Aperture Health, Inc. HEALTHCARE
INFORMATION PRIVACY POLICY
Effective
Date: April 3, 2008
THIS NOTICE DESCRIBES HOW
MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET
ACCESS TO THIS INFORMATION. PLEASE REVIEW THIS POLICY CAREFULLY.
Purpose of This Notice
This notice
tells you about how we use your medical information. It tells you about your
rights and our responsibilities to protect the privacy of your medical
information. It also tells you how to complain to us or the government if you
believe that we have violated any of your rights or any of our
responsibilities.
We are required by law to maintain the privacy of your medical
information, as described below. We must inform you of this notice and gain
your acceptance in order for you to become a member of wellness360. We must and
will follow the terms of this notice that are currently in effect.
We will tell you if we change this notice. A copy of the revised
notice will be available upon request or posted at our location or on our web
site. While we do not plan on modifying our privacy policy for business
purposes, we may be compelled to do so in the future if legislation is enacted
that requires modifications to our privacy policy.
Aperture Health’s Security Policy Guidelines
California’s
Confidential Medical Information Act: Management has elected to establish a stringent security policy
designed to protect the interest of our members. In general, Aperture Health is
a medical information corporation as defined by California’s Confidentiality of Medical
Information Act (“COMIA”; Cal. Civil Code 56 § et seq.) (“COMIA”). As a medical
information corporation as defined by COMIA (Section 56.06(a)), Aperture Health
shall maintain the same standards of confidentiality required of a provider of
health care with respect to medical information disclosed to the corporation (COMIA
Section 56.06(b)) and shall be subject to the same penalties for improper use
and disclosure of medical information as prescribed in Section 56.06 (Section
56.06(b)).
Health Insurance Portability
and Accountability Act: On
August 21, 1996, the Health Insurance Portability and Accountability Act, known
as HIPAA, was signed into law. HIPAA impacts all areas of the health care
industry and is designed to provide insurance portability, to improve the
efficiency of health care by standardizing the exchange of administrative and
financial data, and to protect the privacy, confidentiality and security of
health care data. The various provisions of HIPAA are enforced via rules
promulgated by the U.S. Department of Health and Human Services
("HHS"). Currently, HHS has issued final rules with respect to
transaction and code standards and health care data privacy procedures. HHS has
also issued a proposed rule addressing technical and procedural security
standards whose purpose is to protect patient health care information.
In general, the HIPAA regulations apply to health care providers,
health insurance companies, and health care clearinghouses as well as certain
business associates of such covered entities. While Aperture Health, Inc. (“Aperture
Health”) is not a "covered entity" under HIPAA, however, we
voluntarily comply with these national standards of medical information
privacy. We will never share the identities of our members with anyone outside
of Aperture Health. Aperture Health appreciates the challenges that HIPAA imposes
and we want to give our customers assurance that Aperture Health will be
vigilant in its protection of health care data and intends to fulfill its voluntary
compliance under HIPAA.
Policy
Aperture
Health's policy is to observe all existing state and federal laws and
regulations relating to the transmission, storage, and access to records and
other health care data, and to maintain the security and confidentiality of member-specific
information. Therefore, Aperture Health is committed to ensure compliance with
not only applicable Federal HIPAA legislation and the State of California Civil Code COMIA
regarding any corporation organized for the primary purpose of maintaining
medical information in order to make the information available to the patient
at the request of the patient. Aperture Health will maintain the same standards
of confidentiality required of a provider of health care as described in COMIA.
We fully comply with COMIA by granting immediate access by the member to their
personal health record if they gain access by using their password and login.
This access is always at no charge to the member. Furthermore, Aperture Health will
not disclose any member’s individual medical information to any entity. However,
a member, at his or her sole discretion, may choose to do so.
Aperture Health's administrative, technical and physical
safeguards are designed to maintain the integrity and confidentiality of our
members' data. These safeguards, as well as all Aperture Health policies, are
periodically reviewed, assessed and updated as part of Aperture Health's
ongoing commitment to protect the privacy of our members' data and to comply
with HIPAA, COMIA and all applicable laws.
How We Use Your Medical Information
At Aperture
Health, the confidentiality of our members' data is a fundamental concern, and
as such, we have established numerous technological and administrative
procedures in order to protect such data. The Aperture Health information
system has a number of security mechanisms designed to permit only the
authorized parties to access to the data available via the web site. Your
personal and medical information is only used in a “de-identified” manner which
enables us to provide you with information that is customized to your specific
needs and a profile that is created by your entry of information in your
membership database, health risk assessment and diet and fitness journals. Furthermore,
this proprietary profile allows us to customize the advertising environment
that conforms to your unique profile of gender, age, lifestyle, prescriptions,
disease(s) and health risks. No advertiser will ever have direct access to
you, your personal health record, identity or e-mail address. We will also not
share this information with your employer nor your insurance carrier.
