When registering your students on our site, as appropriate, you may be asked to enter your names, email addresses, mailing addresses, phone numbers, some medical history and other details to help your school clear your student to participate in school activities.
We collect information from you when you register on our site or enter information on our site.
We use this information to help aid schools process students in an timely manner to be cleared to participate in sports or other activities. We may use the information we collect from you when you register, make a purchase/donation, or use certain other site features in the following ways:
Our website is scanned on a regular basis for security holes and known vulnerabilities in order to make your visit to our site as safe as possible. We use regular Malware Scanning.
Your personal information is contained behind secured networks and is only accessible by a limited number of persons who have special access rights to such systems, and are required to keep the information confidential. In addition, all sensitive/credit information you supply is encrypted via Secure Socket Layer (SSL) technology. We implement a variety of security measures when a user places an order enters, submits, or accesses their information to maintain the safety of your personal information.
We do not sell, trade, or otherwise transfer to outside parties your personally identifiable information unless we provide you with advance notice. This does not include website hosting partners and other parties who assist us in operating our website, conducting our business, or servicing you, so long as those parties agree to keep this information confidential. We may also release your information when we believe release is appropriate to comply with the law, enforce our site policies, or protect ours or others' rights, property, or safety. However, non-personally identifiable visitor information may be provided to other parties for marketing, advertising, or other uses.
We do not include or offer third party products or services on our website.
Google's advertising requirements can be summed up by Google's Advertising Principles. They are put in place to provide a positive experience for users. https://support.google.com/adwordspolicy/answer/1316548?hl=en
We have not enabled Google AdSense on our site but we may do so in the future.
We honor do not track signals and do not track, plant cookies, or use advertising when a Do Not Track (DNT) browser mechanism is in place.
It's also important to note that we do not allow third party behavioral tracking.
When it comes to the collection of personal information from children under 13, the Children's Online Privacy Protection Act (COPPA) puts parents in control. The Federal Trade Commission, the nation's consumer protection agency, enforces the COPPA Rule, which spells out what operators of websites and online services must do to protect children's privacy and safety online. We do not specifically market to children under 13.
The Fair Information Practices Principles form the backbone of privacy law in the United States and the concepts they include have played a significant role in the development of data protection laws around the globe. Understanding the Fair Information Practice Principles and how they should be implemented is critical to comply with the various privacy laws that protect personal information.
We will notify the users via email
The CAN-SPAM Act is a law that sets the rules for commercial email, establishes requirements for commercial messages, gives recipients the right to have emails stopped from being sent to them, and spells out tough penalties for violations.
Carty Web Strategies, DBA Home Campus has put into place numerous measures to certify it is compliant with the regulations and conditions set forth in the Health Insurance Portability and Availability Act of 1996 (HIPAA). Home Campus has implemented policies, processes and procedures designed to ensure compliance with Federal and State information security laws, regulations, and rules, and monitors ongoing compliance efforts and maintains several reporting tools that are required by law or requested by its customers in order to remain accountable. For those wishing to obtain more information regarding our compliance please contact Home Campus at (562)206-2486 or support [at] home-campus.com.
Access Control – Each user has unique username and password for identifying and tracking user identity. In the case of emergencies, we have procedures to obtain user information. The system will automatically logoff which will terminate the session after inactivity. We have SSL attached to the site (secured socket layer) which encrypts the data against hackers
Audit Controls – Software mechanisms that record and examine activity in all information systems.
Integrity – Medical information can only be altered by Users. It can be destroyed by School Administration and Home Campus at the end of the school year when sensitive information is purged.
Authentication – Email authentication is required when seeking access to an existing account. School Admin cannot obtain user login information.
Transmission Security – Electronically transmitted medical information can only be modified through User accounts. The site, which includes medical information, is encrypted.
Workstation Use – Home Campus admin (Currently 3 people) must login using their unique login information at any computer that accesses medical information.
Workstation Security – Home Campus offices are locked while unoccupied. Access during off hours is key card protected as well as locked manually. Access is restricted to 2 authorized people.
Device and Media Coverage – Home Campus is a web based program. Disposal of medical information from the server (Amazon Web Services) happens once a year. Schools can choose to save that information for their records before it is cleared from the server.
Security Management Process – Medical information is only managed on AthleticClearance.com by users through their unique login credentials. Implementation of risk analysis and measures to eliminate any chance for HIPAA violations. Employees that fail to comply will be terminated. Regular audits of the system, logs and activity.
Assigned Security Responsibility – Designated HIPAA Security and Privacy Officer – Wes Carty
Workforce Security – 3 Home Campus employees are authorized to access Users medical information. Any employee that does not have authorized access will be terminated if accessing medical information.
Information Access Management – Ensure that medical information is not accessed by partner organizations or subcontractors that are not authorized for access.
Security Awareness and Training – Periodically send updates and reminders about security and privacy policies to employees. Have procedures for guarding against, detecting and reporting malicious software. Procedures for creating, changing and protecting passwords.
Security Incident Procedures – Identify, document and respond to security incidents.
Contingency Plan – Accessible backups of medical information and procedures to restore lost data.
Evaluation – Perform periodic evaluations to see if any changes in business or law require changes to the Home Campus HIPAA Compliance Statement or procedures.
Business Associate Contracts and Other Arrangements – No business partners have access to sensitive information.
Long Beach, CA 90853