Privacy Policy

HealthFirst Data Privacy Statement

1. Overview

At HealthFirst, your privacy is important to us. We process personal information in different contexts, and we do so by respecting your privacy, as part of our unwavering commitment to ethical and responsible practices and as required by law.

This Data Privacy Statement (“Statement”) sets forth the principles that govern our treatment of personal information at HF Acquisition Co., LLC, doing business as HealthFirst (“HealthFirst”). All employees and those with whom we share personal information must adhere to this Statement. 

HealthFirst is committed to protecting personal information that our employees, customers, prospects, suppliers, and vendors have entrusted to us. We collect and use personal information in order to perform our business functions and provide products and services to our customers. 

This Statement applies to personal information in any format or medium, relating to employees, customers, vendors and others who do business with HealthFirst.

Our website contains links to other websites. These websites are not covered by this Statement, and we are not responsible for the privacy practices or the content of these other websites.

2. Categories of Personal Information We Collect and Use

We recognize personal information as any information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual or household.  Depending on the context of your interactions with HealthFirst, we may collect and use different types of personal information from current and prospective employees, contractors, current and prospective customers and vendors.

Categories of Personal Information Collected

Examples

Collected

A. Personal Identifiers. 

A real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, Social Security number, driver’s license number, passport number, or other similar identifiers.

Yes

B. Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)).

A name, signature, Social Security number, physical characteristics or description, address, telephone number, passport number, driver’s license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number, or any other financial information, medical information, or health insurance information. Some personal information included in this category may overlap with other categories.

Yes

C. Protected classification characteristics under California or federal law.

Age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, veteran or military status, genetic information (including familial genetic information).

Yes

D. Commercial information.

Records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.

Yes

E. Biometric information

Genetic, physiological, behavioral, and biological characteristics, or activity patterns used to extract a template or other identifier or identifying information, such as, fingerprints, faceprints, and voiceprints, iris or retina scans, keystroke, gait, or other physical patterns, and sleep, health, or exercise data.

No

F. Internet or other similar network activity

Browsing history, search history, information on a consumer’s interaction with a website, application, or advertisement.

 

Yes

G. Geolocation data

Physical location or movements.

No

H. Sensory data.

Audio, electronic, visual, thermal, olfactory, or similar information.

No

I. Professional or employment related information.

Current or past job history or performance evaluations.

Yes

J. Non-public education information (per the Family Educational Rights and Privacy Act (20 U.S.C. Section 1232g, 34 C.F.R. Part 99)).

Education records directly related to a student maintained by an educational institution or party acting on its behalf, such as grades, transcripts, class lists, student schedules, student identification codes, student financial information, or student disciplinary records.

Yes

K. Inferences drawn from other personal information.

Profile reflecting a person’s preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.

No

3. Categories of Sources of Personal Information

HealthFirst receives and uses various types of personal information in order to conduct our day to day business activities. We apply the data minimization principle in the collection and use of personal information with the aim to only collect information that is necessary and by fair means and providing notice and requiring consent when necessary.

We may collect categories of personal information listed above from the following categories of sources:

• Third party vendors
• Recruitment or talent agencies
• Our distributors
• When you browse, or use our website, e-commerce services, or social media pages
• Our business partners (non-vendors)
• Joint marketing partnerships
• Publicly-available non-government and government data
• Contractors (e.g., consultants, agents and representatives)
• Consumer reporting agencies
• Covered individuals’ email accounts, chat logs, social media accounts
• Covered individuals’ devices
• Directly from covered individuals
• From other individuals, such as friends or family
• Other Company entities

Some of this data is collected in the following situations when:

• You apply for a position, or to do business, with our company
• We establish a contractual employment or commercial relationship
• You provide us with any type of service, as a vendor
• When we provide you with any type of service, product or support
• When you browse, or use our website, e-commerce services, or social media pages

4. Business Uses and Purposes for Which Personal Information Was Collected

The purposes for which we collect and use your personal information may vary depending on the type of relationship you have with us, such as if you are one of our employees, customers, or a website user. The use of personal information for new purposes should be consistent with and meet privacy expectations described in this statement, otherwise we will request your authorization.

