PRIVACY NOTICE
This privacy notice (the “Privacy Notice”) is to inform you how ProScan Imaging, LLC, including all direct and indirect subsidiaries (collectively “ProScan,” “we,” “our,” or “us”), collects, uses, transfers, discloses, stores, and safeguards your Personal Data (as defined below). ProScan provides expert, affordable MRIs, CT Scans, Ultrasounds and Mammograms read by board certified and fellowship-trained radiologists (the “Services”).
1. PURPOSE AND SCOPE OF THIS NOTICE
This Privacy Notice applies to all ProScan websites, including, but not limited to, https://proscan.com and https://proscanonline.com, and any other website, application, or digital service that is owned by ProScan and links or refers to this Privacy Notice (collectively our “Sites”). This Privacy Notice also applies to Personal Data that we obtain and process through other electronic and offline mechanism (for example, Personal Data collected when providing customer support, talking to us on the phone, or otherwise interacting with us as a visitor and not a patient). This Privacy Notice is subject to our Terms of Use which are incorporated herein by reference. Please read this Privacy Notice and our Terms of Use carefully. By using the Sites, you understand and are accepting the practices described in this Privacy Notice and accept its terms. You also give your express permission for us to process Personal Data in accordance with this Privacy Notice.
Our use of any of your individually identifiable health information as a patient is subject to the requirements of the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”). Please review our HIPAA Notice of Privacy Practices for information about how we use and disclose your Protected Health Information (as defined by HIPAA, and further explained below), as well as any other privacy practices we apply to such Protected Health Information. “Protected Health Information” or “PHI” means individually identifiable information that relates to an individual’s past, present, or future physical or mental health condition, the provision of health care to an individual, or the past, present, or future payment for health care. Under most circumstances, any information submitted as a patient through a patient portal or received by ProScan through a licensed radiologist will be subject to our HIPAA Notice of Privacy Practices. If there is ever any conflict between this Privacy Notice and the HIPAA Notice of Privacy Practices, the HIPAA Notice of Privacy Practices will apply to the extent that PHI is involved.
Further, we may work with licensed physicians, radiologists, and other medical professionals (“Medical Professional(s)”) to assist in providing our Services through the Sites. Each Medical Professional is an independent entity with their own practice. This Notice does not apply to the independent practices of each Medical Professional, though the Medical Professional will be required to comply with this Privacy Notice in the course of providing the Services through the Sites.
If you are a consumer residing in the United States (“U.S.”), please review our US Privacy Rights provided pursuant to relevant U.S. state laws. including, but not limited to the California Consumer Privacy Act, as amended by the California Privacy Rights Act, together referred to as CCPA (“CCPA”). The US Privacy Rights section includes general information regarding our collection, use, and disclosure of Personal Data of consumers in US.
NOTE: Our Sites might offer links to other websites that are owned or controlled by third parties, including but not limited to, InteleConnect, MRI Online / Medality, Facebook, LinkedIn, and community partners (including, but not limited to, Cris Collinsworth ProScan Fund, Partners for Breast Cancer Care, ProScan/NCH Mammo Matching Fund). This Privacy Notice applies only to ProScan’s Sites. We do not control or endorse the content of any third-party sites and cannot accept responsibility for the privacy practices of any websites not controlled by us and we encourage you to review the privacy policies of any third-party sites prior to providing them with any of your Personal Data.
We may change this Privacy Notice from time to time. If we make changes, we will notify you by revising the date at the top of this Privacy Notice and, in some cases, we may provide you with additional notice (such as adding a statement to our Sites or sending you a notification). We encourage you to review this Privacy Notice regularly to stay informed about our Personal Data practices and the choices available to you.
2. COLLECTION OF INFORMATION; NOTICE AT COLLECTION
This section describes Personal Data you may choose to provide to us, as well as our practices for the automatic collection and use of certain data related to the use of our Sites. We define Personal Data as any information that can (directly or indirectly) identify, locate, or be used to contact you or communicate with you, such as your name, address, telephone number, and other similar and associated information (“Personal Data”). Personal Data includes certain subsets of Personal Data that are considered “sensitive” pursuant to applicable laws, such as government-issued identifiers (such as social security, driver’s license, or passport number), racial or ethnic origin, or health or medical status (“Sensitive Personal Data”).
