Document name
Our privacy terms and practices
Web and mobile privacy statement
-
This Privacy Policy describes the types of personal information that Aetna Life Insurance Company and its subsidiaries and affiliated companies (“Business,” “we,” “our,” or “us”) collects from and about you, including through your interactions with us on https://www.aetna.com, on the Aetna Health mobile application, or other locations where this Privacy Policy is posted. We refer to these collectively as the “Services.” By using the Services, you agree to the terms of this Privacy Policy.
To the extent that information collected through the Services is member information protected under the Health Insurance Portability and Accountability Act (HIPAA), please consult the relevant plan’s Notice of Privacy Practices in the Privacy Center and not this Privacy Policy. If you have questions about which policy applies to information you have provided, please do not hesitate to contact us via email at PrivacyAetna@Aetna.com.
We reserve the right to change this Privacy Policy at any time. Any changes will become effective when we post the revised Privacy Policy on the Services. Your use of the Services following these changes means that you accept the revised Privacy Policy. We will provide appropriate notice to you and seek your consent, where required by applicable law, if we change this Privacy Policy in a material way. The “Last Updated” legend at the top of this page indicates when this Privacy Policy was last revised. -
We do not knowingly collect personal information online from any person we know to be under the age of 13 and instruct users under 13 not to send us any information to or through the Services without their parents’ consent.
The Services are designed for users from, and are controlled and operated by us from, the United States. By using the Services, you consent to the transfer of your information to the United States or storage of your information in the United States, which may have different data protection rules than those of your country. -
We want you to understand how personal information you provide to us is collected and used. Personal information means information that identifies you or is associated with you. Categories of personal information we may collect include:
- Contact information, such as name, postal address, email address, and phone number.
- Device and network information, such as IP address, cookies, and other online identifiers.
- Internet activity and interactions, such as the webpages you visit and how you use the Services.
- Non-precise geolocation data, such as the state you live in.
- Preferences and feedback, such as communications you wish to receive or surveys.
- Payment or financial information, such as your EFT (Electronic Funds Transfer) banking information if you initiate a payment transaction with us.
We may collect your personal information from the following sources:
- Directly from you, such as when you provide it to us or to our service providers.
- Automatically through the Services, such as through analytics services and tracking technologies (e.g., cookies).
- From third parties, such as public sources.
If you choose not to provide your personal information to us, we may not be able to provide you with the requested products, services or information.
If you submit any personal information relating to other people in connection with the Services, you represent that you have the authority to do so and to permit us to use the information in accordance with this Privacy Policy.
We may combine the information collected from you through the Services with information we receive from and about you from other online and offline sources and use the combined information in accordance with this Privacy Policy. Our goal is to offer you content, products, and services that are most likely to appeal to you.
We may use your personal information to provide you with the Services and for the following purposes:
- Send you communications and marketing materials, such as when you create an account.
- For our business purposes, such as data analysis, audits, fraud monitoring and prevention, detect and investigate incidents or breaches, developing our Services and new products and services.
- To comply with applicable law and protection of our operations, such as enforcing our terms of use and other terms and conditions and protecting our rights, privacy, safety or property and/or that of our affiliates, you, or others.
- With your consent, if you direct us or our service providers to use or disclose your personal information for specific purposes.
- To personalize and tailor the Services, such as providing you with content, products, and services that are most likely to appeal to you.
We may disclose your personal information to the following categories of recipients:
- Service providers: We may disclose your personal information to service providers that provide business and technical services to us and on our behalf, such as web hosting, payment processing, data analytics, and other services.
- Governmental, regulatory or public authorities: We may disclose your personal information only as permitted or if required to do so by government and law enforcement authorities. In matters involving claims of personal or public safety or in litigation where the information is pertinent (including to allow us to pursue available remedies or limit the damages that we may sustain), we may use or disclose personal information, including without court process. We may also use or disclose personal information to enforce our terms and conditions, to protect our operations or those of any of our affiliates, or to protect our rights, privacy, safety or property and/or that of our affiliates, you, or others.
- Affiliates and business partners: We may disclose your personal information to affiliated companies and partners, to the extent permitted by applicable law, who may use it to send you marketing and other communications.
- Other third parties: We may disclose your personal information to (i) third parties to whom you’ve directed or consented to a disclosure; (ii) relevant third parties (e.g., acquiring entity and its advisers) in the case of a reorganization, merger, sale, joint venture, assignment, transfer or other disposition of our business or assets; or (iii) third parties we’ve deemed necessary or appropriate to comply with applicable law, protect our operations, and protect the rights, safety, or property of you and others.
