Web and Mobile Privacy Statement
-
This Privacy Policy describes the types of personal information that Aetna Life Insurance Company and its subsidiaries and affiliated companies (“Business,” “we,” “our,” or “us”) collects from and about you, including through your interactions with us on https://www.aetna.com, on the Aetna Health mobile application, or other locations where this Privacy Policy is posted. We refer to these collectively as the “Services.” By using the Services, you agree to the terms of this Privacy Policy.
To the extent that information collected through the Services is member information protected under the Health Insurance Portability and Accountability Act (HIPAA), please consult the relevant plan’s Notice of Privacy Practices in the Privacy Center and not this Privacy Policy. If you have questions about which policy applies to information you have provided, please do not hesitate to contact us via email at PrivacyAetna@Aetna.com.
We reserve the right to change this Privacy Policy at any time. Any changes will become effective when we post the revised Privacy Policy on the Services. Your use of the Services following these changes means that you accept the revised Privacy Policy. We will provide appropriate notice to you and seek your consent, where required by applicable law, if we change this Privacy Policy in a material way. The “Last Updated” legend at the top of this page indicates when this Privacy Policy was last revised. -
We do not knowingly collect personal information online from any person we know to be under the age of 13 and instruct users under 13 not to send us any information to or through the Services without their parents’ consent.
The Services are designed for users from, and are controlled and operated by us from, the United States. By using the Services, you consent to the transfer of your information to the United States or storage of your information in the United States, which may have different data protection rules than those of your country. -
We want you to understand how personal information you provide to us is collected and used. Personal information means information that identifies you or is associated with you. Categories of personal information we may collect include:
- Contact information, such as name, postal address, email address, and phone number.
- Device and network information, such as IP address, cookies, and other online identifiers.
- Internet activity and interactions, such as the webpages you visit and how you use the Services.
- Non-precise geolocation data, such as the state you live in.
- Preferences and feedback, such as communications you wish to receive or surveys.
- Payment or financial information, such as your EFT (Electronic Funds Transfer) banking information if you initiate a payment transaction with us.
We may collect your personal information from the following sources:
- Directly from you, such as when you provide it to us or to our service providers.
- Automatically through the Services, such as through analytics services and tracking technologies (e.g., cookies).
- From third parties, such as public sources.
If you choose not to provide your personal information to us, we may not be able to provide you with the requested products, services or information.
If you submit any personal information relating to other people in connection with the Services, you represent that you have the authority to do so and to permit us to use the information in accordance with this Privacy Policy.
We may combine the information collected from you through the Services with information we receive from and about you from other online and offline sources and use the combined information in accordance with this Privacy Policy. Our goal is to offer you content, products, and services that are most likely to appeal to you.
We may use your personal information to provide you with the Services and for the following purposes:
- Send you communications and marketing materials, such as when you create an account.
- For our business purposes, such as data analysis, audits, fraud monitoring and prevention, detect and investigate incidents or breaches, developing our Services and new products and services.
- To comply with applicable law and protection of our operations, such as enforcing our terms of use and other terms and conditions and protecting our rights, privacy, safety or property and/or that of our affiliates, you, or others.
- With your consent, if you direct us or our service providers to use or disclose your personal information for specific purposes.
- To personalize and tailor the Services, such as providing you with content, products, and services that are most likely to appeal to you.
We may disclose your personal information to the following categories of recipients:
- Service providers: We may disclose your personal information to service providers that provide business and technical services to us and on our behalf, such as web hosting, payment processing, data analytics, and other services.
- Governmental, regulatory or public authorities: We may disclose your personal information only as permitted or if required to do so by government and law enforcement authorities. In matters involving claims of personal or public safety or in litigation where the information is pertinent (including to allow us to pursue available remedies or limit the damages that we may sustain), we may use or disclose personal information, including without court process. We may also use or disclose personal information to enforce our terms and conditions, to protect our operations or those of any of our affiliates, or to protect our rights, privacy, safety or property and/or that of our affiliates, you, or others.
- Affiliates and business partners: We may disclose your personal information to affiliated companies and partners, to the extent permitted by applicable law, who may use it to send you marketing and other communications.
- Other third parties: We may disclose your personal information to (i) third parties to whom you’ve directed or consented to a disclosure; (ii) relevant third parties (e.g., acquiring entity and its advisers) in the case of a reorganization, merger, sale, joint venture, assignment, transfer or other disposition of our business or assets; or (iii) third parties we’ve deemed necessary or appropriate to comply with applicable law, protect our operations, and protect the rights, safety, or property of you and others.
