor Health Patient Portal to verify and adjust your patient portal communication preferences.
You may not be able to opt out of receiving all communications from Endeavor Health, such as administrative messages, service announcements, messages regarding the terms and conditions of an account or other messages that may contain important information regarding an account to the extent that such information is necessary to complete any services or transactions you have entered into.
Depending on the subscription, you may be able to opt out of receiving optional communications from Endeavor Health, by selecting the "unsubscribe" link from email communications. Depending on the SMS coding, You may be able to opt out of SMS text messages by following the SMS opt out instructions (e.g., replying with “STOP”); please note that this action will permanently opt you out of SMS texts and you will need to manually opt in to restore SMS messages.
If you would prefer that Endeavor Health does not share your PII with Endeavor Health’s business partners or vendors for direct marketing purposes, or to opt-out entirely of all non-required communications, you may send your request to marketing [at] northshore.org (marketing[at]northshore[dot]org).
There is currently no consensus among industry participants as to what “Do Not Track” means and how to respond to "Do Not Track" browser signals. As such, Endeavor Health do not respond to or honor such signals. Instead, to opt-out of website-based, third-party, interest-based or online behavioral advertising, please refer to the "How to manage cookies" section.
Endeavor Health is headquartered in the State of Illinois, and the Endeavor Health Services are intended for users in the United States. By viewing any content or otherwise accessing the Endeavor Health Services, you consent to the transfer of information to the United States to the extent applicable, and the collection, storage, and processing of information under the laws and regulations of the State of Illinois and the United States.
We may update or modify this Privacy Statement from time to time in response to changing legal, technical or business developments. We will obtain your consent to any material Notice changes if and where this is required by applicable data protection laws. The date of the most recent version of this Notice will appear at the top of the page.
When we update our Privacy Statement, we will take appropriate measures to inform you, consistent with the significance of the changes we make. for example, we will notify you of any changes to this Privacy Statement by posting a new Privacy Statement and updating the revision date at the top of this page or by sending the new Privacy Statement to you via email, where appropriate.
Any material changes to this Privacy Statement automatically becomes effective immediately after they are published, or, for users who register or otherwise provide opt-in consent at the time of registration or consent, as applicable. We encourage you to review the Endeavor Health Privacy Statement whenever you visit the Endeavor Health Services to make sure that you understand how we may use any PII you provide via the Endeavor Health Services.
Your privacy is important to Endeavor Health. If you have any questions about this Privacy Statement or your Personal Information, please healthdesk [at] eehealth.org (contact us by email).