Legal
Privacy policy
Last updated 14 September 2026.
The rule that governs this site
No page, form, or integration on this site collects or displays patient information. No table in the systems behind it stores patient data. That constraint is architectural rather than procedural: there is no field to put it in.
What we collect here
- Roster audit requests: group name, work email, clinician count band, states of operation, and an organization NPI or CMS PAC ID where you supply one
- Quote requests: group name, work email, clinician count, target states and notes
- Aggregate traffic measurement, without third-party advertising pixels on page
How submissions are handled
Form submissions route to an endpoint we control. We do not use third-party form services that retain submissions, third-party chat widgets that capture free text, or call recording. Conversion measurement for advertising is server side and carries a click identifier, a generic conversion name and a timestamp, and nothing else.
Provider data in the engagement
Under an engagement we handle credentialing files that contain clinician Social Security numbers and dates of birth. These are not protected health information, and we apply the same protection level because they trigger the breach notification statutes of all fifty states. Access controls and delivery geography are described on the data scope page.
Retention and requests
Audit request records are retained for 24 months unless you ask us to delete them sooner. To access, correct, or delete anything we hold about you or your group, write to us and we will confirm within 30 days.