-
The Services may contain links to, or otherwise make available, third-party websites, services, or other resources not operated by us or on our behalf ("Third Party Services"). These links are provided as a convenience only and do not constitute an affiliation with, endorsement or sponsorship of the Third-Party Services.
Any information you provide to such third parties is not subject to the terms of this Privacy Policy, and we are not responsible for the privacy or security of the information you provide to them or their handling of your information. We recommend that you review the privacy policy of any third party to whom you provide personal information online.
In addition, we are not responsible for the information collection, use, disclosure, or security policies and practices of other organizations, such as Apple, Google, Microsoft, RIM, or any other app developer, app provider, operating system provider, wireless service provider, or device manufacturer. -
We may also obtain data provided by third parties. For example, we may obtain information from companies to improve the accuracy of the information we have about you (e.g., adding your zip code to your address information). This improves our ability to contact you and increases the relevance of our offers and communications to you.
-
We seek to use reasonable physical, technical, and administrative safeguards to protect personal information within our organization. Unfortunately, no data transmission or storage system can be guaranteed to be 100% secure. If you have reason to believe that your interaction with us is no longer secure, please immediately contact us in accordance with the "Contact Information" section below.
-
Like many other websites and online services, we collect information about the Services’ traffic and usage patterns through the use of cookies, web server logs, web beacons and other, similar technologies. We use this information for various purposes, such as to ensure that the Services function properly, to facilitate navigation, to understand use of the Services, to diagnose problems, to measure the success of our marketing campaigns and to otherwise administer the Services.
Cookies are small computer files we transfer to your computer's hard drive. These small text files help us personalize content on our pages. Your browser software can be set to reject or accept cookies. Instructions for resetting the browser are available in the Help section of most browsers.
Our use of cookies also allows us to collect and retain certain information about a website user, such as the type of web browser used by our customer. Reviewing our web server logs and our customers' use of our site helps us to, among other purposes, statistically monitor how many people are using our site and for what purpose.
Your IP address is a number that is automatically assigned to the computer that you are using by your Internet Service Provider. An IP address may be identified and logged automatically in our server log files whenever a user accesses the Services, along with the time of the visit and the page(s) that were visited. Collecting IP addresses is standard practice and is done automatically by many websites, applications and other services. We use IP addresses for purposes such as calculating usage levels of the Services, helping diagnose server problems, and administering the Services. -
We may use third-party advertising companies to display advertisements regarding goods and services that may be of interest to you when you access and use the Services, based on information relating to your access to and use of the Services and other online services. To do so, these companies may place or recognize a unique cookie on your browser (including through the use of pixel tags). You can get more information about this practice* and learn about your choices in connection with it.* We do not respond to browser do-not-track signals.
We may use analytics providers that use cookies, pixel tags and other, similar technologies to collect information about your use of the Services and your use of other websites or online services. -
Please be aware that there may be fraudulent websites that illegally use the Business’s logos, and other aspects of the Business’s brand. The Business is in no way associated with any fraudulent websites. These sites may circulate their presence on the internet via spam email, or through fraudulent phishing practices.
These sites have not been authorized by the Business to use our name and we work aggressively to identify their source and have them shut down. If you are in receipt of this type of spam email, to help protect your privacy you should avoid replying to it or forwarding it to other people.
In addition to our official websites, the Business works with a number of third parties that host websites and micro-sites that provide information and services to our customers. If you are concerned that a website or an email may be fraudulent, please contact us by contacting Member Service at the phone number on your ID card with your concerns. -
You can change your communication preferences at any time on your profile page or by contacting Member Service at the phone number on your ID card. If you opt out of receiving emails from us, we may still send you important administrative messages, from which you cannot opt out.
You can request the removal or modification of the personal information you have provided to us by contacting Member Service at the phone number on your ID card. For your protection, we may only implement requests with respect to the personal information associated with the particular email address that you use to send us your request, and we may need to verify your identity and obtain information on the context in which you provided your personal information before implementing your request. We will try to accommodate your request as soon as reasonably practicable.
You can stop all further collection of information by the Business’s mobile application by uninstalling the Business’s mobile application. You may use the standard uninstall process available as part of your mobile device or via the mobile application marketplace or network.
