WHAT TYPE OF INFORMATION DOES BENEFITS SCIENCE COLLECT?
We may collect three types of information from time to time about users: (1) “Personal Information” (such as name, company/employer, phone number, physical address, email address, IP address, session data for your log-in session, protected health information, and other account-related information); (2) “De-Identified Information” (such as non-identifiable statistical information on the Sites usage); and (3) “Aggregate Information” (such as information about how many users log on to the Sites on a daily basis):
Personal Information is collected online when users voluntarily submit non-public personal information by establishing an account, requesting information, sending or receiving electronic notices or other similar communications on the Sites. Only your IP address and/or user name would be collected automatically when you access the Sites or the Services for purposes of processing your login to your account in the Benefits Science Portal or enhancing your web site browsing via cookies or standard settings. Your Personal Information will be retained for fulfillment of the intended purposes for which such Personal Information is collected. We may obtain your protected health information, as a subset of Personal Information, from third parties in connection with the services We provide to our clients.
De-Identified Information is collected online information in which all personal and individually identifiable health information has been removed by Benefits Science. De-Identified Information is used in a collective manner for analyses and statistics in order to improve the Services. De-Identified Information does not personally identify a specific user.
Aggregate Information is non-identifiable (or anonymous) information about you, such as pages most frequently accessed by you. Aggregate Information is used in a collective manner, and no single person can be identified by that compiled information (for example, the number of people who logged into the Sites in a particular day). Aggregate Information does not personally identify a specific user.
We will establish minimum and maximum retention periods based upon the type of information collected (i.e., sensitivity), the intended purposes and as otherwise may be legally required.
HOW DOES BENEFITS SCIENCE SECURE MY PERSONAL INFORMATION?
• We employ internal access controls to ensure that the only people who see your information are those with a need to do so to perform their official duties.
• We train relevant personnel on our privacy and security measures and applicable legal requirements.
• We physically secure the areas where we hold hard copies (if any) of the information that we collect online.
• We regularly back up the information that we collect online to insure against loss.
• We use technical controls to secure the information that we collect online as appropriate, including but not limited to: encryption, firewalls, and password protections.
• We periodically test our security procedures to ensure personnel and technical compliance.
• We disclose your Personal Information only to your employer and others to whom you have given consent, or as otherwise required or permitted by law.
• We disclose the minimum amount of Personal Information as necessary for the particular purpose in compliance with applicable law.
The Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), and certain privacy and security regulations promulgated by the U.S. Department of Health and Human Services to implement certain provisions of HIPAA and the Health Information Technology for Economic and Clinical Health Act, as modified by the Omnibus Final Rule (collectively the “HIPAA Requirements”), as well as other applicable federal and state privacy and security laws and regulations, regulate and limit the use and disclosure of protected health information (“PHI”). Benefits Science has established privacy practices with respect to any Personal Information, which contains protected health information in order to be compliant with applicable HIPAA Requirements, and, where legally required, enters into BAA agreements with health care organizations for which Benefits Science may store or process protected PHI.
Please note that Personal Information stored on the Sites will be collected, stored and processed in the United States of America.
The Sites may utilize a standard technology called a “cookie” to collect information about how the Sites are used. A “cookie” is a small text file placed on your hard drive by our web page server. These cookies do not collect Personal Information, only Aggregate Information.
We do not combine Aggregate Information collected through cookies with other Personal Information to determine who you are or your e-mail or IP address. The Sites can access the Aggregate Information only from a cookie sent by the Sites. We cannot access other cookies sent by other websites or the information contained in those other websites. Additionally, we cannot learn your email or IP address through the use of a cookie.
In particular, Benefits Science may collect an IP Address from all visitors to the Sites. An IP Address is a number that is automatically assigned to your computer when you use the Internet. We use IP addresses to help diagnose problems with our server, administer our Sites, analyze trends, track users’ movement on the Sites, gather broad demographic information for aggregate use in order for us to improve the Sites, and deliver customized, personalized content. IP addresses, however, are not linked to Personal Information.
Benefits Science also may use a unique assigned number located with the Sites’ URL to determine each web site from which you navigated to get to the Sites. While this number may not be apparent to you, it does not contain your Personal Information.
HOW DOES BENEFITS SCIENCE USE PERSONAL INFORMATION?
Your privacy is important to us. We will use the Personal Information provided by you in accordance with good commercial practice and applicable law. If you provide us with your e-mail address (or have done so in the past), we will send notifications to you. When you set up your user account (and at any time thereafter), you view how Personal Information is shared from your account settings. Your email will be used for notifications only. Benefits Science does not share your public email address with others in its public forums.
We also may use information provided by you, for example, to provide notifications about certain features of our Sites or the Services to measure consumer interest in our various services, and to inform you about various products and services offered on the Sites. These offers may be based on information provided by you as well as information available from external sources. These e-mail offers will come exclusively from Benefits Science.
By providing information using the Sites or the Services, you warrant to Benefits Science that your Personal Information is reliable for its intended uses, accurate, complete and correct, and that you will promptly notify use if such Personal Information is no longer current or correct.
We also may use your Personal Information collected via the Sites in the performance of all Services in order to provide, maintain and improve our Services as well as to develop new products and services to be offered as part of the Services. For example, we may use Personal Information to analyze data, to improve our Services and to tune our outputs and reports based on a particular individual’s patterns of usage of our Services.
DOES BENEFITS SCIENCE SHARE YOUR PERSONAL INFORMATION WITH OTHERS?
We reserve the right to assign or transfer your Personal Information to any successor in interest to our business associated with the Sites or the Services by merger, reorganization, sale of all or substantially all of our assets or equity interests or operation of law. We also may divulge Personal Information if such information is required for us to comply with any valid legal process, such as a subpoena, search warrant, statute or court order, or if we reasonably believe that you have commit unlawful acts or acts that may endanger the health or safety of another user or of the general public.
CAN I MAKE CORRECTIONS TO PERSONAL INFORMATION COLLECTED ONLINE?
Additionally, you may request to view the Personal Information collected about you through your use of the Sites operated by Benefits Science by accessing your user account on the Sites. If you prefer, you can send an e-mail to our Security Officer at the Contact Address below. If you send your request by email, we will likely send such Personal Information (or a summary thereof) to your email address on file for the account name in our database, or we will send the Personal Information to you in another secure manner. If at any time you wish to change, correct or update your Personal Information, or have it removed from our database, you may do so by accessing your user account on the Sites. You also may submit a change request to our Security Officer by sending an email to the Contact Address below.
We have designated our Security Officer, who can be contacted at the following address (“Contact Address”):
By Mail: Benefits Science LLC
129 South Street, 4th Floor
Boston, MA 02111
By Telephone: (888) 767-2744
By Email: firstname.lastname@example.org
DOES BENEFITS SCIENCE COLLECT PERSONAL INFORMATION FROM CHILDREN?
Benefits Science does not knowingly solicit data from children or knowingly market to children. Benefits Science is concerned about the safety of children and their use of the Internet. Therefore, in accordance with the U.S. Children’s Online Privacy Protection Act of 1998, we do not knowingly request or solicit personally identifiable information from anyone under the age of 13 without prior verifiable parental consent. In the event that we receive actual knowledge that we have collected such Personal Information without the required and verifiable parental consent, we will delete that information from our database as quickly as is reasonably practical.
WHAT ABOUT PRIVACY ON INTERNET WEBSITES LINKED TO THE SITES?