Curi Holdings, Inc. (Curi) is committed to treating the information that you provide to us responsibly, and we will take reasonably available steps to safeguard all such information. This Privacy Policy highlights how Curi handles the information you provide to us, either directly at curi.com or indirectly—through software applications, forms, applications, data-capture devices, other websites, agents, or agencies.

We may need to change this Privacy Policy from time to time to address new issues relating to our website or the solutions or tools we provide on our website. We recommend that you check this page regularly.

Personal Information

Personal information is data that identifies you. We, our agents, and third parties may collect personal information from you. Examples of personal information include but are not limited to: name, mailing address, telephone number, email address, social security number, and tax ID number.

In order to provide you with products and services, we may need to collect personal information about you. We use physical, technical, and administrative safeguards to protect your information. We restrict access to this information to only those persons who need it to perform their jobs. We will not intentionally disclose any of your personal information, except as authorized by you, or as required or permitted by statute, common law, regulatory official, or in certain emergency situations. We will not sell this information to anyone. We may share this information with third-party business partners who perform services on our behalf, but any third-party business partner that receives this information from us is bound by law and contract to use the information only for our purposes, and to protect the information just as we are committed to protecting the information.

We may use the information you submit to create aggregated, anonymous data, which we will use to tailor our site to your interests, develop new features and monitor the usage of our site. We may also perform statistical analysis of this aggregate data and disclose the results as permitted by law. In addition, we may use your personal information for our business purposes, such as quality improvement, data analysis, audits, service improvement, usage and trend identification, and direct outreach.

We may also collect various types of non-identifying information including: the type of operating system you use, your IP address, URL’s of the pages you came from and go to, information collected through cookies and pixel tags, demographic information, and aggregated information. We may be required to share this type of information in other, limited circumstances to respond to judicial process; comply with state, federal, or local laws; protect the security or integrity of our databases or website; take precautions against liability; or, to the extent required by law, provide information to law enforcement agencies.

Protected Health Information

From time to time, we may need to collect personal and medical information about your patients, usually in connection with a professional liability incident, claim, or suit. This information may be protected by the Privacy and Security provisions of the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) and/or state-specific consumer protection statutes. We use physical, technical, and administrative safeguards to protect the PHI of your patients. We restrict access to this information to only those persons who need it to perform their jobs. We do not use or disclose the PHI of any patients unless it’s required or permitted under federal and state laws that apply to us or our website. We will not sell this information to anyone. We may share this information with third-party business partners who perform services on our behalf, but any third-party business partner that receives this information from us is bound by law and contract to use the information only for our purposes, and to protect the information just as we are committed to protecting your and your patients’ information.

Links to Third-Party Web Sites

This Privacy Policy does not address, and Curi is not responsible for, the privacy, information, or other practices of any third party, including any third-party service provider or vendor and any third-party operating software applications or websites to which curi.com contains a link. We cannot guarantee the quality, accuracy, safety, timeliness, or privacy policies of any site that is not under our control. Having such a link on curi.com does not imply that we or any of our affiliates or subsidiaries endorse the linked application or website.

Cookies

We use what’s known as cookies to improve your experience at curi.com. Cookies are small pieces of data we place in your computer’s browser to store your preferences. Cookies themselves don’t generate personal information about you, your practice, or your patients. We only use cookies to make your experience on our website more enjoyable. If you choose not to accept cookies, you may be unable to take full advantage of our website’s features.

Security

We’ve taken steps to ensure your security, the security of your patients and practices, and the security of all visitors to our site against unauthorized access and use. All online forms that include information captured from our users are secured using a Secured Socket Layer (SSL), which encrypts the information as it travels from a desktop to our server. We also obtain certification from industry-recognized security vendors to ensure our systems meet security standards. As an additional security measure, we use a firewall to prevent unauthorized access to our site. Site personnel monitor activity logs at regular intervals to look for unauthorized intrusions.

For your protection, please do not send unsecured e-mail to us that contains your personal information or the PHI of your patients. We cannot guarantee the security of these emails before they reach us, in contrast to the security precautions in place when you send us personal information through an online form on this website. We encourage you to utilize our Member Services portal to send secure messages and receive secure messages from us.

Information for our California Customers

We don’t knowingly allow other parties to collect personally identifiable information about your online activities over time and across third-party websites when you use our websites, unless we have your consent.

Do Not Track notice: We don’t currently respond to Do Not Track and similar signals. Please go to All About Do Not Track for more information.

Covered Companies

This Privacy Policy is provided on behalf of the following companies:

Curi Holdings, Inc.

Medical Mutual Insurance Company of North Carolina

Medical Security Insurance Company

MMIC Agency, LLC

Changes in Corporate Status

We may disclose, transfer, or sell the information collected through our website as an asset of the company in conjunction with due diligence for or completion of a merger, reorganization, or sale to a third-party of our company or a major portion of its assets.

Privacy Policy Changes

This Privacy Policy is effective April 20, 2019. We may change this policy page at any time without notice.

Contact us

Curi is sincerely committed to protecting your personal privacy. Any questions about this Privacy Policy or our privacy practices should be directed to Steven Sawyer, Privacy and Security Officer, Curi Holdings, Inc., P.O. Box 98028, Raleigh, NC 27624 or privacyoffice@curi.com.