Note: If you uninstall the mobile application from your device, the Business’s unique identifier associated with your install and/or device might continue to be stored. If you re-install the application on the same device, the Business might be able to re-associate this identifier to your previous transactions and activities.
Please note that we may need to retain certain information for recordkeeping purposes and/or to complete any transactions that you began prior to requesting such change or deletion. There may also be residual information that will remain within our databases and other records, which will not be removed.
-
If you are our customer and a California resident, you may request that we provide you with certain information about the entities with which we have shared our customers' personal information for direct marketing purposes during the preceding calendar year. To do so, please write to us at ConsumerPrivacy@cvshealth.com.
-
By establishing a Services account, you agree that it is your responsibility to:
Authorize, monitor, and control access to and use of your Services account, User ID and password.
Promptly inform us of any need to deactivate a password or an account by contacting Member Service at the phone number on your ID card. -
If you have any questions about the content of this Privacy Policy, please contact the Aetna Privacy Office at the following address: 151 Farmington Avenue, Hartford CT 06156 or by emailing us at PrivacyAetna@Aetna.com.
Last Updated: March 26, 2026
For information about the Notice of Data Privacy Incident from July 01, 2025, visit this link.
Coverage may be underwritten or administered by one or more of the following companies: Aetna Better Health Inc., Aetna Health Inc., Aetna Health of California Inc., Aetna Health of Utah Inc., Aetna Health of Iowa Inc., Aetna Life Insurance Company, Coventry Health Care plans, Aetna Better Health plans, Coventry Health and Life Insurance Company, HealthAssurance Pennsylvania, Inc., Innovation Health plans, and Allina Health and Aetna Insurance Company. Mail order pharmacy services may be provided by Caremark, L.L.C. or one or more of its subsidiaries or affiliates.
Notice of Privacy Practices
How we may use and disclose personal health and financial information when administering a plan of benefits. The Notice of Privacy Practices also explains the legal rights individuals have under the Health Insurance Portability and Accountability Act (HIPAA).
- Aetna Medicare notice of privacy practices – English (PDF)
- Aetna Medicare notice of privacy practices – Español (PDF)
- Aetna Medicare notice of privacy practices – Chinese (PDF)
- Aetna SilverScript Medicare notice of privacy practices – English (PDF)
- Aetna SilverScript Medicare notice of privacy practices – Español (PDF)
- SilverScript Medicare notice of privacy practices – English (PDF)
- SilverScript Medicare notice of privacy practices – Español (PDF)
Security highlights
Aetna takes information security seriously and we diligently safeguard your personal information. Here are some ways Aetna protects your information and steps you can take to help.
-
A list of steps we take to secure your health information
-
Because we’re committed to protecting the privacy of our members, we’re moving away from the use of Social Security numbers whenever possible. Thieves often steal Social Security numbers when they hack websites and computers. A Social Security number is not required for health care services.
Here's how you can help
If you're a health care professional working with us:
- Collect the patient's member ID number, rather than a Social Security number.
- For your own transactions, use your Employer Identification Number (EIN), rather than a Social Security number.
If you're an Aetna member:
- Give your member ID number -- not your Social Security number -- when you go to the doctor, dentist or hospital.
If you're an employer working with us:
- Work with your Aetna Contact or Account Rep to reduce the transmission of SSNs.
-
Protecting the privacy and security of sensitive information is one of our highest priorities. Accordingly, Aetna encrypts all Internet e-mails that contain member-specific health and financial information -- examples include, but aren't limited to, personal and demographic information (e.g., name, SSN, address), employment information, information about payment of benefits, provider information, diagnostic or treatment information, claims status information and information related to behavioral health and/or sexually transmitted disease services.
Use of encrypted e-mail enables us to send quick, reliable communications while maintaining our commitment to protecting the confidentiality of member-specific information.
What is encrypted e-mail?
Encrypted e-mail is scrambled by the sender's e-mail program, which renders it unreadable until it is descrambled or "decrypted" by the recipient. Unencrypted e-mail is similar to a postcard - the message can be viewed by anyone who picks it up. Encrypted e-mail is similar to a sealed letter -- the content cannot be viewed until the envelope is opened - except, in this case, the envelope has a lock on it to which only the recipient has a key.
How does Aetna's use of encrypted e-mail impact recipients?
