Apremia, Inc.
This Privacy Policy applies to Apremia Inc. and its subsidiaries (“Apremia,” “we,” “us,” or “our”), covering all personal information collected on www.apremia.com and through other offline or online means related to our health insurance brokerage, Medicare, ACA, and related services. It applies to information of individuals applying for or enrolled in health insurance and related plans (“Customers”), our licensed insurance agents and their sub-agencies (“Agents”), and any other individuals whose data we collect (e.g. website visitors). This policy covers personal data not otherwise subject to HIPAA or GLBA – see Section 9 for details on how HIPAA/GLBA affect certain data.
We act as a broker/agent for insurance plans and a business associate of health plans. We do not itself provide healthcare or insurance coverage; instead, we facilitate customers’ enrollment in plans offered by insurers. We are committed to protecting personal data under HIPAA, GLBA, and all other applicable laws and regulations.
We collect a broad range of personal information about Customers, Agents, and employees. This includes identifiers (name, date of birth, SSN, driver’s license number, employer information); contact information (addresses, phone, email); financial/payment data (bank account, billing info); health and medical data (PHI) (health conditions, Medicare/Medicaid status, diagnoses, prescriptions, provider names, claims information, Medical ID numbers); demographic data (age, race/ethnicity, gender, language, income bracket); and education/professional data (occupation, education, Medicare insurance plan selections). We also collect technical data on how you use our website (IP address, browsing history, device IDs, cookies, etc.)【21†L124-L134】【10†L75-L82】.
For Agents and sub-agency personnel, we may collect similar information needed to process appointments or commissions (e.g. National Producer Number, license details, tax ID, background check results).
We obtain personal data from multiple sources:
- Directly from Customers and Agents: Through online forms, applications, emails, phone calls, or face-to-face meetings. For example, you provide your name, contact, health, and insurance details when applying for coverage or requesting quotes【10†L75-L82】.
- Insurance Carriers and CMS: Data received from insurers (for eligibility checks, claims, plan enrollment) and government entities (e.g. Centers for Medicare & Medicaid Services) under business associate agreements.
- Affiliated Agents/Sub-Agencies: Agents may input lead or client data into our systems or share it for servicing.
- Lead Vendors and Partners: Third-party lead generation companies (with your consent) provide inquiries or profiles of individuals interested in insurance.
- Public and Third-Party Sources: Public records, consumer report agencies (e.g. credit bureaus for underwriting), or open data sources (e.g. verifiable public health programs eligibility).
- Website and Marketing Analytics: Through cookies and online analytics (see Section 13).
We do not knowingly collect sensitive personal information (e.g. biometric or precise geolocation data) unless necessary for a specific purpose and with consent【21†L131-L139】.
Apremia uses the collected personal data for the following purposes:
- Insurance Enrollment and Servicing: Process and enroll customers in ACA, Medicare, supplemental, or other insurance plans. This includes identity verification, eligibility determination, plan selection assistance, application submission, premium billing, and renewal notices.
- Claims and Eligibility Support: Assist with claims processing, benefits explanations, coverage coordination, and dispute resolution on behalf of insurers and customers.
- Customer Service and Communication: Respond to inquiries, provide customer support, send policy documents, notices, and updates (e.g. plan changes, renewal deadlines).
- Marketing and Outreach (with Consent): With your explicit consent, we may send promotional materials about insurance products, community resources, or partner services. You may opt out at any time (see Section 11). We do not sell personal data for marketing.
- Compliance and Legal Obligations: Comply with federal and state laws (HIPAA, ACA regulations, Medicare regulations, state insurance laws, etc.), perform audits, and cooperate with law enforcement or government requests.
- Fraud Prevention and Security: Detect and prevent fraud, identity theft, or unauthorized activities. We analyze data to verify identity and uncover suspicious patterns.
- Business Operations: Internal uses such as recordkeeping, analytics, quality improvement, training of staff, and management of Agents/Sub-agencies and vendor relationships.
Each use of personal data is based on a valid legal basis: processing necessary to fulfill our contract with you (e.g. to provide insurance services); compliance with legal/regulatory obligations (e.g. Medicare reporting, recordkeeping); your consent (for marketing and certain data collections); or our legitimate business interests (e.g. fraud prevention, service improvements) as permitted by law.
