Aperture Health, Inc. HEALTHCARE INFORMATION PRIVACY POLICY

Effective Date: April 3, 2008

THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW THIS POLICY CAREFULLY.

Purpose of This Notice

This notice tells you about how we use your medical information. It tells you about your rights and our responsibilities to protect the privacy of your medical information. It also tells you how to complain to us or the government if you believe that we have violated any of your rights or any of our responsibilities.

We are required by law to maintain the privacy of your medical information, as described below. We must inform you of this notice and gain your acceptance in order for you to become a member of wellness360. We must and will follow the terms of this notice that are currently in effect.

We will tell you if we change this notice. A copy of the revised notice will be available upon request or posted at our location or on our web site. While we do not plan on modifying our privacy policy for business purposes, we may be compelled to do so in the future if legislation is enacted that requires modifications to our privacy policy.

Aperture Health’s Security Policy Guidelines

California’s Confidential Medical Information Act: Management has elected to establish a stringent security policy designed to protect the interest of our members. In general, Aperture Health is a medical information corporation as defined by California’s Confidentiality of Medical Information Act (“COMIA”; Cal. Civil Code 56 § et seq.) (“COMIA”). As a medical information corporation as defined by COMIA (Section 56.06(a)), Aperture Health shall maintain the same standards of confidentiality required of a provider of health care with respect to medical information disclosed to the corporation (COMIA Section 56.06(b)) and shall be subject to the same penalties for improper use and disclosure of medical information as prescribed in Section 56.06 (Section 56.06(b)).

Health Insurance Portability and Accountability Act: On August 21, 1996, the Health Insurance Portability and Accountability Act, known as HIPAA, was signed into law. HIPAA impacts all areas of the health care industry and is designed to provide insurance portability, to improve the efficiency of health care by standardizing the exchange of administrative and financial data, and to protect the privacy, confidentiality and security of health care data. The various provisions of HIPAA are enforced via rules promulgated by the U.S. Department of Health and Human Services ("HHS"). Currently, HHS has issued final rules with respect to transaction and code standards and health care data privacy procedures. HHS has also issued a proposed rule addressing technical and procedural security standards whose purpose is to protect patient health care information.

In general, the HIPAA regulations apply to health care providers, health insurance companies, and health care clearinghouses as well as certain business associates of such covered entities. While Aperture Health, Inc. (“Aperture Health”) is not a "covered entity" under HIPAA, however, we voluntarily comply with these national standards of medical information privacy. We will never share the identities of our members with anyone outside of Aperture Health. Aperture Health appreciates the challenges that HIPAA imposes and we want to give our customers assurance that Aperture Health will be vigilant in its protection of health care data and intends to fulfill its voluntary compliance under HIPAA.

Policy

Aperture Health's policy is to observe all existing state and federal laws and regulations relating to the transmission, storage, and access to records and other health care data, and to maintain the security and confidentiality of member-specific information. Therefore, Aperture Health is committed to ensure compliance with not only applicable Federal HIPAA legislation and the State of California Civil Code COMIA regarding any corporation organized for the primary purpose of maintaining medical information in order to make the information available to the patient at the request of the patient. Aperture Health will maintain the same standards of confidentiality required of a provider of health care as described in COMIA. We fully comply with COMIA by granting immediate access by the member to their personal health record if they gain access by using their password and login. This access is always at no charge to the member. Furthermore, Aperture Health will not disclose any member’s individual medical information to any entity. However, a member, at his or her sole discretion, may choose to do so.

Aperture Health's administrative, technical and physical safeguards are designed to maintain the integrity and confidentiality of our members' data. These safeguards, as well as all Aperture Health policies, are periodically reviewed, assessed and updated as part of Aperture Health's ongoing commitment to protect the privacy of our members' data and to comply with HIPAA, COMIA and all applicable laws.

How We Use Your Medical Information

At Aperture Health, the confidentiality of our members' data is a fundamental concern, and as such, we have established numerous technological and administrative procedures in order to protect such data. The Aperture Health information system has a number of security mechanisms designed to permit only the authorized parties to access to the data available via the web site. Your personal and medical information is only used in a “de-identified” manner which enables us to provide you with information that is customized to your specific needs and a profile that is created by your entry of information in your membership database, health risk assessment and diet and fitness journals. Furthermore, this proprietary profile allows us to customize the advertising environment that conforms to your unique profile of gender, age, lifestyle, prescriptions, disease(s) and health risks. No advertiser will ever have direct access to you, your personal health record, identity or e-mail address. We will also not share this information with your employer nor your insurance carrier.

