Privacy & Security
Health Insurance Portability and Accountability Act Privacy Policy
Notice of Privacy Practices
Dear Patient
THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.
This Notice of Privacy Practices (the “Notice”) describes the privacy practices of Demo Pharmacies, including its retail outlets and demopharmacy.com (collectively “Demo”). As a company and as required by law, Demo is fully committed to protecting the privacy of your Protected Health Information (PHI). PHI is information that may identify you and that relates to your past, present or future physical or mental health and the related healthcare services. Your PHI is protected by the Health Insurance Portability and Accountability Act (“HIPAA”) and applicable state laws, which require us to provide you with this Notice.
This Notice will describe your rights to your PHI, explain how we may use your PHI, and explain when we are required to get your permission to disclose your PHI. As described in this Notice, we owe you certain duties in regard to your PHI. We will not use or disclose your PHI without your written authorization, except as described or otherwise permitted by this Notice. We are required by law to follow the terms of this Notice.
We reserve the right to change our privacy practices and the terms of this Notice at any time and will make any new Notice available upon request. For more information about our privacy practices or to request additional copies of this Notice, please contact us as provided below.
How and When We May Use or Disclose Your PHI Without Your Permission
Federal law permits the use or disclosure of your PHI without your permission for the following purposes:
- Treatment: We may use or disclose your PHI to provide and coordinate the treatment, medications, and services you receive. For example, we may communicate with physicians, their staff, and other healthcare professionals to ensure you receive appropriate treatment. Furthermore, we may use your PHI to contact you regarding, medications, equipment, refill reminders, product recalls, or treatment alternatives.
- Payment: We may use or disclose your PHI to facilitate billing and payment for the pharmacy services we have provided. For example, we may contact your insurer or healthcare payer to determine whether it will pay for the medications dispensed to you. The information on or accompanying the bill may include information that identifies you and the medications you have been prescribed.
- Healthcare Operations: We may use and disclose your PHI in connection with our healthcare operations. Healthcare operations include quality assessment and improvement activities, reviewing the competence or qualifications of healthcare professionals, evaluating practitioner and provider performance, conducting training programs, and accreditation, certification, licensing or credentialing activities.
Other Special Circumstances When We may Use Your PHI Without Your Permission
While the situations addressed below may never arise, we may disclose your PHI without your permission under federal and state law as described below:
- To Business Associates: We operate our business and provide some services with the assistance of other companies called “business associates.” We may disclose your PHI to our business associates, but we have entered into agreements with these entities to safeguard your PHI.
- To communicate with individuals involved in your care or payment for your care: We may share information about you with your family members and friends who are involved in your care or payment for your care. Whenever possible, we will allow you to tell us who you would like to be involved in your care. However, in emergencies or other situations in which you are unable to tell us who to share information with, we will use our best judgment and share only information that others need to know. You have the right to request restrictions on disclosure to family members, other relatives, close personal friends, or any other person identified by you.
- To parents or legal guardians: If you are a minor, we may release your PHI to your parents or legal guardians when we are permitted or required by law.
- Worker’s Compensation: We may share your PHI with those who need it in order to provide benefits for work-related injuries or illness.
- Law Enforcement: We may disclose your PHI for law enforcement purposes as required by law or in response to a subpoena or court order.
- Public Health: We may disclose your PHI to the appropriate authorities charged with preventing and controlling disease, injury, or disability for public health activities.
We must also disclose your PHI without your permission as required by applicable federal or state law as described below.
- Health Oversight Activities. We may disclose your PHI to an oversight agency for activities authorized by law. These oversight activities include audits, investigations, inspections, and credentialing, as necessary for licensure and for the government to monitor the healthcare system, government programs, and compliance with civil rights laws.
- Judicial and Administrative Proceedings. If you are involved in a lawsuit or a dispute, we may disclose your PHI in response to a court or administrative order, subpoena request, discovery request, or other lawful process.
- Research. We may disclose your PHI to researchers when the research has previously been reviewed and approved by an institutional review board or privacy board that has examined the research proposal and established protocols to ensure the privacy of your information.
