Privacy & Security
Learn about Blue KC privacy and security policies regarding your Protected Health Information (PHI) as well as your personal information (address, email, cell phone, etc.).
Notice of Privacy Practices (NOPP)
Aviso de Prácticas de Privacidad
Your Protected Health Information
Blue KC may use and disclose your Protected Health Information (PHI) to carry out payment activities, healthcare operations, and other purposes that are permitted or required by law, and your rights to access and control your PHI.
Blue KC Responsibilities
We are required by law to maintain the privacy of your PHI. In accordance with the HIPAA Privacy Regulations, we have the right to use and disclose your PHI for payment activities and healthcare operations as explained in the Notice of Privacy Practices. We are most likely to use and/or disclose your PHI for these functions.
Additionally, we may use or disclose your PHI as permitted and required by law. For example, we may use or disclose your PHI for public health activities, legal proceedings, or law enforcement purposes.
Your Rights
You have the following rights regarding your PHI:
- You have the right to request that we restrict the PHI we use or disclose about you for payment or healthcare operations. If you believe that a disclosure of all or part of your PHI, beyond what is provided to the policyholder for financial responsibilities, may be detrimental to you, you may request that we communicate with you regarding your information in an alternative manner or at an alternative location. Explanation of Benefits (EOBs) will always be provided to the subscriber.
- Generally, you have the right to inspect or copy your PHI that is contained in a designated record set.
- If you believe that your PHI is incorrect or incomplete, you may request that we amend your information.
- You have a right to an accounting of certain disclosures of your PHI that are for reasons other than treatment, payment or health care operations.
Your Personal Information
We have taken great strides to protect your information online and when you contact us.
Online Protection
BlueKC.com is a safe, secure way to manage your Blue KC health insurance, 24 hours a day, 7 days a week. By registering with your member ID card to create a unique username and password, and selecting a “challenge question”, you control the access to your online information. The mobile version of our website uses the same security measures as our main website, so you can be assured your information is protected. Although our website logs you out when there is no site activity for a certain period of time, it’s important that you log off after each time you visit BlueKC.com. In addition, for added security, we recommend closing your browser once you’ve logged-off of our website.
Email and Text Communication
Blue KC will never share your email address or cell phone number with anyone other than approved vendors or partners who are assisting in managing your insurance policy.
When communicating with you via email or text messages, we will never disclose your PHI and we will never ask you for personal information such as account numbers or passwords. The most secure way to provide this information is through the member section of our website, or when speaking with one of our Customer Service representatives.
Emails from Blue KC include several features to help you recognize a legitimate email from a fraudulent one. These features include:
- Blue KC Logo in header of email
- “Interact@BlueKC.com” as the “from” address for all Blue KC communications.
Over the Phone
When you contact the Blue KC Customer Service team by phone, you’ll be asked to provide your account information so that we can confirm your identity. This account information includes your member ID number, mailing address, date of birth, along with any specific information required to answer your questions. Our Customer Service representatives have been trained to maintain the confidentiality of your PHI and personal information. If they are unable to verify the caller’s identity and right to access the account, they will not provide any information. This is to protect you and your PHI.
Complaints
You may complain to us if you believe that we have violated your privacy rights. You may also file a complaint with the Secretary of the US Department of Health and Human Services.
Communicating with Blue KC
Please refer to the following information to inquire about the use of your PHI, to exercise your rights about your PHI, or to register a complaint:
Address:
Privacy Office
Blue Cross and Blue Shield of Kansas City
P.O. Box 417012
Kansas City, MO 64141-7012
Phone: 816-395-3784 or Toll-free 800-932-1114
Website Privacy Policy
This Privacy Policy covers those individuals and businesses that utilize Blue Cross and Blue Shield of Kansas City (“Blue KC”), “we”, “us” or “our” websites at Bluekc.com, spiracare.com, medicarebluekc.com, bluekcforyou.com, and their subpages and content, (collectively, the “Site”). We are committed to protecting the privacy of your information. We believe it is a good business practice to disclose to you how your personal information may be used. As a user of this Site, or purchaser of the services or products available through the Site (collectively, “Service(s)”) provided by Blue KC, this Privacy Policy set forth herein (this “Privacy Policy”) is intended to describe in a straight-forward and easily understandable manner:
- the information we collect about you;
- how that information may be used;
- with whom the information may be shared;
- how you may update the information you provide us;
- how you may contact us; and
- your choices about our uses and disclosures of your information.
As noted in the Terms of Service applicable to the Site (the “TOS”), by using the Site and/or Services you accept and acknowledge that you are bound by this Privacy Policy. Accordingly, we encourage you to read this Privacy Policy carefully. If you have questions or concerns regarding this Privacy Policy, please feel welcome to contact us through the Site at: Bluekc.com Alternatively, you can also e-mail us at Privacy@bluekc.com or send mail to Blue Cross and Blue Shield of Kansas City, Attn: Privacy Office, P.O. Box 417012, Kansas City, MO 64141
Information We Collect
We collect information about you so we can continue to provide and improve our Services to you and other users of the Site. The information collected through the Site may include items such as your name, e-mail address, IP address, use of first-party and third-party cookies and other information you send to us through the Site. For more information regarding the protected health information that we collect about you and how we may use or disclose that information, please see our Notice of Privacy Practices. The information collected on the Site may be stored at servers, computers, or other media located in or outside the United States.
