Privacy Policy

Occupational Health Care International, Inc. DBA: CODA Testing and MRO Services

Effective Date: January 1, 2026 | Last Updated: 2026


Occupational Health Care International, Inc., doing business as CODA Testing and MRO Services

(“CODA,” “we,” “us,” or “our”), is committed to protecting the privacy and confidentiality of personal

information we collect in connection with our drug and alcohol testing, Medical Review Officer (MRO),

consortium, and third-party administration (C/TPA) services.


This Privacy Policy describes how we collect, use, disclose, retain, and safeguard information when you

Use our services, visit our website at www.codatesting.com, or communicate with us. By using our services

or website, you acknowledge the practices described in this policy.



1. Information We Collect

We may collect the following categories of information:


Personal Information


  • Name, address, phone number, email address
  • Date of birth, driver’s license, or other government-issued identification numbers
  • Employer name, contact details, and job/position information (including safety-sensitive status for

         regulated testing)


Testing and Related Information


  • Drug and alcohol test results and laboratory data
  • Chain-of-custody forms and collection details
  • Medical Review Officer (MRO) verification and related information
  • Other information necessary to administer DOT and Non-DOT testing programs, such as

         prescription and over-the-counter medications, and relevant physician, dental, or hospital visit

         information disclosed during MRO verification


Website and Technical Information



  • IP address, browser type, device information
  • Pages visited, dates and times of access, and referral sources
  • Cookies and similar technologies (see Section 8)


We collect information directly from individuals or their authorized employers/representatives, from

collection sites and laboratories, from MROs, and automatically through our website or systems (including

our CODA LINX™ platform).


2. How We Use Your Information


  • Provide drug and alcohol testing services (DOT and Non-DOT), MRO review, and related C/TPA

         administration

  • Schedule tests, communicate results to authorized parties, and maintain compliance records
  • Comply with applicable laws and regulations, including U.S. Department of Transportation (DOT)

         regulations under 49 CFR Part 40

  • Process payments and administer client accounts
  • Improve our services, systems, and website functionality
  • Respond to inquiries and provide customer support
  • Detect, prevent, and respond to fraud or security incidents
  • Fulfill other legal or regulatory obligations


We do not sell, rent, or trade personal information or test results for marketing or commercial

purposes.


3. How We Share Information

We share information only as necessary to deliver our services or as required or permitted by law.

Recipients may include:


  • Your employer or other authorized requesting parties (with a permissible purpose)
  • Certified laboratories and collection sites
  • Medical Review Officers (MROs)
  • Other consortia or third-party administrators involved in a testing program
  • Service providers who assist us (for example, IT/hosting, payment processing, or secure data

         storage) under contractual confidentiality and security obligations

  • Government agencies or regulators when required by law (including DOT agencies and the FMCSA

         Clearinghouse where applicable

  • Parties involved in a business transaction (such as a merger or acquisition), subject to appropriate

         confidentiality protections


For DOT-regulated testing, we follow the confidentiality and release-of-information rules in 49 CFR Part 40,

Subpart P. We do not disclose individual test results to unauthorized third parties without the individual’s

specific written consent, except as explicitly authorized or required under applicable regulations.


4. Confidentiality and Regulatory Compliance

We treat drug and alcohol testing information as confidential.


  • DOT Testing: We comply with the confidentiality requirements of 49 CFR Part 40.
  • Non-DOT Testing: We apply comparable confidentiality standards consistent with applicable state

         law and best practices.

  • HIPAA: If we handle Protected Health Information (PHI) in a capacity subject to HIPAA, we comply

         with the applicable Privacy, Security, and Breach Notification Rules. A separate or combined Notice

         of Privacy Practices may apply in those circumstances.


5. Data Security

We implement reasonable administrative, technical, and physical safeguards designed to protect personal

information against unauthorized access, use, disclosure, alteration, or destruction. These measures

include access controls, secure transmission (including SSL/TLS for our CODA LINX™ results interface),

employee training, and other industry-standard protections.


No method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect

your information, we cannot guarantee absolute security.


6. Data Retention

We retain personal information and testing records only as long as necessary to fulfill the purposes

described in this policy and to meet legal or regulatory retention requirements. For DOT-regulated records,

Retention periods generally follow 49 CFR §40.333, which specifies minimum retention periods (for example,

one, two, or five years) depending on the type of record — such as negative test results, refusals, and

violations. Non-DOT records are retained consistent with applicable state law and our contractual

obligations to clients. After the applicable retention period, we securely destroy or de-identify the information

in accordance with our internal policies.


7. Your Privacy Rights

Depending on your state of residence and applicable law, you may have certain rights regarding your

personal information, which may include the right to:


  • Confirm whether we process your personal information and access a copy of it
  • Request correction of inaccurate information
  • Request deletion of certain information (subject to legal retention obligations)
  • Obtain a portable copy of certain data
  • Opt out of the sale of personal information or targeted advertising (we do not sell personal

         information)

  • Non-discrimination for exercising privacy rights


These rights are provided where applicable; state comprehensive privacy law extends them to you; they are

not universal, and availability depends on your state of residence and whether we meet that law’s

applicability thresholds. To exercise any of these rights, contact us using the information in Section 11. We

will verify your request and respond within the time frame required by applicable law. You may also have

the right to file a complaint with your state’s regulatory authority (such as a state Attorney General or

Consumer Protection division).


Utah Residents:


The Utah Consumer Privacy Act (UCPA) provides certain rights to Utah consumers when a business meets

specific revenue and data-volume thresholds. Even where those thresholds do not apply to us, we honor

reasonable requests consistent with this Policy and applicable law.

This Policy does not currently maintain a state-by-state matrix of every applicable privacy law. If you reside

in a state with its own comprehensive privacy law and have questions about rights specific to that state,

please contact us at the information in Section 11 and we will address your request individually.


8. Cookies and Website Tracking

Our website (www.codatesting.com) may use cookies and similar technologies for functionality, analytics,

and performance. You can manage cookie preferences through your browser settings. We do not use

tracking technologies on public pages to collect sensitive testing information.


9. Children's Privacy

Our website is not directed to individuals under 18, and we do not knowingly collect personal information.

through our website from children. Testing and related personal information about minors may be collected.

in the ordinary course of a testing program only where an employer, school, athletic organization, or other

authorized party engages our services and provides any consent required by applicable law for that minor’s

participation. In those circumstances, this policy governs our handling of that information in the same

manner as for adult participants.


10. Changes to This Policy

We may update this Privacy Policy from time to time. The “Last Updated” date at the top of this Policy

reflects when it was most recently revised. Continued use of our services after changes become effective

constitutes acknowledgment of the updated policy. Where required by law, we will provide additional notice

of material changes.


11. Contact Us

If you have questions about this Privacy Policy, our privacy practices, or wish to exercise your rights, please

Contact us:


Occupational Health Care International, Inc.

DBA: CODA Testing and MRO Services


Attn: Privacy Officer


1108 West South Jordan Parkway, Suite C, South Jordan, UT 84095

Phone: (801) 561-2777

Email: info@codatesting.com

Website: www.codatesting.com