- Coroners, Medical Examiners, and Funeral Directors. We may release your PHI to a coroner or medical examiner to identify a deceased person or determine the cause of death. We may also disclose PHI to funeral directors consistent with applicable law to enable them to carry out their duties.
- Organ or Tissue Procurement Organizations. Consistent with applicable law, we may disclose your PHI to organ procurement organizations or other entities engaged in the procurement, banking, or transplantation of organs for the purpose of tissue donation and transplant.
- Notification. We may use or disclose your PHI to notify or assist in notifying a family member, personal representative, or another person responsible for your care, regarding your general condition, status, and location.
- Correctional Institution. If you are an inmate or become incarcerated in a correctional institution, we may disclose to the institution or its agents any PHI necessary for your health and the health and safety of others.
- To Avert a Serious Threat to Health or Safety. We may use and disclose your PHI when necessary to prevent a serious threat to your health and safety or the health and safety of the public.
- Military and Veterans. If you are a member of the armed forces, we may release PHI about you as required by military authorities. We may also release PHI about foreign military personnel to the appropriate foreign military authority.
- National Security, Intelligence Activities, and Protective Services for the President and Others. We may release PHI about you to federal officials for intelligence, counterintelligence, protection of the President or foreign heads of state, and other national security activities authorized by law.
- Victims of Abuse or Neglect. We may disclose PHI about you to a government authority if we reasonably believe you are a victim of abuse or neglect. We will only disclose this type of information to the extent required by law, if you agree to the disclosure, or if the disclosure is allowed by law and we believe it is necessary to prevent serious harm to you or someone else.
Pursuant to South Carolina law, we will not disclose your prescription drug information without first obtaining your consent, except in the following circumstances: (1) the lawful transmission of a prescription drug order in accordance with all state and federal laws pertaining to the practice of pharmacy; (2) communications among licensed practitioners, licensed pharmacists, and other healthcare professionals who provide or have provided medical or therapeutic treatment, pharmacy service, or medical or therapeutic consultation service for the person who received the drug or device; (3) information gained as a result of a person requesting informational material from a prescription drug or device manufacturer or vendor; (4) information necessary to effect the recall of a defective drug or device or other information necessary to protect the health and welfare of an individual or the public generally; (5) information whereby the release or transfer is mandated by other state or federal laws, court order, or subpoena, or regulations including, but not limited to, accreditation or licensure requirements; (6) information necessary to adjudicate or process payment claims for healthcare, whether under a health insurance benefits program or other payment system, if the recipient makes no other use or further disclosure of the information; (7) information voluntarily disclosed by a patient to entities outside of the provider-patient relationship; (8) information used in clinical research monitored by an institutional review board; (9) information which does not identify patients by name, or that is encoded in a manner that information identifying a particular patient by name or address is not generally obtainable, and that is used for epidemiological studies, research, statistical analysis, medical outcomes, or pharmacoeconomic research; (10) information transferred in connection with the sale of a business or medical practice to a successor in interest; (11) information necessary to disclose to third parties in order to perform quality assurance programs, medical records review, internal audits, medical records maintenance, or similar programs, if the third party makes no other use or further disclosure of the information; (12) information that may be revealed to a party who, on behalf of the patient, obtains a dispensed prescription from a pharmacy; (13) information necessary to disclose to third parties in order for a health plan licensed by the South Carolina Department of Insurance to perform case management, utilization management, and disease management for individuals enrolled in that health plan, if the third party makes no other use or further disclosure of the information.
We will not disclose your information or the nature of the professional pharmacy services rendered to you, without your express consent or upon order of a court, except to the persons and entities listed below: (a) a patient, or patient’s agent, or another pharmacist acting on behalf of a patient; (b) the practitioner who issued the prescription drug order; (c) certified/licensed healthcare personnel who are responsible for the care of the patient; (d) an inspector, agent, or investigator of the Board of Pharmacy or any federal, state, county, or municipal officer whose duty is to enforce the laws of this State or the United States relating to drugs or devices and who is engaged in a specific investigation involving a designated person or drug; (e) an agency of government charged with the responsibility of providing medical care for the patient upon written request by an authorized representative of the agency requesting the information.