Automatically Collected Information; Interest-Based Advertising
When you interact with the Sites, advertisements or other content provided by Blue KC or third parties, on behalf of Blue KC, or are receiving our Services through your computer, phone, or mobile device (Devices), we, and third parties, automatically collect certain information (“Automatically-Collected Data”) about or from your Device, such as, without limitation, your browser information on our server logs including your IP address, browser type, browser versions, browser language, browser plug-in type and version, country and time zone, URLs that refer visitors to our Sites, dates and times of visits to our Sites, page views and site navigation, geographic location, cookie information (see below), web beacons, pixel tags, device fingerprinting or other means, the page you requested, duration of activity on our Sites, searches, shopping behavior and preferences, hardware model, operating system version, unique device identifiers, mobile network information, and purchases.
Third-Party Sources
We may obtain personal and non-personal information about you from third-party sources. This information may be utilized, analyzed, and/or compared with information that we have collected from you or that you have submitted to the Site or in the use of the Service. Such third parties may include but are not limited to Microsoft, Google, etc. If Blue KC obtains information from third-party sources, Blue KC takes commercially reasonable measures to ensure the third parties lawfully obtained and provided the information to us. If the third parties unlawfully obtained and/or provided the information to us despite our reasonable measures to ensure the third parties complied with all legal requirements in obtaining and providing the information to us, you understand, agree, and acknowledge that your sole legal remedy is against the third party that engaged in the unlawful activity and that you will not assert any cause of action, claim or demand against us.
Information Collection Technology (Web Beacons and Cookies)
We may use various technologies to collect information from your electronic device about your activities on the Site or your use of the Service. We may collect and store non-personally identifying information through cookies, log files, clear gifs (commonly known as “web beacons”), and third parties to profile user activity and preferences. Technical and specification information about your browser and computer is automatically collected when you use or visit the Site or use the Service. This information may include but not be limited to your Internet Protocol (“IP”) address, your browser type, operating system, geographic location, access time(s), the content of previously accepted “cookies” from us, and the website address that referred you to the Site.
A cookie is data stored on your computer that tracks non-personal information about you. When you use the Site, we may assign your computer one or more cookies that enable us to improve the quality of the Services and to personalize your experience. Cookies allow us to automatically collect information about your activity on the Site, such as the content you access while on the Site, the links you click, and other activity you conduct while using the Site. You may choose to modify your web browser’s setting to disable cookies or limit their use. If you choose to disable or limit cookies, you are still able to access the Site, but you may be unable to use all of the features on the Site. Additional information about cookies may be found at: https://support.microsoft.com/en-us/help/260971/description-of-cookies. Many browsers are set to accept cookies until you change your settings. Further information about cookies, including how to see what cookies have been set on your computer or mobile device and how to manage and delete them, visit www.allaboutcookies.org.
The Site may contain web beacons (also known as “clear gifs”) or similar technologies that gather non-personally identifiable information about your use of the Site. Such technology may also be contained in e-mail messages or newsletters from us that allow us to determine whether messages have been accessed. The purpose of our use of this technology is so that we may analyze the effectiveness of our marketing efforts, the quality of the Site, and the Services we provide.
Cookies We Use
Type of Cookie | Purpose |
Essential Cookies | These cookies are essential to provide you with services available through our website and to enable you to use some of its features. Without these cookies, the services that you have asked for cannot be provided, and we only use these cookies to provide you with those services. |
Functionality Cookies | These cookies allow our website to remember choices you make when you use the Service, such as remembering your language preferences, remembering your login details and remembering the changes you make on other parts of our Site, which you can customize. The purpose of these cookies is to provide you with a more personal experience and to avoid you having to re-enter your preferences every time you visit the Site. |
Analytics and Performance Cookies | These cookies are used to collect information about traffic to our website and how users use the Service. The information gathered does not identify any individual visitor. The information is aggregated and anonymous. The information gathered may include the number of visitors to the Site, the sites that referred them to our Site, the pages you visited on our Site, what time of day you visited our Site, whether you have visited our Site before and other similar information. We use Google Analytics (GA4), Google Universal Analytics, Google Tag Manager, and HotJar for this purpose. Google Analytics (GA4), Google Universal Analytics and Google Tage Manager uses its own cookies. You can find out more information about how Google uses cookies here and about how Google protects your data here. You can prevent the use of Google Analytics relating to your use of our Site by downloading and installing the browser plugin available here. You can find out more on how HotJar utilizes cookies here. |
Targeted and Advertising Cookies | These cookies track your browsing habits to enable us to show advertising that is more likely to be of interest to you. These cookies use information about your browsing history to group with the other users who have similar interests. Based on that information, third party advertisers can place cookies to enable them to show advertisements that we think will be relevant to your interests while you are on third party websites. Our sites may use Google Ads Pixels. Learn more about how Google products use cookies here. Our Sites may use Microsoft Advertising for advertising on non-Google owned browsers. Learn about Microsoft Advertising’s privacy policy here. |
Social Media Cookies | These cookies are used when you visit any public Blue KC social networking website including but not limited to Facebook, X (formerly Twitter), or Linkedin which can record that you have visited this page and could use this information to serve you relevant ads that are in compliance with platform advertising policies. We may use Meta Pixel tracking. Learn what is tracked through Meta here. |
Personal Information About Users Under 18 Years of Age Not Collected
The Site is meant for adults and those who have reached the age of majority as defined by the laws of their domicile. The Site is not meant for individuals under the age of eighteen (18) or those defined by the laws of their domicile as minors. Nonetheless, this Privacy Policy is still designed to comply with the Children’s Online Privacy Protection Act (“COPPA”) to the extent COPPA and/or the California Consumer Privacy Act (“CCPA”) apply. Accordingly, we do not knowingly collect or retain any personal information about users under the age of sixteen (16). If we obtain actual knowledge that we collected or retained personal information about a child under the age of sixteen (16), that information will be promptly deleted from our database, servers, and all other media. Since we do not collect information from users under sixteen (16) years old, no such information is disclosed to third parties.
