Skip to Main Content
BCBSAL Mobile Logo - Go to home page
Search

Sales Enhanced Search Bar Portlet

Search

Quick Links

claims

Shop Health

Home

Menu Display

  • Health
  • Dental
  • FEP Dental
  • Vision
  • Travel
  • Life
  • Change My Plan
  • Find a Doctor
  • Home
  • Individual
  • Medicare
  • Group
  • Provider
Contact Us

Menu Display

  • Home
  • Individual
  • Medicare
  • Employer
  • Provider
Text Size: A A A

Individuals

Log in to myBlueCross
New to myBlueCross? Register

Show/Hide
Forgot username or password?
Log in to myBlueCross
New to myBlueCross? Register

Show/Hide
Forgot username or password?

Menu Display

  • Health
  • Dental
  • FEP Dental
  • Vision
  • Travel
  • Life
  • Change My Plan
  • Find a Doctor
About Us
Contact Us

Sales Enhanced Search Bar Portlet

Search

Quick Links

claims

Shop Health

Accessing My Information - Individuals

Breadcrumb

  1. Individuals
  2. Transparency in Coverage
  3. Accessing My Information

Accessing My Information

Blue Cross and Blue Shield of Alabama Patient Access API

Blue Cross and Blue Shield of Alabama (BCBSAL) is required to provide you with access to detailed information about your health history through a “Patient Access Application Programming Interface (API).” The Patient Access API allows you to easily access your protected health information (PHI) such as claims information, including cost, and a defined sub-set of your clinical information through third-party applications (apps) of your choice. Third-party apps can be downloaded on a smart phone, tablet, computer or other similar devices.

*The information we will disclose may include information about treatment for Substance Use Disorders, mental health treatment, HIV status, or other sensitive information.

It is important for you to understand that the third-party app you choose to download will have access to all of your information. The third-party app is not subject to Health Insurance Portability and Accountability Act (HIPAA) rules and other privacy laws, which generally protect your health information. Instead, the app’s privacy policy describes limitations on how the app will use, disclose, and (possibly) sell information about you.

If you decide to access your information through the Patient Access API, you should look for an easy-to-read third-party app privacy policy that clearly explains how the app will use your data. Things you may wish to consider when selecting a third-party app:

  • What health data will this app collect? Will this app collect non-health data from my device, such as my location?
  • Will my data be stored in a de-identified or anonymized form?
  • How will this app use my data?
  • Will this app disclose my data to third parties?
    • Will this app sell my data for any reason, such as advertising or research?
    • Will this app share my data for any reason? If so, with whom? For what purpose?
  • How can I limit this app’s use and disclosure of my data?
  • What security measures does this app use to protect my data?
  • What impact could sharing my data with this app have on others, such as my family members?
  • How can I access my data and correct inaccuracies in data retrieved by this app?
  • Does this app have a process for collecting and responding to user complaints?
  • If I no longer want to use this app, or if I no longer want this app to have access to my health information, how do I terminate the app’s access to my data?
    • What is the app’s policy for deleting my data once I terminate access?
    • Do I have to do more than just delete the app from my device?
  • How will this app inform me of changes in its privacy practices?

If the app’s privacy policy does not satisfactorily answer these questions, you may wish to reconsider allowing the app to access your health information. Your health information may include very sensitive information. You should be careful by choosing an app with strong privacy and security standards to protect it.

Covered Entities and HIPAA Enforcement


The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) enforces the HIPAA Privacy, Security, and Breach Notification Rules, and the Patient Safety Act and Rule. You can find more information about patient rights under HIPAA and who is obligated to follow HIPAA here. Another helpful document is the HIPAA FAQs for Individuals.

What should I do if I think my data has been breached or an app has used my data inappropriately?

You may submit a complaint directly to the Office for Civil Rights (OCR) or the Federal Trade Commission (FTC), as appropriate.

