IF APPLICABLE: THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.

Who Will Follow This Notice

This Notice is being provided pursuant to certain requirements of the Health Insurance Portability and Accountability Act of 1996 and related regulations (collectively, “HIPAA”). You also have a right to receive a paper copy of this Notice and may ask us to give you a copy of this Notice at any time.

This Notice describes the practices of AXIS Capital Holdings and its Affiliates: (collectively, “AXIS”). All uses of “we”, “our”, “us”, and any like terms in this Notice shall refer to AXIS.

Our Commitment to Your Privacy

Please note that this Notice does not fully describe every use or disclosure. And we may have to meet conditions in HIPAA before we can use or disclose your information for the described purposes.

We understand that your protected health information (“PHI”) is personal and we are committed to protecting that information. We create a record of your benefits, eligibility status and claims history. We need this record to provide you with quality health care services and to comply with certain legal requirements. Hospitals, physicians and other health care providers providing health care services to you may have different policies or notices regarding their uses and disclosures of your PHI.

This Notice will tell you about the ways in which we may use and disclose PHI about you. This Notice will also describe your rights and certain obligations we have regarding the use and disclosure of PHI.

We are required by law to abide by the terms of this Notice to: (1) make sure that PHI that identifies you is kept private; (2) give you this Notice of our legal duties and privacy practices with respect to PHI about you; (3) follow the terms of the Notice that is currently in effect; and (4) notify you following a breach of your unsecured PHI.

You may have additional privacy rights under state law. An applicable state law that provides for greater privacy protection or privacy rights will continue to apply.

How We May Use and Disclose PHI About You

We will not disclose your PHI to anyone, except with your authorization or as otherwise permitted or required by HIPAA and other applicable law. Uses and disclosures other than those described in this Notice will require your written authorization. Your written authorization is required for most uses and disclosures of psychotherapy notes, marketing and any use or disclosure that might constitute a sale of PHI. You may revoke your authorization at any time, but you cannot revoke your authorization if we have already acted on it.

Whenever we use or disclose your PHI as described in this Notice, we will make reasonable efforts to limit the use or disclosure of such PHI to the minimum necessary to accomplish the intended purpose of the use or disclosure, as required by HIPAA.

AXIS Capital Holdings and its Affiliates will share PHI with each other, as necessary to carry out treatment, payment, or health care operations relating to AXIS.

Payment

We may use and disclose your PHI to pay for your medical benefits. These activities may include determining eligibility or coverage for insurance benefits, reviewing services provided to you to determine medical necessity, and undertaking utilization review or case management activities with respect to your claims. For example, we may use and disclose your PHI to pay your claims or process your premium payments.

Treatment

We may use or disclose PHI about you to facilitate medical treatment or services by providers. We may disclose PHI about you to health care providers, including doctors, nurses, technicians, medical students, or other medical personnel who are involved in taking care of you. For example, we might disclose information about you to physicians who are treating you.

Health Care Operations

We may use or disclose PHI about you for our insurance operations. These uses and disclosures are necessary to run the insurance company and make sure that our insureds receive quality service. Here are some examples of the ways that we use your PHI for our health care operations: creation, renewal, replacement or maintenance of your insurance contract; placing an insurance contract for reinsurance of our insurance risks; claims adjudication; disclosures to medical consultants to determine the medical necessity of treatment recommended by your physician; policy administration, underwriting and premium rating; eligibility determinations; detection and investigation of fraud and other unlawful conduct; recovery of overpayments; conduct of grievances and appeals programs; and disclosures to PPO networks for purposes of repricing claims.

We are prohibited from using or disclosing PHI that is genetic information of an individual for underwriting purposes.

We may use or disclose your PHI as necessary to provide you with information about other health-related products or services that are included in your insurance benefits, including communications about replacement of, or enhancements to, an insurance contract. For example, your name and address may be used to send you a newsletter about our organization and your insurance benefits. You may opt-out of receiving such materials. We will not disclose your PHI to third parties for marketing purposes without your written authorization.