If parents or guardians wish to create an account for, and provide information related to, their child who is under the age of eighteen (18), the parent or guardian may do so, but assumes full responsibility for ensuring that the information is kept secure and that the information submitted is accurate. In creating such an account, the parent or guardian accepts that this Privacy Policy will apply to the minor child’s information.
Information Others May Collect
To enhance security and promote operational efficiency, the Site utilizes the resources of reputable hosting facilities that are controlled by third parties. Blue KC is unable to provide any guarantees or warranties about these third parties’ retention or usage of your information.
Information Use & Sharing
We may use and share your information for any legally permissible purpose. We may match, use, and share any of the information we collect from you to any personally identifiable information we obtain through third parties. Examples of some ways we may use or share information that we collect about you include:
- present the Site and its contents to you;
- improve your user experience with Blue KC and expedite access to your account;
- notify you of any Blue KC promotions, deals and other information that may be of use to you or any deals or promotions from our partners;
- create or administer your account and communicate with you about account creation, activity or modification, placed orders and shipping updates;
- notify you about any changes to this Privacy Policy or the TOS;
- respond to your requests and questions;
- fulfill any other purpose for which you provide it or in any other way we describe when you provide it;
- fulfill any purpose with your consent;
- operate, assess, analyze, enhance, and improve our businesses, research, data, marketing and advertising strategies, and our product offerings;
- enforce our rights and carry out our obligations which includes performing accounting, auditing, and billing activities;
- protect against fraud;
- comply with applicable laws, regulations and industry standards and enforce our rights and our TOS and other policies.
- providing you with products or services;
- providing you with customized content and services;
- providing customer support;
- communicating with you by e-mail, United States mail, telephone, text message, and/or mobile devices about products or services that may be of interest to you either from us, or from any of our affiliates, sponsors or other third parties;
- working with our advertising partners; and
- performing functions as otherwise described to you at the time of payment collection.
In order to perform certain services on your behalf, we may publish certain information that you provide. You agree that any testimonial feedback or other comments provided by you to Blue KC becomes the sole and exclusive property of Blue KC and that such information may be used by Blue KC for any legally permissible purpose, including but not limited to marketing and advertising its services and products.
We may also aggregate and anonymize this information with similar information from our other customers in order to understand how our customers use our Sites or our Services, and/or third-party service providers may collect non-personally identifiable information from our Sites.
You acknowledge and agree that Blue KC may use and disclose your personal and non-personal information to public or private third parties: (i) to comply with requests for inspection by law enforcement officials (including potential criminal activity); (ii) to respond to cease and desist letters, arbitration proceedings, legal actions and suits, criminal and civil subpoenas, or any court orders; (iii) to enforce or apply the terms of this Privacy Policy or any other agreement between us, including, the TOS; and (iv) to protect our rights, property, or safety, as well as the rights, property, or safety of our users, or others, whether during or after the term of your use of the Site or any Services.
Health and Financial Information
For more information regarding how we may use or disclose your protected health information or personally identifiable information, please see our Notice of Privacy Practices.
Your Information Will Not Be Sold
We will not sell any information you submit to us to any third party without prior written notice to you and an opportunity for you to opt-out of such sale, provided, however, that we are permitted to sell your information in the event of a merger, acquisition, change of control, or sale of substantially all of our assets or our business (or any substantially similar transaction). However, you agree that we are able to sell aggregated and/or deidentified information that we may collect related to you and your use of the Site or Services.
Communications from Us
Unless you opt out of certain communication features, we may use your information to communicate with you, such as through e-mail, newsletters, and telephone. You may opt out and/or unsubscribe to communications from Blue KC at any time. See the Opt-Out Provisions and Updating Your Information section below for applicable contact information and directions.
Legal Process and Investigation Issues
From time to time, Blue KC may be required to respond to a subpoena, a court order or similar investigative demand from law enforcement, a government agency, or a private litigant. Blue KC reserves all rights to defend, within its sole discretion, against such legal requests, demands, and claims. For instance, Blue KC may raise or waive legal objections or rights. Blue KC also reserves the right to disclose your information, as allowed by applicable law, when we believe it is reasonably appropriate based on the situation. Such disclosure may occur, but is not limited to, disclosing your information in connection with efforts to: (i) investigate, prevent, or commence other actions regarding suspected illegal activity or other wrongdoing; (ii) protect or defend the rights, property or safety of our company, our users, our employees, or others; (iii) comply with applicable law or cooperate with law enforcement; or (iv) enforce the TOS or other agreements or policies between you and us related to the Site or the Services.
