NOTICE OF PRIVACY PRACTICES
This Notice of Privacy Practices (the “Notice”) describes the privacy practices of CVS Caremark mail order pharmacy (“Caremark Mail”) as required under The Health Insurance Portability and Accountability Act (“HIPAA”). Caremark Mail is part of an affiliated group of pharmacies that are owned by CVS Pharmacy, Inc. This affiliated group of pharmacies treats itself as a single entity for purposes of using and disclosing health information about you.
Caremark Mail wants you to know that nothing is more central to our operations than maintaining the privacy of your health information (“Protected Health Information” or “PHI”). PHI is information about you, including basic information that may identify you and relates to your past, present or future health or condition and dispensing of pharmaceutical products to you. We take this responsibility very seriously.
Our Pledge Regarding Your Health Information
We are required by law to protect the privacy of your health information and to provide you with this Notice covering our legal duties and privacy practices regarding your health information. We are also required to notify you in the event there is a breach of your PHI. Our pharmacy staff is required to protect the confidentiality of your PHI and will disclose your PHI to a person other than you or your personal representative only when permitted under federal or state law. This protection extends to any PHI that is oral, written, or electronic, such as prescriptions transmitted by facsimile, modem, or other electronic device. This Notice describes how we may use and disclose your PHI. In some circumstances, as described in this Notice, the law permits us to use and disclose your PHI without your express permission. In all other circumstances, we will obtain your written authorization before we use or disclose your PHI. This Notice also describes your rights and the obligations we have regarding the use and disclosure of your PHI. Under federal and applicable state law, we are required to follow the terms of the Notice currently in effect. In some situations, state privacy or other applicable laws may provide greater privacy protections than those stated in this Notice. For example, depending on the state in which you reside, there may be additional state law privacy protections related to communicable diseases, reproductive health, substance abuse and mental health. When appropriate, we will follow these state or other applicable laws. Please contact the CVS Caremark Chief Privacy Officer at CVS Caremark, P.O. Box 52072 Phoenix, AZ 85072-2072, if you would like a copy of the more protective privacy laws, if any, in your state.
How We May Use and Disclose Your PHI Without Your Permission For Treatment, Payment or Health Care Operations
Below are examples of how federal law permits use or disclosure of your PHI for these purposes without your permission:
1. Treatment: PHI obtained by Caremark Mail will be used to dispense prescription medications. We may also use and disclose your PHI to your physician or other health care provider to recommend treatment options or alternatives, or to tell them about potential drug interactions, dosing issues, side effects and issues related to your therapy. We may contact you to provide treatment-related services, such as refill reminders, treatment alternatives, compliance programs and other health care services that may be of interest to you.
2. Payment: We may contact your insurer, payor or other agent and share your PHI with that entity to determine whether it will pay for your prescription and the payment amount. We may also contact you about a payment or balance due for prescriptions sent to you by Caremark Mail.
3. Health care operations: Your PHI may be used to monitor the effectiveness of our services. Your PHI may be transferred for purposes of carrying out the pharmacy services if we buy or sell pharmacy locations. We may also use your PHI to tell you about health savings available (e.g., generic products) and other opportunities that may be of interest to you, such as health education programs, health-related benefits for preferred Caremark Mail customers or clinical research projects. We may also disclose your PHI to another health care provider or health plan for purposes of their treatment, payment or health care operations. However, we will only do so for their health care operations if they have or have had a relationship with you, if the PHI they request pertains to that relationship, and only for limited purposes, such as conducting quality improvement activities, reviewing the performance of a health care provider, or training purposes.
OTHER SPECIAL CIRCUSTANCES: In addition to the above, we are permitted under federal and applicable state law to use or disclose your PHI without your permission only in certain circumstances, as described below.
Business associates: We provide some services through other entities termed “business associates.” Federal law requires us to enter into contracts with these entities to require them to safeguard your PHI and use and disclose it only as specified by Caremark Mail. Individuals involved in your care or payment for care: We may disclose your PHI to a friend, personal representative or family member involved in your medical care or payment for your care. For example, if we can reasonably infer that you agree, we may provide prescription information to your caregiver on your behalf. Disclosures to parents or legal guardians: If you are a minor, we may release your PHI to your parents or legal guardians when we are permitted or required under federal and applicable state law.
Workers’ compensation: We may disclose your PHI to the extent authorized and necessary to comply with laws relating to workers’ compensation or similar programs established by law.