Generally, we collect, use and disclose your personal information to provide you products and services and as otherwise related to the operation of our business.  For more specific detail on our disclosures of personal information, see the next section “Sharing and Disclosures to Third Parties.”  Subject to restrictions and obligations of applicable laws, HealthFirst and our vendors may use your personal information for some or all the following business purposes:

• Processing Interactions and Transactions
• Managing Interactions and Transactions
• Performing Services
• Research and Development
• Fulfilling regulatory requirements and Quality Assurance
• Security
• Debugging

In addition, we may collect, use and disclose your personal information for the following additional operational business purposes for which we are providing you notice as permitted by applicable law:

Employees and candidates: if you apply for a job via our career center, we use your personal information to consider you for employment and to administer your account. If you have an employment or commercial relationship with HealthFirst, we use your personal information to develop our contractual relationship, to conduct performance evaluations and to comply with legal obligations, including tax and labor regulations.

Customers: we use our customers’ information to maintain our commercial relationship, to ensure the proper operation of the day-to-day business, to comply with tax and other regulations, and to administer sales and marketing activities.

Prospective customers: information from prospective customers is used to respond to their requests for information, products or services, and for marketing activities.

Vendors and suppliers: if you have a business or professional relationship with HealthFirst, we will use your information to develop and conduct our business relationship with you, and to comply with tax and other regulations.

Visitors of company facilities: some of our buildings have physical access controls and video surveillance systems for security purposes.

Website and social media users: we collect personal information from visitors and users of our website and social media pages. We use the information to manage your account registration, to store your preferences and settings, to provide interest-based advertising, to conduct statistics and to analyze how you use our website and online services.

HealthFirst shall use personal information for purposes disclosed above. To the extent required by law, HealthFirst shall inform the individual if their personal information will be used for an additional purpose, and this disclosure shall occur prior to the data being so used, and the individual shall be given a mechanism to provide their consent.

As permitted by applicable law, we do not treat deidentified data or aggregate customer information as personal information and we reserve the right to convert, or permit others to convert, your personal information into deidentified data or aggregate consumer information.  We have no obligation to re-identify such information to respond to your requests.

Our customers may engage service providers or subcontractors to enable them to perform services on our behalf.  This sub-processing is, for purposes of clarity, an additional business purpose for which we are providing you notice.

In addition, we may collect, use and disclose your personal information as required or permitted by applicable law.

5. Sharing and Disclosures to Third Parties

At times, HealthFirst engages third party contractors, service providers, and other vendors to help us accomplish our business objectives. When HealthFirst discloses personal information for a business purpose, we enter a contract that describes the purpose and requires the recipient to both keep that personal information confidential and not use it for any purpose except performing the contract. There are other circumstances where we are required by law to disclose personal information to third parties such as public authorities.

Disclosures for Business Purposes:

In the preceding twelve (12) months, HealthFirst may have disclosed the following categories of personal information for a business purpose:

A. Personal Identifiers
B. Personal Information Records
C. Protected Classifications
D. Commercial Information
E. Internet Usage Information
F. Professional or Employment Information
G. Non-public Education Information

Notwithstanding anything to the contrary in our other privacy notices, we restrict use of your personal information shared with our vendors to business purposes.

We may disclose your personal information for a business purpose to the following categories of third parties:

• Third parties to whom you authorize us to disclose your personal information in connection with products or services we provide to you
• B2B Customers
• Business Partners
• Customer Service Representatives
• External Agencies
• External Auditors
• Finance/Accounting Teams
• Internal Auditors
• Internal Employees on need to know basis
• Legal, Compliance and Regulatory-Quality Teams
• Operations/Maintenance Teams
• Public Authorities/ Government Bodies
• Sales/Marketing Teams, representatives or agents
• Service Providers and Vendors, such as for advertising or marketing purposes, internet service providers, data analytic providers, operating systems and platforms, and social networks

In the preceding twelve (12) months, HealthFirst may have disclosed personal information for the following business purposes:

• Processing Interactions and Transactions
• Managing Interactions and Transactions
• Performing Services
• Research and Development
• Fulfilling regulatory requirements and Quality Assurance
• Security
• Debugging

We engage with third party contractors, service providers and other vendors for certain services. If the engagement involves the transmission of personal information, HealthFirst directs the service provider to treat that data consistent with legal requirements. A contract to protect the personal information should be executed before any data is disclosed.

