Policies and best practices

Digital engagement vendor guidelines

Vendor guidelines ensure non-discrimination practices and better accessibility in all our digital materials and communications.

The vendor guidelines are for your reference when creating Blue Cross and Blue Shield of North Carolina (Blue Cross NC) affiliated materials and communications. This guide follows brand best practices for all digital materials, including external pages, vendor pages, websites and single page sites.

This information is meant to provide guidance alongside our brand standards and usability best practices. The information found on these webpages is subject to change at any time as we strive to constantly improve our products and services. As our partner, it is your responsibility to check this site for updates.

A brand is defined as how consumers feel and think about a company based on how they interact with that company.

As one of the most recognized names in the insurance industry, Blue Cross and Blue Shield (BCBS) ranks 30% higher than national competitors in unaided brand awareness. That’s why it’s imperative that we use brand consistency in all communications we send to our members and consumers.

Our goal is to preserve and maintain the equity of the Blue Cross and Blue Shield brand name. We strive to keep our BCBS brand growing and evolving here in North Carolina.

At Blue Cross and Blue Shield of North Carolina (Blue Cross NC), we’re always looking for ways to improve and build our brand identity. To us, a brand is more than a logo, a new campaign or an icon on a screen. It’s a promise to all North Carolinians that we will consistently exceed their expectations when it comes to quality service and products. Exceeding these expectations builds trust and a stronger relationship within our community.

Our Brand Strategy and Integrated Marketing team works diligently to shape the way Blue Cross NC is perceived by consumers all across North Carolina. Through purposeful and creative campaigns, we can influence how consumers view our company and our brand. Each interaction we have with consumers, big or small, can impact how our members feel about us.

What does that mean for you?

As ambassadors of the Blue Cross NC brand, it’s important that you keep all materials associated with us cohesive and recognizable. The guides on this site are designed to make it easier to find all the guidelines, components, and regulations of the Blue Cross NC brand. These guides should be the first point of reference when creating any and all Blue Cross NC communications or materials.

Blue Cross NC Brand Style Guide (PDF)

The brand style guide download is available for reference when complying with our brand standards and identity.

REMEMBER: Even when implementing the styles provided here, all web pages must be reviewed and approved by Blue Cross NC. Please send requests to your Blue Cross NC contact.

Our social media goal is to create and maintain a two-way dialog with stakeholders and consumers about the health and well-being of North Carolinians and our role in transforming health care.

Our main objectives on social media are to:

  • Protect and enhance our reputation
  • Advance the brand
  • Build and improve relationships

Vendors must consider the following standards when working on social media efforts for Blue Cross NC:

  • Blue Cross NC must review all posts, images and videos prior to publishing.
  • Logo and name use should be reviewed and approved by Blue Cross NC.
  • Posts should not tag other companies unless pre-approved.
  • All links should have an Adobe campaign ID provided by Blue Cross NC.
  • For paid ads, Blue Cross NC should approve all targeting.
  • Review the Social Media and Brand Style Guide for guidance on links to all our social channels and blogs.

Social channels and blogs:

Blue Cross NC ensures our site and communications can be used and read by everyone. This includes anyone with visual, hearing, mental and physical disabilities.

We make it our priority to comply with the WCAG 2.0 Level AA

Learn about WCAG compliance⁠ and "PDF / UA Guidelines in a Nutshell⁠."

The guidelines listed here are to be used to tailor your communications and materials to follow the accessibility standards.

Color contrast

Blue Cross NC follows color contrast standards to ensure foreground and background colors provide enough of a contrast to make text easy to read for anyone with low vision or poor color vision. Smaller text (below 18pt) should have a contrast ratio of 4.5:1. Larger text can have a ratio of 3:1; view the W3C Techniques for Accessibility Evaluation⁠.

You can use the Color Contrast Analyzer⁠ to check the contrast of two colors.

Text size and formatting

Standard text size should be 16px (or 12pt) and a minimum of 12px (or 9pt) for readability. Text links should appear blue, follow color contrast standards and are underlined except in the exceptions such as primary navigation.

