THE EDISON APP • PRIVACY

This page is used to inform website visitors regarding Edison’s policies with the collection, use, and disclosure of Personal Information for all members who have chosen to utilize our Edison app.

If you choose to use our services, then you agree to the collection and use of information in relation to this policy. The Personal Information that we collect is used for providing and improving the Service. We will not use or share your information with anyone except as described in this Privacy Policy. Our Privacy Policy was created with the help of the Privacy Policy Template Generator.

The terms used in this Privacy Policy have the same meanings as in our Terms and Conditions, which is accessible at edisonehs.com/terms, unless otherwise defined in this Privacy Policy.

OUR PRIVACY POLICY

Edison Health Solutions, LLC ("Edison") is required by law to maintain the privacy and security of your protected health information. This policy (the “Privacy Policy”) describes how personal information about you obtained through the website at member.edisonehs.com (the “Website”) may be used and disclosed, and how you can get access to this information. Edison may change the terms of this Privacy Policy. Any changes to this Privacy Policy shall be published on the Website.

INFORMATION SUBJECT TO THIS PRIVACY POLICY

This Privacy Policy applies, in part, to protected health information (“PHI”) as defined under the Health Insurance Portability and Accountability Act of 1996 (known as “HIPAA”). PHI includes health-related information that Edison collects, creates, receives or maintains in connection with your Edison user account and that reasonably could be used to identify you. Edison may receive your PHI directly from you or from a third party, such as your employer-sponsored health plan or medical provider.

Edison has developed and implemented policies and procedures designed to comply with the HIPAA, as amended by the Health Information Technology for Economic and Clinical Health Act provisions of the American Recovery and Reinvestment Act of 2009 (“HITECH”), and the Privacy, Security, Breach Notification and Enforcement regulations thereunder (45 C.F.R. Parts 160 and 164), as the same may be amended from time to time; and HIPAA and HITECH (a “HIPAA/HITECH Policies”). Edison’s use of PHI obtained or provided by you or a third party while using the Website will comply with its HIPAA/HITECH Policies, HITECH, HIPAA, and the rules and regulations promulgated thereunder. Further, any security breach incident shall be handled in accordance with Edison’s HIPAA Breach Notification Policy and/or Edison’s Electronic Data Security Breach Reporting and Response Policy as applicable.

Edison is considered a “business associate” under HIPAA. A “business associate” is a person or entity, other than a member of the workforce of a covered entity, who performs functions or activities on behalf of, or provides certain services to, a covered entity that involves access by the business associate to PHI. Prior to sharing or receiving your PHI from a third party, Edison will have a valid, existing Business Associate Agreement or Subcontractor Business Associate Agreement (collectively referred to herein as a “BAA”) with the third party. A BAA requires that a business associate, among other things, will not use or further disclose PHI other than as permitted or required by the BAA or as required by law. Edison will at all times comply with its applicable BAA when using or disclosing your PHI.

DATA SECURITY

Edison has implemented measures designed to secure your personal information from accidental loss and from unauthorized access, use, alteration, and disclosure. All information you provide to us is stored on our secure servers behind firewalls. Any payment transactions and certain disclosures/uses of PHI (See De-Identification of PHI section below) will be encrypted using SSL technology when necessary. The safety and security of your information also depends on you. Where you have chosen a password to access to certain parts of the Website, you are responsible for keeping this password confidential. Edison strongly advises against sharing your password with anyone. Unfortunately, the transmission of information via the Internet is not completely secure. Although we do our best to protect your personal information, we cannot give a 100% guarantee of the security of your personal information transmitted to our Website. Any transmission of personal information is at your own risk. Edison is not responsible for the circumvention of any privacy settings or security measures contained on the Website.

HOW EDISON MAY USE AND SHARE PHI

Edison may use and share your PHI for the following purposes without first asking for your written permission:

Treatment

Edison may use and share your PHI for treatment-related purposes of a healthcare provider.

Payment

Edison can use and share your PHI with a covered entity or healthcare provider.

Health Care Operations

Edison may use and share your PHI with a covered entity for healthcare operations.