In certain circumstances, HealthFirst may be required to disclose personal information when required by law, when required to protect our legal rights, or in an emergency situation where the health or security of an individual is endangered.

We may also disclose personal information in the context of any sale or transaction involving all or a portion of the business.

Sale:

In the calendar year 2019, we have not sold your personal information (as the term “sold” is defined by the California Consumer Protection Act).

Advertising data:

As you browse healthfirst.com, advertising cookies will be placed on your computer so that we can understand what you are interested in. Our display advertising partner, AdRoll (https://www.adroll.com) then lets us present you with retargeting advertising on other sites based on your previous interaction with healthfirst.com. The techniques AdRoll employs do not collect personal information such as your name, email address, postal address or telephone number.

You can visit http://www.networkadvertising.org/choices/ to opt out of AdRoll’s and their partners’ targeted advertising.

6. Our Statement Towards Children

Our services are not directed to children. If a parent or guardian becomes aware that his or her child has provided us with personal information without their consent, please contact us. If we become aware that a child has registered for a service and has provided us with personal information, we will delete such information from our files.

7. Security

HealthFirst is committed to security, confidentiality and integrity of personal information in accordance with legal requirements. We take commercially reasonable precautions to keep personal information secure against unauthorized access and use and we periodically review our security measures. We are committed to processing your data in a secure manner and have put in place specific technical and organizational measures to prevent the personal information we hold from being accidentally or deliberately compromised. 

HealthFirst uses Let’s Encrypt for its sites’ security certificates. Please be aware that these protection tools do not protect information that is not collected through our Web site, such as information provided to us by e-mail.

We also conduct information risk assessments, we train our staff to understand the importance of protecting personal information, and we are responsibly managing access rights within the company. We include both physical security and IT security in our overall data security approach. We are diligent in selecting vendors that process personal information on our behalf so that they also ensure appropriate technical and organizational measures to protect the data.

HealthFirst makes reasonable efforts to notify individuals and regulatory authorities, as required by law, if we reasonably believe that personal information has been stolen, disclosed, altered or infringed by an unauthorized person. 

We also endorse the concept of privacy by design which is an approach to projects that promotes privacy and data protection compliance from the outset. This means considering the privacy and security implications for any new project or process throughout its lifecycle. 

8. Your Data Protection Rights and Choices

If you reside or otherwise find yourself in jurisdictions with data protection laws, HealthFirst is committed to supporting your rights granted by such applicable data protection laws. Otherwise you can contact us at any time to discuss your privacy concerns.  

Under certain circumstances, you may have the privacy rights described in this section. Any request you submit to us is subject to an identification and verification process. We will not fulfill your request unless you have provided sufficient information for us to reasonably verify you are the individual about whom we collected personal information.  

If you require this notice to be provided in a different format please submit the request to HealthFirst by either:

Calling us at 800-331-1984 or
Visiting us at 11629 49th Pl W, Mukilteo, WA 98275

If we cannot comply with a request, we will explain the reasons in our response. We will use personal information provided in a verifiable request only to verify your identity or authority to make the request and to track and document request responses.

We will make commercially reasonable efforts to identify personal information that we collect, process, store, disclose and otherwise use and to respond to your applicable privacy rights requests. In some cases, we may suggest that you receive the most recent or a summary of your personal information and give you the opportunity to elect whether you want the rest. We will typically not charge a fee to fully respond to your requests; provided, however, that we may charge a reasonable fee, or refuse to act upon a request, if your request is excessive, repetitive, unfounded or overly burdensome. If we determine that the request warrants a fee, or that we may refuse it, we will give you notice explaining why we made that decision. You will be provided a cost estimate and the opportunity to accept such fees before we will charge you for responding to your request.

