Privacy Policy

Updated on April 19, 2024

Welcome to the Mayo Clinic website, mobile app, and related sites and digital and online services (“Mayo Clinic Site,” the “Site,” or “Sites”), an online e-commerce, information, and communications service provided by Mayo Clinic and all affiliates (“Mayo Clinic” or “We” or “Us”).

We take your privacy seriously, and we want you to know how we collect, use, share, and protect your information. In addition to this privacy policy (“Privacy Policy”), users of the Mayo Clinic Site should consult the Mayo Clinic Site Terms of Use as well as any product-specific terms and conditions that apply. You may review policies specifically related to patient information (protected health information or PHI) submitted through Mayo Clinic's Patient Portal.

This Privacy Policy applies to all Sites where it is posted. Other Mayo Clinic online properties may have their own privacy policies that apply to those sites. You should review those privacy policies in connection with your use of those sites.

What information we collect

Information you give us

We respect the right to privacy of all visitors to the Mayo Clinic Sites. We receive and store some information that you enter on our Sites or that you provide to us through the Sites in any other way.

The information we collect or that you provide includes:

  • Personal Data: Data that may personally identify you such as name, address, email, phone numbers, date of birth, SSN, insurance info, payment details, medical data, biometric data, genetic information, etc.
  • Information provided via forms on our Sites (appointments, orders, registrations, problem reports).
  • Records and copies of correspondence (including email).
  • Survey responses.
  • Transaction details and related financial information.

You also may provide information to be published or displayed on public areas of the Sites (“User Contributions”). These are posted and transmitted at your own risk.

Information we collect automatically

We collect information automatically as you navigate our Sites, such as usage details, IP addresses, device info, geolocation (for check-in), and data from cookies, web beacons, and pixels.

  • Usage Details: Visits, traffic, logs, errors, clickstream data, etc.
  • Device Information: Device type, OS, browser, app version, IP address.
  • Location Data: Limited use for mobile app appointment check-in (can be disabled).

We use this information to improve our Sites, personalize services, store preferences, and authenticate returning users.

Technologies we use

  • Cookies: Small data files stored on your device. May be refused via settings.
  • Pixels and Web Beacons: Used to track interactions, verify system integrity (e.g., via Tealium).
  • Google Analytics: For usage analysis and advertising features. See Google’s policy.
  • Do Not Track: Currently not honored.

Email communications, newsletter, and related services

You may subscribe to newsletters or contact Mayo via email. Emails may be shared with staff for responses but are not encrypted.

Surveys

Occasional surveys are conducted. Data is aggregated and shared in de-identified form unless contact info is voluntarily provided.

How we use the information we collect

  • Optimizing performance and user experience
  • Operating and improving our business
  • Providing healthcare services
  • Order fulfillment and returns
  • Marketing and advertising
  • Email newsletters
  • Research and analysis
  • Communications about account, events, surveys
  • Account management

Texting

By signing up, you consent to receive unencrypted text messages related to your relationship with Mayo Clinic. You can opt out by texting STOP. Help is available via HELP keyword, phone, or privacyoffice@mayo.edu.

Data retention

We retain your data while your account is active or as legally required. Some medical or legal data must be retained regardless of requests for deletion.

Disclosure of your information

We may share Personal Data with affiliates, contractors, service providers, advertising/marketing partners, or as legally required (mergers, compliance, safety, fraud prevention, etc.).

Choices about how we use and disclose your information

  • Cookie settings
  • Opt-out from promotional offers via unsubscribe or email
  • Affiliate disclosures opt-out via email
  • Targeted advertising opt-out at DAA or NAI

Your rights regarding your information

Non-patient info may be accessed, corrected, or deleted via account settings or contact information below. Patient info is available through Patient Portal or Mayo’s health info management.

Security

We use encryption (SSL) and other measures to secure your information. However, no internet transmission is completely secure.

Users in the EEA, UK, and Switzerland

Additional rights under GDPR and equivalent laws apply, including rights of access, rectification, erasure, and complaint. Contact INTLcompliance@mayo.edu.

Protecting children's privacy

Sites are not intended for users under 18, except Patient Portal with parental consent for ages 13–17. Data from users under 18 will be deleted if discovered.

Links to other websites

Our Sites may link to other websites with their own privacy policies. Please review them.

Privacy policy updates

We may update this Privacy Policy as needed. Significant changes will be announced prominently.

California residents

Mayo Clinic is exempt from CCPA. California residents may request disclosure information under “Shine the Light” law by contacting us once per year.

Contact information

Mayo Clinic Privacy Officer
200 First St. SW
Rochester, MN 55905
Phone: 507-266-6286
Email: privacyoffice@mayo.edu

0 of 3 (max) selections