Health Decisions Privacy Policy
At Health Decisions, the foundation of our business is information. Given the nature of our work, the protection of personal data is critical for our company and our customers. For these reasons, Health Decisions has developed a comprehensive, global privacy program designed to respect and protect data privacy rights.
Accordingly, Health Decisions first issued (January 1, 2011) a global corporate policy for the protection of the confidentiality of individually identifiable information in accordance with applicable laws and regulations, regardless of the nature, source or form of the information.
Health Decisions intends that its corporate privacy policy and standard practices and procedures will ensure timely compliance with, as applicable, all applicable international laws and regulations, including, for example, the European Union's Data Protection Directive (EUDP), Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), Japan's Personal Information Protection Action (PIPA), and the US Health Insurance Portability and Accountability Act (HIPAA).
To monitor implementation of the company's global policy for the protection of individually identifiable information, Health Decisions has chartered the Health Decisions Privacy Office (HDPO), which serves as Health Decisions' internal privacy board. The Privacy Office includes members and advisors from a representative cross-section of operations and across global geographies and lines of business, including the company's Chief Privacy Officer and the Chief Technology Officer.
In addition, the Privacy Office is charged with monitoring the company's compliance with applicable data protection laws and regulations, as applicable. The HDPO also functions as Health Decisions' privacy inquiry office and has established a complaint office to receive, log and handle any complaints Health Decisions may receive regarding data privacy. Further, the Privacy Office has established an ongoing awareness training program in the company's privacy policy and procedures for the company's employees.
Health Decisions U.S. – EU Safe Harbor Privacy Statement sets forth the privacy principles that Health Decisions follows with respect to transfers of personal information from the European Union to the United States.
Health Decisions values the confidence of its customers and respects individual privacy, including personal information of employees, consumers, healthcare professionals, medical research subjects, clinical investigators, customers, business partners, and investors; and has a tradition of upholding the highest ethical standards in its business practices. Health Decisions adheres to the US - EU Safe Harbor Privacy Principles in connection with the transfer of all personal data from the EU to the US.
Health Decisions' Safe Harbor certification can be found at https://safeharbor.export.gov/list.aspx.
For more information about the Safe Harbor Principles, please visit the U.S. Department of Commerce's Website at http://www.export.gov/safeharbor.
Health Decisions Safe Harbor Privacy Policy (the "Policy"):
SCOPE: This Policy applies to all personal information, either in electronic or paper format, received by Health Decisions in the United States from the EU.
DEFINITIONS: For purposes of this Policy, the following definitions shall apply:
"Agent" means any third party that uses personal information provided to it by Health Decisions to perform tasks on behalf of and under the instructions of Health Decisions.
"Health Decisions" means Health Decisions Inc., its successors, subsidiaries, divisions and groups in the United States.
"Personal information" means any information or set of information that identifies or could be used by or on behalf of Health Decisions to identify an individual. Personal information does not include information that is encoded or anonymized or publicly available information that has not been combined with non-public personal information.
"Sensitive personal information" means personal information that reveals race, ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, or that concerns health or sex life. In addition, Health Decisions will treat as sensitive personal information any information received from a third party where that that information already qualifies as sensitive personal information according to this policy, or where the third party explicitly identifies the information as sensitive.
PRIVACY PRINCIPLES: The privacy principles in this Policy are based on the Safe Harbor Privacy Principles.
NOTICE: Where Health Decisions collects personal information directly from individuals in the EU, it will inform them about the purposes for which it collects and uses personal information about them, the types of non-agent third parties to which Health Decisions discloses that information, and the choices and means, if any, Health Decisions offers individuals for limiting the use and disclosure of their personal information. Notice will be provided in clear and conspicuous language when individuals are first asked to provide personal information to Health Decisions, or as soon as practicable thereafter, and in any event before Health Decisions uses the information for a purpose other than that for which it was originally collected.
Where Health Decisions receives personal information from its subsidiaries, affiliates or other entities in the EU, it will use such information in accordance with the notices provided by such entities and the choices made by the individuals to whom such personal information relates.
CHOICE: Health Decisions will offer individuals the opportunity to choose (opt-out) whether their personal information is (a) to be disclosed to a non-agent third party, or (b) to be used for a purpose other than the purpose for which it was originally collected or subsequently authorized by the individual.
For sensitive personal information, Health Decisions will give individuals the opportunity to affirmatively and explicitly (opt-in) consent to the disclosure of the information to a non-agent third party or the use of the information for a purpose other than the purpose for which it was originally collected or subsequently authorized by the individual.
Health Decisions will provide individuals with reasonable mechanisms to exercise their choices.
DATA INTEGRITY: Health Decisions will use personal information only in ways that are compatible with the purposes for which it was collected or subsequently authorized by the individual. Health Decisions will take reasonable steps to ensure that personal information is relevant to its intended use, accurate, complete, and current.