Methods of Collection
Depending upon your use of the Sites and our interactions with you, we may collect Personal Data directly from you, automatically through the use of cookies and other technologies, from third parties, and/or by deriving such information from other information we collect.
Information You Provide to Us
We collect Personal Data you provide directly to us–-in person, by telephone, by email, and/or via our Sites. For example, you share Personal Data when you create an account on our Sites, make a bill pay account on the ProScan Online portal, use interactive features or applications, sign up to receive a newsletter, enable mobile alerts, or apply online for a job with ProScan. Before providing Sensitive Personal Data to us, we urge you to carefully consider whether to disclose it. If you do provide Sensitive Personal Data to us, you are consenting to its use and disclosure for the purposes and in the manner described at the time of collection and as set forth in this Privacy Notice.
Some of the Personal Data you provide to us may be considered “Health Data” or data that relates to your mental or physical health condition, diagnosis, or treatment, and may include information that relates to your past, present, or future health conditions (including medications, ailments, and prescriptions) that is derived from your use of the Sites. To the extent that your Health Data qualifies as PHI under HIPAA, it will be subject to our HIPAA Notice of Privacy Practices.
Information Automatically Collected When You Interact With Us
When you access or use our Sites or otherwise engage with us, we automatically collect certain information through the use of cookies and other technologies, as further described below in the section entitled Information Automatically Collected.
Information We Collect From Third Parties
We obtain Personal Data from third-party sources. For example, we may collect information about you from healthcare providers or their practices, professional associations, advertising networks, and data analytics providers. Additionally, if you contact ProScan through a third-party platform (such as Facebook or LinkedIn), we will have access to certain information from that platform, such as your name, birthday, and profile picture, in accordance with the authorization procedures determined by such platform. Additional information sources include job applicants’ paper applications and attendance records from educational or other events.
We also collect information from our vendors, suppliers, consultants, professional advisors, and other third parties for the purposes of managing and operating our business. For example, we collect business contact information, financial information, and other information necessary to engage and evaluate suppliers, business partners, and potential merger and/or acquisition targets.
Information We Derive
We may derive information, including Personal Data, or draw inferences about you based on the information we collect. For example, we may make inferences about your location based on your IP address.
Information Automatically Collected
Device & Usage Data
When you access or use our Sites, we automatically collect information about your activity with our Sites, such as entrance or access dates and times, pages viewed, links clicked, and the page you visited before navigating to our Sites. We also collect information about how you access our Sites, including data about the device and network you use, such as your hardware model, operating system version, mobile network, IP address, unique device identifiers, browser type, app version, and system settings such as language your system uses (collectively, “Usage Data”). In accordance with your device permissions, we may collect information about the precise location of your device. You may stop the collection of precise location information at any time (see the Your Choices section below for details).
In certain circumstances, where we link Usage Data and unique device identifiers, such as an IP address, the unique device identifiers or Usage Data may be considered Personal Data. Unique device identifiers may also allow us to identify the country, region, and time zone in which your device is located so we may direct you automatically to the content that is appropriate for your location.
Data Collection Technologies (e.g., Digital Advertising and Cookies)
When you use our Sites, we collect such Usage Data by using technologies such as APIs, web services, scripts, cookies, pixels, tags, web beacons, browser analysis tools, and server logs. We may also use vendors, such as Adobe, Hotjar, and Google, to place cookies and collect data to enable certain services we use, including advertising, visitor tracking, personalization, site analytics and security services, including reCAPTCHA, and the data may be disclosed to our vendors for these purposes. Other data may be disclosed to vendors providing additional services integrated into our Sites, including performance monitoring, user experience components such as user interface frameworks, images and web fonts, maps, and ecommerce functionality.