  • To file a complaint with OCR under HIPAA, visit https://www.hhs.gov/hipaa/filing-a-complaint/index.html
  • Individuals can file a complaint online with OCR using the OCR complaint portal at https://ocrportal.hhs.gov/ocr/smartscreen/main.jsf
  • Individuals can file a complaint with the FTC using the FTC complaint assistant at https://reportfraud.ftc.gov

Apps and Privacy Enforcement


Most third-party apps will not be covered by HIPAA. Most third-party apps will instead fall under the jurisdiction of the Federal Trade Commission (FTC) and the protections provided by the FTC Act. The FTC Act, among other things, protects against deceptive acts (e.g., if an app shares personal data without permission, despite having a privacy policy that says it will not do so). The FTC provides information about mobile app privacy and security for consumers here.

Last Updated: 07/08/2025 19:04

Menu Display

Facebook Twitter Linkedin YouTube PInterest Instagram

Menu Display

Navigation

Company
  • About Us
  • Contact Us
  • Careers
Support
  • Help
  • Accessibility Information
  • Information in Other Languages
  • Rate Change Justification
Compliance
  • HIPAA Privacy Notice
  • Notice of Nondiscrimination
  • Transparency in Coverage
  • Surprise Billing
  • Accessing My Information
  • Claims Payment Policy & Other Information
Legal
  • Fraud & Abuse
  • Privacy Statement
  • Legal Disclaimer
  • Terms of Service

© 2025, BlueCross BlueShield of Alabama is an independent licensee of the BlueCross BlueShield Association.

Third Party Website Disclaimer

You are about to leave Blue Cross and Blue Shield of Alabama's website and enter a website operated by HealthEquity. HealthEquity is our business associate and is an independent company that provides account-based plan services to Blue Cross. HealthEquity has agreed to follow Blue Cross' privacy and security policies regarding the confidentiality and protection of your personal health information.

To continue to the HealthEquity website, click "Accept." If you want to stay on Blue Cross' website, click "Cancel."

Third Party Website Disclaimer

As an Alfa representative, I agree to the payment terms and conditions of Blue Cross and Blue Shield of Alabama and will not collect any checking account, debit card or credit card information on behalf of the consumer for the purchase of health or dental insurance.

To continue , please click "Accept."

Arbitration Terms

As a CHA representative, I agree to the payment terms and conditions of Blue Cross and Blue Shield of Alabama and will not collect any checking account, debit card or credit card information on behalf of the consumer for the purchase of health or dental insurance.

To continue , please click "Accept."

Third Party Website Disclaimer

As an Alabama Health Guidance representative, I agree to the payment terms and conditions of Blue Cross and Blue Shield of Alabama and will not collect any checking account, debit card or credit card information on behalf of the consumer for the purchase of health or dental insurance.

To continue , please click "Accept."

Third Party Website Disclaimer

This link takes you to another website. Some areas of our site may provide links to other external sites that we don't own, control or influence. We reference sites that we think might be useful or of interest to you, but we are not responsible for the content or privacy practices used by other site owners. Information contained in the external sites is not endorsed by BCBSAL.

To continue to this website, click "Accept." If you want to stay on the Blue Cross website, click "Cancel."

Third Party Website Disclaimer

This link takes you to another website. Some areas of our site may provide links to other external sites that we don't own, control or influence. We reference sites that we think might be useful or of interest to you, but we are not responsible for the content or privacy practices used by other site owners. Information contained in the external sites is not endorsed by BCBSAL.

To continue to this website, click "Accept." If you want to stay on the Blue Cross website, click "Cancel."

Third Party Website Disclaimer

This link takes you to another website. Some areas of our site may provide links to other external sites that we don't own, control or influence. We reference sites that we think might be useful or of interest to you, but we are not responsible for the content or privacy practices used by other site owners. Information contained in the external sites is not endorsed by BCBSAL.

To continue to this website, click "Accept." If you want to stay on the Blue Cross website, click "Cancel."

Short Term Application Disclaimer

Thank you for your interest in our Short Term Plan. By clicking "Next", you are acknowledging that you would like to submit your application and continue onto the payment page otherwise, click "Cancel".

Short Term Application Disclaimer

Thank you for your interest in our Short Term Plan. By clicking "Next", you are acknowledging that you would like to submit your application otherwise, click "Cancel".