Other Use and Disclosures of Your Medical Information

Newsletter Information - Your name and address may be added in the future to our mailing list of wellness360 members in order to include you in our list of subscribers to our planned wellness magazine in 2008. If you do not want to receive this magazine, please notify our Designee in writing.

Third-Party Research - We may use and disclose medical, diet and exercise information to any third party. The information, however, will be stripped of all information that could allow for the identity of the member, in compliance with HIPAA and COMIA and assuring that no one without your express permission will receive your private information.

Your Rights

The information contained in your health or medical record is the physical property of Aperture Health, Inc. The information in it belongs to you. You have the right to opt out of receiving information that we have deemed appropriate by the profile created from your information. You have the right to print copies of any and all pages of your Health Risk Assessment and Personal Health Record, including any and all pages that you uploaded into your Personal Health Record. You have the right to request that your personal information is completely deleted from Aperture Health’s system (by informing our designee in writing).

 

Stipulations and Terms

Aperture Health, Inc. ("Aperture Health") is sensitive to the privacy issues raised by use of the Internet and we are committed to protecting your privacy as a Member of wellness360.com ("wellness360" or "Site") in a manner that will allow you to use our resources with complete confidence and comfort. The wellness360 Healthcare Information Privacy Policy describes how we treat the information Members give us, and we believe that it is important that we share this policy with our users ("Members").

The following sections further describe the wellness360 Healthcare Information Privacy Policy, which addresses each of these issues. If a Member has questions about this policy or about how we address any of the foregoing, please send us an e-mail at CindyWells@Aperturehealth.com, and we'll get back to you as soon as possible.

INFORMATION COLLECTION AND USE: Aperture Health is the sole owner of the information collected on the Site. Information collected on the Site that identifies the Member, such as name, address, phone number, or social security number, is considered private ("Private Information"). AT NO TIME WILL APERTURE HEALTH DIVULGE PRIVATE INFORMATION TO ANY THIRD PARTY WITHOUT THE EXPRESS APPROVAL OF THE MEMBER. Aperture Health, reserves the right to sell, rent, loan, share or lease access to any information excluding Private Information ("Sanitized Data").

REGISTRATION: In order to use the Site, a Member must first complete the registration process. During registration a Member is required to give the Member's contact information (such as name, home address, city, state and zip code and e-mail address). This information is used to contact the Member about the services on the Site.

CASH REWARDS ELIGIBLITY: Member understands that in order to be eligible to receive cash rewards, Member agrees to provide Aperture Health additional information including but not limited to valid physical address (and valid tax identification number once their member rewards payment exceed $599.00 in a calendar year). Failure to do so shall result in Member becoming ineligible to receive cash rewards beyond $599.00 in that calendar year.

Checks paid to Members, Sponsors, and Agents must be deposited or cashed within the stated time period or they will be cancelled with no recourse. Checks will not be replaced if misplaced, damaged, or for any other reason. Aperture Health is not liable for transaction charges, bank fees of any kind, or any other financial damages that Members, Sponsors, or Agents may incur.  

 

Please be aware that your Health Risk Assessment must be completed before you are eligible to redeem points. The Redeem Points button is active only during the first fifteen (15) days AFTER the end of each calendar quarter--and only whenever your point value equals or exceeds $25 for that previous quarter. If you miss a redemption period, your points will continue to accumulate until the next available period. Your earned cash will be sent to you in the form of a personal check, and your check will include an additional 25% of the dollar value redeemed by your referred wellness360 “Friend” members.

Final check values will be determined based on a prior review of all points redeemed, and are subject to a carefully-designed and automated adjustment system intended to detect inappropriate/fraudulent usage of the wellness360 website and exploitation of our payment program. In addition, because wellness360 is an advertising revenue sharing program, values for points accrued are regularly adjusted based on the value of revenue generated by our advertisers. wellness360 is designed for those who's priority it is to become more aware of their overall health and well-being. Our point and reward program is just that --a "reward" or extra benefit for taking part in the wellness360 experience. Our business model is to replace expensive on-line subscription health services with a market-based solution to engage consumers in their own healthcare. It is not intended to be a significant source of income but an incentive to pursue a healthier lifestyle. Although we do send quarterly checks to our valued members, those who aren't enjoying the free features and services provided by the wellnesss360 websites and who are clearly accessing the site for the sole purpose of redeeming points for cash, are likely to be disappointed by their own unfounded expectations. Our advertisers want and deserve exposure to individuals that are sincere about improving their health status and enjoying the benefits we offer.