Other Use and Disclosures of Your Medical Information
Newsletter Information - Your name and address may be added in
the future to our mailing list of wellness360 members in order to include you
in our list of subscribers to our planned wellness magazine in 2008. If you do
not want to receive this magazine, please notify our Designee in writing.
Third-Party Research - We may use and disclose medical, diet
and exercise information to any third party. The information, however, will be
stripped of all information that could allow for the identity of the member, in
compliance with HIPAA and COMIA and assuring that no one without your express
permission will receive your private information.
Your Rights
The
information contained in your health or medical record is the physical property
of Aperture Health, Inc. The information in it belongs to you. You have the
right to opt out of receiving information that we have deemed appropriate by
the profile created from your information. You have the right to print copies
of any and all pages of your Health Risk Assessment and Personal Health Record,
including any and all pages that you uploaded into your Personal Health Record.
You have the right to request that your personal information is completely
deleted from Aperture Health’s system (by informing our designee in writing).
Stipulations and Terms
Aperture Health, Inc. ("Aperture Health")
is sensitive to the privacy issues raised by use of the Internet and we are
committed to protecting your privacy as a Member of wellness360.com ("wellness360"
or "Site") in a manner that will allow you to use our resources with
complete confidence and comfort. The wellness360 Healthcare Information Privacy
Policy describes how we treat the information Members give us, and we believe
that it is important that we share this policy with our users
("Members").
The following sections further describe the wellness360 Healthcare
Information Privacy Policy, which addresses each of these issues. If a Member
has questions about this policy or about how we address any of the foregoing,
please send us an e-mail at CindyWells@Aperturehealth.com, and we'll get back
to you as soon as possible.
INFORMATION COLLECTION AND USE: Aperture Health is the
sole owner of the information collected on the Site. Information collected on
the Site that identifies the Member, such as name, address, phone number, or
social security number, is considered private ("Private Information").
AT NO TIME WILL APERTURE HEALTH DIVULGE PRIVATE INFORMATION TO ANY THIRD PARTY
WITHOUT THE EXPRESS APPROVAL OF THE MEMBER. Aperture Health, reserves the
right to sell, rent, loan, share or lease access to any information excluding
Private Information ("Sanitized Data").
REGISTRATION: In order to use the Site, a Member must
first complete the registration process. During registration a Member is
required to give the Member's contact information (such as name, home address,
city, state and zip code and e-mail address). This information is used to
contact the Member about the services on the Site.
CASH REWARDS ELIGIBLITY: Member understands that
in order to be eligible to receive cash rewards, Member agrees to provide Aperture
Health additional information including but not limited to valid physical
address (and valid tax identification number once their member rewards payment
exceed $599.00 in a calendar year). Failure to do so shall result in Member
becoming ineligible to receive cash rewards beyond $599.00 in that calendar
year.
Checks paid to Members, Sponsors, and Agents
must be deposited or cashed within the stated time period or they will be
cancelled with no recourse. Checks will not be replaced if misplaced, damaged,
or for any other reason. Aperture Health is not liable for transaction charges,
bank fees of any kind, or any other financial damages that Members, Sponsors,
or Agents may incur.
Please be
aware that your Health Risk Assessment must be completed before you are
eligible to redeem points. The Redeem Points button is active only during
the first fifteen (15) days AFTER the end of each calendar quarter--and only
whenever your point value equals or exceeds $25 for that previous quarter.
If you miss a redemption period, your points will continue to accumulate until
the next available period. Your earned cash will be sent to you in the form of
a personal check, and your check will include an additional 25% of the dollar
value redeemed by your referred wellness360 “Friend” members.
Final check
values will be determined based on a prior review of all points redeemed, and
are subject to a carefully-designed and automated adjustment system intended to
detect inappropriate/fraudulent usage of the wellness360 website and exploitation
of our payment program. In addition, because
wellness360 is an advertising revenue sharing program, values for points
accrued are regularly adjusted based on the value of revenue generated
by our advertisers. wellness360 is designed
for those who's priority it is to become more aware of their overall health and
well-being. Our point and reward program is just that --a "reward" or
extra benefit for taking part in the wellness360 experience. Our business model
is to replace expensive on-line subscription health services with a
market-based solution to engage consumers in their own healthcare. It is not
intended to be a significant source of income but an incentive to pursue a
healthier lifestyle. Although we do
send quarterly checks to our valued members, those who aren't enjoying the
free features and services provided by the wellnesss360 websites and who are
clearly accessing the site for the sole purpose of redeeming points for cash,
are likely to be disappointed by their own unfounded expectations. Our
advertisers want and deserve exposure to individuals that are sincere about
improving their health status and enjoying the benefits we offer.
