Last Revised: December 15, 2020
We collect several types of information from and about users of our Websites and Apps, (collectively, “personal information”) including information:
-by which you may be personally identified, such as name, home address, billing address, shipping address, email address, home, work, and mobile telephone numbers, country, date of birth, credit or debit card number (for payment purposes only), driver’s license number, audio, images and videos of you, Social Security Number, your medical history, health insurance subscriber information, health information, racial or ethnic origin, religion or religious believes, criminal background checks, criminal history, political organizations or beliefs, sexual orientation or preferences, or any other information you chose to provide to us, or which is collected, on the Websites or Apps that is defined as personal data or personally identifiable information under an applicable law;
- that is about you but individually does not identify you, such as whether you are a current user, product interests, or information related to your inquiry or request, and traffic data, logs, referring/exit pages, location, data and time of your visit to our Websites or use of our Apps, error information, clickstream data, and other communication data and the resources that you access and use on the Websites or through our Apps;
- about your internet connection, the equipment you use to access our Websites or Apps, and usage details; and/or
-about your medical condition, treatment options, physician referrals, prescriptions, and lab results, including protected health information (“PHI”) or other related health information.
We collect this information:
- Directly from you when you provide it to us.
- Automatically as you navigate through the Websites or use our Apps. Information collected automatically may include real-time location data, usage details, IP addresses, and information collected through cookies, web beacons, and other tracking technologies.
- From third party intermediaries, for example, CMG and Providers, Zendesk (a customer service, support and technology provider), a third party pharmacy fulfillment and technology provider, and other business partners and service providers with whom we partner to provide you with services.
The information we collect on or through our Websites or Apps may include:
- Personal information such as the data identified above.
- Information that you provide on our Websites or Apps. This includes information provided when you sign up for our services; when you use our services or other services available through the Websites or Apps, when you purchase products, when we process or respond to your inquiries related to requests for treatment, payment, customer service; and when you provide feedback on our Websites or Apps.
- Records and copies of your correspondence (including email addresses), if you contact us.
- Your responses to questions that we might ask you to complete for research purposes.
- Details of transactions you carry out through our Websites and Apps and of the fulfillment of your inquiries or requests.
- Your search queries on the Websites
As with many other websites and mobile applications, as you navigate through and interact with our Websites or Apps, we may use automatic data collection technologies to collect certain information about your equipment, browsing actions, and patterns, including:
- Details of your visits to our Websites or Apps, including traffic data, location data, logs, language, date and time of access, frequency, and other communication data and the resources that you access and use on the Websites or Apps. Information about your computer and internet connection, including your IP address, operating system, host domain, and browser type.
- Details of referring websites (URL). We also may use these technologies to collect information about your online activities over time and across third-party websites or other online services (behavioral tracking).
- Information about your computer, mobile device, and Internet connection, specifically the device’s unique identifier and telephone number and your IP address, operating system, browser type, mobile network information, and App version information.
- Information stored on your mobile device, including in other applications. This may include, photographs, audio and video clips, and health information. This data will be used only to provide and improve our services, and will not be used or shared with third parties for marketing purposes.
- Real-time information about the location of your device.
The information we collect automatically is statistical data and may include personal information, or we may maintain it or associate it with personal information you provide to us or that we collect in other ways or receive from third parties. It helps us to improve our Websites or Apps and to deliver a better and more personalized service, including by enabling us to:
- Estimate our audience size and usage patterns.
- Forecast future needs, functions, and uses of our Websites, Apps, and services.
- Better understand user satisfaction levels and experiences.
- Store information about your preferences, allowing us to customize our Websites or Apps according to your individual interests.
- Speed up your searches.
- Recognize you when you return to our Websites or Apps.
- In other ways to improve your experience and the quality of our Websites, Apps, and services.
The technologies we use for this automatic data collection may include:
- Pixel Tags. We and are service providers may also collect data by using “pixel tags,” “web beacons,” “clear GIFs,” or similar means (collectively, “pixel tags”) that allow us to know when you visit our Websites or Apps. Through pixel tags, we obtain non-personal information or aggregate information that can be used to enhance your online experience and understand traffic patterns.
- Other Third Party Cookies. We encourage you to review the privacy policies of the other third party cookies deployed on our Websites and Apps, including Microsoft’s (available at https://privacy.microsoft.com/en-us/privacystatement), Rollbar’s (available at https://docs.rollbar.com/docs/privacy-policy), and New Relics’ (available at https://newrelic.com/termsandconditions/privacy).