When you use our Sites, we may place cookies on your computer. Cookies are small text files that websites or mobile apps send to your computer or other Internet-connected device to uniquely identify your browser or to store data or settings in your browser. Cookies allow us to recognize you when you return. They also help us provide a customized experience and enable us to detect certain kinds of fraud. Some of our Sites may use web storage instead of cookies. Cookies can either be session cookies or persistent cookies. A session cookie expires automatically when you close your browser. A persistent cookie will remain until it expires or you delete your cookies. Expiration dates are set in the cookies themselves, some may expire after a few minutes while others may expire at a later time. Cookies placed by the website you’re visiting are sometimes called “first party cookies,” while cookies placed by other companies are sometimes called “third party cookies.”
You can reset your browser to refuse cookies or to indicate when a cookie is being sent. By changing your preferences, you can accept all cookies, you can be notified when a cookie is set, or you can reject all cookies. If you do so and cookies are disabled, you may be required to re-enter your information more often and certain features of our Sites may be unavailable. For more information about cookies and how to disable them, please review the Your Privacy Choices section below.
When we send email communications, we may place a web beacon or similar tracking technology in the email to know whether your device can receive HTML emails, or to collect data on whether the email or an attachment or link in the email has been opened or forwarded.
Third-Party Service Providers
We sometimes utilize third-party service providers to help us track the activity within our Sites. These third parties may use cookies and other tracking technologies. Our third-party service providers include the following:
- Google Analytics (see the Google Analytics section below for details)
Google Analytics
We use Google Analytics, a web analytics service provided by Google, Inc. Google Analytics uses Cookies or other tracking technologies to help us analyze how users interact with the Sites and Services, compile reports on their activity, and provide other services related to their activity and usage. The technologies used by Google may collect information such as your IP address, time of visit, whether you are a returning visitor, and any referring website. The information generated by Google Analytics will be transmitted to and stored by Google and will be subject to Google’s privacy policies.
To prevent your data from being used by Google Analytics, you can install Google’s opt-out browser add-on.
Advertising Industry Resources
You can understand which entities have currently enabled cookies for your browser or mobile device and how to opt-out of some of those cookies by accessing the Network Advertising Initiative’s website or the Digital Advertising Alliance’s website. For more information on mobile specific opt-out choices, visit the Network Advertising Initiative’s Mobile Choices website (https://thenai.org/opt-out/mobile-opt-out).
Please note that these opt-out mechanisms are specific to the device or browser on which they are exercised. Therefore, you will need to opt out on every browser and device that you use.
Types of Personal Data Collected, Used, and/or Disclosed
We may collect, use, and/or share the following categories of Personal Data through the methods identified above in the section entitled Methods of Collection.
This information also serves as our Notice at Collection for the CCPA.
| Category | Personal Data Collected | Purpose for Collection |
|---|---|---|
| Contact data | Name, postal address, online identifier, email address |
We may collect your contact data to:
|
| Commercial data | Account log-in, financial account, debit card, or credit card number in combination with any required security or access code, password, or credentials allowing access to an account |
We may collect your commercial data to:
|
| Internet or other similar electronic network data | Browsing history, search history, information on a consumer’s interaction with a website, application, or advertisement, Internet connection/browser type, IP address, browsing device |
We may collect your internet or other similar electronic network data to:
|
| Geolocation data | Physical location |
We may collect your physical location to:
|
| Sensory data | Voice recordings |
We may collect your sensory data to:
|
| Professional or employment-related data | Employer, title work authorization information, visa status, desired salary, language proficiency, educational background, employment history, and references |
We may collect your professional or employment-related data to:
|
| Profile data | Profile reflecting a person’s preferences, characteristics, psychological trends, predispositions, behavior, attitudes Demographics, age, date of birth. |
We may collect your profile data to:
|
| Sensitive Personal Data | Social security number, driver’s license number, state identification card; Account log-ins, debit or credit card numbers in combination with a security or access code, password, or other credentials, health insurance information, mental or physical health diagnosis, racial or ethnic origin, sexual orientation, age, color, marital status, sex including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions |
We may collect your sensitive data to:
|
We provide the same level of protection to Personal Data regardless of whether we receive it directly through our Sites or by other means. The descriptions below apply to Personal Data collected or received by us, no matter how the information was received.
