CALIFORNIA RESIDENT PRIVACY NOTICE AND NOTICE OF COLLECTION
Effective Date: March 1, 2024
Last Revised Date: March 1, 2024
This California Resident Privacy Notice and Notice of Collection (“California Policy”) provided by Medical Mutual of Ohio and its Family of Companies (“Company” or “we”) supplements the information contained in Website Privacy Policy (“Privacy Policy” or “Policy”) and the State Privacy Law Addendum (“Addendum”) and applies solely to individual residents of the State of California (“consumers” or “you”). Unless otherwise expressly stated herein, all terms in this Collection Notice have the same meaning as described in our Privacy Policy or as defined by the California Consumer Privacy Act (CCPA), as applicable.
California “Shine the Light” Privacy Rights
California law permits our customers who are California residents to request certain information regarding the disclosure of certain personal information to third parties for their direct marketing purposes.
If we have disclosed any personal information to third parties for direct marketing purposes, we will provide a list of the categories of personal information, along with the names and addresses of these third parties to you at your request. To make such a request, write us at the postal address or by Email at CustomerServices@medmutual.com.
This request may be made no more than once per calendar year. We reserve our right not to respond to requests submitted other than to the specified email or postal address. You should put "California Privacy Rights-Direct Marketing" in the email subject line and in the body of your request. You must provide us with specific information regarding yourself so that we can accurately respond to the request.
California Consumer Privacy Act/ California Consumer Privacy Rights Act
If you are a California resident, the California Consumer Privacy Act, Cal. Civ. Code §§ 1798.100 et seq., as amended by the California Consumer Privacy Rights Act of 2020 and may be amended from time to time (“CCPA/CPRA”), provide you with certain rights with respect to your Personal Information, as that term is defined under and subject to the CCPA/CPRA. This California Policy describes your CCPA/CPRA rights with respect to your Personal Information and explains how to exercise those rights, subject to CCPA/CPRA exceptions. Any terms defined in the CCPA/CPRA have the same meaning when used in this California Policy.
Collection, Use and Disclosure of Personal Information in Preceding Twelve (12) Months
The Privacy Policy sets forth the categories of Personal Information that we have collected in the preceding twelve (12) months, the sources from which it was collected, the purpose for which it was collected, and the categories of third-parties to whom it was disclosed.
This Notice of Collection supplements the information contained in our Privacy Policy and applies solely to individual residents in the State of California. We are collecting your Personal Information from our Site to support our business operations. We will not knowingly sell the Personal Information we collect.
Specifically, we collect the following categories of Personal Information:
- Identifiers. We may collect identifiers such as your name, home or work address, unique personal identifier, online identifier, email address, mailing address, telephone number (including a cell phone number), credit card numbers, date of birth, member identification number, member group number, or social security number.
- Technical and Usage Data. As you navigate through and interact with our Site, we may use automatic data collection/tracking technologies to collect technical and usage data. Technical and usage data is information about your internet connection, the equipment you use to access our Site, and usage details. This information may include your IP address; operating system; browser type; domain names; the pages within the Website you visit; access dates and times; referring websites or addresses; and approximate location data (geolocation).
- Sensitive Data. We may collect personal information that reveals racial or ethnic origin, religious beliefs, union membership, a mental or physical health condition or diagnosis, sex life or sexual orientation, status as transgender or nonbinary, or citizenship or citizen (immigration) status.
- Commercial Information. We may collect information about the products or services you have purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.
- Professional or Employment-Related Information. We may collect information about your current job or past job history, including your current or former title.
- Other Personal Information. We may collect other Personal Information about you such as your signature and physical characteristics.
- Inferences Drawn from Personal Information. We may draw inferences from the information we collect about you to create a profile that reflects your preferences, characteristics, geographic location, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and/or aptitudes.
