
- Shop Individual Plans
- Explore Group Plans
- Members
- All Members
- Individual Plan Members
- Group Plan Members
Last Updated June 24, 2020
Welcome to the LifeMap Assurance Company Website (the "Website"). At LifeMap, we want you to get out and enjoy life – LifeMap has you covered.
This privacy policy is intended to inform you of what personal information we collect, how we or our vendors may use this personal information, and the steps we take to protect it.
If you have any questions or concerns about our privacy policy and protections, please contact us at compliance@cambiahealth.com
We collect personal information in two ways:
Through use of the Website, you may provide certain information to us through our web forms, which may include the following types of personal information:
We use various technologies to manage the Website and track use of the content we provide, including:
Automatically collected information collected using these technologies may be combined with information you provide directly to us.
We may automatically collect information about the computer, mobile device or other device you use to access the Website, such as IP address, geolocation information, unique device identifiers, browser type, browser language and other transactional information. This information may be used to offer you optimized experiences based on your device or location.
We may use the information that we collect to fulfill your requests for services and information. For example, we may use your contact information to respond to your inquiry/requests. We may use your personal information to help customize your experience based on your previous activities on the Website.
If you sign up for one of our email or newsletters, we will send you the email or newsletter that you requested. We may also use the information that we collect to send you other communications, such as information about our events. You may opt out of receiving this information by following the directions in the email or newsletter to unsubscribe.
We perform statistical analyses of users of the site, and their viewing and participation patterns, for product development purposes.
We may use the information that we collect to prevent illegal activities, to enforce the Website Terms of Use, or as otherwise required by law.
We do not sell the information we collect.
We may work with third parties to perform site-related services, including database management, maintenance services, analytics, marketing, billing and email distribution. These third parties have access to your information only to perform these tasks on our behalf and have security measures in place to protect your information.
We do not knowingly collect personal information from children under 13. If we learn that we have collected any personal information from a child under the age of 13 without verifiable parental consent, we will delete that information from our database as quickly as possible. If you believe that we may have collected information from a child under 13, please contact us.
To prevent unauthorized access, maintain data accuracy and ensure the appropriate use of information, we have put in place commercially reasonable physical, technical and administrative controls to protect your information. Please note that no method of transmission over the internet is 100% secure.
This privacy policy may be updated from time to time. Any such changes will be posted on this page. We will notify you of any significant or material changes in the way we treat your information by placing a prominent notice on our site or sending a notice to the primary email address specified in your account.
Accessing and Deleting Personal Data (Outside California)
You may access and share the data that we have about you. If you have any concerns about the accuracy of the data, send questions to compliance@cambiahealth.com. If you wish to delete the previous data you have consented to share with us, you may do so by contacting Customer Support. When you request for us to delete your previously provided data, it will be deleted within 60 days after your request unless we reach out to you to request additional time to delete your data.
Individuals who reside in the state of California, a "consumer," as that term is defined under California law, have additional rights reserved under the California Consumer Privacy Act (CCPA) and the California Shine the Light law:
If you are a California consumer and would like to submit a request based on this section of our Privacy Statement, please use this web form, email us at compliance@cambiahealth.com, or call us toll-free at 877-878-2273. Also, be sure to check this policy for updates as we will review it at least every 12 months and make updates as necessary.
We are required by law to verify that any data access request submitted under the authority of the CCPA was made by someone with the legal right to access the personal information requested. Therefore, prior to accessing or divulging any information pursuant to a data subject access request, under the terms of the CCPA, we may request that you provide us with additional information in order for us to verify your identity, your request, and legal authority (ex. authorized representative). Only you, or a person registered with the California Secretary of State that you authorize to act on your behalf, may make a verifiable consumer request related to your personal information. You may also make a verifiable consumer request on behalf of your minor child. Please indicate in your request if either of these apply, as additional verification may apply (ex. verify consumer’s identify and confirm with impacted person(s) that the authorized agent has permission to submit the request).
A verifiable consumer request must provide sufficient information that allows us to reasonably verify you are the person about whom we collected personal information or an authorized representative. A verifiable request must also include sufficient detail that allows us to properly understand, evaluate, and respond to it.
In general, our verification process includes reviewing the information submitted in the request, comparing it to the right(s) requested; the number of verification points/methods required by the CCPA; and the type, sensitivity, and risk of information requested, including to the consumer, from unauthorized disclosure or deletion. An account is not required with us in order to make a request. We will use personal information provided in a verifiable consumer request to verify the requestor's identity and authority to make the request, or otherwise as permitted by the CCPA (ex. record retention). We will respond to a verifiable consumer request within 45 days of its receipt, and if we require more time (up to 90 total days), we will inform you of the reason of the extension in writing. A response to a consumer request will be provided as required by the CCPA, such as through an account (if one exists), or otherwise by mail or electronically.
Under the CCPA, there may be certain circumstances where we would deny your request to access, receive, or delete personal information we hold. For example, we would deny requests where any such access or disclosure would interfere with our regulatory or legal obligations, where we cannot verify your identity, and/or where exemptions/exceptions permitted by the CCPA apply. We also have the ability under the CCPA to deny requests if it would result in our disproportionate cost or effort. Further, certain rights granted by the CCPA will not be effective until January 1, 2021. However, even where we will not substantively complete a request made under the CCPA, we will still provide a response and explanation to your request within a reasonable time frame and as required by law.
