 |
 |
This Privacy Statement discloses the privacy practices for MedTech Reimbursement Services, LLC (“MedTech”).
Statement on HIPAA
The protection of personal data is of utmost concern to MedTech. MedTech is required to maintain the highest security of a patient’s personally identifiable information. MedTech only uses patient information for reimbursement purposes and handles data in accordance with stringent requirements for the protection of patient privacy and the security of information as required by the Health Insurance Portability and Accountability Act (“HIPAA”) . For further information, please see: www.hhs.gov/ocr/privacy/hipaa/understanding/summary/privacysummary.pdf
Statement on GLBA
MedTech also adheres to all requirements of the Gramm-Leach-Bliley Act (GLBA). The Financial Privacy Rule in this act governs the collection and disclosure of customers’ personal financial information by financial institutions. It also applies to companies, whether or not they are financial institutions, who receive such information. For a summary overview of the Financial Privacy Rule, see In Brief: The Financial Privacy Requirements of the Gramm-Leach-Bliley Act.
HIPAA Compliance
In connection with the Services provided, MedTech may be a business associate of you. To the extent you are a covered entity under HIPAA and provide personal health information (“PHI”) to MedTech to perform the Services, the following terms are applicable:
All capitalized terms used in this section of these Terms of Use have the meanings ascribed to them in HIPAA. With regard to its use and/or disclosure of PHI, MedTech agrees to:
- not use or disclose PHI other than as permitted or required by these Terms of Use or as otherwise required or permitted by law;
- use appropriate safeguards to prevent use or disclosure of PHI other than as provided for by these Terms of Use;
- report in writing to you any use or disclosure of PHI not provided for by these Terms of Use of which MedTech’s management becomes aware within ten (10) business days of MedTech’s knowledge of an unauthorized use or disclosure;
- mitigate (after receiving your written approval) to the extent practicable, any harmful effect that is known to MedTech of a use or disclosure of PHI by MedTech in violation of the requirements of these Terms of Use;
- require all of its subcontractors and agents that receive or use, or have access to, PHI, to agree, in writing, to essentially the same restrictions and conditions on the use and/or disclosure of PHI that apply to MedTech pursuant to this section of the Terms of Use;
- make available PHI necessary for you to respond to individuals’ requests for access to PHI about them in the event that the PHI in MedTech’s possession constitutes a Designated Record Set. MedTech shall provide you with the PHI within a reasonable time from the date of the request;
- make available PHI for amendment within a reasonable time of receipt of a written request and incorporate any amendments to the PHI within ten (10) business days in accordance with the Privacy Rule of HIPAA in the event that the PHI in MedTech’s possession constitutes a Designated Record Set;
- provide you with an accounting of disclosures for individual in the form required by 45 C.F.R. § 164.528 within a reasonable time of your request;
- make its internal practices, books and records relating to the use and disclosure of PHI available to you and the Secretary of HHS or designee for purposes of determining your compliance with the Privacy Rule; and
- return to you or destroy, within ninety (90) days of the termination of these Terms of Use, the PHI in its possession as a result of these Terms of Use and retain no copies, if it is feasible to do so. If return or destruction is infeasible, MedTech agrees to extend all protections contained in this section of the Terms of Use to MedTech’s use and/or disclosure of any retained PHI, and to limit any further uses and/or disclosures to the purposes that make the return or destruction of the PHI infeasible.
With respect to Electronic PHI (“EPHI”) that you permit MedTech to create, receive, maintain, or transmit, MedTech agrees to:
- Implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of the EPHI that MedTech creates, receives, maintains, or transmits on your behalf;
- Ensure that any agent, including a subcontractor, to whom MedTech provides such EPHI, agrees to implement reasonable and appropriate safeguards to protect it;
- Report any security incident of which MedTech become aware; provided, that trivial attempts to penetrate MedTech’s systems that occur on a daily basis such as scans, “pings” or other unsuccessful attempts to penetrate computer networks or systems maintained by MedTech, will not be reported; and
- Authorize termination of these Terms of Use by you, if you determine that MedTech has violated a material term of this section of the Terms of Use and if MedTech has failed to cure the violation within thirty (30) days of written notice from you.