3. USE OF INFORMATION
ProScan uses the Personal Data we collect to provide, maintain, and improve our Services, products and Sites as well as for our business, operational, and legal purposes, including to:
- Operate and Maintain Our Sites and Services: to ensure the proper functioning of our websites and services.
- Process Transactions: to manage payments and send related information such as confirmations, receipts, and invoices.
- Enhance User Experience: to personalize content and improve the usability of our Sites.
- Communicate Important Updates: to send technical notifications, security alerts, and support messages (e.g. mobile alerts).
- Respond to Inquiries: to address your questions, comments, and requests through customer support.
- Promote Products and Services: to inform you about products, services, events, and news from us and our partners (you may opt out of these communications at any time; see the “Your Choices” section for more details).
- Monitor Usage and Trends: to analyze user behavior and activities on our Sites to improve Services.
- Internal Research and Development: to conduct studies to refine and expand our products and services.
- Evaluate Risk: to assess financial, credit, or insurance risks in business relationships.
- Ensure Security and Compliance: to detect and prevent fraudulent or illegal activities, protect against security breaches, and uphold our Terms of Use.
- Debug and Improve Functionality: to identify and fix system errors to maintain site reliability.
- Meet Legal Obligations: to fulfill legal and financial responsibilities.
- Additional Purposes: such as to use your information for any other purpose disclosed at the time of collection.
We will give you an opportunity to tell us whether we may use your Personal Data to send you other information about ProScan’s products, activities, or opportunities. In most circumstances, you will be able to “unsubscribe” from these communications by following the instructions provided at the time you sign up for the communications or that are included in such communications. Please see the Your Privacy Choices section below for information about how to opt out of these communications at any time.
We may use the Usage Data we and our partners collect during your future visits. This information allows us to direct you to relevant content on the Sites and to remember your computer/device the next time you visit. If you visit multiple ProScan Sites, we may aggregate the Usage Data from your visits to better understand usage of our Sites.
5. YOUR PRIVACY CHOICES
When using the Sites, you will be given opportunities to make choices about the data we receive and how we use it. US Residents are encouraged to review the US Privacy Rights section below.
Account Information
You may update and correct certain account information at any time by logging into your account or, if you do not have an account, by e-mailing us at privacy@proscan.com or by calling us at 877.776.7226. If you wish to deactivate your account, please visit https://proscan.com/contact-us, but note that we may retain certain information as required by law or for our legitimate business purposes.
Location Information
If you initially consent to our collection of your location information, you may later stop the collection of this information at any time by changing the preferences on your browser and/or computer. You may also stop our collection of this location information by following the standard uninstall process to remove all or some of our mobile apps from your device. If you stop our collection of this location information, some features of our mobile applications may no longer function properly.
You can control the tools on your mobile devices. For example, you can turn on and off the GPS locator or push notification on your phone. Please consult your mobile device’s user guide for instructions on clearing cookies, enabling and disabling location services, and disabling push notifications.
Do Not Track Signals and Global Privacy Control
Certain web browsers and other programs may transmit “do-not-track” or “opt-out” signals, also called Global Privacy Control signals (collectively, “GPC Signals”), to websites with which the browser communicates. In most cases, you will need to change your web browser’s settings or add an application to your web browser to enable it to send a GPC Signal. Our Sites will recognize GPC Signals for website users based on the location of the user when they access our Sites. Some web browsers incorporate other “do-not-track” (“DNT”) or similar features to signal websites with which the browser communicates that a visitor does not want to have their online activity tracked. As of the Effective Date, not all web browsers offer a DNT option and DNT signals are not yet uniform. For this reason, our Sites along with many other digital service operators do not respond to all DNT signals. We do not currently “sell” or “share” your Personal Data as defined under the CCPA; however, we will honor GPC signals to the extent that we are engaged in the sale of your personal data as those terms are applicable to you under the applicable state privacy laws. For more information about the Global Privacy Control, please visit https://globalprivacycontrol.org.
Communications Preferences
You may opt out of receiving promotional communications from ProScan (e.g., email and texts) by following the instructions in those communications or by submitting a request through https://proscan.com/contact-us. If you opt out, we may still send you non-promotional communications, such as those about your account or our ongoing business relations.
