CareMC Privacy Policy
CorVel Corporation ("CorVel") has created this privacy statement in order to demonstrate our firm commitment to privacy. The following discloses our information gathering and dissemination practices for this website: www.caremc.com (the "Site").

Your IP Address
We use your IP address to help diagnose problems with our server, and to administer our website. We do not link your IP address to any personally identifiable information. This means that your session may be tracked, but you will remain anonymous except in areas requiring your user name and password for access.

Cookies
We may place a "cookie" on the browser of your computer's hard disk for record-keeping purposes. The use of cookies is common in the Internet industry, and many major websites use them to provide useful features to their customers. The cookie itself does not contain any personally identifying information, but may be used to tell when your computer has contacted the Site. We use the information for editorial purposes and for other purposes such as the delivery of features and advertisements, so that we can customize delivery of information specific to your interests without compromising privacy. For example, cookies may be used to ensure that you will not see the same ads too often in a single session. We also may use cookies to save your password so you don't have to re-enter it each time you visit the Site.

Linking Sites
The Site contains links to other sites. CorVel is not responsible for the privacy practices or the content of such websites, including any sites that may indicate a special relationship or partnership with CorVel (such as co-branded pages or "powered by" or "in cooperation with" relationships). CorVel does not share information it gathers with other websites or any other entities or individuals unless such sharing is approved in advance by you. Other linked sites, however, may collect personal information from you that is not subject to CorVel's control. To ensure protection of your privacy, always review the privacy policy of the sites you may visit by linking from the Site. Please note that this privacy statement applies only to caremc.com and websites that carry the caremc.com brand, and not to other companies' or organizations' websites to which we link.

Collection of Personal Information
Our website uses a request form for customers to request information, products, and services. We collect customers' contact information (like their email addresses) and demographic information (like their zip codes). Contact information from the request form is used to send information to our customers. Demographic and profile data is also collected at the Site.

Security
CorVel employs security measures utilizing industry-standard technology to protect the loss, misuse or alteration of personal information that you disclose. Personal information is stored in a secured database and always sent via an encrypted Internet channel. Further public disclosure here of our security measures could aid those who might attempt to circumvent those security measures. As a member, if you have additional questions regarding security, please feel free to contact CorVel directly. To ensure that our employees comply with our privacy policies, we have developed a training program that provides all employees with the tools and knowledge to protect member privacy in all aspects of their work. Any employee who violates our privacy policies is subject to disciplinary action, including possible termination and civil and/or criminal prosecution. CorVel may disclose personal information in special cases when we have reason to believe that disclosing this information is necessary to identify, contact or bring legal action against someone who may be violating the CorVel Agreement or may be causing injury to or interference with (either intentionally or unintentionally) CorVel's rights or property, other CorVel users, or anyone else that could be harmed by such activities. CorVel may disclose or access personal information when we believe in good faith that the law requires it and for administrative and other purposes that we deem necessary to maintain, service and improve our products and services.

Your Role in Protecting Your Privacy
Never share your CorVel password with anyone whom you don't want accessing your account. It is your sole responsibility to inform CorVel of any need to deactivate a password.

CorVel and HIPAA

To the extent HIPAA applies to CorVel’s relationships and transactions (other than disability, auto and worker’s compensation), CorVel is working with its clients, vendors and other business associates in order to comply with HIPAA’s electronic transmissions, security and privacy standards, in the time frame mandated by the regulations. CorVel’s compliance program is underway and current examples of procedures adopted by CorVel include:
  • Users accessing CorVel’s network are provided with a user specific authentication/challenge.
  • Outside of CorVel’s secure frame relay network, CorVel utilizes VPN connectivity utilizing 128 bit encryption. Encryption occurs between the end user’s PC and CorVel’s network.
  • CorVel has installed Tumbleweed’s MMS Redirect product which provides for the encryption of confidential information sent in e-mail via the Internet.
  • Systems within CorVel’s secure data center are architected to maintain maximum uptime. Redundancy is added where necessary.
  • Nightly backups are securely stored off site.
  • To enhance security, CorVel’s network is divided into multiple DMZs.
  • Redundant firewalls are utilized.
Since 1994, CorVel has successfully conducted ANSI X12 exchanges with trading partners utilizing the 148, 224, 270, 271, 278, 811, 835, 837 and 997 transaction code sets. CorVel is capable of working with any ANSI X12 transaction codes sets.

Additionally, where applicable, CorVel limits the uses and disclosures of Protected Health Information (“PHI”) to those permitted by HIPAA. Further, CorVel has implemented safeguards to prevent unpermitted uses and disclosures of PHI, by means such as implementing applications to provide levels of granularity so users may only have access to the records for which they are responsible. CorVel also limits the collection of PHI to that which is necessary to perform its business obligations and meet regulatory requirements, and requires all employees to sign written agreements to keep all patient and client information confidential.

Click here to view CorVel's HIPAA Notice of Privacy Practices in Adobe PDF format.

Changes to the Privacy Statement

CorVel may change this privacy statement at any time by posting revisions to the Site. Your use of the Site constitutes acceptance of the provisions of this privacy statement and your continued usage after such changes are posted constitutes acceptance of each revised policy statement. Please check this privacy statement periodically for changes. If you do not agree to the terms of this privacy statement or any revised privacy statement, please exit the Site immediately. If you would like to contact CorVel, you can send us an email at marketing@corvel.com, mail us at the following postal address: CorVel Corporation, 2010 Main Street, Suite 1020, Irvine, CA 92614. If you have any questions about this privacy statement, the practices of the Site, or your dealings with the Site, you can contact:

CorVel Corporation
2010 Main Street
Suite 1020
Irvine, CA 92614
888-7-CORVEL

Copyright © 2007 CorVel Corporation. All rights reserved.