How and When We May Use or Disclose Your PHI With Your Permission
We will obtain your written authorization before using or disclosing your PHI for purposes other than those provided for above (or as otherwise permitted or required by law). Furthermore, once your permission has been obtained, we must use or disclose your PHI in accordance with the specific terms of that permission. You may revoke an authorization in writing at any time. Upon receipt of the written revocation, we will stop using or disclosing your PHI, except to the extent that we have already taken action in reliance on the authorization.
The following uses and disclosures specifically require written authorization:
- Psychotherapy Notes: Most uses and disclosures of psychotherapy notes;
- Marketing: Uses and Disclosures of PHI for marketing purposes unless (i) the communication occurs face-to-face; (ii) consists of marketing gifts of nominal value; (iii) is regarding a prescription refill reminder that is for a prescription currently prescribed or a generic equivalent; (iv) is for treatment pertaining to existing condition(s) and Demo does not receive any financial remuneration in either cash or cash equivalent; and/or (v) communication from a healthcare provider to recommend or direct alternative treatments, therapies, healthcare providers, or settings of care when Demo does not receive any financial compensation for making the communication; and
- Sale of PHI: Disclosures that constitute a sale of PHI.
Your Rights Concerning Your PHI
The records we create and maintain using your PHI belong to Demo, but you have the following rights:
Right to Review and Get a Copy of Your PHI: You have the right to look at and get a copy of your PHI, including billing records. You must first make your request in writing to the Privacy Office (“Privacy Office”) at the address provided at the end of this notice. We may charge a fee to cover copying, mailing, and other costs and supplies used to respond to your request. In very limited situations, we may deny your request for certain information. If we deny your request, we will give you the reason for the denial in writing.
Right to Request an Amendment to Your PHI: If you think our information about you is not correct or not complete, you may ask us to correct the record by writing to our Privacy Office at the address listed at the end of this notice. Your written request must give the reason you ask for a correction. We have thirty (30) days to respond to your request, with the option for a thirty (30) day extension if we provide you with advance written notification. If we accept your request, we will tell you we agree and add the correction. We cannot remove any information out of your medical records, but we can add new information to complete or correct the existing information. If we deny your request, we will tell you in writing the reasons and you have the right to submit a written statement that outlines what information you believe is not correct or is missing. We will add your written statement to your records and include it whenever we share the part of your medical record that your written statement relates to.
Right to Ask for an Accounting of Disclosures: You have the right to request a list of when your PHI was shared without your written consent for purposes other than treatment, payment or healthcare operations. Any accounting of disclosures will not include disclosures made: (1) directly to you or your personal representative; (2) to your family members or friends who are involved in your care; (3) as required or permitted by law as described above; (4) as part of a limited data set with direct identifiers removed. Any accounting will not include any PHI released before April 14, 2003.
Any request for this list must be made in writing to the Privacy Office at the address listed at the end of this notice. The first list you request within a 12-month period will be free, but we will charge you a fee for additional requests made during the same period.
Right to Ask for Limits on the Use and Sharing of Your Medical Information: You have the right to ask that we limit our use or sharing of information about you for treatment, payment or healthcare operations. You also have the right to ask us to limit the PHI we disclose about you to someone who is involved in your care or the payment for your care, like a family member or friend. We reserve the right to accept or reject your request. Generally, we will not accept restrictions on disclosures relating to treatment, payment or healthcare operations, with one exception. As a patient, you now have the right to request that we not disclose to an insurer treatment and/or services you pay for in full with your personal funds only. If you wish to make this request, please make the pharmacy staff aware prior to your prescription being filled.
You must submit your request to restrict the use and sharing of your medical information in writing to the Privacy Office at the address listed at the end of this notice. In your request, you must tell us (1) what information you want to limit (2) whether you want to limit our use, disclosure or both and (3) to whom you want the limits to apply. We will notify you if we do not agree to your request. If we do agree, our agreement must be in writing, and we will comply with the approved restriction except in some emergency situations. We are allowed to end the approved restriction if we inform you in advance. If we end the restriction, it will only affect PHI that was created or received after we notify you that the restriction has ended.
Right to Ask for Confidential Communications: You have the right to ask us to communicate with you in a certain way or at a certain location. For example, you can ask that we contact you only at your place of employment.
