Your Privacy: Security & HIPAA
Protecting the information entrusted to us.
Strategic Managed Care Solutions is committed to protecting privacy, confidentiality, and information security.
Protecting the Information Entrusted to Us
Strategic Managed Care Solutions, LLC ("SMCS," "we," "us," or "our") is committed to protecting the privacy, confidentiality, and security of information entrusted to us by the individuals, families, health-care organizations, and business partners we serve.
SMCS provides non-clinical services to health-care organizations, including member outreach, engagement, scheduling support, coordination, referrals, and related administrative services.
In performing these services, SMCS may receive, create, maintain, use, or transmit information on behalf of health-care organizations. Depending on the services provided and the information involved, this may include Protected Health Information ("PHI") regulated under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA").
When SMCS performs services involving PHI on behalf of a HIPAA-covered health-care organization, SMCS may act as a Business Associate as defined under HIPAA.
We take that responsibility seriously.
Our Role as a Business Associate
SMCS works with health-care organizations to provide non-clinical services that support member engagement, access, referrals, scheduling, and coordination.
When our services involve PHI on behalf of a covered entity, our responsibilities are established through applicable contracts and Business Associate Agreements ("BAAs").
Our BAAs and applicable law govern how SMCS may use, disclose, protect, retain, and dispose of PHI.
SMCS does not use PHI for purposes unrelated to the services we are contracted to provide except where otherwise permitted or required by law or our applicable agreement.
HIPAA generally requires covered entities to establish written arrangements with Business Associates that define permitted uses and disclosures of PHI and require appropriate safeguards. Business Associates are also directly subject to certain HIPAA requirements.
Information We May Handle
Depending on the services provided to a health-care organization, SMCS may handle information such as:
- Name and contact information
- Date of birth
- Member or patient identification information
- Medicaid or insurance-related information
- Eligibility information
- Appointment and scheduling information
- Referral information
- Health-care provider information
- Service coordination information
- Outreach and engagement information
- Information concerning services requested or provided
- Communications and interaction history
- Other information necessary to perform contracted services
Not all information handled by SMCS is PHI. The protections that apply to particular information depend on the nature of the information, the purpose for which it is handled, the applicable contract, and applicable law.
How We Use Information
When acting on behalf of a health-care organization, SMCS uses information only as permitted by our contractual relationship, applicable Business Associate Agreement, and applicable law.
Depending on the services we provide, this may include:
Member Outreach
Contacting individuals identified by our health-care partners for authorized outreach and engagement activities.
Scheduling and Coordination
Helping individuals schedule appointments, coordinate services, or connect with appropriate resources.
Referrals
Supporting referrals and connections to health-care, community, or other authorized services.
Service Documentation
Recording information necessary to document outreach, engagement, scheduling, referrals, and other contracted activities.
Reporting
Providing authorized information and service outcomes to the health-care organizations that engage SMCS.
Operational Support
Using information as necessary to administer and support the services we provide, consistent with applicable contracts and law.
SMCS does not sell PHI.
SMCS does not use PHI for unrelated advertising or marketing purposes unless specifically authorized and permitted by applicable law and contractual requirements.
Minimum Necessary Access
SMCS follows the principle of limiting access to information to what is reasonably necessary for authorized personnel and systems to perform their assigned responsibilities.
Access to PHI and other sensitive information is based on job responsibilities and business need.
Where appropriate, SMCS uses role-based access controls and other safeguards to limit access to authorized individuals.
Our goal is to ensure that employees, contractors, systems, and service providers receive only the information necessary to perform their authorized functions.
Privacy and Confidentiality
SMCS maintains policies and procedures designed to protect confidential information from unauthorized access, use, disclosure, alteration, or loss.
Our workforce members are expected to protect confidential information and follow applicable privacy and security requirements.
Depending on their responsibilities, personnel may receive training regarding privacy, confidentiality, information security, appropriate handling of sensitive information, and applicable regulatory requirements.
Information Security
SMCS maintains administrative, technical, and physical safeguards designed to protect electronic protected health information and other sensitive information.
Depending on the system and information involved, safeguards may include:
- User authentication and access controls
- Role-based permissions
- Password and credential protections
- Multi-factor authentication where appropriate
- Encryption and secure transmission technologies
- System and application security controls
- Logging and monitoring
- Secure data storage
- Backup and recovery procedures
- Device and endpoint protections
- Security updates and vulnerability management
- Workforce security and access management
- Incident response procedures
- Data retention and secure disposal procedures
The specific safeguards implemented may vary based on the nature of the information, the system involved, the services being provided, applicable contractual requirements, and applicable law.
Access Management
SMCS limits access to sensitive information based on authorized job responsibilities.
We use access-management processes designed to:
- Grant access only to authorized users
- Limit permissions according to job responsibilities
- Remove or modify access when responsibilities change
- Disable access when an individual's relationship with SMCS ends
- Review access where appropriate
- Protect administrative and privileged accounts
SMCS continually evaluates opportunities to strengthen access controls as our systems and services evolve.
Security Monitoring and Incident Response
SMCS maintains processes for identifying, evaluating, responding to, and documenting suspected privacy and security incidents.
When a potential incident is identified, SMCS may take steps that include:
- Containing or limiting the incident
- Investigating what occurred
- Identifying the information and systems involved
- Assessing potential impact
- Taking corrective or mitigation measures
- Documenting the incident and response
- Notifying appropriate parties when required
If an incident involves PHI received from or maintained on behalf of a covered entity, SMCS will follow the notification and reporting requirements established by the applicable Business Associate Agreement and applicable law.
HIPAA's Business Associate requirements include obligations concerning security incidents and breaches of unsecured PHI.
Business Associate Relationships
SMCS enters into Business Associate Agreements when required by HIPAA and applicable law.