Disclosure
Disclosure for Legal Reasons: We may be legally compelled to release personal
information to third parties: (1) to comply with valid legal requirements such
as a law, regulation, search warrant, subpoena or court order; or (2) in
special cases, such as a physical threat to you, others or to homeland
security, in which we believe it is reasonably necessary to investigate or
prevent harm, fraud, abuse, or illegal conduct. In the event that we are
legally compelled to disclose your personal information to a third party, we
will make reasonable efforts to notify you unless doing so would violate the law
or court order.
Disclosure of Aggregate Information: We may share aggregated
information collected on this Site with third parties. Aggregated information
is information about users that is combined into groups so that no individual
user can be identified. Depending on the circumstances, we may or may not
charge third parties for this aggregated information. We also may not limit the
third parties' use of the aggregated information.
Changes in Our Corporate Structure: If all or part of our
company is sold, merged or otherwise transferred to another entity, the
personal information you have provided at this Site may be transferred as part
of that transaction. This Site will take steps to assure that, without your
consent, any personal information that is transferred will not be used or
shared in a manner inconsistent with the Web Site privacy policy under which it
was collected.
Disclosure to Operations and Maintenance Contractors: We may contract with
third parties to maintain or provide services to or on behalf of wellness360 or
our business. These contractors include vendors and suppliers that provide us
with technology, services, and/or content related to better operation and
maintenance of our Web Site and others, such as our attorneys and auditors.
Access to your personal information by these contractors is limited to the
information reasonably necessary in order for the contractor to perform its
limited function for or on behalf of this Site.
Disclosure to Linked Sites: For your convenience this Site may provide
links to Web Sites operated by companies owned by or affiliated with Aperture
Health, Inc., however, we do not disclose your personal information to
affiliated Web Sites.
COLLECTED INFORMATION
CUSTOM FITNESS PLANS: In order to develop a
custom fitness plan, a Member will have to enter certain additional information
regarding their gender, measurements, general health status, lifestyle and
eating and exercise habits, as well as their fitness goals.
CUSTOM DIET PLANS: In order to develop a
custom diet plan, a Member will have to enter certain additional information
regarding their gender, measurements, general health status, lifestyle and
eating and exercise habits, as well as their diet goals.
PERSONAL HEALTH RECORDS:
In
order to have access to wellness360’s Personal Health Record, a Member will
have to enter certain additional information regarding their medical
conditions, medications. treatments, family history, etc.
CHILDREN: We are committed to protecting children and
their privacy. Although wellness360 can be used to store children’s medical
records, this activity is intended for their parents or guardians. The
wellness360 Site is designed for an adult general audience and not intended to
attract children under the age of 13. However, parents may build a Personal
Health Record for each of their children.
COOKIES: A cookie is a piece of data stored on the
Member's hard drive containing information about the Member. Usage of a cookie
is in no way linked to any personally identifiable information while on our
site. Once the Member closes their browser, the cookie simply terminates. For
instance, by setting a cookie on our site, the Member would not have to log in
a password more than once, thereby saving time while on our site. If a Member
rejects the cookie, they may still use our site. The only drawback to this is
that the Member will be limited in some areas of our site. For example, the
Member will not be able to participate in any of our Sweepstakes, Contests or
monthly Drawings that take place. Cookies can also enable us to track and
target the interests of our Members to enhance the experience on our site.
Some of our advertisers and sponsors use cookies
on their web sites and will only be employed if the Member clicks on a link
that takes them away from wellness360. As such, we have no access to or control
over these cookies.
CACHE: The Site is designed to cache information
provided by you on your computer. If you do not want information to be cached,
then you must edit your browser preferences to disable this function.
LOG FILES: We use IP addresses to analyze trends, administer
the site, track Members’ movements, and gather broad demographic information
for aggregate use. IP addresses are not linked to personally identifiable
information.
SHARING: No Private Information is ever shared with our
partners or advertisers. If information is distributed to a Aperture Health
partner or advertiser it will be Sanitized Data eliminating any Member Private
Information.
ADVERTISERS and SPONSORS: Advertisers and Sponsors provide Aperture Health the economic capability
to subsidize the wellness360 Cash Rewards Program. At no time does Aperture
Health divulge any identifiable member information to the Advertiser or
Sponsor. Advertiser and Sponsor messages are routed to wellness360 Members
based on data selection criteria provided by the Advertiser or Sponsor. Release
of Member information is at the sole discretion of the Member.
LINKS: This web site contains links to other sites.