Notice about Social Security Numbers
We do not collect social security numbers of customers or other users, and you should not provide such information to Blue KC. Nonetheless, if Blue KC comes into possession of users’ social security numbers or collects such information in the future, the information will be treated confidentially and not shared with third parties unless allowed by law. Additionally, Blue KC will take reasonable steps to limit the access to such social security numbers and take legally required steps to secure the transmission of the data containing such social security numbers.
Third Party Privacy Policies May Be Applicable
This Privacy Policy does not cover any third party’s use or handling of your information once it is shared. Instead, the privacy policies of the third party(ies) will govern. We encourage you to visit the websites of those third parties and fully read and understand their privacy policies. Some of these entities or their servers may be located outside the United States.
Links
The Site may contain links to other websites. Blue KC disclaims any responsibility for the privacy practices of third parties that may have links to or from our website, or any framed content on our website. We encourage you to review the privacy policies/statements of every website that you visit that collects personally identifiable information.
DO NOT TRACK REQUESTS
In some states, users may be entitled to know how we respond to “Do Not Track” browser settings. There is little consensus in the industry about what “Do Not Track” means; however, at this time we do not recognize “Do Not Track” signals as an opt-out for the sharing of your data with third parties. You may still need to contact any third-party companies (including those who may have cookies or beacons on the Site) to direct them to not share your data with third parties as well. To learn more or opt-out from data collection by third-party companies you can visit: http://www.networkadvertising.org/choices or www.aboutads.info/choices/
Opt-Out Provisions and Updating Your Information
We value our users’ privacy and provide them with the option to “opt-out” of having their information used for purposes not directly related to the Site or the Services. If you wish to opt-out, you can opt-out by any of the following means:
- Send a written request to: Blue Cross and Blue Shield of Kansas City, P.O. Box 417012, Kansas City, MO 64141; or
- E-mail Privacy@bluekc.com
Your request will generally be responded to within three (3) business days if your request is via e-mail, or thirty (30) days if your request is via United States mail.
Please note that changing your opt-out preference will only affect future activities or communications from us. In other words, if we already provided your information to a third party before you changed your opt-out preferences, you will need to contact the third party directly. To opt-out of communications from our third-party business partners, if any, please contact them directly.
Information Retention and Security
We may store your information for more than one (1) year from the time of initial submission, as well as automated personal information we collect about you. However, if we obtain or collect your social security number or credit card number, that information will only be stored for a limited time pursuant to your authorization unless the law requires otherwise.
We take reasonable security measures to protect users’ information against unauthorized access, loss, alteration, or destruction. These measures include encryption and physical security measures to guard against unauthorized access to systems where we store personal information, and the usage of reputable third-party vendors. Despite these reasonable measures, we cannot guarantee our security measures are impenetrable. Therefore, although we take reasonable steps to secure your information, we cannot and do not promise or warrant that your information will always remain secure.
Visitors Outside the United States
This Privacy Policy is intended to cover collection of information on the Site and users of the Service from residents of the United States. The laws in other countries may or may not be as comprehensive as those in the United States. If you are a resident of another country and/or are visiting the Site or using the Service from outside the United States, you acknowledge and agree that your information may be transferred to, stored, and processed in the United States where our servers are located and our central database is operated. You also acknowledge that your use of the Site or the Services shall be governed exclusively by the laws of Missouri and as if all transactions with us or otherwise through the Site or use of the Services take place within Missouri. By using the Site and/or the Services, you acknowledge and agree that your information may be transferred to our facilities and those third parties with whom we share it as described in this Privacy Policy. If you are unwilling to accept these terms, then you agree that you will not use or access the Site or our Services.
Privacy Policy Updates and Revisions
This Privacy Policy may be updated from time to time. We reserve the right to modify this Privacy Policy at any time without notice, so please review this Privacy Policy frequently. When changes are made to this Privacy Policy, we will revise the “last updated” date at the top of this Privacy Policy. If we make any material changes in the way we collect, use, and/or share your personal information, we will also post notice of the changes on the Site and/or may notify you by sending an e-mail to the e-mail address you most recently provided us under your account. Your continued use of the Site or any Services after we have posted any Privacy Policy changes indicates your agreement to such changes unless you notify us otherwise.
If you wish to retain a copy of this Privacy Policy, you should print a copy for your records.
Terms of Privacy Policy Survive
If any terms of this Privacy Policy are held invalid and/or unenforceable by a court of law or a competent jurisdiction, the remaining provisions of this Privacy Policy shall remain in full force and effect.
SUPPLEMENTAL PRIVACY POLICY APPLICABLE TO CALIFORNIA, COLORADO, CONNECTICUT, VIRGINIA, UTAH, MONTANA, TENNESSEE, OREGON, TEXAS, IOWA, INDIANA, AND DELAWARE RESIDENTS ONLY.