  • This is a basic text link (#006894): Text Link
  • If the link takes the user to a new website, it should use the New Window icon: Visit Website
  • If you are linking to a PDF file, it should indicate the file type like this: Download File (PDF)

Technical guidelines

Digital analytics

All consumer-facing components of their webpages should include the company’s tag manager scripts. The contents of these scripts include but are not limited to the following:

  1. Adobe Launch (tag manager)
  2. Adobe DTM (legacy tag manager)
  3. Adobe Analytics (web analytics platform)
  4. IBM Tealeaf (web analytics platform)
  5. Qualtrics (experience management platform)
  6. Tracking pixels

An example of the tag manager script, which must be placed inside the <head> tag of any consumer-facing web documents, is shown below:

<script src="//assets.adobedtm.com/launch-123456abcdefg.min.js" async></script>

In addition to the tag manager script, the vendor will provide a standardized data layer object, embedded on the consumer-facing web document and presented in JSON format, so that the company’s web analytics scripts can collect data on user interactions within the user’s experience. Specific interactions catalogued within this data layer will be mutually agreed upon by the parties, in writing.

The company uses a modified version of the Customer Experience Digital Data Layer (CEDDL 1.0) specification, hosted on W3C (PDF)⁠.

Desktop supported browsers

Personal computers:

Supporting the following browsers updated within the last 6 months:

  • Microsoft Internet Explorer 11
  • Microsoft Edge
  • Apple Safari
  • Mozilla Firefox
  • Google Chrome

Mobile devices:

  • Google Chrome on Android
  • Apple Safari on iOS

Performance standards

All Blue Cross NC web applications should go through Performance, Volume and Stress (PVS) testing to ensure they meet our performance requirements.

Peak hourly volume support requirements:

  • Peak Hourly Volume = 5,580 visits per hour
  • PVS Test Volume = 11,160 visits per hour

Page load time requirements:

  • Time to interact (Authentication complete, navigation has loaded): 3 seconds
  • Complete page load (All service calls complete, all data presented on page): 3 seconds

Application availability requirements: 99.5%

Mobile supported browsers

reference
/content/dam/bcbsnc/content-fragments/tables/en-hosted-digital-engagement-vendor-guidelines-table-0
lh-zebra
false
lh-sticky-header-row
false
lh-sticky-header-column
false
lh-header-fill
true
lh-divider
horizontal
lh-cell-padding
tight
lh-width
100%

Identity sharing

There are three recommended approaches to sharing identity:

Just-in-time provisioning

  • Vendor gets member eligibility from member portal
  • Use when there is no need for pre-sharing of membership

Eligibility extract

  • Use when arrangements require a subset of the population or additional data being shared that is too large for SAML

API

  • There are some use cases when it makes more sense to share eligibility on demand and not through enrollment
  • Members go directly to vendor app versus coming to Blue Connect first.
  • Separate login credentials

App registration

  • Subscriber ID
  • Member code: Important to make the same ID as extract file
  • Date of Birth
  • ZIP Code

Login standards

  • Preferred approach: SSO – SAML 2.0
  • Alternate approach: OAuth 2.0

App to app integrations

  • Preferred approach: App to app integration
  • Alternate approach: Responsive web

App registration

  • Subscriber ID
  • Member code: Important to make the same ID as extract file
  • Date of Birth
  • ZIP Code

Login standards

  • Preferred approach: SSO – SAML 2.0
  • Alternate approach: OAuth 2.0

App to app integrations

  • Preferred approach: App to app integration
  • Alternate approach: Responsive web

