Privacy Statement

Updated August 4, 2014

MedImpact Healthcare Systems, Inc. ("MedImpact" or "We") respects the privacy of your information. We provide this explanation about our online information practices as a show of our commitment to protect your privacy. This Privacy Policy is hereby incorporated by reference into the User Agreement.

We have strived to design and manage our site to meet current industry standards of privacy and security, including the Health Insurance Portability and Accountability Act of 1996 (HIPAA) as amended by the Health Information Technology for Economic and Clinical Health Act Section 13402 ("HITECH Act") and implementing regulations (collectively referred to as "HIPAA Regulations"). While no website can be 100% secure, MedImpact has security measures in place to protect against the loss, misuse and alteration of the information under our control. MedImpact's Web Server uses encryption technology to ensure private and authenticated communication by encrypting (via 128-bit SSL encryption standard) all user-identifying data between two parties (customer and Website). In addition, MedImpact's Websites have the added benefit of "secure site verification" for Internet customers issued by Equifax™ (The Certificate Issuing Authority) that MedImpact is indeed a real company.

Access to MedImpact's database is protected by physical security, with access limited to few personnel.  MedImpact's database IP is only accessible through our application and not visible over the Internet. MedImpact's servers are continuously monitored for network intrusion.

The Information We Collect

MedImpact collects and stores your Profile in order for you to manage your health. You may be required to pre-enroll though a provider or health plan, which will then start the enrollment process with us. You can logon to your health plan's website to obtain a user id and password before you access your protected healthcare information.

This Website's registration form may require that you give MedImpact your personal and controlled e-mail address (we strongly recommend that this not be your work-related address) and certain personal information (currently your first and last name, member ID number, and birth date). Using your registration information, MedImpact develops a Profile for you in order for you to receive optimal benefits when you are using our Website.

In addition, MedImpact automatically gathers general statistical information about our Website and visitors, such as IP addresses, browsers, pages viewed, number of visitors, etc., but in doing so we do not reference you by individual name, e-mail address, home address, or telephone number. MedImpact uses this data in the aggregate to determine how much our customers use parts of our Website so we can improve our Website. MedImpact also provides this statistical information to third parties.

The Way We Use information

MedImpact is not engaged in rendering medical advice. There are instances in which MedImpact might use the personal information you voluntarily submit internally. In addition, MedImpact may disclose your personal information – as described herein – to our agents, third-party partners, and affiliates to enable them to perform certain functions for us.

MedImpact uses your personally identifying information to statistically analyze Website usage, to improve our content and product offerings and to customize our Website's content, layout, and services.

MedImpact may ask you to provide us voluntarily with additional information regarding your personal or business interests, experience or requests, which we may use to customize our service for you.

MedImpact may use your e-mail address, your mailing address, and phone number to contact you regarding administrative notices, new product offerings and communications relevant to your use of the Website.

MedImpact may also use or disclose information to resolve disputes, investigate problems, or enforce our User Agreement. At times, MedImpact may review status or activity of multiple users to do so. MedImpact may disclose or access information whenever we believe in good faith that the law so requires or if we otherwise consider it necessary to do so to maintain service and improve our products and services.

MedImpact uses your IP address to help diagnose problems with our server, to manage our Website and to enhance our Website based on the usage pattern data we receive.

Third Party Practices

This Website contains links to other sites. MedImpact is not responsible for the privacy practices of such sites. MedImpact recommends that you review the privacy and security policies of such sites should you so desire.

Member Communications and Forums

This Website may make (as available) chat rooms, forums, message boards, and/or news groups available to you. Please remember that any information (including personal and medical information) that you reveal in MedImpact's public forums (such as a bulletin board, posting, chat room/event) are not protected by this Privacy Policy. Third parties not related to MedImpact will see such postings. What you've written could be used by others in ways MedImpact is unable to control or predict, including to contact you for unauthorized purposes. Also, if you access a third party site from a link on your health plan's website, any information you reveal on that site is not subject to this Privacy Policy. You should consult the privacy policies of each site you visit.

You are responsible for the content and information contained in any communications you may send to this Website, including its truthfulness and accuracy. You agree that you will not upload or transmit any communications that infringe any patent, trademark, trade secret, service mark, copyright or other proprietary rights of any party. You warrant that your communications comply with federal, local and international laws respecting trademark, trade secret, service mark, copyright or other proprietary rights of any party.

Children Under 14

MedImpact has no way of distinguishing the age of individuals who access our Website, and so we carry out the same Privacy Policy for individuals of all ages. If a child has provided MedImpact with personally-identifying information without parental or guardian consent, the parent or guardian should contact us to remove the information and opt out of promotional opportunities.

If you have any questions about this Privacy Policy, the practices of this Website, or your dealings with this Website, you can contact Our Privacy Officer at: PrivacyS@medimpact.com.

Changes to Our Privacy Policy

Any changes to MedImpact's Privacy Policy will be communicated through this Website at least in advance of its effective date. Information collected before changes are made will be secured according to the previous Privacy Policy.

YOUR CONSENT

By using MedImpact's Website, you consent to the collection and use of this information in the manner we describe.