These agreements establish the permitted and required uses and disclosures of PHI and the safeguards that must be maintained.
Our Business Associate relationships may include requirements concerning:
- Permitted uses and disclosures
- Privacy and confidentiality
- Security safeguards
- Reporting of unauthorized uses or disclosures
- Security incidents and breaches
- Cooperation with covered entities
- Individual rights requests
- Regulatory requirements
- Return or destruction of PHI
- Subcontractors that handle PHI
HHS requires BAAs to establish restrictions and conditions on PHI and to require appropriate safeguards.
Our Subcontractors and Service Providers
SMCS may use third-party service providers to support our operations and deliver contracted services.
When a third party creates, receives, maintains, or transmits PHI on behalf of SMCS in a manner that makes the third party a Business Associate subcontractor, SMCS requires appropriate contractual protections consistent with applicable HIPAA requirements.
We evaluate service providers based on the nature of the services they provide and the information to which they may have access.
Where required, applicable agreements include privacy, security, confidentiality, and PHI protection requirements.
HIPAA requires Business Associates to appropriately address subcontractors that handle PHI on their behalf.
Data Retention and Disposal
SMCS retains information for as long as reasonably necessary to perform authorized services, satisfy contractual obligations, meet legal or regulatory requirements, resolve disputes, maintain appropriate business records, and fulfill other legitimate purposes.
Retention periods may vary depending on the type of information, the applicable contract, and legal or regulatory requirements.
When information is no longer required to be retained, SMCS uses reasonable measures to securely dispose of or destroy it, subject to applicable contractual and legal requirements.
Where a Business Associate Agreement requires the return or destruction of PHI following termination of services, SMCS will follow the applicable contractual requirements to the extent required and feasible.
Information We Do Not Sell
SMCS does not sell protected health information.
We also do not permit PHI received on behalf of our health-care partners to be used for unrelated commercial purposes.
Any permitted use or disclosure of PHI is governed by the applicable Business Associate Agreement, other applicable contractual requirements, and applicable law.
Individual Privacy Rights
SMCS recognizes that individuals may have rights concerning their health information under HIPAA and other applicable laws.
For information maintained by SMCS on behalf of a covered health-care organization, requests concerning an individual's HIPAA rights are generally coordinated with the applicable covered entity in accordance with the governing Business Associate Agreement and applicable law.
Depending on the circumstances, individuals may have rights relating to:
- Access to certain health information
- Amendment of certain health information
- Restrictions on certain uses or disclosures
- Confidential communications
- Information concerning certain disclosures
HIPAA places many of these individual-rights obligations directly on covered entities, while Business Associate Agreements establish how a Business Associate assists the covered entity when information held by the Business Associate is involved.
If you believe SMCS maintains information about you on behalf of a health-care organization, you may contact the health-care organization directly or contact SMCS using the information below.
Privacy Complaints
If you believe that your privacy has been violated or that your information has been handled improperly, we encourage you to contact us.
SMCS will review privacy concerns and take appropriate action consistent with applicable policies, contracts, and law.
For information handled by SMCS on behalf of a health-care organization, you may also contact the health-care organization that provides or coordinates your services.
SMCS does not retaliate against individuals for raising a good-faith privacy or security concern.
HIPAA Notice of Privacy Practices
SMCS is a service provider to health-care organizations and, when acting as a Business Associate, is generally not the entity responsible for providing the health-care organization's HIPAA Notice of Privacy Practices.
The applicable health-care organization is generally responsible for its own Notice of Privacy Practices and for communicating its privacy practices and individual rights to its patients or members.
If you are seeking the Notice of Privacy Practices for a particular health-care provider or health plan, please contact that organization directly.
HHS states that the HIPAA Privacy Rule does not generally require a Business Associate to create its own Notice of Privacy Practices.
Other Privacy Laws
HIPAA is not the only privacy law that may apply to information handled by SMCS.
Depending on the nature of the information, services provided, location of the individual, and contractual requirements, additional federal or state privacy and security requirements may apply.
SMCS evaluates applicable requirements and incorporates appropriate contractual, administrative, technical, and operational safeguards into its services.
Where another applicable law provides additional privacy or security protections, SMCS will follow those requirements as applicable.
Website Privacy
This page describes SMCS's approach to privacy and security when providing services to health-care organizations.
Our general practices regarding information collected through the SMCS website are described in our Privacy & Terms policy.
Website visitors should review that policy for information regarding website forms, communications, cookies, analytics, third-party services, and other website-related data practices.
Our Ongoing Commitment
Privacy and security are ongoing responsibilities.
SMCS continually evaluates its policies, procedures, technology, workforce practices, and service-provider relationships to identify opportunities to strengthen the protection of sensitive information.
As our services and technology evolve, we may update our privacy and security practices to address new risks, regulatory requirements, contractual obligations, and industry best practices.
Our commitment is straightforward:
We take the information entrusted to us seriously and work to protect it with appropriate safeguards throughout its lifecycle.
Contact Us
For questions regarding SMCS privacy, security, or the handling of information, please contact:
Strategic Managed Care Solutions, LLCAttn: Privacy & Compliance
70 Richmond Street
Brooklyn, NY 11208
Email: privacy@smcsnow.net
Phone: (844) 303-5958
For questions concerning the privacy practices or Notice of Privacy Practices of a particular health-care provider or health plan, please contact that organization directly.
Important Notice
This page is intended to describe SMCS's general privacy, security, and HIPAA-related practices. It does not replace or modify any Business Associate Agreement, service agreement, applicable law, or other contractual obligation between SMCS and a health-care organization.
Where a contract or applicable law establishes requirements that differ from this general statement, the applicable contract and legal requirements will govern.