Required Disclosures

We will disclose PHI about you when required to do so by federal, state or local law. We must also share your PHI with the Secretary of the Department of Health and Human Services to investigate or determine our compliance with federal privacy laws.

To Avert a Serious Threat to Health or Safety

We may use and disclose PHI about you when necessary to prevent a serious threat to your health and safety or to the health and safety of the public or another person. Any disclosure, however, would only be to someone able to help prevent the threat.

Health Oversight

We may disclose PHI to a health oversight agency for activities authorized by law, such as audits, investigations and inspections. Health oversight agencies include government agencies that oversee health plan administration, state insurance regulatory authorities and certain other government regulatory programs.

Public Health Risks

We may disclose PHI about you for public health activities. These activities may include (1) the prevention or control of disease, injury or disability and (2) notifying people of recalls of products they may be using.

Lawsuits and Disputes

If you are involved in a lawsuit or a dispute, we may disclose PHI about you in response to a court or administrative order. We may also disclose PHI about you in response to a subpoena, discovery request or other lawful process by someone else involved in the dispute, but only if efforts have been made to tell you about the request (which may include written notice to you) or to obtain an order protecting the information requested.

Law Enforcement

We may release PHI if asked to do so by a law enforcement official: (1) in response to a court order, subpoena, warrant, summons or similar process; (2) to identify or locate a suspect, fugitive, material witness or missing person; (3) about the victim of a crime if, under certain limited circumstances, we are unable to obtain the person’s agreement; (4) about a death we believe may be the result of criminal conduct; or (5) in emergency circumstances to report a crime, the location of the crime or victims, or the identity, description or location of the person who committed the crime.

For Specific Government Functions

We may disclose your PHI for the following specific government functions: (1) health information of military personnel, as required by military authorities; (2) health information of inmates, to a correctional institution or law enforcement official; and (3) for national security reasons.

 

Workers’ Compensation

We may disclose your PHI as authorized to comply with workers’ compensation laws and other similar programs established by law.

Business Associates

We may disclose your PHI to our business associates. We will enter into contracts with our business associates that require them to only use and disclose your PHI as we are permitted to do so under HIPAA.

Group Health Plan Sponsors

If your insurance benefits are provided through a group health plan sponsored by an employer, we may disclose your PHI to designated employees of that employer so they can carry out their plan-related administrative functions.

De-Identified Information

We may use your PHI to create information that is not is not individually identifiable health information. We are not required to obtain your authorization when we use or disclose de-identified information.

Other Uses and Disclosures

We may also use or disclose your PHI in the following ways, in accordance with applicable requirements under HIPAA:

  • to a close friend or family member involved in or who helps pay for your health care;
  • To advise a family member or close friend about your condition, your location (for example, that you are in the hospital), or your death;
  • to proper authorities with regard to victims of abuse, neglect or domestic violence;
  • for organ or tissue donation purposes;
  • to coroners and funeral directors, with respect to decedents; or
  • to health information researchers when the individual identifiers within the PHI have been removed or when an institutional review board or privacy board has reviewed the research proposal and established protocols to ensure the privacy of the requested information, and approves the research.

Your Rights

The following is a statement of your rights with respect to your PHI and a brief description of how you may exercise these rights.

Right to Inspect and Copy

You have the right to inspect and obtain a copy of your PHI. You may inspect and obtain a copy of PHI about you for as long as we maintain the PHI. We may charge you a fee for the costs of copying, mailing or other supplies that are necessary to grant your request. You have the right to choose to obtain a summary instead of a copy of your PHI.

Under federal law, however, you may not inspect or copy psychotherapy notes or information compiled in reasonable anticipation of, or for use in a civil, criminal or administrative action or proceeding. We may deny your request to inspect and copy your PHI in certain circumstances, as permitted by HIPAA. If you are denied access to PHI, you may have the right to request that the denial be reviewed. A review will be granted as and to the extent required by HIPAA.