The disclosures in this section (and linked Supplemental Privacy Policy) apply only to individual residents of the States of California, Colorado, Connecticut, Virginia, Utah, Montana, Tennessee, Oregon, Texas, Iowa, Indiana, Delaware as applicable. The Supplemental Policy provides additional information about how we collect, use, disclose, and otherwise process personal information within the scope of the California Consumer Privacy act of 2018, as amended, including its implementing regulations (“CCPA”), Colorado Privacy Act (“CPA”), Connecticut Data Privacy Act (“CTDPA”), Virginia Consumer Data Protection Act (“VCDPA”), Utah Consumer Privacy Act (“UCPA”), Montana Consumer Data Privacy Act (“MTCDPA”), Tennessee Information Protection Act (“TIPA”), Oregon Consumer Privacy Act (“OCPA”), Texas Data Privacy and Security Act (“TDPSA”), Iowa Consumer Data Protection Act (“ICDPA”), Indiana Consumer Data Protection Act (“INCDPA”), and the Delaware Personal Data Privacy Act (“DPDPA”). Residents of California, Colorado, Connecticut, Virginia, Utah, Montana, Tennessee, Oregon, Texas, Iowa, Indiana, and Delaware Residents can click here: To review the Supplemental Privacy Policy.
POLICY APPLICABLE TO NEVADA RESIDENTS ONLY.
If you are a Nevada resident, you may opt-out of the sale of your personal information. To do so, please contact us at Privacy@bluekc.com and title the subject of your email “Nevada Privacy Rights Opt-Out Request”. In response, we will request information from you to verify your identity. We will attempt to respond to your request, once verified, within sixty (60) calendar days.
Limitations
The adoption or publication of this Privacy Policy does not subject Blue KC to any stricter duty in its collection, handling, storage and disclosure of nonpublic information than otherwise applies to Blue KC under applicable law. No person or entity shall have any right or recourse against Blue KC nor any of its affiliates, agents, sponsors, or other related parties based on any alleged violation of or noncompliance with this Privacy Policy. This Privacy Policy is subject to applicable law as well as any separate contract that may be signed between Blue KC and you.
Questions & Complaints
If you have questions or concerns regarding the privacy of your information, please contact:
General Contact
Privacy Office
Blue Cross and Blue Shield of Kansas City
P.O. Box 417012
Kansas City, MO 64141
816-395-3784 or toll free at 1-800-932-1114
Privacy@bluekc.com
Website Privacy Policy Supplement
This Privacy Policy Supplement for California, Colorado, Connecticut, Virginia, Utah, Montana, Tennessee, Oregon, Texas, Iowa, Indiana, and Delaware Residents (the “Supplement”) supplements the information contained in Blue Cross and Blue Shield of Kansas City (“Blue KC”, “we”, “us”, or “our”) Privacy Policy (the “General Privacy Policy”) and applies solely to those consumers who reside in the States of California, Colorado, Connecticut, Virginia, Utah, Montana, Tennessee, Oregon, Texas, Iowa, Indiana, Delaware (“consumers” or “you”). The terms of this Supplement shall govern over any conflict with the General Privacy Policy. We adopt this Supplement to comply with the California Consumer Privacy Act of 2018 (“CCPA”), Colorado Privacy Act (“CPA”), Connecticut Data Privacy Act (“CTDPA”), Virginia Consumer Data Protection Act (“VCDPA”), Utah Consumer Privacy Act (“UCPA”), Montana Consumer Data Privacy Act (“MTCDPA”), Tennessee Information Protection Act (“TIPA”), Oregon Consumer Privacy Act (“OCPA”), Texas Data Privacy and Security Act (“TDPSA”), Iowa Consumer Data Protection Act (“ICDPA”), Indiana Consumer Data Protection Act (“INCDPA”), and Delaware Personal Data Privacy Act (“DPDPA”) and any terms defined in the CCPA, CPA, CTDPA, VCDPA, UCPA, MTCDPA, TIPA, OCPA, TDPSA, ICDPA, INCDPA, DPDPA have the same meaning when used in this Supplement.
Information We Collect
Our websites (www.bluekc.com, www.spiracare.com, www.medicarebluekc.com, www.bluekcforyou.com, www.shutoutthestigma.com, www.mindfulbluekc.com, www.cobalt-venture.com and their subpages and content, collectively the “Site”) collects information that identifies, relates to, describes, references, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer, household, or device (“personal information”). Personal information does not include:
- Publicly available information from government records.
- Deidentified or aggregated consumer information.
- Other information deemed under applicable California, Colorado, Connecticut, Virginia, Utah, Montana, Tennessee, Oregon, Texas, Iowa, Indiana, and Delaware law not to be personal information.