You must make your request in writing to our Privacy Office at the address given at the end of this notice. Your request must specify how or where you wish to be contacted. You will also be required to tell us the appropriate address to send bills for payment. If we are unable to contact you in the requested manner or at the requested locations, we may contact you using any information we have.
Right to be Notified of a Breach: You have the right to be notified in the event that we (or one of our Business Associates) discovers a breach of unsecured PHI involving your information.
Right to Get a Paper Copy of This Notice: You have the right to get a paper copy of this notice, even if you have agreed to receive this notice electronically. You may get a copy at any of our facilities, by contacting the Privacy Office as listed below, or by visiting our website at www.demopharmacy.com
Questions or Complaints about our Use of Your PHI
If you want more information about our privacy practices or have any questions or concerns, please do not hesitate to contact us.
If you are concerned that we may have violated your privacy rights, or you disagree with a decision we made about access to your PHI or in response to a request you made to amend or restrict the use or disclosure of your PHI or to have us communicate with you by alternative means or at alternative locations, you may send a written complaint to our office or to the Secretary of Health and Human Services. We will not retaliate against you and you will not be treated differently if you file a complaint.
Contact Information
Demo Privacy Office
Attn: Privacy Officer
PO Box 6052
Spartanburg, SC 29304
Phone: 1-800-845-7558
Fax: (864) 253-8690
Email: privacyofficer@demopharmacy.com
demopharmacy.com Privacy Policy
demopharmacy.com provides internet-related services to independent pharmacies throughout the United States, including accepting orders from a participating pharmacy’s online customers and forwarding those orders to the pharmacy. demopharmacy.com also makes a variety of health-related information available to those using its site, including the sites of participating pharmacies. As a business associate of the pharmacies we represent CornerDrugstore in full compliance with the Health Insurance Portability and Accountability Act (HIPAA) that governs the protection of your health information.
Your privacy is important to us. At demopharmacy.com, we understand that your health is a very personal, private subject. We want you to feel as comfortable as possible visiting our web site and using our services. Our Privacy Policy will tell you what information we collect that could be used to identify or contact you (“Personal Information”), how we protect this Personal Information, and what choices you have about how this Personal Information is used. We urge you to read this policy so that you will understand our commitment to you and your privacy, and how you can participate in that commitment.
The following sections make up our Privacy Policy. We hope that reading them gives you a clear idea of how we manage your information. Click on the title of any section to quickly access a particular topic.
Terms and Conditions
Our Terms and Conditions are part of and incorporated into this Agreement.
Personal Information We Collect
You may provide Personal Information to demopharmacy.com either at the main demopharmacy.com site or through the sites we operate on behalf of specific, individual participating pharmacies. We collect information in four areas: (1) Selecting a Store; (2) My Account; (3) Profiles; and (4) Filling Prescriptions. The information we collect in these areas includes:
Selecting a Store | My Account Full Name | Profiles Gender | Filling Prescriptions Pharmacy Info |
My Account and the Profiles stored within (“My Account”) allow you to record limited amounts of personal health information, on a voluntary basis, on servers maintained by demopharmacy.com, or on its behalf. The Personal Information in My Account may be modified only by means of a valid password that you create. Whenever you submit or modify the information in My Account, we will send such information over the Internet using Secure Socket Layer (“SSL”), version 3 (or other later versions) encryption technology. The information you submit to My Account will be stored on a secure server. However, we do not guarantee that the information you submit to My Account will be protected against loss, misuse, or alteration by third parties.
We also collect information about you, and your use of our site, through the use of Cookies. Cookies are small computer files that we transfer to your computer’s hard drive. They allow us to know how often someone visits our site and the activities they conduct while on our site. This information helps us to dynamically generate web page content specifically designed for you. It also allows us to statistically monitor how many people are using our site and for what purpose. To use this site, you must have your Internet browser set to allow the use of cookies.
Disclosure of Your Information
demopharmacy.com will share your Personal Information (specifically, your account information, profiles and prescription order history) with the pharmacy you have designated to fill your prescription or other order. Authorized employees and agents of that pharmacy will have access to the Personal Information you provide. demopharmacy.com discloses your account information, profiles and prescription history only to the pharmacy you have designated to fill your prescriptions. Any Personal Information provided to that designated pharmacy is required to be treated in accordance with the terms of this Privacy Policy, unless you are otherwise notified.