Contractors

Third-party contractors provide certain services to Edison or you on our behalf. Edison may share your PHI with these third-party contractors for treatment, payment, or health care operation purposes in accordance with HIPAA and the BAA between Edison and said third party. These contractors are required by law to protect your PHI the same way we do.

Your Employer-Sponsored Health Plan

Edison may use and share your PHI with your health plan administrator or its other service providers as permitted by applicable law.

Other Uses or Disclosures

Edison may and sometimes is required to use or share your PHI in special circumstances without first asking for your written permission (e.g. when required by court order).

HOW EDISON MAY USE AND SHARE YOUR PHI WITH PARTIES INVOLVED IN YOUR CARE OR PAYMENT FOR CARE

Generally, Edison will not share PHI or communicate with someone other than patients, health plans, third party services providers, or health care providers directly.

If you are represented by a legally appointed personal representative, Edison will communicate with your representative in the same manner Edison would communicate with you, provided that Edison has received a valid health authorization designating such as your representative and authorizing them to receive your PHI.

In special circumstances, Edison may share your PHI or communicate with individuals identified as family members, personal relatives, close personal friends, or others involved in your care with your permission or, if you are unable to give permission, only if we believe it is necessary and in your best interest. In the event you are unable to give permission, and Edison determines it is in your best interest to share your PHI with an individual identifying as a family member, other relative, close personal friend or as otherwise involved in your care we will only disclose PHI that is directly relevant to their involvement with your care or payment related to your health care or as otherwise needed for notification purposes.

INFORMATION COLLECTION, USE, AND SHARING

Personal Information

If you create an account through Edison's Website, you may be asked to provide personal information, including but not limited to, your name, telephone number, mailing address, email address, gender, health insurance information, PHI, and other such information.

Non-Personal Information

Edison may collect non-personal information about your activity on the Website, including but not limited to information that you provide to Edison or generate using our Website, records and copies of your correspondence with us, your responses to surveys Edison might ask you to complete, and details of transactions you carry out through our Website. This information, if collected, may be collected via computer code sent to your computer (commonly referred to as "cookies" or "web beacons"). Edison does not collect personal information automatically, but we may tie this non-personal information to personal information about you that we collect from other sources or you provide to us.

"Cookies" are small text files that are placed on your device by a web server when you access our services. Edison may use both session cookies and persistent cookies to identify that you've logged into the services and to tell us how and when you interact with our services. Edison may also use cookies to monitor aggregate usage and web traffic routing on our services and to customize and improve our services. Unlike persistent cookies, session cookies are deleted when you log off from the services and close your browser. You may refuse to accept browser cookies by activating the appropriate settings on your browser. However, if you select this setting you may be unable to access certain parts of our Website. Unless you have adjusted your browser setting so that it will refuse cookies, Edison’s system will issue cookies when you direct your browser to our Website. Some third-party service providers that we engage may also place their own cookies on your device, however, this Privacy Policy only covers Edison’s use of cookies and not third party uses of cookies.

"Web Beacons" are tiny graphics (also referred to as clear gifs, pixel tags, and single-pixel gifs) with a unique identifier that may be included on Edison’s Website for several purposes, including to deliver or communicate with cookies, to track and measure the performance of Edison’s services, to monitor how many visitors view the Website, and to monitor the effectiveness of advertising. Web Beacons are typically embedded invisibly on web pages (or in an e-mail).

The Website may automatically record certain information about how you, or any other individual accessing our Website on your behalf, use Edison’s services ("Log Data"). Log Data may include information such as a user’s Internet Protocol (IP) address, operating system, browser type, the website that a user was visiting before accessing Edison’s Website, the pages or features on Edison’s Website that a user accessed (including the time spent on those pages) and features, search terms, and links on Edison’s Website that a user clicked on and similar statistics. Edison uses Log Data to administer its services and analyze Log Data to improve, customize, and enhance Edison’s services by expanding features and functionality. Edison may collect your IP address and other information about your online activity to generate aggregate, non-identifying information about how our services are used and analytics data regarding users' interactions on the Website.