Please be aware that Aperture Health is not responsible for the privacy
practices of such other sites. We encourage our Members to be aware when they
leave the Site to read the privacy statements of each and every web site that
collects personally identifiable information. This privacy statement applies
solely to information collected by this web site.
NEWSLETTER: Members who register with wellness360
by submitting their e-mail address -- along with other identifying personal
information -- may receive periodic newsletters and other communications from
the web site. Such newsletters and communications will be subject to Aperture
Health's Choice/Opt-out Policy described below.
SURVEYS & CONTESTS: From time to time Aperture
Health will request information from Members via surveys or contests.
Participation in these surveys or contests is completely voluntary and the
Member therefore has a choice whether or not to disclose this information.
Information requested may include contact information (such as name and
shipping address), and demographic information (such as zip code and age
level). Contact information will be used to notify the winners and award
prizes. Survey information will be used for purposes of monitoring or improving
the use and satisfaction of this site.
SECURITY: This web site takes every precaution to
protect our Members' information. When Members submit sensitive information via
the web site, your information is protected both online and off-line.
When Members are requested to enter sensitive
information (such as credit card number, social security number or medical
information), that information is encrypted and protected with the best
encryption software in the industry - SSL. While on a secure page, the lock
icon on the bottom of web browsers such as Netscape Navigator and Microsoft
Internet Explorer becomes locked, as opposed to unlocked, or open, when you are
just 'surfing'.
While we use SSL encryption to protect sensitive
information online, we also do everything in our power to protect
Member-information off-line. All of our Members' information, not just the
sensitive information mentioned above, is restricted in our offices. Only
employees who need the information to perform a specific job (for example, our
billing clerk or a Member services representative) are granted access to
personally identifiable information. Our employees must use password-protected
screen-savers when they leave their desk. When they return, they must re-enter
their password to re-gain access to your information. Furthermore, ALL employees
are kept up-to-date on our security and privacy practices. Every quarter, as
well as any time new policies are added, our employees are notified and/or
reminded about the importance we place on privacy, and what they can do to
ensure our customers' information is protected. Finally, the servers on which we
store personally identifiable information are kept in a secure environment,
behind a locked cage.
If you have any questions about the security at
our web site, you can send an e-mail to privacy@Aperturehealth.com.
SPECIAL OFFERS: We send all new members a welcoming e-mail
to verify password and username. Established members will occasionally receive
information on products, services, special deals, and a newsletter. Out of
respect for the privacy of our Members we present the option to not receive
these types of communications. Please see our Choice/Opt-out Policy below.
SITE AND SERVICE UPDATES: We also send the
Member Site and service announcement updates. Members are not able to
unsubscribe from service announcements, which contain important information
about the service. We communicate with the Member to provide requested services
and in regards to issues relating to his or her account via e-mail or phone.
CHOICE/OPT-OUT POLICY: Members are given the
opportunity to “opt-out” of receiving e-mail notifications from Aperture Health.
Members who no longer wish to receive our newsletter or promotional materials
from our partners may opt-out of receiving these communications by
unsubscribing from the newsletter.
Members of our site are always notified when
their information is being collected by any outside parties. We do this so our
Members can make an informed choice as to whether or not they should proceed
with services that require an outside party.
NOTIFICATION OF CHANGES: If we decide to change
our privacy policy, we will notify you of such changes so our Members are
always aware of what information we collect, how we use it, and under what
circumstances, if any, we disclose it. If at any point we decide to use
personally identifiable information in a manner different from that stated at
the time it was collected, we will notify Members by way of an e-mail. Members
will have a choice as to whether or not we use their information in this
different manner. We will use information in accordance with the privacy policy
under which the information was collected.
If you feel that wellness360 is not abiding by
its posted privacy policy, contact wellness360 by sending an e-mail to privacy@Aperturehealth.com.
Complaints
You have the
right to complain to us and to the United States Secretary of Health and Human
Services if you believe we have violated your privacy rights. There is no risk
involved if you file a complaint.
To
file a complaint with us, contact by phone or by mail:
Director,
Client Services (Designee)
Aperture
Health, Inc.
27201 Puerta Real, Suite 350
Mission Viejo, CA 92691
(949) 609-1966
To file a complaint with the United States Secretary of Health and
Human Services, send your complaint to him or her in care of:
Office
of Civil Rights
U.S.
Department of Health and Human Services
200 Independence Ave,
SW
Washington, D.C. 20201
Questions and Information
If you have
any questions or want more information about this Notice of Privacy Practices,
please contact:
Director,
Client Services (Designee)
Aperture
Health, Inc.
27201 Puerta Real, Suite 350
Mission Viejo, CA 92691
(949) 609-1966
You may contact us by mail with written requests for information
as defined under the Your Rights section of this notice. Complaints or
questions should be made in writing.