Last Update: 6/1/2018
This Policy applies to the information practices of our corporate website mnglabs.com, as well as all subdomains and/or any current or future MNG owned or controlled websites. Note that MNG websites may contain links to other company websites, such as those of our partners. Please be aware that our Policy does not apply to these other websites. Although MNG reviews all links on our website, including links to websites of third parties, we disclaim any responsibility for content that is found on these other websites. We encourage you to thoroughly review the privacy statements of these other websites to understand their use of your personal data.
This Policy provides information about how MNG collects, uses, discloses and protects the personal information (“Personal Information”) we gather when you (i) navigate our website; (ii) order test kits; (iii) pay bills via our Online Bill Pay; (iv) submit information via the Contact Us page; or (v) ask to subscribe to our Newsletter.
If you are a facility that uses our services or a patient serviced by our lab, please see our full Privacy Statement for how we process Personal Information during our lab operations.
The Data We Collect About You
On any MNG website, you may be asked to give us personal or organizational information to fulfill a service provided by MNG or to contact us for more information or assistance.
The Personal Information collected by MNG may include, but is not necessarily limited to:
- Contact information (such as your name, e-mail address, and telephone number);
- Shipping Information (such as your address and postal code);
- Financial/credit card and payment information (please see the “Third Party Payment Processor” section for more information on how we use this information);
- Demographic information and geographic or geo-location information; and
- Additional information as needed for our business and customer service purposes.
We collect Personal Information through different methods, including (without limitation):
- Test Kit Order Form. Our Test Kit Order form securely collects contact information and shipping information to be able to fulfill your kit order. This information is shared securely with a third party vendor that is responsible for handling our kits and shipping them to you. We will also send you a confirmation email to your email address to indicate that your kit order has shipped.
- Contact Us Form. Our Contact Us form provides a means for you to securely request information from the MNG support team. We collect your name and contact information so we can directly contact you on the request. For certain requests, such as questions on interpretation of test results or sample transfer, we may also ask for additional Personal Information to assist in locating the correct sample and/or report in our systems. This additional information may include the name, date of birth, and/or a patient ID. To fulfill your request, our customer service team may need to contact you to verify that you are authorized to make the request, and they may need to send you additional forms to complete for verification. Without this verification, our team may not be able to fulfill your request.
- Sign Up for Our Newsletter. We provide the ability to “opt-in” to receive news from MNG. You will need to supply your email address to allow us to send you news and relevant updates periodically. Your email is placed in our marketing system as a contact so we can send you relevant information on the services MNG provides. You can “opt-out” at any time by submitting a request on our Contact Us form.
- Online Patient Self Pay. MNG allows the option for patients or facilities to use an Online Payment option via credit card to pay for services. In order to process a payment, we collect your contact information and then send you to a Third Party Payment Processor to complete the payment (please see the “Third Party Payment Processor” section below for more information on how we use our payment processor to allow payment of services). MNG does not store nor collect any credit card data or financial information.
Protected Health Information
The MNG website only transmits Protected Health Information (PHI) when necessary to retrieve information for our Contact Us and Online Patient Self-Pay forms. We need to collect name and date of birth information to allow us to properly identify the person for which you are making a request. We make every effort to secure the data submitted to us.
Please note that many of the PDF forms on our website, such as our test requisition forms, require collection of Protected Health Information. These forms are intended to be submitted along with a patient’s sample directly to our facility. Please see our general laboratory Privacy Statement that covers Protected Health Information once it comes to our laboratory for processing.
Protected Health Information is used in accordance with the United States Health Information Portability and Accountability Act (HIPAA) and applicable federal and state laws governing patient privacy.
On our website we do not collect Special Categories of Personal Information about you (this includes details about your government-issued ID numbers [e.g. Social Security Number or driver’s license number], race or ethnicity, religious or philosophical beliefs, sexual orientation, political opinions, trade union membership, nor information about your health and genetic and biometric data). We also do not collect any information about criminal convictions and offenses.
