NC Medicaid Managed Care privacy notice
Last Updated: June 28, 2019
Maximus commitment to privacy
Thank you for visiting the NC Medicaid Managed Care website (Site) and/or Application for mobile devices operated by Maximus Health Services, Inc. for the North Carolina Department of Health and Human Services (DHHS). This Site, located at ncmedicaidplans.gov, and Application are designed to make it easier and more efficient for you to interact with NC Medicaid Managed Care and allow you to view health plans, find a doctor, and enroll in a health plan. This privacy notice governs your use of the Site/Application. Please read this document carefully before you access and use the Site/Application.
Confidentiality is a top priority at Maximus. We are committed to ensuring the security and confidentiality of your information. Maximus respects your privacy and we have developed the following privacy notice to demonstrate our commitment to you.
This privacy notice applies to:
- Information we collect about you
- How we use the information
- Choices you have about how we collect and use your information
This privacy notice does not apply to:
- Privacy practices associated with any activities done outside your use of this Site/Application
- Websites other than this website
- Applications other than this Application
- Products and services not available or enabled through the Site/Application
Information we collect
In order to use some of this Site’s/Application’s features, you may be asked to provide personal information. Maximus does not collect any personal information about you through this Site/Application unless you provide that information voluntarily.
You provide personal information voluntarily when you enroll using this Site/Application. We clearly identify data you must provide so we can deliver the services or information you have requested. Maximus may ask that you provide or verify the following personal information; the list is not exhaustive:
- First and last name
- Date of birth
- Mailing address (including ZIP/Postal CODE)
- Medicaid ID number
- Last 4 digits of your Social Security number
During your visit to the Site/Application, you may complete a transaction such as an enrollment application. The information, including personal information, volunteered by you in completing the transaction is used by Maximus to operate the NC Medicaid Managed Care program, which includes the provision of goods, services and information.
Maximus maintains policies that protect the confidentiality of personal information obtained in the course of its regular business functions. Maximus privacy policies impose a number of standards to guard the confidentiality of, prohibit the unlawful disclosure of, and limit access to personal information (such as Social Security numbers and Medicaid ID numbers). Maximus safeguards personal information by having physical, technical and administrative safeguards in place.
How we use and share the information collected
The collection of information through this Site/Application and the disclosure of that information are subject to the provisions of the Health Insurance Portability and Accountability Act (HIPAA) (Public Law 104-191). To learn more about Health Information Privacy, visit HHS.gov.
Choosing to provide personal information to Maximus, whether we request it or not, constitutes consent to the collection and sharing of the information with the DHHS for the reasons you shared the information with Maximus.
Except as we state below or as otherwise authorized by law, Maximus will only collect or disclose personal information collected through this Site/Application if you have agreed to the collection or disclosure of that personal information. Maximus may collect or disclose personal information without your agreement if it is:
- necessary to perform our statutory duties as authorized by law, or authorized by state or federal statute or regulation
- to comply with valid legal process such as a search warrant, subpoena or court order
Maximus may also disclose personal information to federal or state law enforcement authorities to enforce its rights against unauthorized access or attempted unauthorized access to Maximus information technology assets.
Maximus may disclose personal information to its agents, affiliates, and subcontractors to allow them to perform certain functions relating to your enrollment.
Maximus does not share your personal information with unaffiliated third parties. We may use your information to improve the content, navigation and efficiency of the Site/Application.
In order to make our Site/Application better for you, we may use and share with others aggregated or anonymous (not personally identifiable) information that we have collected based on usage data, surveys or statistical information that we have compiled about our users.
Website time out
For security purposes, your URL online session is set up to end after 30 minutes of user inactivity. You will receive a session timeout warning after 29 minutes of inactivity, allowing you to either continue your session or log out. If you do not make a selection, your session will end after 30 minutes of inactivity.
Information we retain
Maximus retains the information collected through this Site/Application, including personal information that you submit by enrolling, as required by our contract with the DHHS. To find out more about the rules for retaining your information, please mail your questions to the contact information provided below.
Website privacy notice
Our web server automatically collects and logs web usage data from when you visit the Site. This information is collected for purposes related to the services we provide on behalf of the DHHS. This information, including your Internet Protocol (IP) address, referring sites, pages viewed, browser type, operating system, CPU speed, referring or exit web pages, and length of visit, informs us about how visitors use and navigate the Site. Maximus will collect the information above from your visit to the Site only for these purposes and for purposes related to the services we provide on behalf of DHHS.
