Privacy experts say CVS pharmacy customers need to be on alert. If you've signed up for the ExtraCare rewards program for prescription drugs, then you have signed a waiver giving up certain healthcare privacy protections under HIPAA.
If you sign up, you can earn up to 50 bucks a year in store credit. Sounds like a great deal - but consumer advocates say before you say yes, read the agreement. Saving that 50 bucks a year means signing away some of your HIPAA Rights; it's the privacy rule that protects your medical information.
Claire Gastanaga, Executive Director of the ACLU of Virginia says it's up to the consumer to understand what they are singing. "If I were a CVS customer, which I am, I would be looking very carefully at the fine print here," she says.
We couldn't get anyone on camera but CVS did issue a statement. It says, "Earlier this year, CVS/pharmacy launched a new ExtraCare Pharmacy & Health Rewards program to give members more ways to earn rewards for actions they take to stay healthy, such as filling prescriptions and getting a flu shot. Our pharmacy rewards program requires authorization from patients for it to access their prescription information in order to provide rewards based on the number of prescriptions they fill. This authorization is part of our extensive procedures, stringent policies and state-of-the-art technology in place to protect our customers' personal and health information.
The language in our authorization statement is required under the HIPAA privacy law. By signing the HIPAA authorization form, customers are authorizing CVS only to enroll in the Pharmacy & Health Rewards program and to count the number of prescriptions a customer fills as an individual so that we can reward them based on that number. We are committed to protecting the privacy of our customers and we do not share any of their personal information, which remains protected under consumer privacy laws."
Despite that promise, if you sign the waiver, you'll see it still allows "CVS/Pharmacy® and its affiliates to share prescription and other health service records" you share with the pharmacy.
When we pressed more about that sharing clause, and what it meant, CVS says the language is required by HIPAA Law. The company says, "It is against the law to redisclose this information to third parties. Our Pharmacy is a HIPAA covered entity disclosing the number of prescriptions filled by a customer to our ExtraCare program, which is run by our retail business, a non-covered entity. That is the only info ExtraCare receives - number of prescriptions filled by a patient."
"For us, our concern is once they get it, who else is going to get access to it," Gastanaga says. We should point out customers don't have to sign up for the rewards program and can still use the pharmacy. Also, if you sign up and change your mind, you can opt out of the program and can you can cancel your HIPAA authorization.
Zach McCluskey, COO for Retreat Doctors' Hospital, says the CVS waiver is not surprising but calls it unique. He says he can't comment on CVS's reasoning or policies but for hospitals, protecting patient privacy is crucial. '"If you don't feel secure that your information is secure, you may not seek necessary treatment and you may be hesitant to share what is actually going on with you and you may not get the appropriate care that you need," he says.
Gastanaga, says this is all a reminder that consumer privacy is a constant battle. "There are drones that can fly over house and smell the bacon cooking in our kitchen or see a smile from 2 and half miles up. All of this technology is making it this more difficult to guard our privacy," she says.
Signing up for the rewards program is your choice, you just have to ask yourself is it worth it. We checked and Walgreens and Rite Aid have similar rewards programs but don't require a HIPPA waiver.
Thursday, April 17 2014 9:05 PM EDT2014-04-18 01:05:03 GMT
A Mount Tabor reservoir that holds Portland's drinking water has been taken offline out of fear that a group of trespassers urinated in it. Five people were seen at Mount Tabor Park around 1 a.m. Wednesday.More >>
A Mount Tabor reservoir that holds Portland's drinking water has been taken offline after a teenager urinated in the reservoir. More >>
Thursday, April 17 2014 4:43 PM EDT2014-04-17 20:43:50 GMT
Officials with the VA Medical Center in downtown Charleston say a North Charleston man who was initially federally charged with a $525 fine for an $.89 drink refill will instead be given a warning.More >>
Officials with the VA Medical Center in downtown Charleston say a North Charleston man who was initially federally charged with a $525 fine for an $.89 drink refill will instead be given a warning. More >>
Thursday, April 17 2014 10:30 AM EDT2014-04-17 14:30:20 GMT
The York-Poquoson Sheriff's Office is on the hunt for a man who witnesses say, ran over a puppy on purpose. Investigators say, it happened April 15 at the intersection of Hubbard Lane and Hillside Lane. NBC12More >>
A man ran over a puppy on purpose, according to witnesses, and now the York-Poquoson Sheriff's Office is working to track him down. More >>
Thursday, April 17 2014 7:26 AM EDT2014-04-17 11:26:26 GMT
A suspect had to be taken to the hospital following a police pursuit early Thursday morning. The chase started in the city of Richmond around 1:30 a.m. Officers tried to pull the suspect over for a trafficMore >>
A suspect had to be taken to the hospital following a police pursuit early Thursday morning. More >>
Thursday, April 17 2014 4:09 PM EDT2014-04-17 20:09:06 GMT
Petersburg police are investigating a woman's body discovered near South Crater Road Thursday morning. A lawn crew found the body just before noon near the intersection of South Crater Road and East WytheMore >>
Petersburg police say a woman's body discovered near South Crater Road Thursday morning is not suspicious. More >>