We ask that you not send or otherwise share with us any Sensitive Information in our website forms.
MNG uses a Session Cookie to keep track of user navigation during use of the website.
MNG uses Google Analytics, which places a persistent, tracking cookie on your hard drive. These analytics allow MNG to gather data about usage of our website, including your IP address, browser information, device information, and the web pages that you visited. The overall metrics are used by MNG to help improve our website.
Do Not Track Signals
The MNG website does not respond to browser Do Not Track (DNT) signals. We will continue to monitor further development of a DNT standard by the privacy community and industry to determine whether we will implement this capability in future.
How MNG Uses Your Personal Information
We will only use Personal Information provided to us when the law allows us to. Most commonly, we will use your Personal Information in the following circumstances:
- Where we need to perform the contract we are about to enter into or have entered into with you, such as performing a Kit Order, conducting an Online Payment, or asking us to contact you.
- Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.
- Where we need to comply with a legal or regulatory obligation.
MNG does not use third party marketing on our website. You will be able to “opt-in” to receive relevant information regarding MNG’s services by email. If at any time you wish to remove yourself from this service, please contact us to unsubscribe.
DISCLOSURES OF YOUR PERSONAL INFORMATION
MNG shall not disclose user information or data received from visitors to mnglabs.com except in the following circumstances:
- (a) during normal maintenance, operation, and use of mnglabs.com to parties with whom MNG has contracted to provide certain services in connection with the website (e.g. website development, website operations, security reviews) and its systems;
- (b) when we have reason to believe that disclosing this information is necessary to identify, contact, or bring legal action against someone who may be causing injury to or interference with (either intentionally or unintentionally) MNG’s rights or property, other mnglabs.com users, or anyone else that could be harmed by such activities;
- (c) as required by law; or
- (d) as otherwise specified by MNG on mnglabs.com.
We require all third parties to respect the security of your Personal Information and to treat it in accordance with applicable law. We do not allow our third-party service providers to use your Personal Information for their own purposes and only permit them to use your Personal Information for specified purposes and in accordance with our instructions.
Third Party Payment Processor
MNG uses a third-party payment processor for making credit card payments. While making an Online Payment, you will be sent to the third-party processor’s website for completing the payment via credit card. Under our agreement with the payment processor, they are not permitted to store, retain, or use your Personal Information or your billing information except for the sole purpose of credit card processing on our behalf. In certain cases, we may have access to the last four digits of your credit card number, its expiration date, and the billing address, which we will use solely to assist us in auditing payments made. In addition, we and our payment processor may use any information for internal business analyses and fraud prevention. MNG does not store any of the financial information entered on the third-party website in our data centers or databases.
MNG operates its website in data centers residing in the United States of America. All Personal Information as such will therefore be transferred to the United States.
We make every effort to ensure that Personal Information is safeguarded, including encryption in transit and at rest.
We have put in place appropriate security measures to prevent your Personal Information from being accidentally lost, used, altered, disclosed, or accessed in an unauthorized way. In addition, we limit access to your Personal Information to those employees, agents, contractors, and other third parties who have a business need to know. They will only process your Personal Information on our instructions and they are subject to a duty of confidentiality.
All transfers of Personal Information are encrypted using industry standard Secure Sockets Layer (SSL) technology and Personal Information is stored encrypted on controlled servers with restricted access.
We have put in place procedures to deal with any suspected Personal Information breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
How Long will you use my Personal Information?
We will only retain your Personal Information for as long as necessary to fulfill the purposes it was collected, including the purposes of satisfying any legal, accounting, or reporting requirements.
YOUR LEGAL RIGHTS
Under certain circumstances, you have rights under data protection laws (including HIPAA and GDPR) in relation to your Personal Information. If you wish to exercise any of these rights, please contact us.
What We May Need From You
We may need to request specific information from you to help us confirm your identity and ensure your right to access your Personal Information (or to exercise any of your other rights). This is a security measure to ensure that Personal Information is not disclosed to anyone who does not have the right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.