Show Menu
My HealtheVet, Your Personal Health JournalImage for display purposes only
Help
[skip navigation]
Move to contents Health Ed Library | My HealtheVet | Feedback | Search | Facilities Locator | FAQs

Privacy and Security

Introduction

We know that privacy and security of information matters to you. We respect your privacy and have taken measures to provide appropriate levels of security to protect your personal information. We will never release your name, street address, telephone number, e-mail address or any other personal information to others. We deploy computer security technology to protect any information you provide to us. We may at times distribute aggregate (anonymous, collected statistical data) information about our users within the Department of Veterans Affairs for quality assurance and management.

Privacy

The privacy of our customers has always been of utmost importance to the Department of Veterans Affairs (VA). The VA has a long history of protecting your privacy and our concern for your privacy is no different in the electronic age. The VA realizes that the information provided is sensitive, and that many people have concerns about submitting this kind of information over the Internet. Therefore, the VA is making every effort to ensure the confidentiality and privacy of your information by using the current best security practices.

    Our Internet privacy policy is:
  • You do not have to give us personal information to visit our site.
  • We will collect personally identifiable information (name, email address, Social Security number, or other unique identifier) only if specifically and knowingly provided by you.
  • Personally identifying information you provide will be used only in connection with VA programs and services or for such other purposes as are described at the point of collection.
  • Information is collected for statistical purposes and VA sometimes performs analyses of user behavior in order to measure customer interest in the various areas of our site.
  • We do not give, sell or transfer any personal information to a third party.
  • We use temporary session "cookies". A "cookie" is a file placed on your personal computer's hard drive by a Web site that allows it to monitor your use of the site. These temporary session cookies does not contain any personal information, but provides the ability for the My HealtheVet system to know who you are as you move from page to page without forcing you to reenter your information. As soon as you log off the My HealtheVet system or close the browser window, the temporary session cookie is erased. It is also erased whenever the connection is lost for any reason.
  • The system that stores your data is protected by firewalls to prevent access to the system in unauthorized ways.
  • Your personal private medical information is not understandable as it is stored on our systems. The data is individually encrypted so that only you or those you designate can read the data. This is your private data and we have designed the system so only you and those you have designated can access that data.
  • From your computer to the VA, the information will be protected using Secure Sockets Layer (SSL) encryption. This is automatically handled by most browsers, and is widely accepted as appropriate protection for the transmission of information on the Internet. While on a secure page, such as a data entry form, the lock icon on the bottom of Web browsers such as Netscape Navigator and Microsoft Internet Explorer becomes locked, as opposed to un-locked, or open, when you are just 'surfing'
  • Our web servers are protected by firewalls, and several layers of protection are placed between your data and the Internet. Our firewalls and servers are regularly updated and monitored to further protect the systems from inappropriate access.

The Privacy Act of 1974 applies to all Federal agencies. For information on the Federal government's Web Site Privacy Policy, see the following documents:

Family Members and Privacy

Some states have restrictions on disclosure of health information to family members to protect the privacy of certain minors and dependent adult family members. These restrictions on disclosure of information may include accessing personal health and medical information through electronic or Internet based services. If you have questions regarding this matter, we recommend that you contact your local VA Medical Center for more information about disclosure of health information and applicable privacy laws within the state or jurisdiction where you receive care.

Privacy and Linked Web Sites

This web site contains links to other sites. Please be aware that the Department of Veterans Affair is not responsible for the privacy practices of such other sites. We encourage our users to be aware when they leave our site that they should read the privacy statements of each and every web site that collects personally identifiable information. This privacy statement applies solely to information collected by this Web site.

Privacy Act Warning

Information contained in this system is subject to the Privacy Act of 1974 (Title 5 U.S.C. 552a, as amended). Only authorized persons may use personal information contained in this system. Any unauthorized disclosure or misuse of personal information may result in criminal and/or civil penalties. Any individual may be found guilty of a misdemeanor and fined not more than $5,000.00 if he or she willfully discloses personal information to anyone not entitled to receive information. Any individual may file a civil action against a Department of Veterans Affair component or its employees if the aggrieved individual feels that certain provisions of the Privacy Act have been violated. An aggrieved individual may obtain the payment of damage, court costs, and attorney fees in some cases.

My HealtheVet is a web site of the Department of Veterans Affair. The Office of the Under Secretary for Health and the Veterans Health Administration Management provides it as a public service. An individual's private data may only be distributed or copied by the individual or their grantee. Public information presented on this site may be distributed or copied unless otherwise indicated. Use of appropriate byline/photo/image credits is requested.

For site management, information is collected for statistical purposes. This government computer system uses software programs to create summary statistics, which are used for such purposes as assessing what information is of most and least interest, determining technical design specifications, and identifying system performance or problem areas. For site security purposes and to ensure that this service remains available to all users, this government computer system employs software programs to monitor network traffic to identify unauthorized attempts to upload or change information, or otherwise cause damage. Except for authorized law enforcement investigations, no other attempts are made to identify individual users or their usage habits. Raw data logs are used for no other purposes and are scheduled for regular destruction in accordance with National Archives and Records Administration General Schedule 20. Unauthorized attempts to upload information or change information on this service are strictly prohibited and may be punishable under the Computer Fraud and Abuse Act of 1986 (Pub. L. 99-474, Oct. 16, 1986, 100 Stat. 1213).

