Web Privacy Policy
The Company (hereinafter referred to as “us,” “we,” “our,” or “Company”) has created this Privacy Policy to apply to all users of this website (MercyHealthRehabHospital.com) and all digital assets contained, or offered therein (collectively, our “Services”), except as described below. This Privacy Policy describes, among other things, what information we collect from users when you use our Services, how it is used and your options as you interact with our Services.
This Privacy Policy is integrated into our Terms of Use (“Terms of Use”). By using the Services and providing us with your personal Information (defined below), you agree to the practices regarding collection, use, and sharing of information as described in this Privacy Policy and Terms of Use referenced above and to the updates to these policies posted here from time to time. Please read the following carefully before using our Services.
Patients can opt to create a patient portal account. This is a secure portal available for patients to manage their health. Features include reviewing test results, managing appointments, messaging your doctor, renewing your prescriptions, and paying your bills. Before creating an account, please review any Terms and Conditions available on the patient portal. This Privacy Policy does not apply to Protected Health Information (“PHI”) as defined under the Health Insurance Portability & Accountability Act and related regulations (collectively referred to as “HIPAA”), including information you provide to us while being treated as a patient or within the patient portal, which is separate and subject to our Notice of Privacy Practices.
Further, this Privacy Policy does not apply to information collected by or provided in connection with an individual’s application for employment, current or former employment, or independent contractor arrangements with the Company. If you are a Company employee, independent contractor, or applicant for employment, please see the Notice at Collection and Privacy Policy for HR Individuals Who Reside in California or Notice at Collection and Privacy Policy for California Job Applicants for information about how the Company collects, uses, processes, discloses, shares, and retains employment information not covered by this Policy.
Residents of certain states may be entitled to individual rights under the applicable Data Protection Law(s). Please see the Notice to Certain Residents of Data Subject Rights Section of our Privacy Policy for your rights and how to exercise them for users who are residents of states that have enacted data protection laws that apply to our collection of your Information.
I. Information That We Collect
When you reply to any of our communications with a request or engage with our Services, we may need to collect the following categories of information about you which are described in more detail below: (A) information you provide to us, (B) sensitive information, (C) information we may automatically collect, and (D) information we may receive from third parties. All of the information listed in (A)-(D) above, is detailed below, and hereinafter referred to as “Information.”
If you submit any personal information relating to other people, you represent that you have the authority to do so and permit us to use the information in accordance with this Privacy Policy. By submitting personal Information, you grant us the right to transmit, monitor, retrieve, store and use your information in connection with the operation of the website and our Services.
A. Information You Provide to Us
In using our Services, you may provide us with Information, including without limitation:
- Individual Identifiers, including real name, alias, postal address, unique personal identifiers, email address, phone number, cell phone number, social media account information;
- Medical information, insurance policy information, and health insurance information;
- Demographic information and characteristics of protected classifications including marital status, sex, age, and military and veteran status if you choose to complete an online form or provide feedback;
- Professional or employment-related information, including employment status, employment location, name of employer, whether the employer provides health insurance;
- Commercial information, including information on products or services purchased, obtained, or considered, registration data, purchase, service, and installation dates;
- Communications with us, preferences, and other Information you provide to us such as any messages, opinions and feedback that you provide to us, your user preferences (such as in receiving updates and information on relevant topics and services), and other Information that you share with us when you contact us directly (such as for customer support services); and
- Additional Information as otherwise described to you at the point of collection or pursuant to your consent.
In limited situations, we may collect this information about an individual from a relative, power of attorney, attorney-in fact, or other authorized representative acting in the interests of or on behalf of the individual.
B. Sensitive Information
We may need to collect or process information that is deemed “Sensitive Personal Information” under certain laws. We may process the following categories of sensitive personal Information when you use our Services:
- Precise Geolocation data, such as your physical location if you have enabled location services on your device;
- Payment Information including debit or credit card information in combination with any required security or access code collected for purpose of processing payment for our products or Services;
- Authentication data such as account personal information and log in credentials, including unique identifiers such as username, account number, and password;
- Racial or ethnic origin information, religious creed, color, national origin;
- Biometric information;
- Genetic information;
- Personal Information concerning health such as physical or mental disability, medical condition;
- Information concerning gender identity and sexual orientation; and
- Social security number, driver’s license number, state identification card number; or passport number.