 

Disclosure

Disclosure for Legal Reasons: We may be legally compelled to release personal information to third parties: (1) to comply with valid legal requirements such as a law, regulation, search warrant, subpoena or court order; or (2) in special cases, such as a physical threat to you, others or to homeland security, in which we believe it is reasonably necessary to investigate or prevent harm, fraud, abuse, or illegal conduct. In the event that we are legally compelled to disclose your personal information to a third party, we will make reasonable efforts to notify you unless doing so would violate the law or court order.

Disclosure of Aggregate Information: We may share aggregated information collected on this Site with third parties. Aggregated information is information about users that is combined into groups so that no individual user can be identified. Depending on the circumstances, we may or may not charge third parties for this aggregated information. We also may not limit the third parties' use of the aggregated information.

Changes in Our Corporate Structure: If all or part of our company is sold, merged or otherwise transferred to another entity, the personal information you have provided at this Site may be transferred as part of that transaction. This Site will take steps to assure that, without your consent, any personal information that is transferred will not be used or shared in a manner inconsistent with the Web Site privacy policy under which it was collected.

Disclosure to Operations and Maintenance Contractors: We may contract with third parties to maintain or provide services to or on behalf of wellness360 or our business. These contractors include vendors and suppliers that provide us with technology, services, and/or content related to better operation and maintenance of our Web Site and others, such as our attorneys and auditors. Access to your personal information by these contractors is limited to the information reasonably necessary in order for the contractor to perform its limited function for or on behalf of this Site.

Disclosure to Linked Sites: For your convenience this Site may provide links to Web Sites operated by companies owned by or affiliated with Aperture Health, Inc., however, we do not disclose your personal information to affiliated Web Sites.

 

COLLECTED INFORMATION

CUSTOM FITNESS PLANS: In order to develop a custom fitness plan, a Member will have to enter certain additional information regarding their gender, measurements, general health status, lifestyle and eating and exercise habits, as well as their fitness goals.

CUSTOM DIET PLANS: In order to develop a custom diet plan, a Member will have to enter certain additional information regarding their gender, measurements, general health status, lifestyle and eating and exercise habits, as well as their diet goals.

PERSONAL HEALTH RECORDS: In order to have access to wellness360’s Personal Health Record, a Member will have to enter certain additional information regarding their medical conditions, medications. treatments, family history, etc.

CHILDREN: We are committed to protecting children and their privacy. Although wellness360 can be used to store children’s medical records, this activity is intended for their parents or guardians. The wellness360 Site is designed for an adult general audience and not intended to attract children under the age of 13. However, parents may build a Personal Health Record for each of their children.

COOKIES: A cookie is a piece of data stored on the Member's hard drive containing information about the Member. Usage of a cookie is in no way linked to any personally identifiable information while on our site. Once the Member closes their browser, the cookie simply terminates. For instance, by setting a cookie on our site, the Member would not have to log in a password more than once, thereby saving time while on our site. If a Member rejects the cookie, they may still use our site. The only drawback to this is that the Member will be limited in some areas of our site. For example, the Member will not be able to participate in any of our Sweepstakes, Contests or monthly Drawings that take place. Cookies can also enable us to track and target the interests of our Members to enhance the experience on our site.

Some of our advertisers and sponsors use cookies on their web sites and will only be employed if the Member clicks on a link that takes them away from wellness360. As such, we have no access to or control over these cookies.

CACHE: The Site is designed to cache information provided by you on your computer. If you do not want information to be cached, then you must edit your browser preferences to disable this function.

LOG FILES: We use IP addresses to analyze trends, administer the site, track Members’ movements, and gather broad demographic information for aggregate use. IP addresses are not linked to personally identifiable information.

SHARING: No Private Information is ever shared with our partners or advertisers. If information is distributed to a Aperture Health partner or advertiser it will be Sanitized Data eliminating any Member Private Information.

ADVERTISERS and SPONSORS: Advertisers and Sponsors provide Aperture Health the economic capability to subsidize the wellness360 Cash Rewards Program. At no time does Aperture Health divulge any identifiable member information to the Advertiser or Sponsor. Advertiser and Sponsor messages are routed to wellness360 Members based on data selection criteria provided by the Advertiser or Sponsor. Release of Member information is at the sole discretion of the Member.

LINKS: This web site contains links to other sites. Please be aware that Aperture Health is not responsible for the privacy practices of such other sites. We encourage our Members to be aware when they leave the Site to read the privacy statements of each and every web site that collects personally identifiable information. This privacy statement applies solely to information collected by this web site.