Marketing / communication data

  1. Company data being used by the vendor for marketing or member communication should only be used for the specific purpose agreed to by the company.
  2. Company data should only be used by the vendor for marketing or member communication for two weeks following it being provided by the company. At the conclusion of the two weeks, an updated source of company data may be provided if agreed upon by both parties at the beginning of the initiative. Any exception to this must be defined and agreed upon in the Statement of Work.
  3. The company requires all communications being conducted on its behalf to clearly identify that the communication is being executed by the vendor on the company’s behalf.
  4. The vendor must have the ability to capture member opt outs for both email and outbound calls.
  5. If the vendor is conducting member communication via email, the vendor must clearly indicate that any unsubscribe or opt out to their email communication applies only to the vendor emails, and that the company’s record of communication preferences will not be impacted. The vendor must also include a link to the company’s member preference portal in the email communication with this unsubscribe language.
  6. If the vendor is conducting member communication via outbound phone call, the vendor must comply with the company’s telephone solicitation policies.
  7. If the vendor conducts any marketing or member communication, including but not limited to physical, digital, web or email, on behalf of the company, the vendor must provide data and analytics related to the marketing / communication to the company. The specific data and analytics required will be defined in the Statement of Work and comply with the standards outlined in the Touchpoint Data Input section of this exhibit.
  8. Any marketing collateral or communication prepared by vendor requires approval by Blue Cross NC prior to distribution. Please send requests to your Blue Cross NC contact.
  9. Company shall be the system of record for all communication preferences for company members unless mutually agreed to by the parties in writing. Company will send communication preferences via MFT on an agreed upon schedule.

Overview

Blue Cross NC wants to standardize the vendor input file format requirements to streamline the data ingestion process and increase efficiency in data exchange. This guideline details the data-interchange format, required data attributes and definitions for any files exchanged between Blue Cross NC and vendor partners.

Any digital or human interaction between vendor and Blue Cross NC customers / stakeholders need to be captured and sent to Blue Cross NC following this guideline, as well as the Data Exchange Balancing Guidelines.

Exceptions to these standards require approval by Blue Cross NC.

Touchpoint definition

A touchpoint is defined as an interaction, digital or human, a consumer experiences at any point during their entire journey with an organization and its associated partners.

A consumer can have multiple touchpoint events through various channels across their journey phases with an organization. Each of these touchpoints contribute to overall consumer experience.

Each touchpoint event is documented in the TPH file sent to Blue Cross NC and must minimally include information about:

  • Who initiated
  • When
  • About what
  • With whom
  • Via which channel

Touchpoint history (TPH) data file

The TPH data file includes information about every touchpoint event for a consumer. Standard attributes for each event are defined below. The JSON data-interchange format should be used to exchange this data with Blue Cross NC:

  • eventTimestamp – A timestamp to identify the date and time of day that a customer interacts with a business.
  • sourceSystemCode – The name of the source who provides the data file.
  • touchpointEventCode - An event name to identify customer's interaction with a business at various touch points. For example: BOUNCE, CLICK, OPEN, SENT, AccountLogin, etc.
  • touchpointEventCategory - An event category name to identify the type of customer's interaction with a business. For example: EMAILENGMT, MBRSRVY, PAYMENT, etc.
  • touchpointEventChannel – An event channel name to identify whether the customer's interaction be person-to-person, through a website, an app or any form of communication. For example: EMAIL, WEB, MobileApp, etc
  • customerIdentification - An array contains memberid, personid and any information to uniquely identify which member has done the event.
  • extensionDataElement - Any information that the source wants to provide.

A sample JSON:

[

[

{

"eventTimestamp": "2018-10-29T09:00:34Z",

"sourceSystemCode": "ABC", #Source Name#

"touchpointEventCode": "XYZ", #Event Name#

"touchpointEventCategory": "ABC", #Event Category Name#

"touchpointEventChannel": "Web", #Event Channel Name#

"customerIdentification": [

{

"identityName": "memberId",

"identityValue": "ABC12345163800"

},

{

"identityName": "personId",

"identityValue": "1234567"

}

],

"extensionDataElement": [

{

"name": "",

"value": ""

},

{

"name": "",

"value": ""

},

{

"name": "",

"value": ""

}

]

}

]

]

Blue Cross NC enterprise listening standards were created to ensure consistency in experience metrics, appropriate branding and appropriate legal guidelines / conditions are followed.