In particular, our Site has collected within the last twelve (12) months, and intends to continue collecting, the following categories of personal information from consumers:
Category | Examples | Collected |
A. Identifiers. | For example, Blue KC may collect one of the following identifiers: A real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, social security number, driver’s license number, passport number, or other similar identifiers. | YES |
B. Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80I). | For example, Blue KC may collect one of the following identifiers: A name, signature, social security number, physical characteristics or description, address, telephone number, passport number, driver’s license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number, or any other financial information, medical information, or health insurance information. Some personal information included in this category may overlap with other categories. | YES |
C. Protected classification characteristics under California, Colorado, Connecticut, Virginia, Utah Montana, Tennessee, Oregon, Texas, Iowa, Indiana, Delaware or federal law. | For example, Blue KC may collect one of the following identifiers: A Age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, veteran or military status, genetic information (including familial genetic information). | YES |
D. Commercial information. | For example, Blue KC may collect one of the following identifiers: Records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies. | YES |
E. Biometric information. | For example, Blue KC may collect one of the following identifiers: A Genetic, physiological, behavioral, and biological characteristics, or activity patterns used to extract a template or other identifier or identifying information, such as, fingerprints, faceprints, and voiceprints, iris or retina scans, keystroke, gait, or other physical patterns, and sleep, health, or exercise data. | NO |
F. Internet or other similar network activity. | For example, Blue KC may collect one of the following identifiers: A Browsing history, search history, information on a consumer’s interaction with a website, application, or advertisement. | YES |
G. Geolocation data. | For example, Blue KC may collect one of the following identifiers: A Physical location or movements. | YES |
H. Sensory data. | For example, Blue KC may collect one of the following identifiers: A Audio, electronic, visual, thermal, olfactory, or similar information. | NO |
I. Professional or employment-related information. | For example, Blue KC may collect one of the following identifiers: A Current or past job history or performance evaluations. | NO |
J. Non-public education information (per the Family Educational Rights and Privacy Act (20 U.S.C. Section 1232g, 34 C.F.R. Part 99)). | For example, Blue KC may collect one of the following identifiers: A Education records directly related to a student maintained by an educational institution or party acting on its behalf, such as grades, transcripts, class lists, student schedules, student identification codes, student financial information, or student disciplinary records. | NO |
K. Inferences drawn from other personal information. | For example, Blue KC may collect one of the following identifiers: A Profile reflecting a person’s preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes. | YES |
We obtain the categories of personal information listed above from the following categories of sources:
- Directly from you. For example, from forms you complete or products and services you purchase.
- Indirectly from you. For example, from observing your actions on our Site.
- From other third parties, including those listed on our General Privacy Policy.
The information we obtain about you from third parties may be combined and utilized with the information you provide to us.
Use of Personal Information
We may use, share, or disclose the personal information we collect for one or more of the following purposes:
- To fulfill or meet the reason you provided the information. For example, if you share your name and contact information to request a price quote or ask a question about our products or services, we will use that personal information to respond to your inquiry. If you provide your personal information to purchase a product or service, we will use that information to process your payment and facilitate delivery. We may also save your information to facilitate new product orders or process returns.
- To provide, support, personalize, and develop our Site, products, and services.
- To create, maintain, customize, and secure your account with us.
- To process your requests, purchases, transactions, and payments and prevent transactional fraud.
- To provide you with support and to respond to your inquiries, including to investigate and address your concerns and monitor and improve our responses.
- To personalize your Site experience and to deliver content and product and service offerings relevant to your interests, including targeted offers and ads through our Site, third-party sites, and via email or text message (with your consent, where required by law).
- To help maintain the safety, security, and integrity of our Site, products and services, databases and other technology assets, and business.
- For testing, research, analysis, and product development, including to develop and improve our Site, products, and services.
- To respond to law enforcement requests and as required by applicable law, court order, or governmental regulations.
- As described to you when collecting your personal information or as otherwise set forth in the CCPA, CPA, CTDPA, VCDPA, UCPA, MTCDPA, TIPA, OCPA, TDPSA, ICDPA, INCDPA, DPDPA.
- For other purposes provided in our General Privacy Policy.
- To evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which personal information held by us about our Site users and customers is among the assets transferred.
We will not collect additional categories of personal information or use the personal information we collected for materially different, unrelated, or incompatible purposes without providing you notice.
Sharing Personal Information
We may share your personal information by disclosing it to a third party for a business purpose. We only make these business purpose disclosures under written contracts that describe the purposes, require the recipient to keep the personal information confidential, and prohibit using the disclosed information for any purpose except performing the contract. In the preceding twelve (12) months, we have disclosed personal information for a business purpose to the categories of third parties indicated in the chart below.
We may also share your personal information, including by selling it to third parties, subject to your right to opt-out of those sales. Our personal information sales do not knowingly include information about individuals we know are under the age of sixteen (16), regardless if we have parental consent. In the preceding twelve (12) months, we have sold the following categories of personal information to the categories of third parties indicated in the chart below. For more on your personal information sale rights, see Personal Information Sales Opt-Out and Opt-In Rights.
Personal Information Category | Category of Third-Party Recipients | |
Business Purpose Disclosures | Sales* | |
A. Identifiers. | IP Address, first and third-party cookies, name and email address may be collected. | No |
B. California Customer Records personal information categories. | No | |
C. Protected classification characteristics under California, Colorado, Connecticut, Virginia, Utah or federal law. | No | |
D. Commercial information. | No | |
E. Biometric information. | No | |
F. Internet or other similar network activity. | May be collected | No |
G. Geolocation data. | May be collected | No |
H. Sensory data. | No | |
I. Professional or employment-related information. | May be collected | No |
J. Non-public education information. | May be collected | No |
K. Inferences drawn from other personal information. | No |
* Except as provided on our Privacy Policy.
Reselling Personal Information
The CCPA, CPA, CTDPA, VCDPA, UCPA, MTCDPA, TIPA, OCPA, TDPSA, ICDPA, INCDPA, and DPDPA prohibits a third party from reselling personal information unless you have received explicit notice and an opportunity to opt-out of further sales. If you would like a list of the businesses with whom we may share or resell your information, you may contact us to request that information. Generally speaking, however, we only share your information with our business partnership who aid in providing you the services associated with Blue Cross and Blue Shield of Kansas City’s website and application, and for third-party website analytics (e.g. Google). To opt-out of those sales, please see opt-out procedure provided on Your Rights and Choices Under the CCPA section.
