PRIVACY POLICY 1
Privacy Policy
Summary
For
Health Insurance Company (HIC) Inc.
Emmylou Bice
CSOL 540 Cyber Security Operations Policy
University of San Diego
PRIVACY POLICY 2
HIC, Inc. Data Handling Privacy Policy Summary
Introduction
HIC, Inc. is a health insurance organization that collects, stores, and transmits, different types of
information. This data handling privacy policy summary applies to all HIC, Inc. resources
including websites, services, and applications. HIC, Inc. is dedicated to ensure that personal
information shared and stored on company resources is protected and kept confidential (InTouch
Health, n.d.). This policy summary identifies the different domains HIC, Inc. information falls in,
the data within these domains, laws and regulations pertaining to the data and domains, and the
responsible party who controls the data.
Privacy Domains
HIC, Inc. data that falls into two main domains, public and private. The public domain is open
for all to access. The private domain, on the other hand, is kept internal to the company. All HIC,
Inc. information begins as information in the private domain until reviewed and released to the
public domain. Not all information is released to the public domain. The following sections
detail the domains even further by identifying the subdomain information, major laws,
regulations, and individuals or parties that control the privacy of the data.
Public Domain
Information
Corporate Privacy Policy: HIC, Inc. publishes the privacy policy online to all users accessing
company resources for their awareness and acknowledgement.
Corporate Privacy Related Plans and Reports: This information consists of reports HIC, Inc.
provides to the government to include Financial Reports and Security Reports.
PRIVACY POLICY 3
Corporate Insurance Plans: This information consists of HIC, Inc. insurance plans, customers
qualifications, and pricing.
Applicable Laws, Regulations, & Standards
Genetic Information Nondiscrimination Act: Prohibits health insurance and employment
“discrimination on the basis of genetic information” (U.S. EEO, 2008).
California Online Privacy Protection Act (CalOPPA): Requires operators of commercial sites and
online services to display the privacy policy (de la Torre, 2019).
Control of Data Privacy
HIC, Inc.’s public relations department is responsible for reviewing and approving any data or
information before released in the public domain. Once the data is in the public domain, the
company no longer has control over the information as it is on the internet for all to access.
Private Domain
HIC, Inc. collects many types of information and keeps it in the private domain, or internal to the
company and appropriate parties. Some of the information in this domain relating to corporate
data may be released to the public domain after appropriate review and approvals.
Information Types
Personal Health Information (PHI): HIC, Inc. collects information relating to personal health
information to include social security numbers, addresses, phone numbers, email addresses,
health issues, insurance claims, etc.
Personally Identifiable Information (PII): HIC, Inc. collects personally identifiable information
to include social security numbers, family information, phone numbers, driver’s license
information, or credit card information. of both clients and employees.
PRIVACY POLICY 4
Non-Personal Information: HIC, Inc. collects non-personal information pertaining to a user’s
experience with company resources. This includes information relating to user visiting HIC, Inc.
websites such as how the user go to the site, personalized ads, or demographic information. This
information is used to enhance HIC, Inc. services to consumers.
Corporate Confidential Data: This information includes business development or strategic plans
that have not been made available to the public. This information also includes any intellectual
property information.
Applicable Laws, Regulations, & Standards
Health Insurance Portability and Accountability Act of 1996 (HIPAA): HIPAA requires the
establishment of security standards for health information (Bosworth, et al., 2014). Under
HIPAA, HIC, Inc. must:
Provide clients with a privacy disclosure identifying hoe HIC, Inc will use, keep, and
disclose information (Bosworth, et al., 2014).
Provide clients access to their information (Bosworth, et al., 2014).
Permitted use and disclosure must only include the minimum amount necessary
(Bosworth, et al., 2014).
Electronic Communications Privacy Act: ECPA prohibits unauthorized and intentional
interception of communications during transmission of electronic information unless it is the
employers who provides the system the information is sent and obtains employee consent
(Bosworth, et al., 2014).
Financial Modernization Act of 1999: This act governs how financial organizations collect and
disclose customer financial information through the Financial Privacy Rule and ensures the
PRIVACY POLICY 5
information is adequately protected with safeguards in place through the Safeguards Rule (FTC,
n.d.). This applies to the personal financial information HIC, Inc. collects from customers.
Control of Data Privacy
HIC, Inc. controls all information in the private domain. For corporate data, HIC, Inc. reviews
some of this information like business strategies, new insurance plans, and marketing and
releases it to the public domain. For PHI and PII, employees and customers may access this
information to update or change at any time. To update, change, or remove PII or PHI, login to
your account or contact the Data Privacy Protection Officer by emailing
dataprotection@[Link]. HIC, Inc. in will require identity verification prior to modifying any
information.
PRIVACY POLICY 6
References
Bosworth, S., Kabay, M. E., & Whyne, E. (2014). Computer Security Handbook, Set, 6th
Edition. Hoboken, NJ: John Wiley & Sons.
De la Torre, L. (2019, May 11). What is ‘CalOPPA’? From [Link]
data/what-is-caloppa-b781b0cd5e39
FTC. (n.d.). Financial Privacy. From [Link]
resources/protecting-consumer-privacy/financial-privacy
InTouch Health. (n.d.). InTouch Health Privacy Policy. From [Link]
policy/
U.S. EEO. (2008, May 21). The Genetic Information Nondiscrimination Act of 2008. From
[Link]