Right to Amend

If you feel that the PHI we have about you is incorrect or incomplete, you may ask us to amend the information. You have the right to request an amendment for as long as the information is kept by us. You must also provide a reason that supports your request. We may deny your request for an amendment if it is not in writing or does not include a reason to support the request. In addition, we may deny your request if you ask us to amend any of the following information: (1) information that is not part of the PHI kept by us; (2) information that was not created by us, unless the person or entity that created the information is no longer available to make the amendment; (3) information that is not part of the information which you would be permitted to inspect and copy; or (4) information that is accurate and complete.

Right to an Accounting of Disclosures

You have the right to request an accounting of disclosures (that is, a list of certain disclosures of your PHI) that we have made within the six-year period immediately preceding the date on which the accounting is requested. You do not have a right to an accounting of disclosures under certain circumstances including, but not limited to, the following:

  • for treatment, payment or health care operations;
  • to you about your own health information;
  • incidental to other permitted disclosures;
  • where authorization was provided;
  • to family or friends involved in your care (where disclosure is permitted without authorization);
  • for national security or intelligence purposes or to correctional institutions or law enforcement officials in certain circumstances; or
  • as part of a limited data set where the information disclosed excludes identifying information.

To request this list or accounting of disclosures you must submit your request, which shall state a time period, which may be for a period of time less than six years from the date of the request. Your request should indicate in what form you want the list (for example, paper or electronic). The first list you request within a 12-month period will be free. For additional lists, we may charge you for the costs of providing the list. We will notify you of the cost involved and you may choose to withdraw or modify your request at that time before any costs are incurred.

Right to a Restriction

You have the right to request a restriction or limitation on the PHI we use or disclose about you for treatment, payment, or health care operations. You also have the right to request a limit on the PHI we disclose about you to someone who is involved in your care or the payment for your care, like a family member or friend. For example, you could ask that we not use or disclose information about a surgery that you had. You can also request restrictions on uses or disclosures in instances in which you are not present or when your permission cannot practicably be obtained due to your incapacity or an emergency circumstance, and on disclosures to a public or private entity authorized by law or by its charter to assist in disaster relief efforts.

We are not required to agree to a restriction that you request. If we do agree to a requested restriction, we will put the agreement in writing and follow it, except in emergency situations. We cannot agree to limit uses or disclosures of information that are required by law.

Right to Request Confidential Communications

You have the right to request that we communicate with you about medical matters in a certain way or at a certain location. For example, you can ask that we only contact you at work or by mail. We will accommodate all reasonable requests. We are required by law to accommodate reasonable requests to receive communications of PHI by alternative means or at alternative locations if you clearly state in your written request for confidential communications that disclosure of all or part of the information could endanger you. Your request must specify how or where you wish to be contacted.

Changes to Notice

We can change the terms of this Notice at any time. If we do, the new terms and policies will be effective for all of the PHI we already have about you as well as any information we receive in the future. If there is a material change to the way we use or disclose your PHI, your rights, our legal duties or other privacy practices as stated in this Notice, we will send you a copy of the revised notice.

Complaints

If you believe your privacy rights have been violated, you may file a complaint with us using the contact information below or with the Secretary of the Department of Health and Human Services at www.hhs.gov/ocr/privacy/hipaa/complaints/. All complaints must be submitted in writing. You will not be penalized for filing a complaint.

HOW TO CONTACT US

Please address all inquiries, requests, and other communications regarding your personal information or this Privacy Notice to:

Contact: Data Protection Officer Email: [email protected] Address: 10000 Avalon Boulevard, Suite 200, Alpharetta, GA 30009 Phone: 1 888 914 9661, PIN 292703

Effective: 11 May 2023

Revised: 1 April 2024