When required by applicable law, we will collect consent prior to processing certain categories of sensitive Information.
C. Information We May Automatically Collect About You
Our Services may automatically collect the following categories of usage and technical Information about you. This Information is used by the Company for the operation of the Services, to maintain the quality and security of the Services, and to provide general statistics regarding use of the Services. This Information may include:
- IP address, which is the number associated with the service through which you access the Internet, like your ISP (internet service provider);
- Date and time of your visit or use of our Services;
- Domain server from which you are using our Services;
- Type of computer, web browsers, search engine used, operating system, or platform you use;
- Data identifying the web pages you visited prior to and after visiting our website or use of our Services;
- Your movement and activity within the website, which is aggregated with other Information; and
- Mobile device Information, including the type of device you use, operating system version, and the device identifier (or “UDID”).
D. Cookies, Tracking and Internet-based Advertising
We work with companies that offer third-party products or services (“Service Providers”). We and/or certain service providers operating on our behalf may collect Information about your activity, or activity on devices associated with you over time, on our sites and applications, and across non-affiliated websites or online applications to help us track and analyze visitor activity on the website.
We may collect this Information by using certain technologies, such as cookies, web beacons, software developer kits, third-party libraries, and related technologies. These can be set by us or by our Service Providers.
- Cookies. Cookies are small data files that online services can store on, and retrieve from, a user’s computer or mobile device through the user’s web browser. The Information is stored and retrievable either for the duration of a website visit (known as “session cookies”), or until some later point in time set by the website setting the cookie (known as “persistent cookies”). Examples of Information we and our Service Providers collect include how often someone visits this website and what they do while on the website. We and our Service Providers use this Information in the aggregate to understand how our visitors as a group use different resources and to help us operate and improve our website. We and our Service Providers may also collect information about the activity of individual website users.
- Web Beacons. Website pages may contain small electronic files known as web beacons (also referred to as clear gifs, pixel tags, and single-pixel gifs) that permit us, for example, to count users who have visited those pages and for other related statistics (for example, recording the popularity of certain content and verifying system and server integrity). We also use these technical methods to analyze the traffic patterns, such as the frequency with which our users visit various parts of the Services. These technical methods may involve the transmission of Information either directly to us or to a third party authorized by us to collect Information on our behalf. We also use web beacons in HTML emails that we send to determine whether the recipients have opened those emails and/or clicked on links in those emails.
- Analytics and Fraud Detection. Analytics are tools we may use, such as Google Analytics, to help provide us with Information about traffic to our website and use of our Services, which Google may share with other services and websites that use the collected data to contextualize and personalize the ads of its own advertising network. We calculate metrics like bounce rate, page views, sessions, and the like to understand how our website/app is used. We may create visitors’ profiles based on browsing history to analyze visitor behavior, show personalized content and run online campaigns. We may also use reCAPTCHA, a tool that utilizes advanced risk analysis techniques to distinguish humans and bots in order to help us protect our websites from fraud, spam, and abuse. You can view Google’s Privacy Practices here: Privacy Policy – Privacy & Terms – Google.
- Mobile Application Technologies. If you access our website and Services through a mobile device, we may automatically collect Information about your device, your phone number, and your physical location.
We do not use online tracking technologies which may be considered a “sale” or “sharing” under certain laws.
E. Information We May Receive from Third Parties
We may collect additional Information about you from third-party websites, social media platforms and/or sources providing publicly available information (e.g., from the U.S. postal service) to help us provide services to you, help prevent fraud, and for marketing and advertising purposes.
This Privacy Policy only applies to Information collected by our Services. We are not responsible for the privacy and security practices of those other websites or Social Media Platforms or the Information they may collect (which may include IP address). You should contact such third parties directly to determine their respective privacy policies and practices. Links to any other websites or content do not constitute or imply an endorsement or recommendation by us of the linked website, Social Media Platform, and/or content.
