Cookie Policy
This Cookie Policy explains how Members Health Co (“we,” “us,” or “our”) uses cookies and similar technologies on the Patient Portal at portal.membershealthco.com (the “Portal”). It supplements our Privacy Policy and our Notice of Privacy Practices.
1. What is a cookie?
A cookie is a small text file that a website places on your device (computer, phone, or tablet) when you visit it. Cookies are used to keep you signed in, remember your preferences, and allow basic functionality of the site between page loads. Cookies set by the website you are visiting are called “first-party” cookies; cookies set by another domain that the site embeds are called “third-party” cookies.
2. Categories of cookies we use
The Portal uses only strictly necessary first-party cookies. These are required for the site to function. We do not use cookies for advertising, behavioral tracking, analytics, or cross-site profiling on the Portal.
3. Specific cookies the Portal sets
The cookies below are all first-party (set by portal.membershealthco.com), marked HttpOnly (not readable by JavaScript) where their function allows, marked Secure (only sent over HTTPS), and use SameSite=Lax to limit cross-site exposure.
| Cookie | Purpose | Lifetime | Required? |
|---|---|---|---|
mhc_session |
Keeps you signed in to the Patient Portal between page loads. Contains a cryptographically signed reference to your session, not your password. | 24 hours | Yes — without it you cannot stay signed in. |
mhc_staff_session |
The equivalent session cookie for Members Health Co clinic staff signing in through the staff app. Patients will never see this cookie set on their device. | 8 hours | Yes, for staff users only. |
mhc_impersonate |
Set on a clinic staff member’s device when they use the “View as patient” tool to verify how the Patient Portal renders for a particular patient (a quality-assurance feature used to investigate display issues a patient reports). It carries the staff member’s identity and the patient ID being previewed; nothing is sent to or readable by the patient’s device. The cookie is only honored while the staff member’s own session cookie is also valid, and every activation and exit is recorded in the staff audit log. | 1 hour (or until the staff member clicks “Exit”) | Yes, for staff users only — never set on a patient’s device. |
auth_pending_email |
Set during the email magic-link sign-in flow so that the verification page knows which email address is being verified. | 15 minutes (or until verified) | Yes — required to complete email sign-in. |
oauth_pkce_verifier, oauth_state |
Used during Members Health Co staff sign-in to prevent cross-site request forgery and to complete the OAuth handshake. Patients do not have these cookies set. | 5 minutes | Yes, for staff users only. |
mhc_cookie_consent |
Records that you have dismissed the cookie banner so we do not show it again on subsequent visits. Stored in your browser’s localStorage rather than as a server-side cookie. |
Until you clear browser storage | No, but dismissing the banner sets it. |
4. Server-side caches (not cookies, disclosed for transparency)
In addition to the browser cookies described above, our server keeps a small set of in-memory caches that exist only on the Portal’s back-end servers. These are not cookies, are not stored on your device, are not readable by JavaScript, and are not shared with third parties. We disclose them here so the description of how we process your information stays complete.
| Cache | What it holds | Lifetime | Why |
|---|---|---|---|
admin_settings cache |
Whichever portal-wide configuration toggles an administrator has set (e.g., maintenance mode on/off, which patient tabs are visible). | 5 seconds per setting | Collapses repeat database reads during a single page render so the Portal stays responsive as staff usage grows. |
| Staff role cache | For signed-in clinic staff only: a boolean for “is admin” and a string for clinical role (e.g., “provider”), keyed by the staff member’s email address. Never populated for patient sessions. | 15 seconds per staff email | Avoids a separate database lookup on every gated page the staff member loads. Role changes by an administrator invalidate the entry immediately for the same server process. |
| Pending-refill count cache | The total number of unresolved patient refill requests across the clinic — the number shown in the staff navigation badge. No patient identifiers. | 10 seconds | Avoids running a COUNT query on every staff page render. |
These caches live only in the running server process’s memory and are discarded automatically when the server restarts (a routine event in our Cloud Run hosting environment). They are not persisted to disk or to a separate cache service, and they do not change what is sent to or stored on your device.
5. Cookies we do not use
We want to be explicit about what we do not do on the Portal:
- We do not load the Meta (Facebook) Pixel, Google Analytics, Google Tag Manager, or any other third-party analytics or advertising pixel.
- We do not load session-replay tools (such as Hotjar or FullStory).
- We do not use cookies to build advertising profiles about you, share data with ad networks, or enable cross-context behavioral advertising.
- We do not sell information collected via cookies.
The one exception to third-party loading is Google reCAPTCHA Enterprise, which the sign-in page loads only when you request an SMS one-time code, and only to prevent automated abuse of the SMS-sending service. reCAPTCHA does not run on any page where your health information is visible. See Section 3.2 of our Privacy Policy for details.
6. Your choices
Because the Portal only uses strictly necessary cookies, blocking them will prevent the Portal from working — in particular, you will not be able to stay signed in. You can still:
- Configure your browser to alert you when cookies are being set, or to refuse them, through your browser’s settings. Help pages for the major browsers: Chrome, Firefox, Safari, Edge.
- Clear cookies from your device at any time through your browser settings; you will need to sign in again the next time you visit.
- Use private / incognito browsing, which discards cookies when the window is closed.
If you choose to block or clear the cookies above, you can continue to reach our clinic through normal channels (phone or in person).
7. Do Not Track and Global Privacy Control signals
Some browsers send a “Do Not Track” (DNT) header or a Global Privacy Control (GPC) signal. Because we do not run third-party advertising or behavioral tracking on the Portal in the first place, these signals do not change our behavior — there is nothing on the Portal for them to opt out of. We honor GPC where it applies under state privacy laws as described in our Privacy Policy.
8. Changes to this Cookie Policy
We may update this Cookie Policy from time to time. When we do, we will update the “Last updated” date above. Material changes will be announced within the Portal.
9. How to contact us
If you have questions about how we use cookies, contact us at:
Members Health Co
Attn: Privacy Officer
705 Merritt Ave, Nashville, TN 37203
(615) 601-3600
info@membershealthco.com