Law enforcement: We may disclose your PHI for law enforcement purposes as required by law or in response to a court order and in certain conditions, a subpoena, warrant, summons or similar process; to identify or locate a suspect, fugitive, material witness or missing person; about a death resulting from criminal conduct; about crimes on the premises or against a member of our workforce; and in emergency circumstances, to report a crime, the location, victims, or the identity, description, or location of the perpetrator of a crime.
As required by law: We must disclose your PHI when required to do so by applicable federal or state law.
Judicial and administrative proceedings: We may disclose your PHI in response to a court or administrative order, and under certain conditions, a subpoena, discovery request or other lawful process.
Public health: We may disclose your PHI to federal, state or local authorities, or other entities charged with preventing or controlling disease, injury or disability for public health activities. These activities may include the following: disclosures to report reactions to medications or other products to the U.S. Food and Drug Administration or other authorized entity; disclosures to notify individuals of recalls, exposure to a disease or risk for contracting or spreading a disease or condition.
Health oversight activities: We may disclose your PHI to an oversight agency for health oversight activities authorized by law. These activities include audits, investigations, inspections, licensing and for government monitoring of the health care system, government programs, and compliance with federal and applicable state law.
United States Department of Health and Human Services: Under federal law, we are required to disclose your PHI to the U.S. Department of Health and Human Services to determine if we are in compliance with federal laws and regulations regarding the privacy of health information.
Research: Under certain circumstances, we may use or disclose your PHI for research purposes. However, we will only do so if the research project has been approved by an institutional review board or privacy board that has established protocols to ensure the privacy of your PHI.
Coroners, medical examiners and funeral directors: We may release your PHI to assist in identifying a deceased person or determine a cause of death.
Administrator or executor: Upon your death, we may disclose your PHI to an administrator, executor or other similarly authorized individual under applicable state law.
Organ or tissue procurement organizations: Consistent with applicable law, we may disclose your PHI to organ procurement organizations or other entities engaged in the procurement, banking or transplantation of organs for the purpose of tissue donation and transplant.
Notification: We may use or disclose your PHI to assist in a disaster relief effort so that your family, personal representative or friends may be notified about your condition, status and location.
Correctional institution: If you are or become an inmate of a correctional institution, we may disclose to the institution or its agents PHI necessary for your health and the health and safety of others.
To avert a serious threat to health or safety: We may use and disclose your PHI to appropriate authorities when necessary to prevent a serious threat to your health and safety or the health and safety of another person or the public.
Military and veterans: If you are a member of the armed forces, we may release your PHI as required by military command authorities. We may also release PHI about foreign military personnel to the appropriate military authority.
National security and intelligence activities: We may release your PHI to authorized federal officials for intelligence, counterintelligence and other national security activities authorized by law.
Protective services for the President and others: We may disclose your PHI to authorized federal officials so that they may provide protection to the President, other authorized persons, or foreign heads of state, or conduct special investigations.
How We May Use or Disclose Your PHI for Other Purposes Only With Your Authorization.
Your written authorization to use and disclose your PHI is required in order for us to:
- Use and disclose psychotherapy notes containing your PHI (to the extent we hold any)
- Send marketing communications to you. If we will receive payment for making a marketing communication, we will state this in the authorization.
- Receive payment in exchange for your PHI.
In addition to the above situations, any other uses and disclosures of your PHI not described elsewhere in this Notice will be made only with your prior written authorization. You may revoke this authorization at any time by submitting a written notice to our Customer Care address listed below. Your revocation will not apply to information released before we receive it.
You have the following rights with respect to your PHI:
For all other restriction requests, contact the CVS Caremark Customer Care Department at PO Box 6590, Lee’s Summit, MO 64064-6590 All requests must include your full name, date of birth, address and plan identification number.
Complaints: If you believe your privacy rights have been violated, you can file a complaint with the CVS Caremark Investigations & Incident Response team at CVS Caremark P.O. Box 52072, Phoenix, AZ 85072-2072, or with the Secretary of the United States Department of Health and Human Services.
All complaints must be submitted in writing. You will not be penalized in any way for filing a complaint. Changes to this Notice: We reserve the right to change our privacy practices. We reserve the right to make the revised Notice effective for PHI we already have about you as well as any information we receive in the future, as of the effective date of the revised Notice. Upon request to the Privacy Office, CVS will provide a revised Notice to you. We will also post the revised Notice on our Web site at www.caremark.com .
Effective Date: This Notice is effective as of September 23, 2013.