II. How We Use This Information
A. Use and Purpose of Processing Your Information
We use and process the Information for numerous business and operational purposes that may include, but are not limited to, the following:
- Auditing related to a current interaction with the consumer and concurrent transactions, including, but not limited to, counting impressions to unique visitors, verifying positioning and quality of impressions, and auditing compliance with the law;
- Detecting security incidents, protecting against malicious, deceptive, fraudulent, or illegal activity, and prosecuting those responsible for that activity;
- Debugging to identify and repair errors that impair existing intended functionality;
- Performing services, including maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments, and providing analytic services;
- Undertaking internal research for technological development and demonstration;
- Undertaking activities to verify or maintain the quality or safety of a service or device that is owned, manufactured, manufactured for, or controlled by the Company, and to improve, upgrade, or enhance the service or device that is owned, manufactured, manufactured for, or controlled by the Company;
- Product and service training, for example, by providing training and information on using, servicing, selling, and displaying our products and services;
- Facilitating communications, for example, by collecting and organizing contact information, establishing means of communications, and communicating with current and prospective customers, including regarding questions and feedback;
- Responding to consumer comments or concerns posted on social media platforms, our website or other outlets relating to the Company or a Company-operated facility;
- Enhance and personalize the site, to communicate with consumers via email and to understand a consumer’s preferences and patterns;
- To conduct market research and analysis;
- Improve our website offerings and send you information and updates;
- Comply with our Terms of Use;
- To fulfill contracts we have with you;
- Comply with any applicable laws and regulations and respond to lawful requests; and/or
- For any other purposes disclosed to you at the time we collect your Information and/or pursuant to your consent.
B. Disclosing Your Information
We may disclose your Information as set forth in the Privacy Policy and in the following circumstances:
- Third-Party Service Providers. We may disclose information to third-party, service providers that perform certain functions or services on our behalf (such as to host the Services, manage databases, perform analyses, process credit card payments, provide customer service, or send communications for us, to help us manage this website, provide content and information, and interact better with our patients and visitors). These third-party service providers are authorized to use your Information only as necessary to provide these services to us for example a third-party contracted by us may have access to your Information to perform a specific task, for example, to send you an e-newsletter. In some instances, we may aggregate Information we collect so third parties do not have access to your identifiable Information to identify you individually.
- Disclosure of Information for Legal and Administrative Reasons. We may disclose your Information without notice: (i) when required by law or to comply with a court order, subpoena, search warrant, or other legal process; (ii) to cooperate or undertake an internal or external investigation or audit; (iii) to comply with legal, regulatory, or administrative requirements of governmental authorities (including, without limitation, requests from the governmental agency authorities to view your Information); (iv) to protect and defend the rights, property, or safety of us, our subsidiaries and affiliates, and any of their officers, directors, employees, attorneys, agents, contractors, and partners, and the website Service users; (v) to enforce or apply our Terms & Conditions; and (vi) to verify the identity of the user of our Services.
- Healthcare Entities. We may also disclose personal information to other healthcare entities, insurance companies, or other payor sources in order to verify insurance benefits or process payment for medical services. We may also share personal information of prospective patients for the purposes of locating appropriate healthcare services for a consumer.
- Transfer in the Event of Business Transfer. If the ownership of our business changes or we need to transfer assets relating to this website to a third party such as where we: (i) merge with or are acquired by another business entity; (ii) sell all or substantially all of our assets; (iii) are adjudicated bankrupt; or (iv) are liquidated or otherwise reorganize, we may transfer your personal information to the third party. Your information would remain subject to the promises made in the applicable Website Privacy Policy unless you specify otherwise.
- Information Shared with our Subsidiaries and Affiliates. We may share your Information with our subsidiaries and affiliates.
- De-Identified or Aggregated Data. We may share your Information on an aggregated basis for any purpose in which your specific personal Information is blinded, masked, or otherwise not identifiable. For example, occasionally we may request feedback on this website to better understand how we can improve what information we present and how we present it. These surveys do not ask questions that could personally identify you. We may ask for contact information to follow-up, but you can decline to provide that Information. Information that you provide in a survey may be shared with employees or third parties to aggregate the data.