This is information we receive about you if you use any of the other websites we operate or the other services we provide. We are working closely with third parties (including, for example, third party intermediaries, such as the physicians, medical professionals, and pharmacies with whom we partner to provide you with services, sub-contractors in technical, advertising networks, analytics providers, and search information providers).
In connection with providing you with the Websites, Apps, and services, we may use, compile, analyze, and save your information in the following ways:
-To provide our Websites and their functionality, contents and services to you.
- To provide and improve our Apps and their functionality, contents and services.
- For the purposes of treatment, quality, improvement of health status, customer and patient experience, customer and patient engagement and/or behavior modification, peer review, payment, efficiency, cost effectiveness and/or other purposes relating to operations and provisions of telehealth services.
- To carry out the services and, as applicable, facilitate the provision of health care services to you by your physician or other health care provider and ensure that physicians or health care providers have the services and support necessary for health care operations.
- To communicate with you about the Websites, Apps, and services, or your use of the Websites, Apps, and services, and send you communications on behalf of physicians or other health care providers utilizing the services to meet your needs.
- To provide you with information that you have requested or to respond to your inquiries.
- To provide you with technical support and to improve our Websites, Apps, and services.
- To verify your identity and administer your account, including processing your payments and fulfilling your orders.
- In order to ensure that content from our Websites and Apps is presented in the most effective manner for you and for your computer or mobile phone, to allow you to participate in interactive features of our services (when you choose to do so), and as part of our efforts to keep our Websites and Apps safe and secure.
- To communicate with you about our products and services and those of our subsidiaries, affiliates, and parent companies and any of their related businesses and those of our third-party partners that may be of interest to you.
- To fulfill any other purposes for which you provide it, including to allow you to transfer your user account to a new device, or sync other applications offered by Cerebral and its affiliates and third-party partners.
- To measure or understand the effectiveness of advertising we serve to you and others, and to deliver relevant advertising to you.
- In the event of a sale, merger, consolidation, change in control, transfer of substantial assets, reorganization, or liquidation, we may transfer, sell, or assign to third parties information concerning your relationship with us, including, without limitation, personal information that you provide and other information concerning your relationship with us.
- To carry out our obligations and enforce our rights arising from any contracts entered into between you and us, including for billing and collection.
- To notify you about changes to our Websites, Apps, or services.
- In any other way we may describe when you provide the information.
- For any purpose where you have given your consent.
- To comply with applicable federal and state law.
We may also use your information to contact you about goods and services that may be of interest to you, such as user surveys or promotions, including through newsletters. If you wish to opt-out of receiving such communications, you may do so at any time by visiting the “Notifications” section on your “My Account” page. For more information, see Choices About How We Use and Disclose Your Information.
Information We Receive From Other sources. We will combine information we receive from other sources with information you give to us and information we collect about you. We will use this information and the combined information for the purposes set out above (depending on the types of information we receive).
Health Information. Some information Cerebral collects constitutes PHI under the U.S. Health Insurance Portability and Accountability Act (“HIPAA”). As set forth above, CMG (or your own medical provider if you do not use a CMG Provider) will provide you with a Notice of Privacy Practices describing its collection, use and disclosure of your PHI, not Cerebral, Inc. Cerebral will use or disclose PHI only as permitted in Cerebral’s agreements with CMG (or your own medical provider if you do not use a CMG Provider) and we only collect the PHI we need to fully perform our services and to respond to you or your Provider. We may use your PHI to contact you to the extent permitted by law, to provide requested services, to provide information to your Providers and insurers, to obtain payments for our services, to respond to your inquiries and requests, and to respond to inquiries and requests from your Providers and benefits program. We may combine your information with other information about you that is available to use, including information from other sources, such as from your Providers, insurers or benefits program, in order to maintain an accurate record of our participants. PHI will not be used for any other purpose, including marketing, without your consent.
- To any member of our group, which means our subsidiaries and affiliates, including our ultimate holding company and its subsidiaries.
- To CMG Providers (i) to schedule and fulfill appointments and provide health care services as part of the services, (ii) to whom you send messages through our services, and (iii) for other treatment, payment or health care operations purposes, including pharmacy services, upon your request.
- To health care organizations, pharmacies, contractors, service providers, and other third parties we use to support our business or in connection with the administration and support for your healthcare treatment purposes, such as CMG and Providers, Zendesk (a customer service, support and technology provider), and a third party pharmacy fulfillment and technology provider.
- To our third party service providers that provide services such as hosting our Websites or Apps, data analysis, IT services and infrastructure, customer service, email delivery, auditing, ordering, marketing, payment processing, and other similar services.
- To any third parties we believe necessary or appropriate to comply with applicable laws.