-
The Services may contain links to, or otherwise make available, third-party websites, services, or other resources not operated by us or on our behalf ("Third Party Services"). These links are provided as a convenience only and do not constitute an affiliation with, endorsement or sponsorship of the Third-Party Services.
Any information you provide to such third parties is not subject to the terms of this Privacy Policy, and we are not responsible for the privacy or security of the information you provide to them or their handling of your information. We recommend that you review the privacy policy of any third party to whom you provide personal information online.
In addition, we are not responsible for the information collection, use, disclosure, or security policies and practices of other organizations, such as Apple, Google, Microsoft, RIM, or any other app developer, app provider, operating system provider, wireless service provider, or device manufacturer. -
We may also obtain data provided by third parties. For example, we may obtain information from companies to improve the accuracy of the information we have about you (e.g., adding your zip code to your address information). This improves our ability to contact you and increases the relevance of our offers and communications to you.
-
We seek to use reasonable physical, technical, and administrative safeguards to protect personal information within our organization. Unfortunately, no data transmission or storage system can be guaranteed to be 100% secure. If you have reason to believe that your interaction with us is no longer secure, please immediately contact us in accordance with the "Contact Information" section below.
-
Like many other websites and online services, we collect information about the Services’ traffic and usage patterns through the use of cookies, web server logs, web beacons and other, similar technologies. We use this information for various purposes, such as to ensure that the Services function properly, to facilitate navigation, to understand use of the Services, to diagnose problems, to measure the success of our marketing campaigns and to otherwise administer the Services.
Cookies are small computer files we transfer to your computer's hard drive. These small text files help us personalize content on our pages. Your browser software can be set to reject or accept cookies. Instructions for resetting the browser are available in the Help section of most browsers.
Our use of cookies also allows us to collect and retain certain information about a website user, such as the type of web browser used by our customer. Reviewing our web server logs and our customers' use of our site helps us to, among other purposes, statistically monitor how many people are using our site and for what purpose.
Your IP address is a number that is automatically assigned to the computer that you are using by your Internet Service Provider. An IP address may be identified and logged automatically in our server log files whenever a user accesses the Services, along with the time of the visit and the page(s) that were visited. Collecting IP addresses is standard practice and is done automatically by many websites, applications and other services. We use IP addresses for purposes such as calculating usage levels of the Services, helping diagnose server problems, and administering the Services. -
We may use third-party advertising companies to display advertisements regarding goods and services that may be of interest to you when you access and use the Services, based on information relating to your access to and use of the Services and other online services. To do so, these companies may place or recognize a unique cookie on your browser (including through the use of pixel tags). You can get more information about this practice* and learn about your choices in connection with it.* We do not respond to browser do-not-track signals.
We may use analytics providers that use cookies, pixel tags and other, similar technologies to collect information about your use of the Services and your use of other websites or online services.
-
Please be aware that there may be fraudulent websites that illegally use the Business’s logos, and other aspects of the Business’s brand. The Business is in no way associated with any fraudulent websites. These sites may circulate their presence on the internet via spam email, or through fraudulent phishing practices.
These sites have not been authorized by the Business to use our name and we work aggressively to identify their source and have them shut down. If you are in receipt of this type of spam email, to help protect your privacy you should avoid replying to it or forwarding it to other people.
In addition to our official websites, the Business works with a number of third parties that host websites and micro-sites that provide information and services to our customers. If you are concerned that a website or an email may be fraudulent, please contact us by contacting Member Service at the phone number on your ID card with your concerns. -
You can change your communication preferences at any time on your profile page or by contacting Member Service at the phone number on your ID card. If you opt out of receiving emails from us, we may still send you important administrative messages, from which you cannot opt out.
You can request the removal or modification of the personal information you have provided to us by contacting Member Service at the phone number on your ID card. For your protection, we may only implement requests with respect to the personal information associated with the particular email address that you use to send us your request, and we may need to verify your identity and obtain information on the context in which you provided your personal information before implementing your request. We will try to accommodate your request as soon as reasonably practicable.
You can stop all further collection of information by the Business’s mobile application by uninstalling the Business’s mobile application. You may use the standard uninstall process available as part of your mobile device or via the mobile application marketplace or network.
Note: If you uninstall the mobile application from your device, the Business’s unique identifier associated with your install and/or device might continue to be stored. If you re-install the application on the same device, the Business might be able to re-associate this identifier to your previous transactions and activities.