- With Your Consent. We may share Information consistent with this Privacy Policy with your consent.
The Company does not use or disclose sensitive personal Information, other than for the business purposes permitted by law as described above.
C. Sales and Sharing of Personal Information
The CCPA defines “sale” as disclosing or making available personal information to a third-party in exchange for monetary or other valuable consideration, and “sharing” includes disclosing or making available personal information to a third-party for purposes of cross-context behavioral advertising. We do not sell or share sensitive personal information, nor do we sell or share personal information about individuals we know are under age sixteen (16).
III. Data Security
We are committed to protecting the privacy of the personal Information you provide to us. Accordingly, we use reasonable and appropriate administrative, physical, and technical security measures in efforts to prevent unauthorized access. We use a secure firewall and a security infrastructure that protects the integrity and privacy of personal Information submitted to us via this website. Although we work hard to protect your personal Information, we cannot guarantee the security of any Information you transmit to us through online applications, and you do so at your own risk. Therefore, we do not promise or guarantee, and you should not expect, that your Information or private communications will always remain private or secure. We do not guarantee that your Information will not be misused by third parties. We are not responsible for the circumvention of any privacy settings or security features. You agree that we will not have any liability for misuse, access, acquisition, deletion, or disclosure of your Information.
If you believe that your Information has been accessed or acquired by an unauthorized person, you should promptly Contact Us so that necessary measures can quickly be taken.
Please do not provide personal Information via email to us unless it is through a secure channel (these will be marked, as secure online forms, for example). If you have personal Information to communicate, please use the appropriate secure online form or contact the necessary party using traditional means such as phone or mail.
If you receive an email that looks like it is from us and asks for your personal Information, do not respond. This may be a scam or “Phishing” email intended to steal your Information. We will never request your password, username, credit card information or other personal Information through email.
IV. Links to External Websites
This online Privacy Policy applies only to our Services. This website may contain links to other websites or services that are not owned or controlled by us, including links to Social Media Platforms such as Facebook, Instagram, or YouTube, or may redirect you off our website away from our Services. Please be aware that this Privacy Policy only applies to Information collected by our Services and does not apply to those websites. We are not responsible for the privacy and security practices of those other websites or Social Media Platforms or the Information they may collect (which may include IP address). We encourage you to read the Privacy Policy on any other websites before providing them with personal information. Certain interactive patient applications may be linked to this website as a convenience for you. If you choose to utilize a specific patient application, please be sure to read the privacy policy associated with that application. Links to any other websites, applications or content do not constitute or imply an endorsement or recommendation by us of the linked website, Social Media Platform, and/or content.
V. Data Retention
We will retain your Information for as long as needed to provide you Services, and as necessary to comply with our legal obligations, resolve disputes, and enforce our policies. We will retain and use your Information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements. In accordance with our routine record keeping, we may delete certain records that contain Information you have submitted to us. We are under no obligation to store such Information indefinitely and disclaim any liability arising out of, or related to, the destruction of such Information.
VI. Your Choices
- Text Messages. You may sign up to receive text messages from the Company or third-party service providers on behalf of the Company (e.g., text message marketing). By using our Services, signing up for text messaging services or otherwise opting in to receive text messages (opting in via short code or entering your phone number into an on-site collection widget), you agree that you have provided the Company or its third-party service providers with prior express written consent to be contacted by text message, including recurring automated promotional and personalized marketing text messages.
- By providing prior express and/or prior express written consent, you agree to receive text messages under the Telephone Consumer Protection Act and related state laws, including by the use of an automatic telephone dialing system (“ATDS”) to deliver text messages to the mobile phone number which you provided to us. While you consent to receive messages sent using an ATDS (or “autodialer”), the foregoing shall not be interpreted to suggest or imply that any or all of our mobile messages are sent using an autodialer. We will use the Information provided by you in connection with the text messaging services in accordance with this Privacy Policy. Your consent is not a condition of any purchase or use of our Services and your consent to be contacted as described is voluntary. The number of text messages you receive may vary based upon the text messaging service(s) you sign up for. Message and data rates may apply.
