Website Privacy Policy & Online Privacy Compliance

 

Websites collect significant amounts of information about their visitors. Contact forms, appointment requests, newsletter subscriptions, analytics tools, cookies, advertising pixels, account registrations, payment systems, and other online technologies may collect or transmit personal information—sometimes without the website owner fully realizing what information is being gathered or where it is being sent.

A properly drafted Website Privacy Policy explains what information a business collects, how that information is used, whether it is shared with third parties, what choices or legal rights users may have, and how individuals can contact the organization about its privacy practices.

For health care organizations, website privacy compliance can be particularly complicated. A website may be subject to general state consumer privacy laws while certain information collected through patient portals, appointment tools, or other online services may also implicate HIPAA, Business Associate Agreements, breach notification requirements, or restrictions on online tracking technologies.

G2Z Law Group assists health care providers, professional practices, technology companies, and other businesses with Website Privacy Policies, online privacy compliance, website tracking technologies, consumer privacy disclosures, and related data-protection requirements.

Does Every Website Need a Privacy Policy?

 

Whether a privacy policy is legally required depends upon the nature of the business, the information being collected, the individuals using the website, and the jurisdictions whose laws apply.

Even when a particular law does not expressly require a privacy policy, a business that collects personal information through its website should generally provide users with clear information about its data practices.

Websites may collect information such as:

  • names and contact information;

  • email addresses and telephone numbers;

  • account or login information;

  • appointment requests;

  • payment information;

  • IP addresses and device identifiers;

  • geographic information;

  • browsing activity;

  • cookie and tracking information;

  • advertising identifiers;

  • health-related information; and

  • information submitted through online forms.

The privacy policy should accurately reflect what the website actually does. Using a generic template that does not match the website's technology or business practices can create compliance concerns of its own.

What Should a Website Privacy Policy Include?

 

The content of a Website Privacy Policy depends upon applicable law and the organization's actual data practices.

Common provisions address:

  • categories of personal information collected;

  • sources of the information;

  • purposes for which information is used;

  • cookies and similar technologies;

  • website analytics;

  • advertising and marketing activities;

  • disclosure or sharing with service providers and other third parties;

  • sale or sharing of personal information, where applicable;

  • consumer privacy rights;

  • procedures for submitting privacy requests;

  • data retention;

  • security practices;

  • children's information;

  • links to third-party websites;

  • changes to the privacy policy; and

  • contact information for privacy questions.

Some state privacy laws impose specific disclosure requirements. Virginia's Consumer Data Protection Act, for example, requires covered controllers to provide a reasonably accessible, clear, and meaningful privacy notice describing categories of personal data processed, processing purposes, how consumers can exercise their rights, categories of information shared with third parties, and categories of third parties receiving that information.

Do State Consumer Privacy Laws Affect Website Privacy Policies?

 

Increasingly, yes.

A growing number of states regulate how businesses collect, use, disclose, sell, or share personal information. Whether a particular law applies may depend upon factors such as the number of consumers whose data is processed, revenue, the nature of the business, and whether personal information is sold or used for targeted advertising.

Applicable laws may give consumers rights to:

  • access personal information;

  • request correction;

  • request deletion;

  • obtain copies of their information;

  • opt out of certain sales or sharing;

  • opt out of targeted advertising; or

  • appeal certain privacy-request decisions.

For example, California privacy law requires covered businesses to provide mechanisms through which consumers can exercise specified privacy rights, and the California Privacy Protection Agency explains that privacy policies play an important role in communicating those procedures. California businesses may also be required to recognize qualifying opt-out preference signals such as Global Privacy Control.

Businesses operating nationally should therefore avoid assuming that compliance with the law of the state where the company is headquartered is sufficient.

How Does HIPAA Affect a Health Care Website?

 

HIPAA does not automatically apply to every piece of information collected through every health care website. However, a website operated by a HIPAA-covered entity or business associate can create HIPAA obligations when online technologies create, receive, maintain, or transmit protected health information (PHI).

This can become particularly important with:

  • patient portals;

  • online appointment scheduling;

  • symptom-checking tools;

  • patient registration;

  • telehealth platforms;

  • online forms containing medical information; and

  • third-party tracking technologies.