Where required under applicable law, we rely on one or more of the following legal grounds:
- Contract/Performance: We process data to perform our contract with you (e.g. insurance application) and provide requested services.
- Compliance: We process data to comply with legal obligations (e.g. HIPAA, Medicare/ACA regulations, tax/reporting laws).
- Consent: Where applicable, we obtain explicit consent (for example, to receive marketing communications via SMS or email)【21†L83-L87】. You may withdraw consent at any time.
- Legitimate Interest: We may use data for legitimate business purposes (e.g. improving our services, ensuring security), where those interests do not override your privacy rights. For instance, we have a legitimate interest in preventing fraud or conducting actuarial analyses, which may involve limited use of customer data.
We document and carefully assess each processing activity. Where required by law, we obtain any necessary authorizations (e.g. HIPAA authorizations for certain PHI uses beyond treatment/payment).
Apremia operates under multiple privacy regimes:
- HIPAA (Health Insurance Portability and Accountability Act): Customers’ health information (PHI) processed by Apremia on behalf of health plans is protected under HIPAA. Apremia is a Business Associate of health plans【4†L90-L98】. We limit PHI use/disclosure to HIPAA-permitted purposes (treatment, payment, operations, or as agreed in business associate agreements). We use appropriate safeguards (see Section 10) and must report any breaches of unsecured PHI to covered entities【27†L178-L185】. We also observe all CMS Privacy Act obligations for Agents/Brokers, meaning we do not disclose applicants’ PII to unauthorized parties and train staff on these rules【8†L822-L830】【8†L835-L843】.
- GLBA (Gramm-Leach-Bliley Act): Insurance is a financial service under GLBA. Apremia is treated as a “financial institution” for privacy purposes. We comply with the GLBA privacy requirements and related state insurance privacy laws (e.g. NAIC model laws)【10†L47-L51】【38†L113-L121】. We provide notice of our data practices and afford customers an opt-out of sharing certain nonpublic personal financial information with unaffiliated third parties【38†L113-L121】.
- State Privacy Laws: As applicable, we comply with state-level laws (for example, California’s CCPA/CPRA). These laws grant additional rights (access, deletion, opt-out of sale/sharing, etc.) to residents【30†L206-L214】. While Apremia does not primarily market to minors, we note that CCPA includes special rules for minors under 16.
- FTC Principles: We also follow the Federal Trade Commission’s guidance for fair information practices (notice, choice, access, security) in all marketing and consumer interactions.
Apremia shares personal data only as necessary and permitted:
- With Insurance Carriers and CMS: We disclose customer data to insurance companies and CMS/Medicare to enroll you, report eligibility, and service benefits. PHI is shared in strict accordance with HIPAA Privacy Rules.
- With Agents and Sub-Agencies: We share relevant customer data with appointed agents or partner agencies to assist in enrollment, servicing, or renewal, strictly under their confidentiality obligations.
- With Service Providers: Third-party vendors (e.g. IT hosting, billing processors, call center, marketing agencies, compliance consultants) may process data on our behalf. We only engage vendors who commit (by contract) to safeguard personal data at least as strictly as Apremia does【36†L124-L131】【36†L133-L139】. We enter Business Associate Agreements (BAAs) or similar data processing agreements with vendors handling PHI.
- Law Enforcement and Legal Obligations: We may disclose data to comply with court orders, subpoenas, or laws (e.g. reporting to regulators or responding to law enforcement requests). We notify you of legal disclosures when permitted by law.
- Health or Safety Situations: In limited cases, we may share personal health information to avert a serious threat to health or safety, as allowed by law (e.g. public health reporting).
- Business Transactions: In the event of a merger, acquisition, or sale of assets, personal data may be transferred to the new owner under confidentiality terms.
We do not sell or rent your personal data for marketing. Any sharing of data for advertising or analytics (e.g. with ad networks or social media platforms) is done only with clear notice and opt-in, or otherwise as permitted by law. We do not disclose data to unaffiliated third parties for their own marketing without consent【10†L98-L104】.
On our websites and apps, we use cookies, web beacons, and similar technologies to provide functionality, analyze usage, and personalize content. Types of cookies include:
- Necessary Cookies: Required for site functionality (e.g. login, form submissions).
- Analytical Cookies: Collect anonymous usage data (pages visited, session length) to improve our services.
