Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The Policy states that UnitedHealthcare may combine information collected through Online Services with offline data from internal and vendor sources and use or disclose the combined dataset for the purposes described in the Policy or for internal business purposes.
This analysis describes what UnitedHealthcare's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision authorizes data aggregation across online behavioral data, health and medical information, financial data, and offline records from vendors, which may produce enriched data profiles extending beyond what users submit directly through Online Services. The permissibility of such combination involving Protected Health Information is subject to HIPAA's minimum necessary and permissible use standards.
Interpretive note: The operational scope of permitted data combination depends on which specific vendor data sources are used and how HIPAA minimum necessary standards are applied to each combination use case, which is not specified in the document.
Under this clause, data collected through UnitedHealthcare's websites and mobile applications may be combined with offline records and vendor-sourced data to create enriched information profiles used for the purposes described in the Policy, including analytics, marketing, and service delivery. The categories of data that may be combined include health and medical information, financial data, and behavioral tracking data.
Cross-platform context
See how other platforms handle Data Combination from Online and Offline Sources and similar clauses.
Compare across platforms →Monitoring
UnitedHealthcare has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"We may, when permitted, combine your Information with other information, whether online or offline, maintained or available to us from you or from other sources, such as from our vendors, and we may use and disclose combined data for the purpose described in this Section or for internal business purposes.Excerpt from UnitedHealthcare's Privacy Policy
1. REGULATORY LANDSCAPE: This provision engages HIPAA's minimum necessary standard and permissible use provisions where PHI is included in combined datasets. FTC Act Section 5 authority applies to unfair or deceptive data aggregation practices. CCPA and other state comprehensive privacy statutes may require disclosure of data combination practices and provide opt-out rights for certain uses of combined personal information. 2. GOVERNANCE EXPOSURE: Medium. The breadth of the data combination authorization, encompassing health information, financial data, behavioral data, and offline sources including vendors, creates a data mapping and provenance challenge for compliance purposes. Demonstrating HIPAA minimum necessary compliance for combined datasets requires documented analysis of each use case. 3. JURISDICTION FLAGS: California residents may have CCPA rights regarding the use of combined personal information profiles for targeted advertising or sales, depending on how the combined data is processed and shared. State health privacy laws in several jurisdictions impose limits on combining health data with non-health data for marketing purposes. 4. CONTRACT AND VENDOR IMPLICATIONS: The reference to vendor-sourced offline data as an input to combined datasets requires that data sharing and processing agreements with those vendors address permissible downstream uses and comply with applicable privacy requirements including HIPAA BAA obligations where PHI is involved. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should conduct a data lineage review to document which offline vendor data sources are combined with online behavioral and health data, assess the legal basis for each combination use case under HIPAA and applicable state law, and ensure that privacy notices accurately reflect the combined data uses that are operationally implemented.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision authorizes data aggregation across online behavioral data, health and medical information, financial data, and offline records from vendors, which may produce enriched data profiles extending beyond what users submit directly through Online Services. The permissibility of such combination involving Protected Health Information is subject to HIPAA's minimum necessary and permissible use standards.
Under this clause, data collected through UnitedHealthcare's websites and mobile applications may be combined with offline records and vendor-sourced data to create enriched information profiles used for the purposes described in the Policy, including analytics, marketing, and service delivery. The categories of data that may be combined include health and medical information, financial data, and behavioral tracking data.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by UnitedHealthcare.