1. Who We Are
Medical Assurance Limited (“Medical Assurance”, “we”, “us” or “our”) provides and/or facilitates access to diagnostic, health-related and membership services, directly or through appropriately authorised independent providers, depending upon the jurisdiction and service concerned.
We are committed to protecting the privacy, confidentiality and security of personal information entrusted to us.
This Global Website & Enquiry Privacy Notice explains how we collect, use, disclose, store and protect personal information when individuals visit our website, request information, submit an enquiry, communicate with us or express an interest in Medical Assurance programs or services.
This Notice primarily applies to website visitors, prospective members and persons making general enquiries.
Different or supplemental privacy notices may apply when an individual enrols as a member, accesses diagnostic or healthcare-related services, interacts with a healthcare provider, or provides health information through an authorised channel.
Medical Assurance operates, or may operate, through different entities and service arrangements across Trinidad and Tobago, the United Kingdom and the United States. The laws applicable to personal information may therefore vary according to the relevant entity, location of the individual, location of processing and nature of the service provided.
Where applicable law provides protections greater than those described in this Notice, applicable law will prevail.
2. Information We May Collect
Depending upon your interaction with Medical Assurance, we may collect:
- Identity and Contact Information: Your name, email address, telephone number, country or region, and postal address where reasonably necessary.
- Enquiry Information: Information that you voluntarily provide when asking about Medical Assurance, our programs, membership options, diagnostic-access services or locations.
- Membership Interest Information: Information regarding the Medical Assurance program or service in which you have expressed an interest.
- Transaction Information: Where applicable, limited information concerning payments or transactions. Payment-card information may be processed directly by authorised payment-service providers and may not be stored by Medical Assurance.
- Technical and Website Information: Information such as IP address, browser type, device information, operating system, security logs, website interactions and cookie or similar technology information where permitted by applicable law.
- Communication Records: Information contained in communications between you and Medical Assurance, including email, telephone and website enquiries.
We seek to collect only personal information reasonably necessary and proportionate to the purpose for which it is required.
3. Health And Medical Information
Our general website enquiry forms are not intended for the submission of medical records or detailed health information.
Unless Medical Assurance specifically requests information through an authorised and appropriately secured channel, you should not submit diagnostic reports, laboratory or blood-test results, imaging results, prescriptions, genetic information, medical histories, government identification documents or other sensitive health information through our general website enquiry forms or ordinary email.
If health information becomes necessary for a particular Medical Assurance service, you will be informed of the appropriate means through which such information should be provided.
Additional privacy terms may apply to the collection and processing of health information.
Medical Assurance does not require the disclosure of medical examination results or completion of a medical questionnaire merely for an individual to make a general website enquiry.
Health information is treated as particularly sensitive under several privacy regimes. Under UK data-protection law, for example, health data is special-category personal data and requires both an appropriate lawful basis and a separate condition permitting special-category processing.
4. How We Use Personal Information
Subject to applicable law, we may use personal information to:
- Respond to enquiries and provide requested information.
- Communicate with prospective and existing members.
- Administer expressions of interest, applications or membership relationships.
- Process authorised transactions.
- Provide customer and member support.
- Operate, maintain and secure our website and information systems.
- Detect, investigate and prevent fraud, misuse, security threats or unlawful activity.
- Maintain appropriate business, transaction, compliance and audit records.
- Improve our website, programs and services through appropriately aggregated, anonymised or de-identified information.
- Comply with legal, regulatory, accounting, taxation and reporting requirements.
- Establish, exercise or defend legal claims.
- Protect the rights, property, safety and legitimate interests of Medical Assurance, its members, personnel and others where legally permitted.
We will not use personal information for a materially incompatible new purpose without taking any steps required by applicable law.
5. Lawful Bases For Processing
Where applicable data-protection law requires a lawful basis for processing, Medical Assurance will rely upon the lawful basis appropriate to the particular processing activity.
Depending upon the circumstances, this may include:
- Contractual necessity: where processing is necessary to take steps at your request before entering into a contract or to perform a contract with you.
- Legal obligation: where processing is necessary for Medical Assurance to comply with applicable law.
- Legitimate interests: where processing is reasonably necessary for legitimate business, operational, security or administrative purposes and those interests are not overridden by applicable individual rights.
- Consent: where consent is required or otherwise constitutes the appropriate lawful basis.
Where special-category personal information is processed, Medical Assurance will identify any additional legal condition required by applicable law.
The ICO expressly requires organisations subject to UK GDPR to tell individuals their applicable lawful basis and, where relevant, legitimate interests and special-category processing basis.