- You may revoke your consent and opt out to discontinue text messages at any time. If you no longer want to receive text messages from us, reply STOP or otherwise follow opt-out instructions within the text.
We are not responsible for the effectiveness or compliance of third party opt-out mechanisms or programs. Please note that if you delete your cookies or upgrade your browser after having opted out, you will need to opt out again. Further, if you use multiple browsers or devices you will need to opt out on each browser or device. You can access the information on this website without enabling cookies in your browser but disabling cookies may result in a diminished ability to take advantage of the services and related informational content on the website.
VII. Notice to Certain Residents of Data Subject Rights
Residents of certain U.S. states may have rights and choices regarding their Information. To the extent any data protection law applies to our collection of your Information, this supplemental section of our Privacy Policy outlines the individual rights you may be entitled to and how to exercise those rights.
Depending on where you live and subject to certain exceptions, you may have some or all of the following rights.
- Right to Know and Access. You may have the right to request that we confirm whether we process your Information, and to request information about our collection and use of your Information, including whether we sell or share your Information. You also have the right to request access to Information we may process about you.
- Right to Data Portability. Where the processing is carried out by automated means, and subject to certain exceptions, you may have the right to request and obtain a copy of your Information that you previously provided to us in a portable format. In addition, to the extent technically feasible, you may have the right to obtain your Information in a readily usable format that allows you to transmit the Information to another data controller without hindrance.
- Right to request Correction of Inaccurate Information. To the extent that we may maintain inaccurate Information, you may have the right to request that we correct such inaccurate Information, taking into account the nature of the Information and the purposes of the processing of the Information.
- Right to Request Deletion. You may have the right to request that we delete certain Information or records provided by or obtained about you, with certain exceptions and limitations as allowed under law.
- Right to Opt Out of the Sale and Sharing of Information. Some data protection laws provide consumers with the right to opt out of the processing of their Information for purposes of sale and sharing and/or targeted advertising. However, as noted elsewhere we do not sell or share your Information or use your Information for targeted advertising purposes.
- Right to Opt-Out of the use of Information for Targeted Advertising and Profiling. Some data protection laws provide consumers with the right to opt out of the processing of their Information for purposes of profiling in furtherance of decisions that produce legal or similarly significant effects concerning them. However, we do not use your personal Information for such profiling purposes.
- Right to Limit Use and Disclosure of Sensitive Information. You may have the right to request that we limit the ways we use and disclose your sensitive Information to uses which are necessary for us to perform the Services, or deliver the goods reasonably expected by you, or and as authorized by law. As noted elsewhere we do not sell, use, or disclose your sensitive information other than for the permitted business purposes outlined above.
- Right to Non-Discrimination. You may have a right to not be discriminated against in the Services or quality of Services you receive from us for exercising your rights. We will not discriminate against you for exercising any of your rights in this section including denying goods or Services, charging different prices or rates for goods or Services, or providing a different level of quality of goods and Services.
- Right to Disclosure of Direct Marketers. You may have a right to know the categories and names/addresses of third parties that have received Information for their direct marketing purposes upon simple request, and free of charge. We do not share Personal Information for direct marketing purposes.
- Right to Appeal. You may have the right to appeal our denial of any request you make under this section. To exercise your right to appeal, please submit an appeal request via the information in the Contact Us section below or using the Your Privacy Choices form. Within the certain timeframe of receipt of your appeal, as proscribed by the applicable law we will inform you in writing of any action taken or not taken in response to your appeal, including a written explanation of the reasons for the decisions. If we deny your appeal, you may contact the Attorney General or another authority which we will help you identify.
To learn more about whether you are guaranteed certain rights, or to submit a request to exercise your rights, please contact us using any of the methods in the Contact Us section.
VIII. Exercising Your Data Subject Rights
To exercise any of the rights described above, please submit a verifiable consumer request to us via the methods described below. The verifiable consumer request must:
- Provide sufficient Information that allows us to reasonably verify you are the person about whom we collected Information or an authorized representative; and
- Describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.