Your Rights and Choices Under the CCPA
The CCPA provides consumers, employees, potential employees and businesses that are California residents with specific rights regarding their personal information. This section describes CCPA rights available to those persons and explains how to exercise those rights.
NOTE: In some instances, we may NOT be able to comply with your request given that we are not the data controller, but instead, are a data processor and/or may be required under applicable law to maintain your data.
Right to Know and Data Portability
You have the right to know what information we have collected about you over the past twelve (12) months and how we use it. Once we receive your request to exercise your right to know and confirm your identity (see Exercising Your Rights), we will disclose to you:
- The categories of personal information we collected about you.
- The categories of sources for the personal information we collected about you.
- Our business or commercial purpose for collecting or selling that personal information.
- The categories of third parties with whom we share that personal information.
- If we sold or disclosed your personal information for a business purpose, two (2) separate lists disclosing:
- sales, identifying the personal information categories that each category of recipient purchased; and
- disclosures for a business purpose, identifying the personal information categories that each category of recipient obtained.
- The specific pieces of personal information we collected about you in a readable format (also called a data portability request).
Right to Correct
You have the right to correct inaccuracies in your personal information that we collected from you and retained. Once we receive your request to exercise your right to correct and confirm your identity (see Exercising Your Rights), we will use commercially reasonable efforts to correct the inaccurate personal information as directed by you. We may deny your request if a response is impossible or would involve disproportionate effort to correct inaccurate information.
Right to Delete
You have the right to request that we delete any of your personal information that we collected from you and retained, subject to certain exceptions. Once we receive your request to exercise your right to delete and confirm your identity (see Exercising Your Rights), we will review your request to see if an exception allowing us to retain the information applies. We may deny your request if retaining the information is necessary for us or our service provider(s) to:
- Complete the transaction for which we collected the personal information, provide a good or service that you requested, take actions reasonably anticipated within the context of our ongoing business relationship with you, fulfill the terms of a written warranty or product recall conducted in accordance with federal law, or otherwise perform our contract with you.
- Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for such activities.
- Debug products to identify and repair errors that impair existing intended functionality.
- Exercise free speech, ensure the right of another consumer to exercise their free speech rights, or exercise another right provided for by law.
- Comply with the California Electronic Communications Privacy Act (Cal. Penal Code § 1546 et. seq.).
- Engage in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to all other applicable ethics and privacy laws, when the information’s deletion may likely render impossible or seriously impair the research’s achievement, if you previously provided informed consent.
- Enable solely internal uses that are reasonably aligned with consumer expectations based on your relationship with us.
- Comply with a legal obligation.
- Make other internal and lawful uses of that information that are compatible with the context in which you provided it.
If your request to delete is not subject to one of the above exceptions, we will grant your request to delete or deidentify personal information from our records and will direct our service providers to take similar action.
Right to Opt Out of Sale or Sharing
You have the right to opt out of the sale or sharing of your personal information to third parties. For instructions on exercising your right to opt out of the sale or sharing of your personal information, see Personal Information Sales and Targeted Advertising Opt-Out and Opt-In Rights.
Right to Limit Use and Disclosure of Sensitive Personal Information
You have the right to limit the use of your sensitive personal information to that use which is necessary to perform the services and goods we provide as mentioned above in the “Sharing Personal Information” section.
Exercising Your Rights
To exercise your right to know, right to correct, right to delete, or right to limit as further described above, please submit a request by either:
- Calling us at 816-395-3784 or toll free at 1-800-932-1114
- Emailing us at privacy@bluekc.com
Only you, or someone legally authorized to act on your behalf, may make a request related to your personal information.
You may also make a request on behalf of your child by contacting us at the information above and provide information that will allow us to properly identify your child and your relationship as the parent or guardian of your child.
You may only submit a request twice within a twelve (12) -month period. Your request must:
- Provide sufficient information that allows us to reasonably verify you are the person about whom we collected personal information or an authorized representative, which may include:
- Contact information.
- Information about prior purchase history.
- Other information as we may reasonably request.
- Describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.
- If you are an authorized agent of a third party, you must provide us with: (i) sufficient information demonstrating your role as an authorized agent for the individual you are making the request about (e.g. Court order, power of attorney, etc.); (ii) information that will allow us to verify your identity; and (iii) any other information that we may reasonably request consistent with applicable law in order to authenticate your request.
We cannot respond to your request or provide you with personal information if we cannot verify your identity or authority to make the request and confirm the personal information relates to you.
You do not need to create an account with us to submit a request to know or delete. However, we do consider requests made through your password protected account sufficiently verified when the request relates to personal information associated with that specific account.
We will only use personal information provided in the request to verify the requestor’s identity or authority to make it.
Please note that additional time may be needed to process the deletion of personal information from backup and/or archival databases.
For instructions on exercising your sale opt-out or opt-in rights, see Personal Information Sales and Targeted Advertising Opt-Out and Opt-In Rights.
Response Timing and Format
We will confirm receipt of your request to exercise your right to know, right to correct, right to delete, and/or right to limit within ten (10) business days. If you do not receive confirmation within the ten (10) -day timeframe, please call us at 816-395-3784 or toll free at 1-800-932-1114.