6. Information We Do Not Sell
Medical Assurance does not sell identifiable personal or health information to data brokers.
We do not disclose identifiable health information to third-party advertisers for behavioural advertising.
We do not authorise service providers to use personal information entrusted to them for their own independent marketing merely because they provide services to Medical Assurance.
Where applicable U.S. privacy legislation assigns specific statutory meanings to terms such as “sale,” “sharing,” “targeted advertising” or similar activities, any additional disclosures or opt-out rights required by applicable law will be provided.
7. When We May Share Personal Information
Medical Assurance may disclose personal information where reasonably necessary and legally permitted to:
- Authorised Medical Assurance personnel who require access for legitimate purposes.
- Relevant Medical Assurance affiliated or operating entities where necessary for authorised administration or service delivery.
- Technology, cybersecurity, communications, payment, hosting, analytics, customer-support and other service providers acting on our behalf.
- Professional advisers, including attorneys, accountants, auditors and insurers.
- Healthcare providers, diagnostic facilities or other service providers where you request or authorise a service requiring the relevant disclosure.
- Regulators, courts, governmental authorities or law-enforcement agencies where disclosure is required or permitted by applicable law or valid legal process.
- Parties involved in an actual or proposed corporate restructuring, financing, merger, acquisition, sale or transfer of business assets, subject to appropriate confidentiality and legal safeguards.
- Other persons where disclosure is necessary to establish, exercise or defend legal rights, investigate fraud or security incidents, or protect individuals from serious harm, where legally permitted.
Where third parties process personal information on our behalf, Medical Assurance seeks to impose appropriate contractual confidentiality, security and data-protection obligations.
8. International Processing And Data Transfers
Because Medical Assurance has an international operating model, personal information may be accessed, processed or stored in countries other than the country in which it was originally collected.
Privacy and data-protection laws may differ between jurisdictions.
Where applicable law restricts international transfers of personal information, Medical Assurance will use an appropriate lawful transfer mechanism and safeguards required by that law.
Where UK data-protection law applies, such safeguards may include applicable adequacy regulations, approved contractual mechanisms or other legally recognised transfer safeguards.
Information regarding applicable safeguards may be requested using the contact information below.
9. Data Minimisation And Access Controls
Medical Assurance seeks to limit the collection, use, access and retention of personal information to what is reasonably necessary for authorised purposes.
Access to personal information is intended to be restricted according to role, responsibility and legitimate business need.
Where reasonably practicable, information may be aggregated, anonymised or de-identified before being used for statistical, analytical, operational or service-improvement purposes.
10. Security
Medical Assurance maintains administrative, organisational, technical and physical safeguards designed to protect personal information against accidental or unlawful loss, destruction, alteration, misuse, unauthorised disclosure or unauthorised access.
Depending upon the information and systems concerned, safeguards may include encryption, authentication, access controls, audit logging, monitoring, secure hosting, vendor controls, confidentiality obligations, backup procedures and incident-response measures.
However, no internet transmission, electronic storage system or security technology can be guaranteed to be completely secure.
Accordingly, although Medical Assurance takes measures appropriate to the nature and sensitivity of the information processed, we cannot guarantee absolute security.
11. Privacy And Security Incidents
Medical Assurance maintains procedures intended to identify, assess, contain, investigate and respond to suspected unauthorised access, acquisition, disclosure, alteration or loss of personal information.
Where an incident creates a legal notification obligation, Medical Assurance will provide notifications to affected individuals, regulators or other authorities as required by applicable law.
In the United States, it is important not to assume that only HIPAA can govern health-data incidents. The FTC Health Breach Notification Rule applies to certain vendors of personal health records and related entities and requires notification following qualifying breaches of unsecured information.
12. Retention
Medical Assurance retains personal information only for as long as reasonably necessary for the purposes for which it was collected and for legitimate legal, regulatory, contractual, taxation, accounting, audit, insurance, security and dispute-resolution requirements.
Retention periods may vary according to the nature of the information, relationship involved and applicable jurisdiction.
Where personal information is no longer required, Medical Assurance will take appropriate steps to delete, destroy, anonymise or otherwise securely dispose of it, subject to applicable legal requirements and legitimate record-retention obligations.
Information may be retained for longer where reasonably necessary in connection with litigation, regulatory proceedings, investigations, legal holds, fraud prevention or the establishment, exercise or defence of legal claims.
13. Your Privacy Rights
Depending upon your jurisdiction and applicable law, you may have rights concerning your personal information, including rights to:
- Access personal information held about you.
- Request correction of inaccurate or incomplete information.
- Request deletion in circumstances permitted by law.