- Advertising/Tracking Cookies: To deliver targeted content or ads (only with your consent).
We allow browser-based opt-out of non-essential cookies, and we support Global Privacy Control (GPC) signals as an opt-out preference【21†L175-L184】. Disabling cookies may affect some site features. You can manage cookies via your browser settings (deleting or blocking cookies) or device preferences. For more information, see our Cookie Policy [link].
Our services are not intended for children under 16. We do not knowingly collect personal information from minors. If we become aware that a child under 16 has provided personal data without parental consent, we will delete such data promptly【21†L189-L192】.
Apremia primarily operates in the U.S. and does not intentionally transfer personal data outside the United States. If any international transfer occurs (for example, through cloud service providers with global infrastructure), we ensure appropriate safeguards are in place (e.g. encryption, and compliance with applicable cross-border data laws).
Apremia implements reasonable and appropriate security measures to protect personal data. These include:
- Administrative Safeguards: Policies and training to ensure staff and agents understand privacy obligations【8†L835-L843】. Access to personal data is restricted to employees who need it to perform their duties (principle of least privilege)【10†L109-L118】【36†L124-L131】.
- Technical Safeguards: Encryption of data in transit and at rest, firewalls, intrusion detection, multi-factor authentication, secure password policies, and regular monitoring of networks and systems【10†L109-L118】【36†L124-L131】.
- Physical Safeguards: Secure office and data center facilities, locked storage of paper records, and controlled access to equipment storing personal data.
- Data Integrity: We take steps to ensure data is accurate and complete. Customers and agents can update their information, and we use verification processes (e.g. verifying SSNs or addresses) to maintain accuracy.
Despite these measures, no system is foolproof. In the event of a breach or incident, we will act promptly under our Incident Response Plan. We will comply with all applicable breach notification laws (HIPAA requires notifying affected individuals within 60 days of discovery of an unsecured PHI breach, etc.), and will notify regulators as required. We also have cyberinsurance and forensic experts on standby as part of our contingency planning.
Apremia retains personal data only as long as necessary for the purposes described or as required by law and our record-keeping policies【30†L221-L229】. Retention factors include legal obligations (e.g. Medicare/ACA mandates), the needs of our business (e.g. servicing ongoing policies), and customer expectations (e.g. ability to re-enroll).
When data is no longer needed, we securely dispose of it (e.g. shredding paper records, wiping storage media) or anonymize it for analytical uses. We retain health records according to HIPAA record-retention rules, and financial records per GLBA/state insurance law requirements. Customers and agents may also request deletion of data, subject to legal exceptions (see Section 12).
- Access and Correction: You may request access to your personal information held by Apremia, and ask to correct any inaccuracies. We will verify your identity and respond within a reasonable time. If we deny your request (for valid legal reasons), we will explain why.
- Deletion: You may request deletion of your personal information. We will honor deletion requests unless we need the data to comply with legal obligations (e.g. reporting to Medicare), to detect/prevent fraud, or to fulfill our contract with you. In such cases, we may anonymize or aggregate the data instead.
- Portability: Where technically feasible, we will provide your data in a portable format if you request (e.g. summary of enrollment or billing data).
- Objection and Restriction: You have the right to object to certain processing (e.g. direct marketing) and ask us to restrict how we use your data. We will consider such requests under applicable law.
- Opt-Out: You may opt out of promotional communications at any time by contacting us or following the unsubscribe instructions in emails/texts. For California residents, you may exercise your CCPA rights: right to know (what information we have), right to delete, right to correct, right to opt-out of sale/sharing (we do not sell data), right to limit use of sensitive info, and right to non-discrimination for exercising rights【30†L196-L204】【30†L206-L214】.
To exercise any right, please contact us as described below. We will respond within the time frames required by law.
Our Agents and sub-agencies have separate obligations under their appointment agreements. All Agents must agree to:
- Use personal data only for authorized purposes (selling and servicing insurance for the customer) and in compliance with this Privacy Policy and all laws (HIPAA, GLBA, etc.)【36†L124-L131】.
- Maintain data confidentiality and security. Agents must implement safeguards (at least industry-standard physical, technical, and administrative controls) to protect data against unauthorized access or disclosure【36†L124-L131】.
- Not disclose customer data to unauthorized parties. Disclosure is permitted only to other covered insurers/carriers for service purposes or as required by law, and any staff or subcontractors must be bound by confidentiality at least as strict as Apremia’s【36†L133-L139】.