My HealtheVet is a Department of Veterans Affairs (VA) computer system. This computer system, including all related equipment, networks, and network devices (specifically including Internet access) are provided only for authorized U.S. government use. VA computer systems may be monitored for all lawful purposes, including ensuring that their use is authorized, for management of the system, to facilitate protection against unauthorized access, and to verify security procedures, survivability, and operational security. Monitoring includes active attacks by authorized VA entities to test or verify the security of this system. During monitoring, information may be examined, recorded, copied and used for authorized purposes. Under certain unusual circumstances, authorized VA personnel may monitor or copy information, placed or sent over this system. An example of an unusual circumstance would be complying with a court order.

Use of this VA computer system, authorized or unauthorized, constitutes consent to monitoring of this system. Unauthorized use may subject you to criminal prosecution. Evidence of unauthorized use collected during monitoring may be used for administrative, criminal, or civil action.

Security of Information

At all times, security maintenance and administration is an essential element of web site operation and maintenance. My HealtheVet employs several levels of security to protect the personal identifiable information of registered users. In addition, these security levels are anticipated to be in compliance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA) (Pub. L.104-191, Aug 21, 1996,110 Stat. 1936).

Registration and Login

You are always welcome to use My HealtheVet without registering or logging in. However, we require you to register and login for certain services, like entering data and obtaining copies of key portions of your VA medical record. To obtain a registered account, you only need to visit a medical center where your identity will be checked and your account will be created for you. This process assures that your medical data is never sent anywhere unless you have specifically requested this service. It also assures that your data is only sent to your My HealtheVet account.

Password Protection

When you register for a My HealtheVet account, access to your personal pages will be password protected. Choose your password that is easy for you to remember. The password must be at least eight (8) characters long, start with letter, include at least three of the four classes of characters and cannot use a form of the account name. The four classes of characters include upper case letters, lower case letters, numbers and certain special characters (like “!”, “#” or “~”). We strongly recommend that you do not divulge your password to anyone. My HealtheVet personnel will never ask for your password in an unsolicited phone call or unsolicited e-mail. For your protection, if you forget your password, you will need to visit your local VA Medical Center, with proper identification, to request password reset on your account.

Logging Out

You should remember to log out and close your browser when you are finished accessing password protected My HealtheVet services. This prevents someone else from accessing your personal information if you leave, share, or use a public computer (i.e., like a library, kiosk, or Internet café) . To protect your information completely it is recommended that you close your browser after your session.

Exit Site Notice

My HealtheVet has links to many other federal agencies. In a few cases we link to private organizations, with their permission. Once you link to another site, you are subject to the privacy and security policy of the new site. When My HealtheVet links to external Internet sites, it does so by opening a new window (or browser) on your screen. Any information in these secondary windows (browsers) should be considered external to the My HealtheVet website, and My HealtheVet and the VA are not responsible for its content.

Saving of Passwords by Browser

Many Internet Browsers (such as Internet Explorer and Netscape Navigator) allow users to save user Ids and passwords. Because My HealtheVet may contain sensitive medical information, the practice of saving User Ids and passwords in a browsers' memory is prohibited, as it could potentially allow persons who gain access to a workstation where the user had saved their password to access the users' medical information.

Surveys, Questionnaires, and Polls

To improve the quality of our service, My HealtheVet may use surveys, questionnaires and polls to facilitate feedback and input from our end users. You are not required to respond to these. When you choose to respond to surveys, questionnaires or polls related to our site, we might, at times, ask you for demographic information such as your age or gender. This information is collected only as anonymous, aggregated information and is used for statistical purposes. Otherwise, we do not collect or store your personal responses.

Changes to This Policy

This privacy and security policy may be revised periodically. When we make a significant change that affects our collection and use of your personal information or our security and privacy policy, we will post a notice on the My HealtheVet home page for thirty (30) days. The most recent changes to the security and or privacy policy will be highlighted in a different color within the policy. We recommend that you read the policy whenever you visit the My HealtheVet site in case you missed our notice or have not previously registered for a My HealtheVet service or feature.

My HealtheVet will be partnering with select third parties to provide you with quality health information and services. We recommend that you read the privacy and security policies of these third party partners before using their tools and services.

General Disclaimer

Medical Disclaimer

My HealtheVet User Agreement

Top

Health Ed Library | My HealtheVet Pilot | Feedback | Search | Facilities Locator | FAQs | Log Off
General Disclaimer | Medical Disclaimer & Agreement | Privacy & Security Statement
VA Home Page | Site Map | Contact the VA | Current Benefits | Accessibility Notice | Freedom of Information Act

Contact Us or refer to the User Guide for assistance.

Reviewed/Updated: August 2, 2001