Privacy Policy
Occupational Health Care International, Inc. DBA: CODA Testing and MRO Services
Effective Date: January 1, 2026 | Last Updated: 2026
Occupational Health Care International, Inc., doing business as CODA Testing and MRO Services
(“CODA,” “we,” “us,” or “our”), is committed to protecting the privacy and confidentiality of personal
information we collect in connection with our drug and alcohol testing, Medical Review Officer (MRO),
consortium, and third-party administration (C/TPA) services.
This Privacy Policy describes how we collect, use, disclose, retain, and safeguard information when you
Use our services, visit our website at www.codatesting.com, or communicate with us. By using our services
or website, you acknowledge the practices described in this policy.
1. Information We Collect
We may collect the following categories of information:
Personal Information
- Name, address, phone number, email address
- Date of birth, driver’s license, or other government-issued identification numbers
- Employer name, contact details, and job/position information (including safety-sensitive status for
regulated testing)
Testing and Related Information
- Drug and alcohol test results and laboratory data
- Chain-of-custody forms and collection details
- Medical Review Officer (MRO) verification and related information
- Other information necessary to administer DOT and Non-DOT testing programs, such as
prescription and over-the-counter medications, and relevant physician, dental, or hospital visit
information disclosed during MRO verification
Website and Technical Information
- IP address, browser type, device information
- Pages visited, dates and times of access, and referral sources
- Cookies and similar technologies (see Section 8)
We collect information directly from individuals or their authorized employers/representatives, from
collection sites and laboratories, from MROs, and automatically through our website or systems (including
our CODA LINX™ platform).
2. How We Use Your Information
- Provide drug and alcohol testing services (DOT and Non-DOT), MRO review, and related C/TPA
administration
- Schedule tests, communicate results to authorized parties, and maintain compliance records
- Comply with applicable laws and regulations, including U.S. Department of Transportation (DOT)
regulations under 49 CFR Part 40
- Process payments and administer client accounts
- Improve our services, systems, and website functionality
- Respond to inquiries and provide customer support
- Detect, prevent, and respond to fraud or security incidents
- Fulfill other legal or regulatory obligations
We do not sell, rent, or trade personal information or test results for marketing or commercial
purposes.
3. How We Share Information
We share information only as necessary to deliver our services or as required or permitted by law.
Recipients may include:
- Your employer or other authorized requesting parties (with a permissible purpose)
- Certified laboratories and collection sites
- Medical Review Officers (MROs)
- Other consortia or third-party administrators involved in a testing program
- Service providers who assist us (for example, IT/hosting, payment processing, or secure data
storage) under contractual confidentiality and security obligations
- Government agencies or regulators when required by law (including DOT agencies and the FMCSA
Clearinghouse where applicable
- Parties involved in a business transaction (such as a merger or acquisition), subject to appropriate
confidentiality protections
For DOT-regulated testing, we follow the confidentiality and release-of-information rules in 49 CFR Part 40,
Subpart P. We do not disclose individual test results to unauthorized third parties without the individual’s
specific written consent, except as explicitly authorized or required under applicable regulations.
4. Confidentiality and Regulatory Compliance
We treat drug and alcohol testing information as confidential.
- DOT Testing: We comply with the confidentiality requirements of 49 CFR Part 40.
- Non-DOT Testing: We apply comparable confidentiality standards consistent with applicable state
law and best practices.
- HIPAA: If we handle Protected Health Information (PHI) in a capacity subject to HIPAA, we comply
with the applicable Privacy, Security, and Breach Notification Rules. A separate or combined Notice
of Privacy Practices may apply in those circumstances.
5. Data Security
We implement reasonable administrative, technical, and physical safeguards designed to protect personal
information against unauthorized access, use, disclosure, alteration, or destruction. These measures
include access controls, secure transmission (including SSL/TLS for our CODA LINX™ results interface),
employee training, and other industry-standard protections.
No method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect
your information, we cannot guarantee absolute security.
6. Data Retention
We retain personal information and testing records only as long as necessary to fulfill the purposes
described in this policy and to meet legal or regulatory retention requirements. For DOT-regulated records,
Retention periods generally follow 49 CFR §40.333, which specifies minimum retention periods (for example,
one, two, or five years) depending on the type of record — such as negative test results, refusals, and
violations. Non-DOT records are retained consistent with applicable state law and our contractual
obligations to clients. After the applicable retention period, we securely destroy or de-identify the information
in accordance with our internal policies.
7. Your Privacy Rights
Depending on your state of residence and applicable law, you may have certain rights regarding your
personal information, which may include the right to:
- Confirm whether we process your personal information and access a copy of it
- Request correction of inaccurate information
- Request deletion of certain information (subject to legal retention obligations)
- Obtain a portable copy of certain data
- Opt out of the sale of personal information or targeted advertising (we do not sell personal
information)
- Non-discrimination for exercising privacy rights
These rights are provided where applicable; state comprehensive privacy law extends them to you; they are
not universal, and availability depends on your state of residence and whether we meet that law’s
applicability thresholds. To exercise any of these rights, contact us using the information in Section 11. We
will verify your request and respond within the time frame required by applicable law. You may also have
the right to file a complaint with your state’s regulatory authority (such as a state Attorney General or
Consumer Protection division).
Utah Residents:
The Utah Consumer Privacy Act (UCPA) provides certain rights to Utah consumers when a business meets
specific revenue and data-volume thresholds. Even where those thresholds do not apply to us, we honor
reasonable requests consistent with this Policy and applicable law.
This Policy does not currently maintain a state-by-state matrix of every applicable privacy law. If you reside
in a state with its own comprehensive privacy law and have questions about rights specific to that state,
please contact us at the information in Section 11 and we will address your request individually.
8. Cookies and Website Tracking
Our website (www.codatesting.com) may use cookies and similar technologies for functionality, analytics,
and performance. You can manage cookie preferences through your browser settings. We do not use
tracking technologies on public pages to collect sensitive testing information.
9. Children's Privacy
Our website is not directed to individuals under 18, and we do not knowingly collect personal information.
through our website from children. Testing and related personal information about minors may be collected.
in the ordinary course of a testing program only where an employer, school, athletic organization, or other
authorized party engages our services and provides any consent required by applicable law for that minor’s
participation. In those circumstances, this policy governs our handling of that information in the same
manner as for adult participants.
10. Changes to This Policy
We may update this Privacy Policy from time to time. The “Last Updated” date at the top of this Policy
reflects when it was most recently revised. Continued use of our services after changes become effective
constitutes acknowledgment of the updated policy. Where required by law, we will provide additional notice
of material changes.
11. Contact Us
If you have questions about this Privacy Policy, our privacy practices, or wish to exercise your rights, please
Contact us:
Occupational Health Care International, Inc.
DBA: CODA Testing and MRO Services
Attn: Privacy Officer
1108 West South Jordan Parkway, Suite C, South Jordan, UT 84095
Phone: (801) 561-2777
Email: info@codatesting.com
Website: www.codatesting.com
