SIHO Mobile Application
PRIVACY POLICY ADDENDUM
The Mobile Application Privacy Policy Addendum (“Addendum”) supplements the SIHO Insurance Services Notice of Privacy Practices (“NPP”) and applies specifically to the SIHO mobile application (“App” or “Mobile App”). If this Mobile Application Privacy Policy Addendum conflicts with SIHO’s Notice of Privacy Practices regarding protected health information, the Notice of Privacy Practices will control as required by law.
This Privacy Policy describes how the SIHO Mobile Application collects, uses, stores, discloses, and safeguards information when you use the application. It is intended to be consistent with language reflected in SIHO’s published Notice of Privacy Practices and related privacy materials, while also addressing the specific features and functions of a mobile application. Please review this Privacy Policy carefully.
The Mobile Application Developer is “mPulse, Inc.”
Effective Date
This Privacy Policy is effective as of June 18, 2026.
Information We Collect
We may collect information that you provide directly, information generated through your use of the application, and information received from health care providers, health plans, employers acting on behalf of a group health plan, or service providers supporting SIHO’s operations. This information may include account registration details, identifiers, contact information, device and log data, submitted forms, benefit and eligibility information, claims-related information, and, where applicable, protected health information and electronic protected health information.
We collect only the information necessary to provide, maintain, secure, and improve the services offered through the mobile application (“App”) and related member services. We limit the collection of personal information and protected health information to the minimum necessary to support the App’s operation, security, and functionality and to deliver requested services.
How We Use Information
Use of Member Data
We use personal information and protected health information (“PHI”), collectively referred to as “Member Data,” solely for legitimate business and health care-related purposes, including the following:
- Providing access to health plan information and services
- Supporting claims, eligibility, benefits, and care management functions
- Authenticating users and maintaining account security
- Responding to member inquiries and support requests
- Maintaining, improving, and troubleshooting the App
- Detecting, preventing, and responding to fraud, abuse, unauthorized access, and security incidents
- Complying with legal, regulatory, and contractual obligations
SIHO’s use of Member Data does not include:
- Use of Member Data for unrelated commercial purposes
- Sales of Member Data to third parties
- Sharing or use of Member Data for third-party advertising, marketing, or profiling purposes unrelated to the services provided through the App
How We May Disclose Information
We may disclose information to affiliated entities, health care providers, health plans, employers acting on behalf of a group health plan, business associates, contractors, and service providers that perform functions on our behalf, provided they are authorized and required to protect the information appropriately. We may also disclose information as permitted or required by law, including for payment, health care operations, public health activities, law enforcement requests, regulatory compliance, fraud prevention, security investigations, and protection of the rights, safety, and property of SIHO, app users, and others.
Sharing of Information with Third Parties
We may share member data with third parties only as needed to provide, support, secure, maintain, or improve the App and related health care operations.
Such third parties may include:
- Technology and cloud hosting providers
- Identity verification and authentication providers
- Customer support and communications providers
- Health care operations, claims, care management, and benefits administration partners
- Regulatory, government, or law enforcement authorities, when required by law
When required by law, we enter into appropriate agreements, including Business Associate Agreements (“BAAs”), with third parties that access, process, or store Member Data on our behalf.
Third parties may use the information only to provide services to us and must maintain appropriate confidentiality, privacy, and security protections. They may not use member data for their own marketing, advertising, or other independent commercial purposes.
Protected Health Information
To the extent the SIHO Mobile App creates, receives, maintains, or transmits protected health information or electronic protected health information, we will handle that information in accordance with applicable privacy and security requirements, including reasonable administrative, technical, and physical safeguards, applicable rights of access and amendment, and breach notification obligations.
Data Retention and Deletion
We retain personal information only as long as necessary for the purposes described in this Privacy Policy or as required or permitted by law. After that, we securely dispose of the information in accordance with applicable law and aligned with procedures outlined in NIST 800-88. We may retain information longer to comply with legal obligations, resolve disputes, enforce agreements, respond to law enforcement requests, support security and fraud prevention, or protect the integrity of our services. Log files may be retained for a shorter period unless a longer retention period is required by law or needed for security or operational purposes.
Mobile Device Features and Permissions
With your permission, the app may use certain device features such as biometric authentication supported by your device, push notifications for service-related messages, and storage access needed for secure operation of app features. You can manage many permissions through your device settings. If you disable certain permissions, some app features may not function properly. The SIHO Mobile App is not intended to collect more information from your device than is reasonably necessary for the services you request or the secure operation of the app.
Member Access Control
Users are responsible for maintaining the confidentiality of their login credentials, safeguarding access to their devices, and promptly notifying SIHO of suspected unauthorized access or other security concerns.
Members may request removal of access to the App by contacting SIHO Member Services (memberservices@siho.org).
Where required by applicable law, members may also request access to, or correction of, certain personal information maintained by SIHO by contacting SIHO Member Services (memberservices@siho.org).
Compliance with the Children’s Online Privacy Protection Act
SIHO complies with the Children’s Online Privacy Protection Act, which requires the consent of a parent or guardian for the collection of personally identifiable information from children under 13 years of age. SIHO does not knowingly collect, use or disclose personal information from children under 13, or equivalent minimum age in the relevant jurisdiction, without verifiable parental consent. However, it is possible that we may inadvertently receive information pertaining to children under 13. If you believe that we have received information about your child that is under the age of 13, please notify us at memberservices@siho.org. When we receive your notification, we will obtain your consent to retain the information or will delete it permanently.
Data Usage Consent
You may, if the laws of your U.S. state otherwise require, withdraw your consent where consent is required or otherwise object to uses of your information as described above by contacting SIHO Member Services (memberservices@siho.org).
If you do so, SIHO will cease using your personal information for the above purposes and remove it from its systems unless such personal information is permitted to be used by SIHO for another purpose set out in this Privacy Statement or SIHO determines and demonstrates a compelling legitimate interest to continue in processing your personal information.
In case of withdrawal of consent, SIHO will not process your personal information subject to this consent any longer unless legally required to do so.
In case SIHO is required to retain your personal information for legal reasons, your personal information will be restricted from further processing and only retained for the term required by law.
Any withdrawal has no effect on past processing of personal information by SIHO up to the point in time of your withdrawal. Furthermore, if your use of a SIHO offering requires your prior consent, SIHO will not be able to provide the relevant product, service, offer, or event to you after your withdrawal.
Please direct any such request for withdrawal to memberservices@siho.org.
Changes to This Privacy Policy
SIHO may update this Privacy Policy from time to time. When material changes are made, we may provide notice through the app, on the SIHO website, or by other appropriate means. The updated Privacy Policy will become effective as of the date stated in the revised version.
Contact Information
If you have questions about this Privacy Policy or SIHO privacy practices, please contact SIHO Member Services by mail at SIHO Insurance Services, 417 Washington Street, Columbus, Indiana 47201, or by phone at (800) 443-2980 or (812) 378-7070, or by email at memberservices@siho.org.