Except as otherwise specified in these Terms of Use, MedTech may make any and all uses and disclosures of PHI necessary to perform its obligations under these Terms of Use. Unless otherwise limited herein, MedTech may: (a) use the PHI in its possession for its proper management and administration and to carry out the legal responsibilities of MedTech; (b) disclose the PHI in its possession to a third party for the purpose of MedTech’s proper management and administration or to carry out the legal responsibilities of MedTech, provided that the disclosures are required by law or MedTech obtains reasonable assurances from the third party regarding the confidential handling of such PHI as required under the Privacy Rule; (c) provide Data Aggregation services relating to your health care operations; and (d) de-identify any and all PHI obtained by MedTech under these Terms of Use, and use such de-identified data, all in accordance with the de-identification requirements of the Privacy Rule.
You shall notify MedTech, in writing, of any arrangements between you and an individual that is the subject of PHI that may impact in any manner the use and/or disclosure of that PHI by MedTech under this Agreement. You may immediately terminate these Terms of Use if you determine that MedTech has breached a material term of these Terms of Use and if MedTech has failed to cure the violation within thirty (30) days of written notice from you. If MedTech commits a material breach of its obligations; MedTech did not take reasonable steps to cure the breach or end the violation or the steps were unsuccessful; and termination of this Agreement is not feasible, then you may report the breach to the Secretary of HHS.
Data and How We Use It
Your personally identifiable information, including your e-mail address, gathered on this site will not be sold, rented, licensed, or otherwise shared with third parties. Personal information you voluntarily provide and the non-personally identifiable information we collect will be confidential.
Collection, retention, and use of personal information may occur if users interact with MedTech’s Website, by either registering with the site or participating in one of MedTech’s services. Users may be required to provide their name, address, telephone number, e-mail address, and/or other identifying information, in order for MedTech to respond to inquiries and/or requests. Any personally identifiable information you give us on this Site will be used only to provide the service or information you have requested. It does not otherwise use personally identifiable information.
This Site also collects general non-identifiable data including pages visited, operating systems, Internet domain, time and date of visit, and web browser type (Windows, Safari, Mozilla, Opera, etc.) and version for statistical purposes. A unique number called an IP address identifies each computer on the Internet. Each time users connect to the Internet, their computer is assigned an IP address. When users connect to MedTech’s Website, the IP address is stored in anonymous form without reference to your person for statistical purposes. This information is collected automatically without user interaction. In doing so, MedTech may analyze on which days and at which time the MedTech website is particularly frequented. The non-personally identifiable information we gather may be used to improve our site.
When you visit our Site, we may place a cookie on your computer that will allow us to customize and enhance your experience on our Site, to make improvements, or to report Site activity. Our cookies will never be used to track your activity on any third party web sites or to send spam, nor will cookies provide us with any personally identifiable information about you. Upon the termination of your session the cookie will be automatically deleted.
Except with respect to PHI, any communication or material that you transmit to MedTech by electronic mail or otherwise, including any data, questions, comments, suggestions, or the like, is, and will be treated as, nonconfidential and nonproprietary information, and MedTech shall not have any obligation of any kind with respect to such information. MedTech may use such information for any purpose whatsoever, including, but not limited to, reproduction, disclosure, transmission, publication, broadcast, and further posting. Further, MedTech shall be free to use such information, including, but not limited to, any ideas, concepts, know-how, or techniques contained therein, for any purpose whatsoever, including, but not limited to, researching, developing, manufacturing, and marketing products incorporating such information.
Countries
Nothing contained on the Site should be construed as a solicitation or promotion for any product or for the use of any product or service in a way which is not authorized by the country in which the reader is physically located.
Links to Other Web Sites
This Web site may contain links to other Web sites. If you choose to use any of the links we provide to other third-party resources, you will be leaving our website and going to a new website. Protection of your privacy at those other sites will be governed by the privacy policies at those sites. MedTech is not responsible for and does not control the contents or performance of such Web sites, and accepts no responsibility for the consequences of your use thereof.
Indemnity
You agree to indemnify and hold MedTech, other third party service providers, and our respective affiliates, officers, directors, employees and agents harmless from and against any third party claim, action or demand and all liabilities and settlements related thereto, including without limitation, reasonable legal and accounting fees (including defense costs), resulting from, or alleged to result from, a breach of these Terms of Use or your use of the Site or its services.
Changes to these Terms and Conditions
MedTech reserves the right to amend these Terms and Conditions, in the event that this becomes necessary due to gaps in these Terms and Conditions identified after their release, or in the event that it becomes necessary with respect to additional or amended services provided by MedTech.
Version: 02 January 2009
|
 |