6. US PRIVACY RIGHTS
Depending upon your US state of residence, you may have certain rights under applicable state data privacy laws. These rights are described generally below, but may be subject to certain exceptions set out in the applicable state data privacy law.
| Right to Confirm | You have the right to confirm whether or not we are processing your Personal Data. |
| Right to Know / Right to Access | You have the right to know and request disclosure of, or the right to access, the Personal Data we have collected about you and information on how we use and share it. |
| Right to Delete | You have the right to request we delete Personal Data which we have collected from you and require we tell our service providers, contractors, and other third-parties with whom we have shared your Personal Data to do the same. |
| Right of Correction | You have the right to request we correct inaccurate Personal Data we have about you. |
| Right to Obtain a Copy / Right to Data Portability | You have the right to obtain a copy of the Personal Data you have provided to us in a portable, readily usable format that can be easily transferred to a third party. |
| Right to Opt-Out |
You have the right to request that we stop selling your Personal Data (i.e., exchanging your Personal Data for valuable consideration), sharing your Personal Data for purposes of targeted advertising, or using your Personal Data for profiling purposes (i.e., certain automated decision-making functions). Please note, as of the Effective Date, we do not use your Personal Data for profiling purposes. We do not currently “sell” or “share” your Personal Data as defined under the CCPA. |
| Right to Non-Discrimination | You have the right to not be retaliated or discriminated against by us because you exercised any of the aforementioned rights. Please note that we may charge a different price or rate or provide a different level or quality of goods and/or services to you, if that difference is reasonably related to the value provided to our business by your Personal Data. We may also offer loyalty, rewards, premium features, discounts, or club card programs consistent with these rights or payments as compensation, for the collection of Personal Data, the sale of Personal Data, or the retention of Personal Data. |
If you or an authorized representative want to review, access, correct, or withdraw consent to the use of your Personal Data you may send us an email at privacy@proscan.com to request access to, correct, or delete any Personal Data that you have provided to us. We may not accommodate a request to change information if we believe the change would violate any law or legal requirement or cause the information to be incorrect. We may request specific information from you to help us confirm your identity and your right to access, correct, or delete, and to provide you with the Personal Data that we hold about you or make your requested changes. Any Personal Data we collect from you to verify your identity in connection with you request will be used solely for the purposes of verification. To verify a request, you will need to provide:
- Enough information to identify you;
- Proof of your identity and address; and
- A description of what right you want to exercise and the information to which your request relates.
If your request is submitted on your behalf by an authorized representative, you will need to provide proof of the representative’s authority to act on your behalf by writing signed by you.
If we are unable to verify your request, we may deny the request or ask you for additional information that is reasonably necessary to authenticate your identity in connection with the consumer request.
Once submitted, you will receive an email within 10 days that we will use to verify your identity and provide confirmation of your request. We will respond to your request to know or delete or correct within 45 days from the day we receive the request. If necessary, we may extend the time period to a maximum of 45 additional days. In such case, you will receive an email notifying you of the extension and explaining the reason for the extension.
Applicable law may allow or require us to refuse to provide you with access to some or all of the Personal Data that we hold about you, or we may have destroyed, erased, or made your Personal Data anonymous in accordance with our record retention obligations and practices. If we cannot provide you with access to your Personal Data, we will inform you of the reasons why, subject to any legal or regulatory restrictions.
You also have the right to appeal our decision if we deny your consumer request. If we deny your consumer request, you can send an email to privacy@proscan.com requesting an appeal of the denial. Within 45 days of receipt of your appeal, we will inform you of the action we took or did not take in response to your appeal. We may extend the 45-day period by an additional 15 days where reasonably necessary and inform you of the delay and the reasons for the delay. If your appeal is denied, we will provide you with an online mechanism to contact the Attorney General to submit a complaint in your respective state.
If you are concerned about our response or would like to correct the information provided, you may contact our Privacy Officer at privacy@proscan.com.
7. HOW WE DISCLOSE, SHARE, AND SELL PERSONAL DATA
We disclose Personal Data as shown below.
