1. Introduction
Atlas Managed Care ("Atlas," "we," "us," or "our") is a California workers' compensation managed care company. We provide triage, employee advocacy, nurse case management, utilization review, bill review, Medical Provider Network (MPN), and Medicare Set-Aside services to injured workers, employers, claims administrators, and providers.
This Privacy Policy explains how we collect, use, disclose, and protect personal information, including Protected Health Information (PHI) under the Health Insurance Portability and Accountability Act of 1996 (HIPAA), and personal information protected under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA).
We administer utilization review services under a written delegation agreement with Arissa Cost Solutions, a URAC-accredited Workers' Compensation Utilization Management Organization (accreditation date April 27, 2024).
2. Information We Collect
2.1 Protected Health Information (PHI)
In the course of providing managed care services, we collect, receive, and process PHI about injured workers, including: name, date of birth, contact information, claim number, date of injury, employer, diagnosis, treatment history, medications, imaging and lab results, treatment authorization requests, physician records, and return-to-work status.
2.2 Personal Information
For employer clients, claims adjusters, attorneys, providers, and other business contacts, we collect: name, employer/organization, professional role, business email, business phone, business address, and communications you send us.
2.3 Website & Communication Data
When you visit our website or call our offices, we may collect: IP address, browser type, pages visited, referral source, call recordings (with notice and consent where required by law), SMS messages exchanged with our service lines, and email communications.
3. How We Use Information
We use the information we collect for the following purposes:
- Treatment, Payment, and Health Care Operations: to deliver triage, advocacy, case management, utilization review, bill review, and MSA services in accordance with HIPAA 45 CFR § 164.506.
- Communication with Injured Workers: to coordinate care, schedule appointments, deliver utilization review determinations, and provide case status updates by phone, secure email, secure portal, and (with explicit opt-in) SMS text message.
- Compliance with Law: to meet our obligations under California Labor Code § 4610, 8 CCR §§ 9792.6 – 9792.9.5, HIPAA, and other applicable federal and state laws.
- Quality Improvement & Auditing: to monitor service quality, audit reviewer determinations, and maintain URAC and HIPAA compliance.
- Service Improvement: to improve our website, our services, and our communications.
4. How We Share Information
We share information only as necessary to provide our services and as permitted or required by law:
- With your treating providers for purposes of treatment coordination.
- With your employer's claims administrator and workers' compensation insurer for purposes of claim adjudication and payment.
- With Arissa Cost Solutions as the URAC-accredited URO under our written delegation agreement.
- With Atlas business associates (cloud infrastructure, communications, voice/SMS providers) under written Business Associate Agreements (BAAs) as required by HIPAA. Our current business associates include Amazon Web Services (AWS), Twilio, Bland AI, and Cloudflare.
- With government regulators when required by law, including the California Division of Workers' Compensation (DWC), the federal Centers for Medicare & Medicaid Services (CMS), and the U.S. Department of Health and Human Services Office for Civil Rights (HHS OCR).
- Pursuant to legal process such as subpoenas, court orders, or in response to a lawful government investigation.
We do not sell personal information. We do not share personal information with third parties for their own marketing purposes.
5. Security & Safeguards
Atlas implements administrative, physical, and technical safeguards designed to protect personal information against unauthorized access, use, disclosure, alteration, and destruction. Our safeguards include:
- Encryption at rest (AES-256 via AWS Key Management Service) and in transit (TLS 1.2+).
- Multi-factor authentication for all employee access to systems containing PHI.
- Role-based access controls and least-privilege provisioning.
- Continuous logging and monitoring with 7-year immutable audit log retention.
- Annual security risk assessments and penetration testing.
- Workforce HIPAA training at onboarding and annually.
- Signed Business Associate Agreements with every vendor that touches PHI.
- Multi-region disaster recovery with daily encrypted backups.
6. Retention
We retain personal information and PHI for the longer of: (a) seven (7) years from the date of last service, as required by California Labor Code § 4610 and 8 CCR § 9792.6; (b) the period required by HIPAA 45 CFR § 164.316(b)(2)(i) (six years); or (c) any longer period required by applicable law or legal process.
Upon expiration of the retention period, records are securely destroyed using cryptographic erasure (for electronic records) or NAID AAA-certified shredding (for paper records).
7. Your Rights
Under HIPAA, CCPA/CPRA, and other applicable laws, you have the right to:
- Request access to and a copy of the personal information we hold about you.
- Request correction of inaccurate information.
- Request restrictions on certain uses or disclosures.
- Request communication by alternative means or at alternative locations.
- Receive an accounting of certain disclosures.
- File a complaint with us or with the U.S. Department of Health and Human Services Office for Civil Rights.
- Opt out of SMS communications at any time by replying STOP. See our SMS Communication & Consent policy.
- Withdraw consent for non-required communications at any time.
To exercise any of these rights, contact us using the information in Section 10 below.
8. Children's Privacy
Our services are not directed to children under 18, except where a minor is the injured worker covered by a workers' compensation claim. We do not knowingly collect personal information from children for any other purpose.
9. Changes to This Policy
We may update this Privacy Policy from time to time. The most current version will always be posted on this page with an updated "Last Updated" date. Material changes will be communicated to affected individuals where required by law.
10. Contact Us
For questions about this Privacy Policy, to exercise your rights, or to file a complaint, contact us at:
Atlas Managed Care
Attn: Privacy Officer
3400 Cottage Way, Ste. G2 #34605
Sacramento, CA 95825
Phone: 1-877-828-5276
Email: privacy@atlasmanagedcare.com
You may also file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights at www.hhs.gov/ocr.