Usage of Data

Edison uses non-personal information to manage the Website. Edison may analyze the data about visits to the Website to make it more accessible and interesting for visitors. Further, Edison may share this data with third party service providers associated with the maintenance of the Website. Additionally, Edison may disclose non-personal information about pages you visit on the Website, as well as the frequency with which you visit pages, but not in a manner that is inconsistent with the applicable law. We will not sell or rent this information to anyone.

Any personal info submitted to the Website will only be used for the purpose requested, for which it is collected, or authorized. That information may be stored and maintained by Edison. Edison may share this information with third-party service providers that work with us to administer and provide the services. These third-party service providers have access to your personal information and financial information only for the purpose of performing services on our behalf.

Edison will not share your information with any third party outside of our organization, other than with trusted partners to help us fulfill your request, perform statistical analysis, send you email or postal mail, provide customer support, provide other services to Website users, or otherwise consistent with HIPAA, HITECH, or other applicable law, rule or regulation. Edison has taken and will continue to take measures to ensure the secure and safe handling of your personal information.

Information Sent by Your Mobile Device

We collect certain information that your mobile device (e.g. device identifier, user settings and the operating system of your device) sends when you use Edison’s services.

Location Information

When you use the Website, Edison may collect and store information about your location by converting your IP address into an approximate geo-location or by accessing your mobile device's GPS coordinates, if location services are enabled on your device. Location services are used to personalize your experience on the Website. If you do not want Edison to collect location information, you should disable said features on your device.

De-Identification of PHI

In certain circumstances, HIPAA may require Edison to de-identify PHI prior to making certain disclosures. In such a case, Edison shall, prior to making any disclosure, de-identify the PHI in accordance with Section 164.514 of the HIPAA Privacy Rule.

Information Disclosed in Connection with Legal Requirements

Edison may disclose any personal (in compliance with the rules and regulations set forth in HIPAA and HITECH) or non-personal information collected to the extent it reasonably believes that such disclosure is necessary to comply with the law, such as in response to any subpoena, to the extent reasonably necessary to establish or defend a legal claim and for other purposes permitted by applicable law.

USE OF WEBSITE BY CHILDREN

This Website is not intended to be used by, nor is this Website marketed to, minors (i.e. children under the age of 18). Only parents/guardians of a minor child may submit any personal or non-personal information (including PHI) concerning their minor child. As such, the Children’s Online Privacy Protection Rule, and similar state laws, are not applicable to this Privacy Policy. Any information provided to Edison via the Website, by a parent/guardian of a minor child, that concerns a minor child shall (i) be deemed given with the parent’s/guardian’s informed consent, and (ii) shall be treated consistent with this Privacy Policy and applicable law.

CONTACT EDISON

Where your health plan has contracted with us to provide our services to you, Edison may forward some of your requests to the health plan for response or input as required by our contract.

Get an electronic copy of your PHI

You may see the PHI Edison has collected about you by signing into your member portal.

Get a copy of this Privacy Policy

You may ask us for a paper copy of this communication at any time by emailing us at memberservices@edisonehs.com. Edison will provide you with a paper copy promptly.

General Questions

If you have any questions regarding this Privacy Policy or Edison’s services in general, you may contact a representative as follows:

Email: info@edisonehs.com
Telephone: (800) 967-2077
Mailing Address: 2488 E 81st St Suite 1700, Tulsa, OK 74137

Revoke of Permission

If you have given Edison permission to use or share PHI in a certain way, you may change your mind at any time. Let us know by emailing us at memberservices@edisonehs.com.

Modifying Your Information

If you want us to delete your account or modify the information contained on your account with Edison, please contact us via email at memberservices@edisonehs.com with your request. Edison will promptly delete or modify the relevant information and provide you with a confirmation email upon the deletion or modification of such information.

NOTICE TO CALIFORNIA RESIDENTS

FOR USERS IN CALIFORNIA

With regard to users in California, this Privacy Policy is designed to comply with the California Online Privacy Protection Act (“CalOPPA”). The following disclosures and provisions shall supplement this Privacy Policy for individual residents of California who access the Website. To the extent the terms of this supplement conflict with the Privacy Policy, this supplement shall control for consumer residents in California.

“Do-Not-Track” Signals – Edison does not respond to “Do-Not-Track” signals from users’ web browsers.