Vendors must adhere to the following when conducting research (e.g., surveying, focus groups, etc.) with Blue Cross NC stakeholders (e.g., members, customers, employees, providers, group clients, agents, etc.):

  • Research must adhere to the principles of market / opinion research (CASRO Standards⁠) High level overview below:

    • Participation is voluntary, members must have ability to opt out of future research
    • Participants' personal information is kept confidential and secure
    • Clarify that participation (or lack thereof) will have no negative impact on them
    • Local laws / regulations are followed
    • To be conducted with honesty, transparency and with purpose
    • Research to be conducted by person with appropriate qualifications in research and methodology being used (e.g., survey – online / phone, focus group, etc.)
  • If research is not branded Blue Cross NC, it must clearly appear as coming from the vendor (e.g., vendor logo, etc.) with no reference to Blue Cross NC sponsoring or outsourcing vendor resource.

  • Research structure must be done in a way to mitigate survey and question bias.

  • For online surveys, three Blue Cross NC key questions must be included with the approved scales (see below). If other research methodologies are conducted, seek Blue Cross NC guidance on inclusion / exclusion.

Satisfaction

“Overall, how satisfied are you with Blue Cross NC as your health insurance provider?” 5-point scale (very dissatisfied, somewhat dissatisfied, neither satisfied nor dissatisfied, somewhat satisfied, very satisfied)

Ease

“Thinking about all of your experience with Blue Cross NC in 2020, how easy has Blue Cross NC been to work with?” 6-point scale (very difficult, somewhat difficult, neither easy nor difficult, somewhat easy, very easy, I have not had any experiences with Blue Cross NC)

NPS

“How likely are you to recommend Blue Cross NC, to a friend or colleague?” 11-point scale (0- not at all likely to recommend, 10- extremely likely to recommend)

  • Blue Cross NC must be given option to review all research materials prior to being used.
  • When random drawings, gifts, etc. are used to encourage participation, the appropriate disclosures must be made available to all (e.g., make accessible via link at bottom of survey in footnote, when asking “if interested in being entered into drawing,” add a link to disclosures, etc.).
  • All final materials used in research (e.g., survey, raw data, aggregated data, final reports, list of opt outs, etc.) must be made available to Blue Cross NC.
All webpages must include specific legal notifications as required by the federal and state governments and Blue Cross NC approved policies. All legal notifications must always be in made conjunction with active Blue Cross NC consultation and approval.

Multi-language

Below is the Blue Cross NC approved notification for multi-language requirement. We have information in many other languages.

You can access any of these languages on our Non-descrimination Policy and Accessibility Services page:

Non-discrimination

Below is the Blue Cross NC approved notification for our non-discrimination requirement.

Blue Cross and Blue Shield of North Carolina does not discriminate on the basis of race, color, national origin, sex, age or disability in its health programs and activities.

Learn more about our non-discrimination policy and no-cost services available to you.

The company's Blue Connect member portal shall be the identity provider for any consumer-facing vendor system(s) and / or website(s) requiring authorized user authentication for company members, unless otherwise mutually agreed to by the parties, in writing.

Guidelines for authorized use of our brand

The Blue Cross and Blue Shield Association is a national federation of 36 independent, community-based and locally operated Blue Cross® and Blue Shield® companies.

Each company has its own brand “signature” that we use to identify everything we produce and distribute. These signatures consist of a photographic style, color palette, typographic family, icon family and easy-to-understand language.

Presenting a strong and consistent brand image across each of the 38 companies within the Association is the responsibility of everyone who produces assets for the brand.

alignment
left
size
large
button-type
lh-button
variant
outlined
text
Corporate Brand Guidelines / Style Guide (PDF)
media-label
label
link
/content/dam/bcbsnc/pdf/policies/corporate-style-guide.pdf
icon-position
right
anchor-id
button-b1a88d4e31
analytics-id
button-b1a88d4e31-0a3953b220-Corporate Brand Guidelines / Style Guide (PDF)
full-width
false
full-width-mobile
false