Long Term Care Associates, Inc.
Confidentiality & Security Guidelines
Internet Security
Any information transmitted via the Internet is done so at your own risk. Long Term Care Associates, Inc. (LTCA, Inc.) cannot guarantee that information transmitted via the Internet will remain confidential throughout the entire transmission process. We do however make every effort to maintain a secure online environment. A secured certificate issued by VeriSign to ensure 128-bit data encryption and proper data redirection protects each "Request For Information" page. LTCA, Inc. will never ask you for your social security number, credit card information, or drivers license number. The information we do ask for is basic in nature and, except for limited health information provided at your discretion, is typically available to the general public. Your name and any other private or personal information is never available, sold, rented or shared with any party not directly involved in the process of handling LTCA, Inc. business operations.
Protected Health Information
Protected Health Information ("PHI") shall be defined as "Information that can be used to identify an individual that is directly related to that individual's health and is maintained or transferred in any medium." We do not sell or disclose PHI to non-affiliates for marketing purposes, except by client request. The PHI of customers who cease to be customers is treated with the same privacy sensitivity as current customers.
Information on personal computers
Only those employees and agents who need access to our customer databases and/or PHI in order to process or service a transaction or product authorized or requested by the client are given such access. Each employee or agent who has access to customer information is given a unique password to obtain access, which is revoked when employment is terminated. Agents who have access are restricted solely to their own policyholders' records. Customer information that is stored on-site is on a single server accessed via peer-to-peer network. The server and each workstation are protected by firewall [Norton] and anti-virus software [Norton].
Paper files
Customer files containing PHI that are used by employees and agents are stored and securely locked during evening and weekend hours. Original customer files and copies are not allowed to leave the premises (save for necessary and normal course of business, for example but not limited to transmitting original client applications to Insurers for underwriting, and forwarding issued policies to policyholders). Surplus documents containing PHI are shredded.
Telephone / Mail / Fax
For customers who make requests by phone, mail, or fax, we have established a verification method to make sure that the person making the request is actually the customer or his/her authorized representative. Phone verification includes identification of partial social security number, and paper and fax verification includes matching of signature on file. For authorized representatives, we must have on file a signed authorization from the customer in order to provide PHI or other unique policy information.
Security audit procedures
Our agency does an annual audit to determine if security procedures are being followed by all employees and agents of our agency. Such audits are also necessary to determine if changes need to be made in our security procedures. To comply with the Health Insurance Portability and Accountability Act and the privacy obligations of our agency agreements with Insurers, our books, records, and internal practices are available to the US Dept. of Health and Human Services for audit.
Training of new employees and agents
New employees and agents hired by our agency are trained as to our security procedures, as well as to become familiar with the permissible uses of protected personal health information and the other pertinent regulations of the HIPAA Privacy Rule. At agency meetings, security procedures are reviewed on a periodic basis.
Written security procedures
This document forms the foundation of our written security procedures regarding PHI and customer information used by our agency. It forms the basis of our employee and agent training, the annual review of our security procedures, and to provide to regulators to show our compliance with state and federal privacy laws and regulations. This privacy policy may be modified from time to time to comply with applicable laws or conform to our current business practices, without prior notice.