We endeavor to substantively respond to a verifiable consumer request within forty-five (45) days of its receipt. If we require more time (up to another forty-five (45) days), we will inform you of the reason and extension period in writing.
If you have an account with us, we will deliver our written response to that account. If you do not have an account with us, we will deliver our written response by mail or electronically, at your option.
Any disclosures we provide will only cover the twelve (12) -month period preceding our receipt of your request. The response we provide will also explain the reasons we cannot comply with a request, if applicable. For data portability requests, we will select a format to provide your personal information that is readily useable and should allow you to transmit the information from one entity to another entity without hindrance.
We do not charge a fee to process or respond to your verifiable consumer request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.
Personal Information Sales and Targeted Advertising Opt-Out and Opt-In Rights
If you are age sixteen (16) or older, you have the right to opt-out of the sale of your personal information at any time. We do not sell the personal information of consumers we actually know are less than sixteen (16) years old regardless if we receive parental consent. Consumers who opt in to personal information sales may request to opt out of future sales at any time.
To exercise the right to opt out of the sale of your personal information, you (or your authorized representative) may submit a request to opt-out to us by visiting the following Internet Web page link: “Do Not Sell My Personal Information”.
Once you make a request to opt-out of the sale of your personal information, we will wait at least twelve (12) months before asking you to reauthorize personal information sales. However, you may change your mind and opt back into personal information sales at any time by contacting us.
You do not need to create an account with us to exercise your right to opt-out of the sale of your personal information. We will only use personal information provided in a request to opt-out of the sale of your personal information to review and comply with the request to opt-out.
Non-Discrimination
We will not discriminate against you for exercising any of your CCPA rights set forth above. Unless permitted by the CCPA, we will not:
- Deny you goods or services.
- Charge you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties.
- Provide you a different level or quality of goods or services.
- Suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services.
However, we may offer you certain financial incentives permitted by the CCPA that can result in different prices, rates, or quality levels. Any CCPA-permitted financial incentive we offer will reasonably relate to your personal information’s value and contain written terms that describe the program’s material aspects. Participation in a financial incentive program requires your prior opt-in consent, which you may revoke at any time by calling us at 816-395-3784 or toll free at 1-800-932-1114 or emailing us at Privacy@bluekc.com. We may provide financial incentives from time to time including through promotions, contests, gift cards, giveaways, discounts/sales, and rewards. The terms of any such incentives will be communicated with that particular financial incentive.
Other California Privacy Rights
California’s “Shine the Light” law (Civil Code Section § 1798.83) permits users of our Site that are consumers, employees, potential employees and businesses that are California residents to request certain information regarding our disclosure of personal information to third parties for their direct marketing purposes. To make such a request, please send an email or write us at the addresses provided below.
Your Rights and Choices under the CPA, CTDPA, VCDPA, UCPA, MTCDPA, TIPA, OCPA, TDPSA, ICDPA, INCDPA, DPDPA
The disclosures in this section apply solely to individual residents of the States of Colorado, Connecticut, Virginia, Montana, Tennessee, Oregon, Texas, Iowa, Indiana, and Delaware as applicable. If you are a resident of one of these states, we may share your personal information by disclosing it to a third party for a business purpose.
Privacy laws in these states give residents certain rights with respect to their personal data when they take effect over the course of 2023 through 2026. Those rights include:
- Right of Access: You have the right to access and obtain a copy of your personal data.
- Right to Correct: You have the right to correct inaccuracies in your personal data.
- Right to Deletion: You have the right to request that we delete personal data provided by or obtained by you.
- Right to Opt-Out of Targeted Advertising: You may ask us not to use or disclose your information for the purposes of targeting advertising to you based on your personal data obtained from your activity across different businesses, services, websites, etc.
- Right to Opt-Out of Personal Information Sales to third parties.
- Right to Non-Discrimination: We may not process personal data in violation of state and federal consumer anti-discrimination laws or discriminate against you for exercising rights under these state laws.
To submit a request to exercise any of the above rights, please refer to the above section “Exercising Your Rights”. You may email us at privacy@bluekc.com with the subject line “Privacy Rights Request” and let us know in which state you live. Please see the above section “Personal Information Sales and Targeted Advertising Opt-Out and Opt-In Rights” for a description of how to exercise your right to opt-out of targeted advertising or sales and uses for purposes not directly related to the Website.
Changes to this Supplement
We reserve the right to amend this Supplement at our discretion and at any time. When we make changes to this Supplement, we will post the updated notice on the Site and update the notice’s effective date. Your continued use of our Site following the posting of changes constitutes your acceptance of such changes to this Supplement.
Contact Information
If you have any questions or comments about this Supplement, the ways in which Blue KC collects and uses your information described herein this Supplement, your choices and rights regarding such use, or wish to exercise your rights under California, Colorado, Connecticut, Virginia, Utah, Montana, Tennessee, Oregon, Texas, Iowa, Indiana, Delaware law, please contact us at:
Phone: | 816-395-3784 or toll free at 1-800-932-1114 |
Website: | www.bluekc.com |
Email: | privacy@bluekc.com |
Postal Address: | P.O. Box 417012, Kansas City, MO 64141. |
If you need to access this Supplement in an alternative format due to having a disability, please contact Privacy@bluekc.com or 816-395-3784 or toll free at 1-800-932-1114.