Except as set forth in this and the following paragraphs, demopharmacy.com will not disclose to other third parties any of your Personal Information. In the following limited circumstances we will consider, and may release, Personal Information to third parties: (1) to comply with valid legal requirements such as a law, regulation, search warrant, subpoena or court order; or (2) in special cases where we in good faith believe that disclosing this information is necessary to identify, contact or bring legal action against someone who may cause injury to others.
demopharmacy.com may provide information about you, which does not allow you to be identified or contacted (“Aggregate Information”), to third parties. For example, we might inform third parties of the number of users of our site and the activities they conduct while on our site. We might also inform a pharmaceutical company (that may or may not be an advertiser on our site) that “30% of our users live east of the Mississippi” or that “25% of our users have tried alternative medicine.” Depending on the circumstances, we may or may not charge for this information.
Except as provided in this section, demopharmacy.com will not disclose any Personal Information that you store in My Account. The My Account service is a powerful storage tool that we hope you will enjoy. However, please note that you are responsible for taking all reasonable steps to ensure that no unauthorized person knows your password to My Account. It is your sole responsibility to (1) control the dissemination and use of activation codes and passwords; (2) authorize, monitor, and control access to and use of your My Account password; (3) promptly inform demopharmacy.com of any need to deactivate a password. To deactivate a password, please call a Customer Care Representative at 1-800-559-5489.
demopharmacy.com’s Policy Concerning Information from Children
demopharmacy.com does not collect or maintain Personal Information for individuals that identify themselves as children under the age of 13. The demopharmacy.com site is not intended for use by children under the age of 13.
If information from a child under the age of 13 is knowingly received by demopharmacy.com, we will respond to the inquiry, if appropriate, and delete all personally identifiable information concerning that child from our records. That information will not be used for any other purposes, nor will it be disclosed to any other parties.
If a parent believes that his or her child has submitted personal information to demopharmacy.com, they may contact demopharmacy.com by e-mail at support@demopharmacy.com ; by postal mail at 201 West Saint John Street, P.O. Box 6052, Spartanburg, SC 29306; or by phone at 800-559-5489.
demopharmacy.com will promptly delete the information upon learning that it relates to a child. As noted above, demopharmacy.com will not knowingly collect any information from a child.
How demopharmacy.com Handles Privacy Internally
demopharmacy.com wants your personal information to remain as secure as reasonably possible. We provide technical safeguards and have a code of conduct for demopharmacy.com employees that are permitted to access our customers’ personal information.
On the technical side, demopharmacy.com uses SSL to help ensure the integrity and privacy of the Personal Information you provide to us via the Internet. All of our web servers are protected by a high security layer (Firewall) to prevent unauthorized access to our web site and servers. As an additional security measure, your Personal Information is kept on a separate server where your password is encrypted and stored on a database behind an additional layer of security (Firewall).
All demopharmacy.com employees must abide by our Privacy Policy. Those who violate our Privacy Policy are subject to disciplinary action, up to and including termination. Access by authorized personnel is controlled by secure authentication (i.e., an I.D., Encrypted Password). If you link to another site from this site, demopharmacy.com cannot be responsible for the security of your personal information on that site or their privacy policies.
Your Privacy Choices
When you create My Account, you will be given the option of receiving recurring emails from demopharmacy.com and/or third parties about new products, site features and special offers, and/or about new health and wellness features. You may choose not to receive these emails at the time you create My Account, or by changing your preferences within My Account at any time.
Updating Your Personal Information and Contacting demopharmacy.com
You can always contact us in order to (i) deactivate your account and profiles, (ii) update the Personal Information that you have provided to us, and (iii) change your preferences with respect to marketing contacts, by emailing us at support@demopharmacy.com .
Your use of the site constitutes acceptance of the provisions of this Privacy Policy. demopharmacy.com may change this Privacy Policy at any time. Registered users will be notified by email if there are substantive changes in this Privacy Policy. At that time, users will be given the opportunity to cancel their accounts if they do not accept the policy changes. If you do not agree to the terms of this Privacy Policy, or any revised policy, please do not use the site.