- To a buyer or other successor in the event of a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of Cerebral’s assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which personal information held by Cerebral about our Website or App users is among the assets transferred.
- To fulfill the purpose for which you provide it. For example, if you email us asking us to contact a third party (including a medical professional), we may transmit the contents of your email to the recipient.
- For any other purpose disclosed by us when you provide the information.
- With your consent.
We strive to provide you with choices regarding the personal information you provide to us. We have created mechanisms to provide you with the following control over your personal information.
Do Not Track. Some web browsers permit you to broadcast a signal to websites and online services indicating a preference that they “do not track” your online activities. We do not currently respond to “do not track” signals.
Promotional Offers from Cerebral. If you do not wish to have your contact information used by Cerebral to promote our own products or services, you can check certain boxes on the forms we use to collect your data. You can also always exercise your right to ask us not to process your personal information for marketing purposes by contacting us at the address below. If we have sent you a promotional email, you may send us a return email asking to be omitted from future email distributions. This opt out does not apply to information provided to Cerebral as a result of your use of the services.
Location Information. You can choose whether or not to allow our Apps to collect and use real-time information about your device’s location through the device’s privacy settings. If you block the use of location information, some parts of our Apps may then be inaccessible or not function properly.
Targeted Advertising. To learn more about interest-based advertisements and your opt-out rights and options, visit the Digital Advertising Alliance and the Network Advertising Initiative (NAI) websites (www.aboutads.info and www.networkadvertising.org). Please note that if you choose to opt out, you will continue to see ads, but they will not be based on your online activity. We do not control third parties’ collection or use of your information to serve interest-based advertising. However, these third parties may provide you with ways to choose not to have your information collected or used in this way. You can also opt out of receiving targeted ads from members of the NAI on its website.
With respect to any PHI Cerebral may obtain, you have certain rights under HIPAA to access your data, to restrict use and disclosure of it, to request communication methods, to request corrections to your data, to receive an accounting of disclosures and to receive notice of any breach. See the Notice of Privacy practices provided to you by your Provider for more information.
You can review and change your personal information, or delete your Cerebral account, by logging onto our Websites or Apps and visiting your “My Account” page. You may also contact us at the address below—or by emailing email@example.com—to request access to, correct, or delete any personal information that you have provided to us. We cannot delete your personal information except by also deleting your user account. If Cerebral deletes your user account, medical providers, including Providers, and other affiliates may still have the right to retain information as required by applicable law, regulations, or their own retention policy. We may not accommodate a request to change information if we believe the change would violate any law or legal requirement or cause the information to be incorrect. Unless otherwise required by law, Cerebral will also erase personal information when the personal information is no longer necessary in relation to the purposes for which was collected or otherwise processed; when you withdraw your consent (where lawfulness of processing was based on your consent) and there is no other legal ground for the processing; when you object to the processing and there are no overriding legitimate grounds for the processing; when your personal information has been unlawfully processed; and when it is necessary to comply with legal obligations.
With respect to any PHI Cerebral may obtain, you have certain rights under. Please review the Notice of Privacy Practices provided to you by your Provider for more information.
We have implemented measures designed to secure your personal information from accidental loss and from unauthorized access, use, alteration, and disclosure. We use encryption technology for information sent and received by us.
The safety and security of your information also depends on you. Where we have given you (or where you have chosen) a password that enables you to access certain parts of our Websites and Apps, you are responsible for keeping this password confidential. We ask you not to share a password with anyone. The information you share in public areas may be viewed by any user of the Websites or Apps.
Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal information, we cannot guarantee the security of your data transmitted to our Websites or Apps; any transmission is at your own risk.
Categories of Personal Information Cerebral Collects – California Residents
Personal information does not include information that is: (a) publicly available information from government records; (b) de-identified or aggregated consumer information; or (c) certain information excluded from the scope of CCPA (e.g., PHI covered under HIPAA and medical information covered under the California Medical Information Act).
Categories of Sources from which Cerebral has collected Personal Information
We collect personal information directly from you, for example when you provide it to us to when you contact us to our Websites or Apps, for the creation of a Cerebral account; and indirectly from you automatically through your computer or device as you use our Websites or Apps. We may also collect personal information about you from our advertising partners and service providers.
Use of Personal Information Collected from California Residents
Sharing Personal Information - California Residents
Cerebral may disclose your personal information to a third party for one or more business purposes. When we disclose personal information for a business purpose, such as to service providers, we enter a contract that describes the purpose and requires the recipient to both keep that personal information confidential and not use it for any purpose except performing the contract.