Device and carrier information
Through your use of the mobile Application, we may collect information about your device, such as the device model, name, operating system, or IP address. This information will be retained by Maximus as long as needed and will only be used for the limited purposes stated within this notice.
Cookies, “Do Not Track” signals, and Webtrends Analytics
Our Application uses Webtrends Analytics, a service which transmits traffic data to Webtrends Analytics servers in the United States. Webtrends does not identify individual users or associate your IP address with any other data held by Webtrends Analytics. We use reports provided by Webtrends Analytics to help us understand Application traffic and webpage usage. You may view the Webtrends Analytics Privacy Statement located here.
Opt-out of cookies and Webtrends Analytics
If you do not want your device to accept cookies, you can modify the cookie option in your device’s settings. However, some Application features or services may not function properly or be accessible without cookies. For additional information on opting-out of Webtrends Analytics tracking cookies, please see Webtrends Analytics Cookie Management Tool locate here.
“Do Not Track”
“Do Not Track” is a preference you can set in your web browser to let the websites you visit know that you do not want them collecting information about you. The Site/Application does not currently respond to a "Do Not Track" or similar signals.
Maximus is strongly committed to protecting personal information collected through this Site/Application against unauthorized access, use or disclosure. Maximus limits employee access to personal information collected through this Site/Application to only those employees who need access to the information in the performance of their official duties. Employees who have access to this information follow appropriate procedures in connection with any disclosures of personal information.
Maximus uses various technological and procedural security measures in order to protect the personal information we collect through the Site/Application from loss, misuse, alteration or destruction. We have documented Information Security & Privacy policies to address data protection. We regularly provide information security and privacy awareness training to our employees. However, you should be aware that, due to the open and unsecured character of the Internet, Maximus cannot be responsible for the security of transmissions of personal information over the Internet. We have prepared a formal incident response plan in case of a data breach.
To protect your communications through the Site, we authenticate, monitor, audit and encrypt activity. You can tell when the site is secure by looking at the location (URL) field. If the URL begins with https:// (instead of http://), the document comes from a secure server. This means your personally identifiable information cannot be read or deciphered by unauthorized individuals. This is part of our continuing commitment to protecting your information. Please note, that despite our efforts, no security measures are completely secure. Use of this system constitutes consent to such monitoring and auditing.
Access to the State of North Carolina, Department of Health and Human Service, Privacy and Security Manual is found here.
Maximus is committed to complying fully with the Children's Online Privacy Protection Act. Although parents are free to use this website and mobile Application on behalf of their children, we don't direct this Site to children or knowingly collect personal information from children. We're pleased to work with parents and guardians to delete from our records personal information that a child may have disclosed improperly on this website. Maximus appreciates your cooperation with this federally mandated requirement.
Reviewing and correcting your information
We try to keep information about you accurate and current. To change or update any personal information maintained by our program, you may write Maximus at the address below. In your correspondence, please indicate with as much detail as possible. Personal information maintained by any of our contracts administered on behalf of federal, state or local government entities should be corrected by contacting the customer service department in the individual program. Please refer to the section on “How to contact us.”
Information provided on this Site/Application is intended to allow the public immediate access to public information. While all attempts are made to provide accurate, current, and reliable information, Maximus recognizes the possibility of human and/or mechanical error. Therefore, Maximus, its employees, officers and agents make no representations as to the accuracy, completeness, currency or suitability of the information provided by this Site/Application and deny any expressed or implied warranty as to the same.
Changes to this privacy notice
We will occasionally update this privacy notice. When we do, we will revise the “last updated” date at the top of the privacy notice. Please check the Site/Application from time to time for the most current version of our privacy notice. Your continued use of the Site/Application after we have notified you of changes as described above constitutes your acceptance of the changes.
How to contact us
If you have any questions or concerns about reviewing and correcting your information, please contact us by:
- Phone: 1-833-870-5500 (TTY: 1-833-870-5588)
5001 Hospitality Ct
Morrisville, NC 27560
If you have any questions or concerns about our privacy notice, please contact us by:
Maximus Privacy Official Office
1891 Metro Center Drive
Reston, VA 20190