How to write your privacy policy
To get production access to the Blue Button API, your organization must have a publicly available privacy policy. This document needs to be easy for Medicare enrollees to find and understand; they are your users, and they need to trust that you protect their data.
Your privacy policy must clearly explain to Medicare enrollees how your app uses, stores, and potentially shares their healthcare data. When you apply for production access, confirm that your privacy policy meets all requirements in the Blue Button API Terms of Service. Read the Blue Button API Terms of Service carefully and check your privacy policy against them before submitting.
Privacy policy checklist
Use this checklist to make sure your privacy policy is complete and ready for review.
Your privacy policy should:
- Be easy to read (plain-language), especially from a Medicare enrollee’s perspective
- We encourage you to ensure that your policy is written at no higher than a 9th-grade level.
- You can use a free editor, such as the Hemingway App, to verify its readability.
- Be based on industry best practices
- Be prominent and publicly accessible
- Require users to actively opt in: do not default to agreement on their behalf
- Have working links that go to the correct destination
- Have no grammatical or spelling issues
Your privacy policy should clearly address:
Data collection and sharing
- Whether and how data is shared
- What data is shared, and with whom
- Whether data is shared with third parties on a one-time basis or collected persistently
- If data is persistently collected, the time frame over which it is collected
De-identified data
- Any use or sharing of de-identified, anonymized, or pseudonymized data
- Note: Even anonymized data can sometimes be used to identify people with specific medical conditions or personal attributes
- Risks of re-identification, if applicable
Data lifecycle
- What happens to a user’s data if they revoke access: do you delete it or keep it?
- Your policy for dormant or closed accounts
- Data retention periods
AI tools, if applicable
If your app uses AI, refer to our AI Guidelines page for guidance on what to include.
Notifications
- How you notify users of a security breach, per the FTC’s Health Breach Notification Rule
- What steps can users take to protect themselves?
- How you notify users if the company is sold and what happens to their data in that situation
- How you notify users of privacy policy changes (with the ability to update settings or opt out)
Third-party vendors
- Whether your vendors
- Commit to data protection requirements consistent with applicable law.
- Understand the sensitivity of the data they receive or collect on your behalf
Changes to your privacy policy
Before rolling out any updates:
- Send draft versions of the updated document and a draft notification to enrollees to: BlueButtonAPI@cms.hhs.gov
- The Blue Button API team will review and respond with feedback or approval within five business days
- Do not publish the updated documents or notify enrollees until you receive CMS approval
Privacy Notice (Optional but Recommended)
In addition to your privacy policy, consider creating a separate, publicly hosted privacy notice. A privacy notice is a plain-language summary of your privacy policy terms.
We recommend using the Office of the National Coordinator for Health Information Technology (ONC) Model Privacy Notice (MPN) template as a starting point.