TRANSFERS TO AGENTS: Health Decisions may share an individual's information with agents, contractors or partners of Health Decisions in connection with services that these individuals or entities perform for, or with, Health Decisions. Health Decisions may, for example, provide an individual's personal information to agent contractors or partners for hosting our databases, for data processing services, or to send to that individual the information that he or she requested.
Health Decisions will obtain assurances from its agents that they will safeguard personal information consistently with this Policy. Examples of appropriate assurances that may be provided by agents, include: a contract with provisions obligating the agent to provide at least the same level of protection as is required by the relevant Safe Harbor Principles, being subject to the EU Data Protection Directive, Safe harbor certification by the agent, having Binding Corporate Rules approved by the European Commission, or being subject to another European Commission adequacy finding (e.g., Argentina, Canada, Guernsey, Isle of Mann, Switzerland).
Where Health Decisions knows that an agent, contractor or partner is using or disclosing personal information in a manner contrary to this Policy, Health Decisions will take reasonable steps to prevent or stop the use or disclosure.
ACCESS AND CORRECTION: Upon request, individuals will be provided with the personal information that Health Decisions holds about them. In addition, upon request, Health Decisions will take reasonable steps to provide individuals with a means to correct, amend, or delete information that is found to be inaccurate or incomplete. Due to regulatory, statistical, and contractual requirements, we are not able to grant direct access to research data to research participants or clinical investigators.
SECURITY: Health Decisions will employ reasonable safeguards to protect personal information in its possession from loss, misuse and unauthorized access, disclosure, alteration and destruction. For personal information subject to electronic storage or transmission, Health Decisions maintains an internal private, secure global network that is protected from computer virus infection and monitored for unauthorized access. Both electronic and paper based records holding personal information are maintained in access controlled facilities for which business continuity plans are required.
ENFORCEMENT: Health Decisions' internal privacy board, the Health Decisions Privacy Office (HDPO), has put into place internal, self-assessment procedures for periodically conducting reviews of compliance of its relevant privacy practices to verify adherence to the company's Safe Harbor Privacy Policy.
Any employee that Health Decisions determines is in violation of this Safe Harbor Privacy Policy will be subject to disciplinary action up to and including termination of employment.
DISPUTE RESOLUTION: Any questions or concerns regarding the use or disclosure of personal information should be directed to the Health Decisions Privacy Office at the email address given below. Health Decisions will investigate and attempt to resolve complaints and disputes regarding use and disclosure of personal information in accordance with the principles contained in this Policy.
For complaints involving all other personal data other than human resources data that cannot be resolved between Health Decisions and the employee, such disputes will be referred to the European Data Protection Authorities
For internal complaints by individuals involving human resources data that cannot be resolved between Health Decisions and an employee after following the internal review, complaint, and appeal procedures, Health Decisions has agreed to participate in the dispute resolution procedures of the applicable national data protection authority to resolve disputes pursuant to the Safe Harbor Principles.
CONTACT INFORMATION: Questions or comments regarding this Policy should be submitted to the Health Decisions Health Decisions Privacy Office by e-mail as follows: privacy@HealthDec.com or The Health Decisions Business Ethics Help Line inside the U.S. at 1-919-967-1111, extension 4444 or Outside of the US, dial the AT&T country access code, then 919-967-1111, extension 4444.
RESERVATION OF RIGHTS: Health Decisions reserves the right to share an individual's information as required by law or to duly authorized information requests of government authorities.
CHANGES TO THIS SAFE HARBOR PRIVACY POLICY: This Policy may be amended from time to time, consistent with the requirements of the Safe Harbor Principles. Appropriate public notice will be given concerning such amendments.
* * *
If you feel that Health Decisions may not have abided by the US - EU Safe Harbor Privacy Principles, you may contact Health Decisions or the US Federal Trade Commission.
SAFE HARBOR POLICY PRIVACY POLICY - EFFECTIVE DATE: JANUARY 1, 2011. Last Updated JANUARY 1, 2011
* * *
In addition to this Privacy Policy Statement, which includes the European Union – U.S. Safe Harbor Privacy Policy Statement, the Health Decisions' "Web Site Privacy Policy" is available on this Internet site at www.HealthDec.com/privacy. Health Decisions sees the Internet and the use of other technologies as valuable tools for communicating and interacting with consumers, employees, healthcare professionals, business partners, and others. Health Decisions recognizes the importance of maintaining the privacy of information collected online and has created a specific "Web Site Privacy Policy" governing the treatment of personal information collected through web sites that it operates. With respect to personal information that is transferred from the European Economic Area to the U.S., the "Web Site Privacy Policy" is subordinate to the European Union – U.S. Safe Harbor Privacy Statement. However, the "Web Site Privacy Policy" also reflects additional legal requirements and evolving standards with respect to Internet privacy.
* * *
Should you have other questions or concerns about these privacy policies, please contact us at 919-967-1111, extension 4444, or send an email to the Health Decisions Privacy Office in care of privacy@HealthDec.com.