Pursuant to applicable data protection laws, your privacy rights may include the following:

Information Rights:

You may have the right to send us a request, no more than twice in a twelve-month period, for any of the following for the period that is 12 months prior to the request date:

• The categories of personal information we have collected about you.
• The categories of sources from which we collected your personal information.
• The business or commercial purposes for our collecting your personal information.
• The categories of third parties to whom we have shared your personal information.
• The specific pieces of personal information we have collected about you.
• A list of the categories of personal information disclosed for a business purpose in the prior 12 months, or that no disclosure occurred.
• A list of the categories of personal information sold about you in the prior 12 months, or that no sale occurred. If we sold your personal information, we will explain:
     1. The categories of your personal information we have sold.
     2. The categories of third parties to which we sold personal information, by categories of personal information sold for each third party.

To make a request, email us at privacy@healthfirst.com or call us at 800-331-1984.

Obtaining Copies of Personal Information:

You may have the right to obtain a copy, no more than twice in a twelve-month period, of your personal information that we have collected and are maintaining. To make a request, email us at privacy@healthfirst.com or call us at 800-331-1984.

Do Not Sell:

If you are 16 years of age or older, you may have the right to direct us to not sell your personal information.

You may alternatively exercise more limited control of your personal information by opting out of HealthFirst marketing emails by clicking the unsubscribe link on the bottom of a HealthFirst email, which removes you from the marketing email list. Please note: you will not be removed from receiving the types of operational emails that the business deems necessary to communicate to you about products and solutions you have from HealthFirst.

We do not sell the personal information of an individual we know are under 16 unless we receive an opt-in from the individual who is between 13 and 16, or the parent or guardian of an individual younger than 13. Individuals who opt-in to personal information sales may opt-out at any time. If you think we may have unknowingly collected personal information for sale of yourself, if you are between 13 and 16, or of your child under the age of 13, exercising the opt-out will stop our selling of the personal information.

In the calendar year 2019, we have not sold your personal information (as the term “sold” is defined by the California Consumer Protection Act).

Delete:

Except to the extent we have a basis for retention under applicable law, you may request pursuant to applicable law that we delete your personal information that we have collected and are maintaining. Our retention rights include, without limitation, complete transactions and service you have requested or that are reasonably anticipated, for security purposes, for legitimate internal business purposes, including maintaining business records, to comply with law, to exercise or defend legal claims, and to cooperate with law enforcement. To make a request, email us at privacy@healthfirst.com or call us at 800-331-1984.

We will not discriminate against you in a manner prohibited by applicable law because you exercise your privacy rights. You may have the right to exercise these rights via an authorized agent who meets the agency requirements of the applicable law.

Mailings, Calls, Faxes:

If you supply us with your street address, e-mail address, phone number or fax number, you may receive periodic mailings, calls or faxes from us with information about new products and services or upcoming events. If you do not wish to receive such mailings or calls, you may “opt out” by writing, calling, or e-mailing us at the addresses/number listed below:

HealthFirst
11629 49th Pl W
Mukilteo, WA 98275
customerservice@healthfirst.com
Phone: 425-771-5733 | Direct
Phone: 800-331-1984 | Toll Free
FAX: 425-775-2374
www.healthfirst.com

If you do not wish to receive such faxes from us, you may “opt-out” by writing, faxing, or calling us at the address/numbers listed below:

HealthFirst
11629 49th Pl W
Mukilteo, WA 98275
Attn: Fax Desk
Phone: 425-771-5733 | Direct
Phone: 800-331-1984 | Toll Free
FAX: 425-775-2374

9. Changes to This Statement

We reserve the right to modify this Privacy Statement and related business practices at any time. We will duly inform you of any changes.

The time stamp you see on the statement will indicate the last date it was revised.

10. Contact Information

If you have any privacy concerns or questions about how your personal information is used, please feel free to contact us.

If you have any concerns or questions about how your personal information is used, please contact us at:

HealthFirst
11629 49th Pl W
Mukilteo, WA 98275
privacy@healthfirst.com 


Last Updated: Dec. 31, 2019