NEWSLETTER: Members who register with wellness360 by submitting their e-mail address -- along with other identifying personal information -- may receive periodic newsletters and other communications from the web site. Such newsletters and communications will be subject to Aperture Health's Choice/Opt-out Policy described below.

SURVEYS & CONTESTS: From time to time Aperture Health will request information from Members via surveys or contests. Participation in these surveys or contests is completely voluntary and the Member therefore has a choice whether or not to disclose this information. Information requested may include contact information (such as name and shipping address), and demographic information (such as zip code and age level). Contact information will be used to notify the winners and award prizes. Survey information will be used for purposes of monitoring or improving the use and satisfaction of this site.

SECURITY: This web site takes every precaution to protect our Members' information. When Members submit sensitive information via the web site, your information is protected both online and off-line.

When Members are requested to enter sensitive information (such as credit card number, social security number or medical information), that information is encrypted and protected with the best encryption software in the industry - SSL. While on a secure page, the lock icon on the bottom of web browsers such as Netscape Navigator and Microsoft Internet Explorer becomes locked, as opposed to unlocked, or open, when you are just 'surfing'.

While we use SSL encryption to protect sensitive information online, we also do everything in our power to protect Member-information off-line. All of our Members' information, not just the sensitive information mentioned above, is restricted in our offices. Only employees who need the information to perform a specific job (for example, our billing clerk or a Member services representative) are granted access to personally identifiable information. Our employees must use password-protected screen-savers when they leave their desk. When they return, they must re-enter their password to re-gain access to your information. Furthermore, ALL employees are kept up-to-date on our security and privacy practices. Every quarter, as well as any time new policies are added, our employees are notified and/or reminded about the importance we place on privacy, and what they can do to ensure our customers' information is protected. Finally, the servers on which we store personally identifiable information are kept in a secure environment, behind a locked cage.

If you have any questions about the security at our web site, you can send an e-mail to privacy@Aperturehealth.com.

SPECIAL OFFERS: We send all new members a welcoming e-mail to verify password and username. Established members will occasionally receive information on products, services, special deals, and a newsletter. Out of respect for the privacy of our Members we present the option to not receive these types of communications. Please see our Choice/Opt-out Policy below.

SITE AND SERVICE UPDATES: We also send the Member Site and service announcement updates. Members are not able to unsubscribe from service announcements, which contain important information about the service. We communicate with the Member to provide requested services and in regards to issues relating to his or her account via e-mail or phone.

CHOICE/OPT-OUT POLICY: Members are given the opportunity to “opt-out” of receiving e-mail notifications from Aperture Health. Members who no longer wish to receive our newsletter or promotional materials from our partners may opt-out of receiving these communications by unsubscribing from the newsletter.

Members of our site are always notified when their information is being collected by any outside parties. We do this so our Members can make an informed choice as to whether or not they should proceed with services that require an outside party.

NOTIFICATION OF CHANGES: If we decide to change our privacy policy, we will notify you of such changes so our Members are always aware of what information we collect, how we use it, and under what circumstances, if any, we disclose it. If at any point we decide to use personally identifiable information in a manner different from that stated at the time it was collected, we will notify Members by way of an e-mail. Members will have a choice as to whether or not we use their information in this different manner. We will use information in accordance with the privacy policy under which the information was collected.

If you feel that wellness360 is not abiding by its posted privacy policy, contact wellness360 by sending an e-mail to privacy@Aperturehealth.com.

Complaints

You have the right to complain to us and to the United States Secretary of Health and Human Services if you believe we have violated your privacy rights. There is no risk involved if you file a complaint.

To file a complaint with us, contact by phone or by mail:

Director, Client Services (Designee)

Aperture Health, Inc.
27201 Puerta Real, Suite 350
Mission Viejo, CA 92691
(949) 609-1966

To file a complaint with the United States Secretary of Health and Human Services, send your complaint to him or her in care of:

Office of Civil Rights
U.S. Department of Health and Human Services
200 Independence Ave, SW
Washington
, D.C. 20201

Questions and Information

If you have any questions or want more information about this Notice of Privacy Practices, please contact:

Director, Client Services (Designee)

Aperture Health, Inc.
27201 Puerta Real, Suite 350
Mission Viejo, CA 92691
(949) 609-1966

You may contact us by mail with written requests for information as defined under the Your Rights section of this notice. Complaints or questions should be made in writing.