Privacy Policy

Draft. Have a privacy attorney review this policy before launch. Bracketed items still need to be filled in.

Effective date: [DATE]

[LEGAL NAME], LLC ("we") runs Medical Bill Buster. This policy explains what we collect, why, who we share it with, and your rights. We are not a health care provider or health plan, so HIPAA generally doesn't apply to the data you give us directly. We protect it as sensitive health information anyway.

What we collect

  • Identifiers and contact details: name, email, mailing address, date of birth (if you add it to a form), IP address.
  • Health and billing information: the bills, Explanations of Benefits, and statements you upload, including procedure codes (CPT/HCPCS), diagnosis codes (ICD-10), dates of service, provider names, account and claim numbers, and amounts.
  • Payment information: handled by our payment processor, Stripe. We store only a reference to your saved payment method, never your full card number.
  • Consent records: what you agreed to, when, and from which IP address.

How we use it

To audit your bill, create your letters, check your final bill, calculate and collect our fee, send you reminders, keep records we're legally required to keep, and protect against fraud. We do not sell your information, and we do not use it for advertising.

Consumer health data (Nevada and similar laws)

Your bills are consumer health data. We collect it only to provide the service you asked for, after you check the consent box on the upload form. We share it only with the service providers listed below, under contracts that limit their use of it to providing our service. We will ask for your separate consent before sharing it with anyone else. We never sell it, and we don't use location-based targeting around health care facilities. You can withdraw consent or ask us to delete your data at any time. Nevada's consumer health data law (NRS 603A.400 to 603A.550) is enforced by the Nevada Attorney General.

Who we share it with

  • Payment processing: Stripe.
  • Hosting and storage: [HOSTING PROVIDER].
  • Document reading (OCR): [PROVIDER, if any; otherwise processed on our own servers].
  • Email delivery: [PROVIDER].
  • Legal requirements: when required by law or to protect our rights.

If you ask us to contact your provider or insurer and sign an authorization, we exchange information with them for that purpose.

How long we keep it

  • Bill images: deleted as soon as they are read.
  • Audits you never unlock: deleted after 7 days.
  • Case details for unlocked audits: kept while your case is open, then deleted [12 months] after it closes.
  • Fee and payment records: kept for up to 7 years for tax and accounting purposes.

Security

Audit records are encrypted at rest with AES-256, and data is encrypted in transit. If a breach affects your health information, we will notify you and the authorities as required by law, including under the FTC Health Breach Notification Rule (16 C.F.R. Part 318) and state breach laws.

Your rights

Wherever you live in the United States, you can ask us to:

  • tell you what personal information we have about you and how we use it;
  • delete it;
  • correct it;
  • confirm that we don't sell or share it (we don't);
  • limit our use of your sensitive information to what's needed to provide the service;
  • withdraw your consent.

We won't treat you differently for using these rights. We honor Global Privacy Control browser signals as an opt-out of sale or sharing.

California residents have these rights under the California Consumer Privacy Act (Cal. Civ. Code § 1798.100 et seq.). Nevada residents may submit a verified request that we not sell their covered information (NRS Chapter 603A); we don't sell it.

How to ask: use the form below, email privacy@medicalbillbuster.com, or call [TOLL-FREE NUMBER]. We'll verify your identity by email, confirm receipt within 10 business days, and respond within 45 days. We may need 45 more days in complex cases and will tell you if so. An authorized agent may make a request for you with your signed permission.

If you live outside the United States

We process your data in the United States. When you upload a bill from outside the US, we ask for your consent to that transfer.

If the EU or UK GDPR applies to you, we rely on your consent and on the need to perform our contract with you. You have the right to access, correct, delete, restrict, or object to processing of your data, to data portability, to withdraw consent, and to complain to your data protection authority (in the UK, the Information Commissioner's Office). Where required, we notify the authority of a personal data breach within 72 hours. Transfers use [Standard Contractual Clauses / UK International Data Transfer Addendum]. Data protection contact: dpo@medicalbillbuster.com.

Children

The service is for adults. We don't knowingly collect information from children under 13. A parent or guardian may upload a child's bill for them.

Changes

If we make material changes, we'll post the new policy here with a new effective date and email you if you have an open case.

Contact

[LEGAL NAME], LLC. [ADDRESS]. privacy@medicalbillbuster.com

Make a privacy request

We’ll verify your identity by email before acting on the request.