If we cannot verify your identity based on the processes described above, we may ask you for additional verification Information. If we do so, we will permanently delete the verification information that you provide promptly after we have completed the verification process. We will not use that Information for any purpose other than verification. Under certain U.S. Privacy Laws, you may also designate an authorized agent to make these requests on your behalf, provided that the authorized agent is a natural person or a business entity that you have authorized to act on your behalf. If you use an authorized agent to submit a request, we may need to collect additional Information, such as (1) proof of written permission for the authorized agent to make requests on your behalf, and identity verification from you; or (2) proof of power of attorney pursuant under applicable law; to verify your identity before processing your request to protect your information.
If we cannot verify your identity to a sufficient level of certainty to respond to your request, we will let you know promptly and explain why we cannot verify your identity.
A. Requests Through Your Password-Protected Account:
If you created a password-protected account with us before the date of your request, we will rely on the fact that your request has been submitted through your account as verification of your identity. We may require that you to verify your identity before we disclose your personal information in response to a request to know and before we delete your personal information in response to a request to delete. You are responsible for protecting the security of your log-in credentials for your account. Please do not share your log-in credentials with anyone. If we suspect fraudulent or malicious activity on or from your account, we will not respond to a request to know or a request to delete until we have been able to confirm, through further verification procedures, that you made the request.
B. Requests Other Than Through A Password-Protected Account:
If you submit a request by any means other than through a password-protected account that you created before the date of your request, the verification process that we follow will depend on the nature of your request.
To help protect your privacy and maintain security, if you request access to or deletion of your Information, we will take steps and may require you to provide certain Information to verify your identity before granting you access to your Information or complying with your request. In addition, if you ask us to provide you with specific pieces of Information, we may require you to sign a declaration under penalty of perjury that you are the consumer whose Information is the subject of the request. Only you or your authorized agent may make a verifiable consumer request related to your Information. If you designate an authorized agent to make a request on your behalf, we may require you to provide the authorized agent written permission to do so and to verify your own identity directly with us (as described above). You may also make a verifiable consumer request on behalf of your minor child.
You can exercise rights in the following ways:
Email us: privacy.inquiries@lifepointhealth.net
Call us: (866) 483-1804
Write us: Lifepoint Health
Attention: Privacy Requests
330 Seven Springs Way
Brentwood, TN 37027
IX. Children’s Information
The Services are intended only for users over the age of sixteen (16). If we become aware that a user is under sixteen (16) (or a higher age threshold where applicable) and has provided us with Information, we will take steps to comply with any applicable legal requirement to remove such Information. Contact us if you believe that we have mistakenly or unintentionally collected Information from a child under the age of sixteen (16).
X. Difficulty Accessing Our Privacy Policy
Individuals with disabilities who are unable to usefully access our Privacy Policy online may contact us to inquire how they can obtain a copy of our policy in another, more easily readable format.
XI. “Do Not Track” Signals
We do not currently support “Do Not Track.” Do Not Track is a preference you can set in your web browser to inform websites that you do not want to be tracked. You can enable or disable “Do Not Track” by visiting the “Preferences” or “Settings” page of your web browser. Do Not Track is different from Global Privacy Controls (“GPC”), which may notify websites of consumers’ privacy preferences regarding the sale or sharing of personal Information, or the use of sensitive personal Information.
XII. Changes to This Policy
We have the right to change or update this Website Privacy Policy from time to time without notice, so please review it periodically to keep informed of any changes. If you have questions about this Privacy Policy or concerns about how we collect, use or protect your personal information, please contact us as listed below.
XIII. Contact Us
If you have questions about this Privacy Policy or concerns about how we collect, use or protect your personal information, please contact us at the following:
Email us: privacy.inquiries@lifepointhealth.net
Call us: (866) 483-1804
Write us: Privacy Requests
c/o Lifepoint Health
330 Seven Springs Way
Brentwood, TN 37027
Submit a request using Your Privacy Choices
Last Revised July 2024