Protecting Your Information on Mobile Apps
Patients and insurance plan members can use mobile apps to access their health information. It is important to take an active role in protecting your health information. Knowing what to look for when choosing an app can help you make an informed decision.
Look for an easy-to-read privacy policy that clearly explains how the app will use your data. Do not use an app until you have reviewed the privacy policy.
Some things you should also consider:
If the app’s privacy policy does not clearly answer these questions, rethink using the app to access your health information. Health information is very sensitive. Be careful to choose apps with strong privacy and security standards.
What should a member consider if part of an enrollment group?
Some health plan members may be part of an enrollment group where they share the same health plan as other members of their tax household. This is more common with members who are covered by Qualified Health Plans (QHPs) on Federally-facilitated Exchanges (FFEs). Often, the primary policyholder and other members can access information for all members of an enrollment group unless a request is made to restrict access to member data.
Members should be told how their data will be accessed and used if they are part of an enrollment group. This access and use is based on the enrollment group policies of their health plan in the state where they live.
Members who share a tax household but who do not want to share an enrollment group have the option of enrolling each household member into separate enrollment groups. This can even be done while applying for exchange coverage and financial assistance on the same application. But, this may cause higher premiums for the household and some members. For example, dependent minors may not be able to enroll in all QHPs in a service area if using their own enrollment group. It may also cause higher total out-of-pocket expenses if each member has to meet a separate annual limit on cost-sharing, such as your out-of-pocket maximum.
Are third-party apps covered by HIPAA?
Most third-party apps are not covered by HIPAA. Instead, these apps are often controlled by the Federal Trade Commission (FTC) and the protections of the FTC Act. The FTC Act, among other things, protects against dishonest acts. For example, it would protect against an app sharing personal data without permission, even though there is a privacy policy that says it will not do so.
What should you do if you think someone has gained access to your data or an app has used your data in a way it should not have?
If you have a complaint about how Sanford Health Plan has used or disclosed your data, please contact us:
Sanford Health Plan
PO Box 91110
Sioux Falls, SD 57109-1110
Sanford Health Plan Customer Service
(800) 752-5863
THIS NOTICE DESCRIBES HOW HEALTH INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.
This Notice of Privacy Practices (“Notice”) applies to Sanford Health Plan including Align powered by Sanford Health Plan and Great Plains Medicare Advantage. If you have questions about this Notice, please contact Customer Service at (800) 752-5863 (toll-free) | TTY/TDD 711.
This Notice describes how we will use and disclose your health information. The terms of this Notice apply to all health information generated or received by Sanford Health Plan, whether recorded in our business records, your medical record, billing invoices, paper forms, or in other ways. Unless otherwise provided by law, any data or information pertaining to the health, diagnosis, or treatment of a Member under a policy or contract, or a prospective Member, obtained by Sanford Health Plan from that person or from a health care Provider, regardless of whether the information is in the form of paper, is preserved on microfilm, or is stored in computer-retrievable form, is confidential and may not be disclosed to any person except as set forth below.
HOW WE USE AND DISCLOSE YOUR HEALTH INFORMATION
We use or disclose your health information as follows (In Minnesota we will obtain your prior consent):
We may share your health information in the following situations unless you tell us otherwise. If you are not able to tell us your preference, we may go ahead and share your information if we believe it is in your best interest or needed to lessen a serious and imminent threat to health or safety:
We may also use and share your health information for other reasons without your prior consent:
We may contact you in the following situations:
YOUR RIGHTS THAT APPLY TO YOUR HEALTH INFORMATION
When it comes to your health information, you have certain rights.
Contact Information:
Sanford Health Plan
Customer Service
PO Box 91110
Sioux Falls, SD 57109-1110
(800) 752-5863 (toll-free) | TTY/TDD 711
OUR RESPONSIBILITIES REGARDING YOUR HEALTH INFORMATION
CHANGES TO THIS NOTICE
We may change the terms of this Notice, and the changes will apply to all information we have about you. The new Notice will be available upon request and online at www.sanfordhealthplan.com.
EFFECTIVE DATE
This Notice of Privacy Practices is effective February 1, 2022.
NOTICE OF AFFILIATED COVERED ENTITY DESIGNATION
Sanford Health Plan, Sanford Health, and The Evangelical Lutheran Good Samaritan Society, as covered entities under common ownership and control, have designated themselves and subsidiaries as a single covered entity for purposes of the Health Insurance Portability and Accountability Act (HIPAA). Sanford Health Plan shares health information about its members with the affiliated covered entity participants for treatment and other purposes as allowed by HIPAA and applicable law.