Disclosures of Personal Information for Business Purposes:
We may disclose your personal information for our business purposes, such as your contact information, other information you have provided to us and unique identifiers that identify you to us or to our service providers, such as companies that assist us with marketing and advertising. Please refer to Information We Collect About You and How We Collect It for additional information and details.
We disclose your personal information to certain third parties such as our health care Provider partners, service providers, including companies that assist us with marketing and advertising. For additional information please refer to “How We Use Your Information” and “Disclosure of Your Information”).
Access Request Rights
California residents have the right to request that Cerebral disclose certain information to you about our collection and use of your personal information over the past 12 months for the above business and commercial purposes. To submit an access request, see Exercising Access and Deletion Rights. Once we receive and confirm your verifiable consumer request, we will disclose to you:
- The categories of personal information we collected about you.
- The categories of sources for the personal information we collected about you.
- Our business or commercial purpose for collecting that personal information.
- The categories of third parties with whom we share that personal information.
- The specific pieces of personal information we collected about you.
- If we sold or disclosed your personal information for a business purpose, two separate lists disclosing:
Deletion Request Rights
California residents have the right to request that Cerebral delete your personal information that we collected from you and retained, subject to certain exceptions. Once we receive and confirm your verifiable consumer request, we will delete (and direct our service providers to delete) your personal information from our records, unless certain exceptions apply.
Exercising Access and Deletion Rights
To exercise the access and deletion rights described above, please submit a verifiable consumer request to us by either:
- Calling us at 415-403-2156.
- Emailing us at firstname.lastname@example.org.
Only you, or a person registered with the California Secretary of State that you authorize to act on your behalf, may make a verifiable consumer request related to your personal information. You may also make a verifiable consumer request on behalf of your minor child. You may only make a verifiable consumer request for access twice within a 12-month period. The verifiable consumer request must:
- Provide sufficient information that allows us to reasonably verify you are the person about whom we collected personal information or an authorized representative.
- Describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.
We will not discriminate against you for exercising any of your CCPA rights. Unless permitted by the CCPA, we will not:
- Deny your goods or services.
- Charge you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties.
- Provide you a different level or quality of goods or services.
- Suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services.
Other California Privacy Rights
California Civil Code Section 1798.83 (California’s “Shine the Light” law) permits users of our Websites that are California residents and who provide personal information in obtaining products and services for personal, family, or household use to request certain information regarding our disclosure of personal information to third parties for their own direct marketing purposes. If applicable, this information would include the categories of personal information and the names and addresses of those businesses with which we shared your personal information with for the immediately prior calendar year (e.g. requests made in 2020 will receive information regarding such activities in 2019). You may request this information once per calendar year. To make such a request, please contact us by email at email@example.com.
This notice describes how the medical information about you may be used and disclosed and how you can get access to this information. Please review it carefully:
This Notice of Privacy Practices (the “Notice”) describes how Cerebral Medical Group, P.A. and all members of its Affiliated Covered Entity (collectively, “Cerebral Medical Group,” “we,” “our,” or “us”) may use and disclose your protected health information to carry out treatment, payment or business operations and for other purposes that are permitted or required by law. An Affiliated Covered Entity is a group of health care providers under common ownership or control that designates itself as a single entity for purposes of compliance with the Health Insurance Portability and Accountability Act (“HIPAA”). The members of the Cerebral Medical Group Affiliated Covered Entity will share protected health information with each other for the treatment, payment, and health care operations of the Cerebral Medical Group Affiliated Covered Entity and as permitted by HIPAA and this Notice of Privacy Practices. For a complete list of the members of the Cerebral Medical Group Affiliated Covered Entity, please contact the Cerebral Medical Group Privacy Office.
“Protected health information” or “PHI” is information about you, including demographic information, that may identify you and that relates to your past, present or future physical health or condition, treatment or payment for health care services. This Notice also describes your rights to access and control your protected health information.
Uses and disclosures of protected health information:
Your protected health information may be used and disclosed by our health care providers, our staff, and others outside of our office that are involved in your care and treatment for the purpose of providing health care services to you, to support our business operations, to obtain payment for your care, and any other use authorized or required by law.
We will use and disclose your protected health information to provide, coordinate, or manage your health care and any related services. This includes the coordination or management of your health care with a third party. For example, your protected health information may be provided to a health care provider to whom you have been referred to ensure the necessary information is accessible to diagnose or treat you.
Your protected health information may be used to bill or obtain payment for your health care services. This may include certain activities that your health insurance plan may undertake before it approves or pays for your services, such as: making a determination of eligibility or coverage for insurance benefits and reviewing services provided to you for medical necessity.