As defined by the CCPA, categories of personal information collected from consumers by us within the past 12 months include:
Categories | Examples | Collected (Yes or No) |
---|---|---|
A. Identifiers. | A real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, Social Security number, driver's license number, passport number, or other similar identifiers. | Yes |
B. Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)). | A name, signature, Social Security number, physical characteristics or description, address, telephone number, passport number, driver's license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number, or any other financial information, medical information, or health insurance information. Some personal information included in this category may overlap with other categories. | Yes |
C. Protected classification characteristics under California or federal law. | Age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, veteran or military status, genetic information (including familial genetic information). | Yes |
D. Commercial information. | Records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies. | Yes |
E. Biometric information. | Genetic, physiological, behavioral, and biological characteristics, or activity patterns used to extract a template or other identifier or identifying information, such as, fingerprints, face prints, and voiceprints, iris or retina scans, keystroke, gait, or other physical patterns, and sleep, health, or exercise data. | No |
F. Internet or other similar network activity. | Browsing history, search history, information on a consumer's interaction with a website, application, or advertisement. | No |
G. Geolocation data. | Physical location or movements. | Yes |
H. Sensory data. | Audio, electronic, visual, thermal, olfactory, or similar information. | No |
I. Professional or employment-related information. | Current or past job history or performance evaluations. | No |
J. Non-public education information (per the Family Educational Rights and Privacy Act (20 U.S.C. Section 1232g, 34 C.F.R. Part 99)). | Education records directly related to a student maintained by an educational institution or party acting on its behalf, such as grades, transcripts, class lists, student schedules, student identification codes, student financial information, or student disciplinary records. | No |
K. Inferences drawn from other personal information. | Profile reflecting a person's preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes. | No |
Personal information may also be collected in the course of a natural person acting as a current or former job applicant, employee, director, officer, or contractor within the context of that natural person’s role. Additional information collected may include emergency contact and information to administer benefits, including to another person.
"Personal information" does not include publicly available information, meaning information that is lawfully made available from federal, state, or local government records. "Publicly available" does not mean biometric information collected by a business about a consumer without the consumer’s knowledge. "Personal information" also does not include consumer information that is deidentified or aggregate consumer information. This Notice addresses online and offline practices by us. Information excluded from the CCPA’s scope includes health or medical information covered by the Health Insurance Portability and Accountability Act of 1996 (HIPAA). Other information excluded includes those covered by the California Confidentiality of Medical Information Act (CMIA) or clinical trial data, and personal information covered by certain sector-specific privacy laws, including the Fair Credit Reporting Act (FCRA), the Gramm-Leach-Bliley Act (GLBA) or California Financial Information Privacy Act (FIPA), and the Driver’s Privacy Protection Act of 1994.
Personal information is collected and may be used to provide the services to you, to perform obligations under agreements, to provide information and notifications to you or an authorized representative, to protect the rights and safety of you and/or others, to comply with court and other legal requirements, for business purposes and as otherwise set forth in the CCPA, to conduct organizational and operational needs, and as otherwise described when collecting personal information or within this page. A request for personal information collected and/or deletion, noted above, may involve categories and/or specific pieces of information. However, certain exemptions and exceptions may apply in responding to a request.
This business has not sold categories of personal information within the meaning of the CCPA, including minors under 16 years of age.
Categories of personal information from our consumers disclosed for a business purpose within the past 12 months include:
Business purposes may include auditing (ex. auditing and legal/regulatory compliance), security (ex. detecting security breaches), debugging (ex. identifying and fixing technical errors), short-term uses (ex. ad customization), performing services (ex. processing transactions), internal research (ex. product development), and testing/improvement (ex. improvement of technology).
Categories of sources from which personal information was directly and indirectly collected in the past 12 months include from you and/or authorized agents (ex. documents provided to us related to the services for which you/they engage us, and information we collect in the course of providing services to you/them); interaction with our platforms and services (ex. website portal); and third parties (ex. those that provide services such as purchased information, advertising networks, internet service providers, operating systems and platforms, social networks, and data brokers). This could include information obtained on websites and services from third parties that interact with us in connection with the services we perform or are linked to.
Categories of third parties with whom the business shared personal information in the past 12 months include authorized agents, affiliates, service providers (such as those described previously), contractors, and authorized third parties.
To make a request please contact the us at compliance@cambiahealth.com with "CCPA Personal Information Request" in the subject line, and provide us with full details in relation to your request, including your contact information and any other detail you feel is relevant. You can also use the other contact methods mentioned previously. If you are from another area (ex. state) and believe you are entitled to exercise applicable right(s), please use the email address and/or phone number given and include relevant details. If you have questions or concerns about the business’s privacy policies and practices, you can use the contact methods mentioned above (ex. telephone, email) in this Notice to contact us.
© 2019 LifeMap Assurance Company® All Rights Reserved