Privacy of Data
ONLINE PRIVACY and SECURITY STATEMENTS
ehealthxchange respects your right to privacy and will not
collect, use or disclose any personal information regarding you without
your consent.
What information is collected at the ehealthxchange.com website
and why?
A) Personal Information
Personal information is defined as information about an
identifiable individual. We require personal information (such as
your Address, Insurance carrier, Group/Member ID#) to confirm your
identity.
B) Medical Information
To get maximum benefit and convenience from the website,
you have the option to store your medical history, medication history
on the ehealthxchange.com website.
C) Email Address
We also require your email address so that we can send
email/text message appointment changes or reminders to you through
the automated features of the Web site.
D) Credit card transactions
All Web transactions for services obtained via ehealthxchange.com
require the following information:
- Personal identifying information such as name, address, email;
- Credit card information.
Personal identifying information collected in these sections of
the site is used for billing of goods or services sold. Credit card
information is securely transmitted to First Data Corp for approval
and processing of the online transaction. This information is used
for no other purpose than to process credit card transactions conducted
at ehealthxchange.com. ehealthxchange.com retains a record of your
billing and shipping information and credit card information.
E) Disclosing Information
ehealthxchange will not sell or share personal information
collected at the ehealthxchange.com website with other organizations
except as directed by you, or to the extent that disclosure is required
by a valid legal requirement such as a law, regulation or search
warrant. Should you voluntarily enter your medical profile,
you should be aware that when making an appointment with an ehealthxchange
healthcare provider; your medical profile becomes visible to that
provider and the information is then subject to the provider’s
privacy practices.
F) Accessing Your Personal Information
If at any time you wish to update the information you provided
or to verify its accuracy, you may visit the "ACCOUNT PREFERENCES" section
of the website.
G) Security
1) Network Communications Security
All Internet connections between ehealthxchange and its
users employ Secure Socket Layer (SSL) protocol using a 128-bit
key. SSL protocol provides security and privacy over the Internet
and supports both client and server authentication. ehealthxchange
purchases its certificates from Thawte (www.thawte.com),
leaders in the security field in order to limit the possibility
of fraud.
The SSL protocol authenticates our server to your computer --
so you know it is ehealthxchange you are working with -- before sensitive
data is exchanged by higher-level applications. The SSL protocol
uses message and authentication codes to maintain the integrity of
the connection. Data exchanged during an SSL session is encrypted
in both directions and each ehealthxchange session uses SSL to communicate
to the ehealthxchange Server.
2) Authentication
As an ehealthxchange member you authenticate to the system
using a user name and password. Members may change their password
at any time during their membership from ACCOUNT PREFERENCES > ONLINE
after logging into the exchange. Passwords are not known to ehealthxchange
staff. If you forget your password please use the ‘Forgot
my password’ link at the login screen, and you will be emailed
a temporary password, this will enable you to login, and create
your own password.
3) Access Control
ehealthxchange application security starts with web servers
that process Internet HTTP transactions from clients that communicate
over the Internet via authenticated and encrypted SSL sessions.
Each valid ehealthxchange user has a user ID on the system. ehealthxchange
applications provide privacy to sensitive data by encrypting the
data. The database fields that contain especially sensitive information
are made available to you as an authorized and authenticated requestor.
All data accesses are logged in permanent, archived records and
all access requests without proper credentials or application authentication
are stored in our system
4) Site Security
ehealthxchange.com site security consists of comprehensive
physical and logical controls and a multi- layered network and firewall
architecture. In addition, ehealthxchange has deployed its web and
database servers within the NAP
of the Americas (a Tier 1 Secure facility) that ensures the
safety of physical and logical access. The NAP has 24x7 onsite
security and state of the art physical security restrictions limiting
access to only those authorized ehealthxchange staff and support
personnel. You can be assured that ehealthxchange makes every
reasonable effort to protect your personal information from loss,
misuse or alteration by malicious parties.
Link to other websites
ehealthxchange provides links to web sites operated by other
parties. The links are provided for your convenience only. The presence
of a link does not imply any endorsement of the material on the web
sites or any association with the web site's operators. ehealthxchange
does not operate, control or endorse any information, products or
services provided by third parties through the Internet. ehealthxchange
is not responsible for the content and performance of these sites.
Use of linked sites is strictly at your own risk including any risks
associated with destructive viruses.
Questions about this Policy Statement
This privacy statement applies only to the ehealthxchange.com
website. Once you access another website from ehealthxchange.com,
we are not responsible for the privacy or security practices of these
sites. We encourage you to look for and review the privacy statements
of each and every website that you visit through a link on ehealthxchange.com
or any site that collects personal information from you. If
you have any questions about the ehealthxchange.com Online Privacy
Statement, please feel free to email privacy@ehealthxchange.com. |