HHS guidance explains that tracking technologies such as cookies, pixels, session-replay tools, and similar technologies can collect information about website users and transmit that information to third parties. When information transmitted by a HIPAA-regulated entity constitutes PHI, the HIPAA Privacy, Security, and Breach Notification Rules may apply.

Health care organizations should therefore review not only what their privacy policy says, but also what their website actually transmits to analytics, advertising, and technology vendors.

Is a Website Privacy Policy the Same as a HIPAA Notice of Privacy Practices?

 

No.

A Website Privacy Policy and a HIPAA Notice of Privacy Practices serve different purposes.

A Website Privacy Policy generally describes how information collected through a website or online service is handled. A HIPAA Notice of Privacy Practices explains how a HIPAA-covered entity may use and disclose protected health information and describes the individual's rights under HIPAA.

A health care organization may need both documents.

Importantly, simply disclosing a data practice in a website privacy policy does not make an otherwise impermissible disclosure of PHI lawful. HHS specifically states that identifying tracking technologies in a privacy policy, notice, or website terms does not by itself authorize a disclosure of PHI to a tracking vendor. Where a vendor is acting as a business associate, an appropriate Business Associate Agreement and a permitted HIPAA disclosure may still be required.

What About Cookies, Analytics, and Tracking Pixels?

 

Modern websites frequently use third-party tools for analytics, advertising, customer engagement, and website functionality.

These may include:

  • cookies;

  • tracking pixels;

  • web beacons;

  • session-replay technology;

  • advertising identifiers;

  • analytics platforms; and

  • social-media tracking technologies.

These tools can transmit information directly to third-party vendors. The website owner should understand what is being collected, whether the information is linked to identifiable individuals, why the information is being used, and whether applicable law requires notice, consent, opt-out mechanisms, or contractual protections.

This issue is particularly significant for health care websites because HHS continues to maintain guidance addressing HIPAA-regulated entities' use of online tracking technologies. That guidance also notes that a federal court vacated a portion of HHS's earlier interpretation concerning certain visits to unauthenticated public webpages, making careful factual analysis particularly important.

Should a Privacy Policy Be Copied From Another Website?

 

Generally, no.

A privacy policy should reflect the organization's actual collection, use, disclosure, and retention practices.

Copying another company's policy or relying exclusively on an automated template can create discrepancies between what the website says and what the organization actually does. The business may also be subject to different laws, use different vendors, collect different types of information, or offer different consumer rights.

Drafting an accurate Website Privacy Policy should therefore begin with an assessment of the organization's website, data flows, third-party vendors, and applicable legal requirements.

What Can G2Z Law Group Do for My Business?

 

G2Z Law Group assists health care organizations, professional practices, technology companies, and other businesses with Website Privacy Policies and online privacy compliance.

Our attorneys can help identify applicable privacy requirements, review the types of information collected through a website, evaluate third-party tracking and analytics technologies, draft or revise Website Privacy Policies, and coordinate privacy disclosures with the organization's actual business practices.

For health care organizations, we can also evaluate whether online activities implicate HIPAA, Business Associate Agreements, patient privacy requirements, tracking technologies, breach notification obligations, or other health care regulatory requirements.

A well-designed privacy policy should do more than satisfy a website requirement. It should accurately communicate the organization's data practices and form part of a broader system for managing privacy, security, and regulatory risk.

Contact us.

Please review the disclaimer below before sending us an email.

info@g2zlaw..com
(202) 656-8387

1250 Connecticut Ave. NW, Suite 700
Washington, DC 20036

 

Disclaimer: Completing and submitting the above electronic form does not establish an attorney-client relationship with us. Our Law Firm cannot agree to represent you until we determine there would be no conflict of interest an notify you that you are a client. Any information sent to the Law Firm via this website before we have agreed to represent you will not be treated as confidential. Information submitted to the Law Firm before we agree to represent you will not bar the Law Firm from representing or continuing to represent someone whose interests are adverse to yours in connection with your case.

Copyright 2020, G2Z Law Group, PLLC