- Whenever Aetna transmits member-specific health or financial information via Internet e-mail, the e-mail includes a message indicating that the content has been secured via encryption.
- Encrypted e-mails from Aetna include instructions on how to decrypt the message for viewing - this requires the recipient to perform a few simple clicks.
- Anyone who receives an encrypted e-mail from Aetna is able to send an encrypted reply.
- Third party messages that are sent to Aetna via the "Contact Us" feature on Aetna.com are also encrypted.
Who can receive member-specific health and financial information?
Aetna has strict procedures in place for determining if a third party can receive member health and financial information i.e., Aetna employees are required to verify whether a requestor is authorized to receive the information before it is released.
Whom can the recipient of an Aetna encrypted e-mail call with questions?
Each encrypted e-mail from Aetna includes instructions on how to open the message and view the secure content. In the event a recipient receives an error message while in the process of trying to open an Aetna-generated encrypted e-mail, the error message provides guidance for troubleshooting the problem. In addition, the error message includes the following contact information:If you experience any problems, please contact 1-800-237-7476 ${tty}, option 4 (Secure Email) during normal business hours; 8AM to 6PM ET.
-
Medical identity theft happens when someone steals your personal or health insurance information. They use it to get medical care, prescriptions, insurance payouts, even surgery. It’s a lot like regular identify theft. It can damage your credit rating. Cost you money and take time to clear up. Even hurt your chances to get some jobs. And it's happening more and more in the United States.
Here are a few steps to protect yourself
Be careful with your member ID card
It could be used to get medical services or drugs. And these will be on your medical record permanently. If your card is missing, lost or stolen, notify Aetna Member Services right away.
Keep personal information personal
Don’t give out your insurance ID, Social Security or driver’s license numbers on the phone or by mail to just anyone. Make sure you initiated the contact. And make sure there is a valid reason for giving out the number.
Be on guard even if someone claims to be from Aetna
We avoid asking for your Social Security number. However, there are times we need it. For example, if you:
- Sent us a form that requested your Social Security number but you didn’t provide it or it is not readable, we might call you to ask for it.
- Left a voice mail for someone at Aetna that did not include enough information to identify you, we might ask for additional information when returning your call.
Review health care information
Take time to read mailed Explanation of Benefits (EOB) statements or online claims. Even if they are marked, “This is not a bill." Look for:- Wrong group or identification numbers
- Unfamiliar provider offices or hospitals
- Dates for services on which you did not receive care
- Prescriptions you did not fill
Make sure “free” is free
If you visit a free clinic, make sure it’s free. Don’t show your ID card for any reason.
Check your credit report
Identity thieves can run up medical costs in your name. The bills can be mailed to another address. You won’t know unless you check your report. Or you get a call from a collection agency.Find out how you can get a credit report for free. Visit the Federal Trade Commission website.
For information about the Notice of Data Privacy Incident from July 01, 2025, visit this link.
Privacy and security educational resources
-
Certain Aetna1 members have the right to direct Aetna to disclose their claims data, encounter data, and clinical data (collectively “health data”) held by Aetna or certain of its government program health plan subsidiaries and affiliates to a designated third-party application (app) through certain standardized technology.2
Aetna is also required by law to provide these educational resources, which you may use when making decisions about who you choose to share your health data with.Currently, only Medicare Advantage plan members may direct Aetna are able to give consent to share their health data with third party apps via Aetna's Patient Access API. Patient Access API functionality for certain other Aetna members will be available in the first half of 2021.
-
- It is important for you to take an active role in protecting your own health data.
- If you direct Aetna to share your health data with a third-party app, Aetna has no control over how the third-party app will use or share your health data. Aetna does not review or evaluate third-party apps or their privacy or security practices for your health data.
- Some third-party apps may share your health data with other third parties.
- Health data can be very sensitive, and you should be careful to choose apps with strong privacy and security standards to protect it.
- Any app you choose to receive your health data should have an easy-to-read privacy policy that clearly explains how the app will use your data. If an app does not have a privacy policy, you should consider not using the app.
- Before you direct Aetna to share your health data with an app, you should read carefully the app’s terms of use (sometimes this information is contained in the app’s “end user license agreement”) and privacy policy to understand how the app will use and share your health data.
- Below are factors to consider when selecting an app to receive your health data. If an app’s privacy policy does not clearly answer these questions, you should reconsider allowing the app to access your health data.
