OMNIBUS Rule
HIPAA NOTICE OF PRIVACY PRACTICES
Ebix Inc.
1 Ebix Way
Johns Creek, GA 30097
IMPORTANT NOTICE
THIS NOTICE DESCRIBES HOW PROTECTED HEALTH INFORMATION (PHI) ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN ACCESS THIS INFORMATION UNDER THE HIPAA OMNIBUS RULE OF 2013.
PLEASE REVIEW IT CAREFULLY
For purposes of this Notice, “we,” “us,” and “our” refer to Ebix, Inc., and “you” refers to participants or their legal representatives. When you receive health and wellness services from us, we may obtain access to your PHI (for example, biometric screening results).
We are committed to safeguarding your PHI and have implemented procedures to ensure its protection. HIPAA and applicable state laws require us to maintain confidentiality and provide you rights to understand and control how your information is used.
This Notice is effective September 23, 2013. We reserve the right to update this Notice at any time and will notify you of material changes within 60 days.
Information We Routinely Collect
This information may include:
- Demographic information (e.g., name, email address, occupation)
- Biometric and screening data
-
Health survey responses
-
Program eligibility and participation data
-
Physical activity tracking data (e.g., steps, exercise duration)
- Points, rewards, and incentive activity data
We may also use your contact information to send program-related communications. Your information will not be sold or rented without your consent.
Google User Data & OAuth Permissions
The beBetter Health wellness portal may integrate with third-party services, including Google services, to provide wellness tracking features.
When you connect your Google account, we may request access to certain data through Google’s secure OAuth authorization process with your explicit consent.
Types of Google Data Accessed
-
Basic profile information (e.g., name, email address)
-
Fitness and activity data (e.g., steps, activity duration via Google Fit)
How Google User Data Is Used
We use Google data solely to:
-
Enable fitness and wellness tracking features
-
Support activity tracking, challenges, and incentive programs
-
Provide personalized insights and progress tracking
Google API Limited Use Disclosure
Our use of Google data complies with the Google API Services User Data Policy, including Limited Use requirements:
-
We only use Google data to provide or improve user-facing features
-
We do not sell Google user data
-
We do not use Google data for advertising
-
We do not share Google data except as required to provide services or comply with laws
- We do not use Google data for AI or machine learning without explicit approval
Storage, Retention, and User Control
Google data is protected using the same safeguards described in this Notice. Data is retained only as necessary for services and legal compliance.
You may revoke access at any time by:
Upon revocation, access to your Google data will stop and applicable data will be deleted in accordance with legal requirements.
How We Use Information About You
We use your information to:
- Provide wellness services and program features
-
Customize your experience
- Facilitate participation in challenges and incentive programs
-
Communicate program-related updates
-
Improve products and services
We may create de-identified data by removing personal identifiers and use it for analysis and program improvement.
Information may also be used for program eligibility, reporting, and benefit administration and shared with sponsoring organizations when required.
Use and Disclosure of Protected Health Information
By using the site, you acknowledge and accept this Notice. You may revoke consent at any time in writing, subject to legal limitations.
Permitted Uses Without Authorization
We may use or disclose PHI without your consent in limited circumstances including:
-
Legal requirements
-
Emergencies and safety situations
-
Public health reporting
-
Government oversight and audits
-
Legal proceedings
-
Worker’s compensation
-
National security
-
Organ donation
-
Approved research
-
De-identified data creation
Minimum Necessary Rule
We limit PHI access to what is necessary for job responsibilities. Staff and partners are trained in HIPAA compliance and bound by confidentiality agreements.
Disclosures are limited to the minimum required unless full records are necessary for treatment, legal compliance, or your request.
Incidental Disclosure & Breach Notification
We use safeguards such as secure systems, encryption, password protection, and restricted access to protect PHI.
If a breach occurs, we will:
-
Assess the situation using HIPAA-required methods
-
Document and report breaches as required
-
Notify affected individuals within required timeframes
Business Associates
Business Associates who access PHI must comply with strict confidentiality and HIPAA requirements. They are prohibited from unauthorized re-disclosure and must report any data breaches.
Security Practices
We use administrative, technical, and physical safeguards to protect your information, including data obtained through third-party integrations such as Google APIs.
While we take reasonable precautions, no system is completely secure and we cannot guarantee absolute protection from unauthorized access.
Your Rights
You have the right to:
-
Request restrictions on use of your PHI
-
Request confidential communications
- Access and obtain copies of your PHI
-
Request amendments to your PHI
-
Receive breach notifications
Requests must generally be made in writing.
California Privacy Rights (CCPA)
California residents may request access to, deletion of, or restrictions on the use of their personal data through the data controller. Ebix acts as a service provider where applicable.
For inquiries, contact: Privacy@ebix.com
Complaints and Contact Information
If you believe your privacy rights have been violated, you may file a complaint without penalty.
If you have a complaint or concern about how we use your personal data, please contact us in the first instance and we will attempt to resolve the issue as soon as possible. In the US, the supervisory authority for data protect ion is the I COOAG ( https://oag.ca.gov/privacy/ccpa ). We do ask that you please attempt to resolve any issues with us first, although you have a right to contact your supervisory authority at any time.
Further information on CCPA regulation can be found at https://oag.ca.gov/privacy/ccpa
U.S. Department of Health & Human Services
Office for Civil Rights
200 Independence Ave., S.W.
Washington, DC 20201
Phone: 877-696-6775
Ebix Privacy Officer
Ebix, Inc.
1 Ebix Way
Johns Creek, GA 30097
These privacy practices comply with HIPAA Omnibus Rule requirements and remain in effect until replaced.