- Request restriction of certain processing.
- Object to certain processing.
- Request portability of eligible information.
- Withdraw consent where processing is based upon consent.
- Make a complaint to an applicable data-protection or supervisory authority.
These rights are not absolute and may be subject to legal exceptions, identity-verification requirements and lawful record-retention obligations.
Medical Assurance may take reasonable measures to verify the identity and authority of anyone submitting a privacy request.
We will not unlawfully discriminate against an individual for exercising an applicable privacy right.
14. United Kingdom
Where UK data-protection legislation applies, individuals may have rights under the UK GDPR and other applicable UK data-protection legislation.
Individuals may also have the right to lodge a complaint with the UK Information Commissioner’s Office.
The ICO currently states that privacy information should address matters including identity and contact details, purposes, lawful basis, recipients, international transfers, retention, individual rights and complaint rights.
15. United States
Privacy obligations in the United States vary according to federal and state law and the nature of the entity, information and service concerned.
Medical Assurance does not represent through this Global Website & Enquiry Privacy Notice that every Medical Assurance entity, service or website interaction is subject to HIPAA.
Where a Medical Assurance entity or activity is subject to HIPAA, applicable protected health information will be handled in accordance with applicable HIPAA requirements and any legally required Notice of Privacy Practices.
HHS confirms that HIPAA applies to defined covered entities and business associates rather than automatically to every organisation handling health-related information. Where a covered entity uses a business associate to perform qualifying functions involving protected health information, appropriate written arrangements are generally required.
Additional state-specific privacy notices will be provided where required.
16. Trinidad And Tobago
Where the processing of personal information is subject to the laws of Trinidad and Tobago, Medical Assurance will process personal information in accordance with applicable Trinidad and Tobago privacy, confidentiality, data-protection and other legal requirements.
Where rights, restrictions or regulatory requirements under applicable Trinidad and Tobago law differ from provisions of this Global Notice, the applicable statutory requirements will govern.
17. Cookies And Similar Technologies
Medical Assurance may use cookies and similar technologies for essential website functionality, security, preference management, performance measurement and appropriately configured analytics.
Where applicable law requires consent before non-essential cookies or similar technologies are activated, Medical Assurance will seek such consent as required.
We do not knowingly use identifiable health information supplied to Medical Assurance for third-party behavioural advertising.
Additional information may be provided through a separate Cookie Notice and cookie-preference mechanism.
18. Children And Minors
Our general website and enquiry channels are intended primarily for adults.
We do not knowingly solicit sensitive personal or health information directly from children through our general website enquiry channels except where permitted by applicable law and appropriately provided or authorised by a parent, guardian or other legally authorised representative.
Where Medical Assurance services are made available to minors, separate requirements regarding parental authority, consent, confidentiality, healthcare information and the minor’s own legal rights may apply according to the jurisdiction and nature of the service.
19. Independent Healthcare Providers And Third Parties
Certain healthcare providers, diagnostic facilities, laboratories, specialists or other organisations accessible through the Medical Assurance network may operate as legally independent organisations and may independently determine how and why they process personal information.
Where another organisation acts independently in relation to personal information, its processing may be governed by its own privacy notice and legal obligations.
Nothing in this Notice excludes or limits any responsibility of Medical Assurance that cannot lawfully be excluded or limited.
20. Automated Decision-Making
Unless otherwise specifically disclosed, Medical Assurance does not use information collected through its general website enquiry process to make decisions based solely on automated processing that produce legal or similarly significant effects upon an individual.
Should this practice materially change, we will provide any information and safeguards required by applicable law.
This provision is worth including because UK privacy information requirements specifically address significant automated decision-making and profiling where applicable.
21. Changes To This Privacy Notice
Medical Assurance may amend this Privacy Notice periodically to reflect changes in law, regulation, technology, business operations, services or information-processing practices.
The “Last Updated” date displayed at the beginning of this Notice identifies its most recent revision.
Where applicable law requires additional notification or consent before a material change becomes effective, Medical Assurance will take the required steps.
22. Contacting Medical Assurance
For general privacy enquiries or requests:
- Medical Assurance Limited, Privacy Office
- Email: info@medicalassurance.co
- Phone: +44 7349 916959 (London), +1-868-620-7025 (Trinidad)
- Post: Medical Assurance Limited, Trinidad London U.S.A.
Registered and/or operating-office information for the relevant Medical Assurance entity should be provided where legally required.
Please do not send medical records, diagnostic reports, laboratory results, prescriptions, identification documents or other highly sensitive information to this general email address unless Medical Assurance has specifically instructed you to do so through an authorised process.