Health care operations:
We may use or disclose, as needed, your protected health information in order to support the business activities of this office. These activities include, but are not limited to, improving quality of care, providing information about treatment alternatives or other health-related benefits and services, development or maintaining and supporting computer systems, legal services, and conducting audits and compliance programs, including fraud, waste and abuse investigations.
Uses and disclosures that do not require your authorization:
We may use or disclose your protected health information in the following situations without your authorization. These situations include the following uses and disclosures: as required by law; for public health purposes; for health care oversight purposes; for abuse or neglect reporting; pursuant to Food and Drug Administration requirements; in connection with legal proceedings; for law enforcement purposes; to coroners, funeral directors and organ donation agencies; for certain research purposes; for certain criminal activities; for certain military activity and national security purposes; for workers’ compensation reporting; relating to certain inmate reporting; and other required uses and disclosures. Under the law, we must make certain disclosures to you upon your request, and when required by the Secretary of the Department of Health and Human Services to investigate or determine our compliance with the requirements of HIPAA. State laws may further restrict these disclosures.
Uses and disclosures that do require your authorization:
Other permitted and required uses and disclosures will be made only with your consent, authorization or opportunity to object unless permitted or required by law. Without your authorization, we are expressly prohibited from using or disclosing your protected health information for marketing purposes. We may not sell your protected health information without your authorization. Your protected health information will not be used for fundraising. We will not use or disclose your psychotherapy notes without your authorization, except as permitted by law. If you provide us with an authorization for certain uses and disclosures of your information, you may revoke such authorization, at any time, in writing, except to the extent that we have taken an action in reliance on the use or disclosure indicated in the authorization.
Your rights with respect to your protected health information:
You have the right to inspect and copy your protected health information.
You may request access to or an amendment of your protected health information.
You have the right to request a restriction on the use or disclosure of your protected health/personal information. Your request must be in writing and state the specific restriction requested and to whom you want the restriction to apply. We are not required to agree to a restriction that you may request, except if the requested restriction is on a disclosure to a health plan for a payment or health care operations purpose regarding a service that has been paid in full out-of-pocket.
You have the right to request to receive confidential communications from us by alternative means or at an alternate location. We will comply with all reasonable requests submitted in writing which specify how or where you wish to receive these communications.
You have the right to request an amendment of your protected health information. If we deny your request for amendment, you have the right to file a statement of disagreement with us. We may prepare a rebuttal to our statement and we will provide you with a copy of any such rebuttal.
You have the right to receive an accounting of certain disclosures of your protected health information that we have made, paper or electronic, except for certain disclosures which were pursuant to an authorization, for purposes of treatment, payment, healthcare operations (unless the information is maintained in an electronic health record); or for certain other purposes.
You have the right to obtain a paper copy of this Notice, upon request, even if you have previously requested its receipt electronically by e-mail.
Revisions to this notice:
We reserve the right to revise this Notice and to make the revised Notice effective for protected health information we already have about you as well as any information we receive in the future. You are entitled to a copy of the Notice currently in effect. Any significant changes to this Notice will be posted on our web site. You then have the right to object or withdraw as provided in this Notice.
Breach of health information:
We will notify you if a reportable breach of your unsecured protected health information is discovered. Notification will be made to you no later than 60 days from the breach discovery and will include a brief description of how the breach occurred, the protected health information involved and contact information for you to ask questions.
Complaints about this Notice or how we handle your protected health information should be directed to our HIPAA Privacy Officer. If you are not satisfied with the manner in which a complaint is handled you may submit a formal complaint to the Department of Health and Human Services, Office for Civil Rights by sending a letter to 200 Independence Avenue, S.W., Washington, D.C. 20201, calling 1-877-696-6775, or visiting www.hhs.gov/ocr/privacy/hipaa/complaints/. We will not retaliate against you for filing a complaint.
We must follow the duties and privacy practices described in this Notice. We will maintain the privacy of your protected health information and to notify affected individuals following a breach of unsecured protected health information. If you have any questions about this Notice, please contact us at (415) 403-2156 and ask to speak with our HIPAA Privacy Officer.
Acknowledgment of receipt of notice of privacy practices:
By clicking and opting in, you acknowledge that you have received or been given an opportunity to receive this Notice of Privacy Practices.
If you are the parent or personal representative of the Patient, by clicking and opting in, you acknowledge on behalf of the Patient that you have received or been given an opportunity to receive this Notice of Privacy Practices.
340 S Lemon Ave #9892 Walnut, CA 91789
Email: firstname.lastname@example.org or email@example.com