Please note that we may need to retain certain information for recordkeeping purposes and/or to complete any transactions that you began prior to requesting such change or deletion. There may also be residual information that will remain within our databases and other records, which will not be removed. -
If you are our customer and a California resident, you may request that we provide you with certain information about the entities with which we have shared our customers' personal information for direct marketing purposes during the preceding calendar year. To do so, please write to us at ConsumerPrivacy@cvshealth.com.
-
By establishing a Services account, you agree that it is your responsibility to:
Authorize, monitor, and control access to and use of your Services account, User ID and password.
Promptly inform us of any need to deactivate a password or an account by contacting Member Service at the phone number on your ID card. -
If you have any questions about the content of this Privacy Policy, please contact the Aetna Privacy Office at the following address: 151 Farmington Avenue, Hartford CT 06156 or by emailing us at PrivacyAetna@Aetna.com.
Last Updated: March 26, 2026
For information about the Notice of Data Privacy Incident from July 01, 2025, visit this link.
Coverage may be underwritten or administered by one or more of the following companies: Aetna Better Health Inc., Aetna Health Inc., Aetna Health of California Inc., Aetna Health of Utah Inc., Aetna Health of Iowa Inc., Aetna Life Insurance Company, Coventry Health Care plans, Aetna Better Health plans, Coventry Health and Life Insurance Company, HealthAssurance Pennsylvania, Inc., Innovation Health plans, and Allina Health and Aetna Insurance Company. Mail order pharmacy services may be provided by Caremark, L.L.C. or one or more of its subsidiaries or affiliates.
Text message alert terms and conditions
Privacy notices for your plan
The Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule affords members the right to receive a notice that describes how health information may be used and disclosed and how to get access to this information. Aetna is required to send a notice ("notice of privacy practices") to members of our insured health and long-term care plans and mail-order pharmacy customers.
Aetna is also required to send a privacy notice ("notice of information practices") to our insured life and disability plan members and to our large case pension payees.
Notice of privacy practices by plan type
|
|
Language |
|---|---|
|
Medical, dental, pharmacy, managed behavioral health and vision plans: Notice of privacy practices |
|
|
Federal risk plans: Notice of privacy practices |
|
|
Aetna Senior Supplemental Health plans: Notice of privacy practices |
|
|
Aetna Student Health plans: Notice of privacy practices |
|
|
Employee assistance plans: Notice of privacy practices |
|
|
Long-term care plans: Notice of privacy practices |
|
|
Aetna voluntary plans: Notice of privacy practices |
|
|
Aetna International (U.S.-based plans): Notice of privacy practices |
|
Document name |
Medical, dental, pharmacy, managed behavioral health and vision plans: Notice of privacy practices |
|---|---|
|
Language |
|
|
Document name |
Federal risk plans: Notice of privacy practices |
|
Language |
|
|
Document name |
Aetna Senior Supplemental Health plans: Notice of privacy practices |
|
Language |
|
|
Document name |
Aetna Student Health plans: Notice of privacy practices |
|
Language |
|
|
Document name |
Employee assistance plans: Notice of privacy practices |
|
Language |
|
|
Document name |
Long-term care plans: Notice of privacy practices |
|
Language |
|
|
Document name |
Aetna voluntary plans: Notice of privacy practices |
|
Language |
|
|
Document name |
|
|
Language |
Notice of information practices by plan type
|
Document name |
Language |
|---|---|
|
Large case pension: Notice of information practices |
|
|
Life and disability: Notice of information practices |
|
|
Life privacy notice for American/ Continental: Notice of information practice |
|
Document name |
Large case pension: Notice of information practices |
|---|---|
|
Language |
|
|
Document name |
Life and disability: Notice of information practices |
|
Language |
|
|
Document name |
Life privacy notice for American/ Continental: Notice of information practice |
|
Language |
Complaints
If you think your HIPAA Privacy Rights have been violated, you can:
- Call us at the toll-free Member Services number on your ID card. Or contact the Aetna Privacy Office at this address:
HIPAA Member Rights Team
Aetna Inc.
P.O. Box 14079
Lexington, KY 40512-4079 - You also may write to the Secretary of the U.S. Department of Health and Human Services.
Legal notices
Aetna is the brand name used for products and services provided by one or more of the Aetna group of companies, including Aetna Life Insurance Company and its affiliates (Aetna).
Health benefits and health insurance plans contain exclusions and limitations.