We may use your personal information and member health information for several purposes, including to:
- Operate, present, maintain and improve the Site and our Services;
- Administer your account;
- Provide you with information or Services you request, including but not limited to sharing your personal information and member health information with third parties with your approval and at your direction;
- Process an application or quotation requested by you;
- Resolve disputes;
- Comply with laws and regulations;
- Prevent prohibited activities and enforce our Terms of Use;
- Facilitate your use of, and our operation of, our Services;
- Analyze trends and statistics and for marketing, research, and development;
- Deliver targeted service updates;
- Contact you on behalf of external business partners about a particular offering that may be of interest to you, as permitted by HIPAA;
- Verify information with third parties; and
- For any other purpose described to you through the Site, that you consent to, or that is otherwise permissible under the laws that apply to us.
We retain your Personal Information only for as long as is necessary to accomplish these business purposes and to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with laws that apply to us), resolve disputes, and enforce our legal agreements and policies.
The Right to Know / Specific Information
You have the right to know and request the following information relating to the Personal Information we may have collected and disclosed:
-
The categories of Personal Information we have collected about you;
-
The categories of sources of the Personal Information;
-
The purposes for collecting the Personal Information; and
-
If we sold, shared or disclosed your Personal Information for a business purpose, two separate lists disclosing:
- the categories of personal information that was disclosed for a business purpose and the categories of recipients of such information; and
- the categories of Personal Information that we sold to or shared with third parties and the categories of recipients of such information.
We are not required to provide you with this information more than twice in a twelve (12) month period.
The Right to Access
You have the right to access and obtain a copy of the specific pieces of Personal Information we have collected about you, upon verification of your identity.
The Right to Correct
You have the right to request that we correct the inaccurate Personal Information that we collected and maintain about you.
The Right to Request Deletion
You have the right to request that we delete the Personal Information that we collected from you, subject to certain exceptions. Once we receive and confirm your verifiable consumer request, we will delete (and direct our service providers to delete) your Personal Information from our records, unless an exception applies.
To Submit a Request to Exercise Your Right to Access, Correct and Deletion
Call us at 1-800-382-5729 during regular business hours.
We may ask you to provide additional Personal Information so that we can properly identify you in our dataset to track compliance with a request. We will only use Personal Information provided in a request to review and comply with the request. If you chose not to provide this information, we may only be able to process your request to the extent we are able to identify you in our data systems. In certain circumstances, we may decline a request to exercise the rights described above.
Response Timing and Format
We will endeavor to respond to a verifiable consumer request within forty-five (45) days of receipt. If we are unable to process your request in such time, we will inform you of the delay in writing.
If you have an account with us, we will deliver our written response to that account. If you do not have an account with us, we will deliver our written response by mail or electronically.
Information provided in response to a consumer request will be provided free of charge, up to twice. We reserve the right to charge a fee to process or respond to your verifiable consumer request if we determine that such request is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.
Right to Appeal
If we are unable to comply with all or a portion of your request, we will explain the reasons we cannot comply. You may appeal our decision by resubmitting a request and we will inform you of any action taken or not taken in response to the request and explain the reasons for our decision within sixty (60) days of receiving the request.
The Right to Opt-Out of Targeted Advertising, Sale or Sharing of Personal Information
You have the right to direct us not to process your Personal Information for the purposes of (i) targeted advertising; or (ii) sell or share Personal Information we have collected about you. You have the right to limit the use and disclosure of Sensitive Personal Information we have collected about you.
To opt out of the potential sale or sharing of your Personal Information or to limit the use and disclosure of your Sensitive Personal Information, visit the applicable opt-out page:
If you have submitted Personal Information through this Site, you may request a restriction on the use and disclosure of your information. You may also request access to your Personal Information held by Medical Mutual and you may request that we correct or amend your Personal Information
You may designate an authorized agent to exercise an opt-out right on your behalf.
Minor Children Between Ages 13-16
We do not sell the Personal Information of consumers we know to be less than 16 years of age, unless we receive affirmative authorization (the “right to opt-in”) from a consumer who is between 13 and 16 years of age. As set forth in the Privacy Policy, we do not knowingly collect Personal Information from children under 13. If we learn we have collected or received Personal Information from a child under 13 without verification of parental consent, we will delete that information.