- Promptly report any security incident or suspected breach involving personal data to Apremia.
These requirements are typically documented in our Agent/Broker contracts and Subagency agreements. Sample clauses include confidentiality obligations and compliance with HIPAA/GLBA standards【36†L124-L131】【36†L133-L139】.
We carefully vet all service providers and enter appropriate agreements:
- Due Diligence: Before engaging any vendor, we assess their security practices and require evidence of compliance (e.g. SOC 2 reports). For vendors handling PHI or sensitive personal data, we sign Business Associate Agreements or data processing addenda.
- Data Protection Impact Assessments (DPIAs): For any new or high-risk data processing (e.g. implementing a new analytics platform or AI tool that processes customer data), we conduct DPIAs to identify and mitigate privacy risks.
- Audits and Oversight: We periodically audit critical vendors to ensure compliance with contractual and regulatory requirements.
We also comply with legal requirements for online privacy notices (e.g. providing a clear “Cookie Policy” and allowing opt-out of tracking cookies). We may use Google Analytics, Facebook pixels, or similar tools; in each case we anonymize data (IP masking) where possible and honor Do Not Track/GPC signals.
If you have questions or concerns about this Privacy Policy or our data practices, or wish to exercise your rights, please contact our Privacy Officer:
- Privacy Officer, Apremia Inc.
- 100 Maple Ave S, Lehigh Acres, FL 33936
- Phone: (855) 588-5444 | Email: [email protected]
For disputes, we will attempt good-faith resolution. If unsatisfied, you may file a complaint with state or federal regulators (e.g. HHS OCR for HIPAA issues, FTC, or state insurance commissioner).
We may update this Privacy Policy periodically (e.g. as laws change or we introduce new services). We will post the updated Effective Date. Continued use of our services after updates constitutes acceptance of the revised policy. We encourage you to review this policy regularly.
Note: This Privacy Policy does not replace any separate notices (e.g. HIPAA Notice of Privacy Practices from your health plan, or insurer privacy notices under GLBA). Where another notice applies, its terms will govern that data.
Preguntas frecuentes
Sabemos que al momento de elegir o renovar un seguro médico surgen muchas dudas. Aquí respondemos las más comunes para ayudarte a entender mejor nuestros servicios y coberturas.
¿No encontraste lo que buscabas? Contáctanos y con gusto resolveremos todas tus preguntas.
Si usted necesita atención médica de emergencia, la mayoría de los planes le permitirán dirigirse al proveedor más cercano. Si no es una atención médica de emergencia, pero necesita atención antes de asistir a una consulta de rutina al médico, probablemente deba dirigirse a un proveedor del plan. Siempre debe ponerse en contacto con el proveedor de atención primaria o la compañía de seguros tan pronto como le sea posible. Algunos planes exigen que pague una porción adicional de los gastos si no se comunica con ellos antes de que transcurran 48 horas desde que recibió atención en una sala de emergencias.
- la edad
- el estado de salud
- el lugar de residencia
- el nivel de protección del seguro
- si hay copago y de qué tipo es
- el número de asegurados
- Por falta de pago.
- Si no se entrega a tiempo las evidencias de estatus legal, ingresos u otras que solicita el mercado de salud al momento de activar la cobertura.
Tu Espacio de Información
Encuentra consejos prácticos, noticias y la mejor información para tomar decisiones inteligentes sobre tu cobertura médica.
🦷👓¿Tu seguro médico no cubre lentes o tratamientos dentales? Descubre cómo una póliza complementaria puede ayudarte
Muchas personas creen que tener un seguro médico significa estar completamente protegidas. Sin embargo,…
¿Perdiste tu cobertura médica? Health Guard Protector puede ser una opción para ti
Muchas personas se enfrentan a una situación complicada: necesitan atención médica, pero no cuentan…
Exámenes preventivos para ti mamá: beneficios que puede incluir el seguro médico ACA
Ser mamá muchas veces significa cuidar de todos antes que de una misma. Entre…
Únete a Nuestro Equipo de Agentes
Sé parte de Apremia y ayuda a más familias a obtener la cobertura que necesitan. Te ofrecemos capacitación, herramientas y acompañamiento para que crezcas profesionalmente.