The first chart shows the categories of Personal Data we disclose to our service providers and contractors for business or commercial purposes. Although we do not sell Personal Data in exchange for money, some of the ways in which we disclose Personal Data for advertising or to our affiliated brands and companies may be considered “sales” under some state consumer data privacy laws. We do not have actual knowledge that we sell or share the Personal Data of consumers under 13 years of age.
Disclosures for a Business or Commercial Purpose
| Category of Personal Data | Categories of Recipients | Purposes for Disclosure |
|---|---|---|
| Contact data | Service providers and affiliates to provide services on our behalf |
|
| Commercial data | Service providers and affiliates to provide services on our behalf |
|
| Internet or other similar electronic network activity | Service providers and affiliates to provide services on our behalf |
|
| Geolocation data | Service providers and affiliates to provide services on our behalf |
|
| Professional or employment-related information | Service providers and affiliates to provide services on our behalf |
|
| Profile data | Service providers and affiliates to provide services on our behalf |
|
| Sensitive Personal Data | Service providers and affiliates to provide services on our behalf |
|
8. SHINE THE LIGHT LAW (CALIFORNIA RESIDENTS ONLY)
If you are a California resident, California Civil Code § 1798.83 permits you to request information regarding the disclosure of your Personal Data by us to third parties for the third -parties’ direct marketing purposes (as those terms are defined in that statute). To make such a request, please send an email to privacy@proscan.com with the subject line “Shine the Light Request.”
9. CHILDREN’S PRIVACY
ProScan does not intend to collect Personal Data from children under age 13 without consent from the child’s parent or legal guardian, pursuant to applicable law. We do not share Personal Data of anyone under 13 years of age with anyone outside of ProScan except where required by law and with vendors, service providers, and consultants bound by law or contract to protect Personal Data and only use Personal Data in accordance with our instructions or the agreements we have signed with them.
Children under 13 years of age should not submit any Personal Data to us without the express permission of their parent or legal guardian. If you believe that your child has submitted Personal Data and you would like for it to be removed from our systems, please submit a request through https://proscan.com/contact-us. We will make reasonable efforts to comply with your request.
10. PROTECTION OF INFORMATION
Consistent with applicable laws and requirements, we have implemented reasonable physical, technical, and administrative safeguards designed to protect Personal Data from loss, misuse, alteration, theft, unauthorized access, and unauthorized disclosure consistent with legal obligations and industry practices. However, as is the case with all websites, applications, products, and services, we are not able to guarantee security for data collected through our Sites.
We are not responsible for any interception or interruption of any communications or for changes to or losses of data through the internet. Users of the Sites are responsible for maintaining the security of any password, user ID, or other form of authentication involved in obtaining access to password protected or secure areas of the Sites. Any access to the Sites through your user ID and password will be treated as authorized by you. If we believe it is necessary or advisable to help protect your Personal Data and/or the integrity of the Sites, we may suspend your use of all or part of the Sites, without notice.
Unauthorized access to any of the Sites is prohibited and may lead to criminal prosecution.
11. LOCATION OF OUR SITE
Our Site is hosted and operated in the United States. However, we and our service providers may store information about individuals, including Personal Data, in the United States, or we may transfer it to, and store it within, other countries.
Visitors from jurisdictions outside the United States visit us at their own choice and risk. If you are not a resident of the United States, you acknowledge and agree that we may collect and use your Personal Data outside your home jurisdiction and that we may store your Personal Data in the United States or elsewhere. Please note that the level of legal protection provided in the United States may not be as stringent as that under privacy standards or the privacy laws of other countries, possibly including your home jurisdiction.
12. RETENTION OF PERSONAL DATA
We retain your Personal Data for as long as necessary to fulfill the purposes for which we collect it, such as to provide you with the service you have requested, and for the purpose of satisfying any legal, accounting, contractual, or reporting requirements that apply to us.
13. CONTACT US
If you have any questions about this Privacy Notice or about your Personal Data, you may contact us as follows:
ProScanAttn: Privacy
5400 Kennedy Avenue
Cincinnati, Ohio, 45213
Email: privacy@proscan.com
If you wish to receive a response by email, please be sure to include your name, postal address, and email address. If we do not receive an email address, we will respond by postal mail.