-
- What health data will this app collect?
- Will this app collect non-health data from my device, such as my location?
- Will my data be stored in a de-identified or anonymized form?
- How will this app use my data?
- Will this app disclose my data to third parties?
- Will this app sell my data for any reason, such as advertising or research?
- Will this app share my data for any reason? If so, with whom? For what purpose?
- How can I limit this app’s use and disclosure of my data?
- What security measures does this app use to protect my data?
- What impact could sharing my data with this app have on others, such as my family members?
- How can I access my data and correct inaccuracies in data retrieved by this app?
- Does this app have a process for collecting and responding to user complaints?
- If I no longer want to use this app, or if I no longer want this app to have access to my health information, how do I terminate the app’s access to my data?
- What is the app’s policy for deleting my data once I terminate access? Do I have to do more than just delete the app from my device?
- How does this app inform users of changes that could affect its privacy practices?
-
- The Health Insurance Portability and Accountability Act (HIPAA) is a federal law. One part of it helps protect personal health information. The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) enforces the HIPAA Privacy, Security, and Breach Notification Rules, and the Patient Safety Act and Rule.
- You can find HIPAA FAQs for individuals from HHS here: https://www.hhs.gov/hipaa/for-individuals/faq/index.html.
-
- Organizations and individuals who must follow HIPAA regulations are called “covered entities,” which can include:
- Health plans, like health insurance companies, health maintenance organizations (HMOs), company health plans, and certain government programs that pay for health care, like Medicare and Medicaid
- Many health care providers—those that conduct certain business electronically, such as electronically billing your health insurance—including most doctors, health clinics, hospitals, psychologists, chiropractors, nursing homes, pharmacies, and dentists
- Health care clearinghouses
- Additionally, “business associates” who provide certain services for covered entities must follow parts of the HIPAA regulations. Examples of business associates include billing companies, health care claims processors, companies that store or destroy medical records, and those that help administer health plans.
- Many organizations that have health information about you do not need to follow HIPAA rules. Examples of these organizations may include life insurers, employers, workers compensation carriers, many schools and school districts, many state agencies, many law enforcement agencies, and many municipal offices.
- You can find more information from HHS about patient rights under HIPAA and who is obligated to follow HIPAA here: https://www.hhs.gov/hipaa/for-individuals/guidance-materials-for-consumers/index.html.
- Organizations and individuals who must follow HIPAA regulations are called “covered entities,” which can include:
-
- Most third-party apps will not be covered by HIPAA. Most third-party apps will instead fall under the jurisdiction of the Federal Trade Commission (FTC) and the protections provided by the FTC Act.
- The FTC Act, among other things, protects against deceptive acts, for example, when an app shares personal data without a user’s permission, despite having a privacy policy that says it will not do so.
- The FTC provides information about mobile app privacy and security for consumers here: https://www.consumer.ftc.gov/articles/0018-understanding-mobile-apps.
-
- If you think your HIPAA Privacy Rights have been violated, you can contact us using the toll-free Member Services number on your health plan ID card or you may contact the Aetna Privacy Office directly at the address below:
HIPAA Member Rights Team
Aetna Inc.
P.O. Box 14079
Lexington, KY 40512-4079
- You may also write the Secretary of the U.S. Department of Health and Human Services.
- To learn more about filing a complaint with HHS OCR under HIPAA, visit: https://www.hhs.gov/hipaa/filing-a-complaint/index.html.
- Individuals can file a complaint with HHS OCR using the OCR complaint portal: https://ocrportal.hhs.gov/ocr/smartscreen/main.jsf.
- If you think your HIPAA Privacy Rights have been violated, you can contact us using the toll-free Member Services number on your health plan ID card or you may contact the Aetna Privacy Office directly at the address below:
-
- Individuals can file a complaint with the FTC using the FTC complaint assistant: https://reportfraud.ftc.gov/#/.
1 “Aetna” and the pronouns “we,” “us,” or “our” may refer to one or more of the Aetna group of subsidiary companies and their affiliates.
2 See The Centers for Medicare & Medicaid Services (“CMS”) Interoperability and Patient Access Final Rule (CMS-9115-F).
Need help with Aetna Medicare enrollment?
Call a licensed Aetna agent at ${dynamicPhone} ${tty}, ${hours}.
Aetna Member Services
Get help from Member Services. Find contact info for your plan and other resources.