Privacy Policy

    Privacy Policy

    At Zenith Healthcare Solutions, we are committed to protecting your privacy and handling your personal information with the highest standards of care and security.

    Effective Date: January 1, 2025

    Information We Collect

    Information You Provide Directly

    • Contact Information: Name, email address, phone number, business address
    • Professional Information: Practice specialty, number of providers, patient volume
    • Communication Records: Messages, inquiries, and support requests
    • Assessment Data: Information provided during practice assessments

    Information Collected Automatically

    • Usage Data: Pages visited, time spent, click patterns, referral sources
    • Device Information: IP address, browser type, device type, operating system
    • Cookies and Tracking: Website preferences, session data, analytics information

    Information from Third Parties

    • Professional Databases: Publicly available healthcare provider information
    • Marketing Partners: Business contact information from legitimate sources
    • Social Media: Information from professional networking platforms (with consent)
    How We Use Your Information

    Service Delivery

    • Providing medical billing and revenue cycle management services
    • Conducting practice assessments and consultations
    • Processing inquiries and providing customer support
    • Delivering requested information and resources

    Communication

    • Responding to your inquiries and requests
    • Sending service updates and important notifications
    • Providing educational content and industry insights
    • Marketing our services (with opt-out options)

    Business Operations

    • Improving our website and services
    • Analyzing usage patterns and preferences
    • Preventing fraud and ensuring security
    • Complying with legal and regulatory requirements

    Legal Basis for Processing (GDPR)

    • Legitimate Interests: Business communications and service improvement
    • Consent: Marketing communications and non-essential cookies
    • Contract Performance: Delivering requested services
    • Legal Compliance: Meeting regulatory requirements
    Data Protection and Security

    Security Measures

    • Encryption: All data transmitted and stored using industry-standard encryption
    • Access Controls: Role-based access with multi-factor authentication
    • Regular Audits: Quarterly security assessments and penetration testing
    • Employee Training: Regular privacy and security training for all staff

    HIPAA Compliance

    As a healthcare service provider, we maintain strict HIPAA compliance standards:

    • Business Associate Agreements with all healthcare clients
    • Secure handling of Protected Health Information (PHI)
    • Regular risk assessments and security updates
    • Incident response procedures for data breaches

    Data Retention

    • Contact Information: Retained for 7 years after last contact
    • Service Records: Retained per regulatory requirements (typically 7-10 years)
    • Website Analytics: Aggregated data retained for 2 years
    • Marketing Data: Deleted immediately upon opt-out request
    Information Sharing and Disclosure

    We DO NOT sell your personal information.

    Limited Sharing Scenarios

    • Service Providers: Third-party vendors who assist with our operations (under strict confidentiality)
    • Legal Requirements: When required by law, court order, or regulatory request
    • Business Transfers: In the event of a merger or acquisition (with notification)
    • Consent: When you explicitly authorize sharing

    Third-Party Service Providers

    • Cloud hosting and data storage providers
    • Email and communication platforms
    • Analytics and marketing tools
    • Customer support systems

    All third parties are bound by confidentiality agreements and privacy requirements.

    Your Privacy Rights

    General Rights

    • Access: Request information about what personal data we have about you
    • Correction: Request correction of inaccurate personal information
    • Deletion: Request deletion of your personal information (subject to legal requirements)
    • Opt-Out: Unsubscribe from marketing communications at any time

    California Residents (CCPA/CPRA)

    • Right to know what personal information is collected and used
    • Right to delete personal information
    • Right to opt-out of sale or sharing of personal information
    • Right to correct inaccurate personal information
    • Right to non-discrimination for exercising privacy rights

    European Residents (GDPR)

    • Right of access to your personal data
    • Right to rectification of inaccurate data
    • Right to erasure ("right to be forgotten")
    • Right to restrict processing
    • Right to data portability
    • Right to object to processing
    • Right to withdraw consent

    How to Exercise Your Rights

    To exercise any of these rights, please contact us:

    • Email: info@zhcsolutions.com
    • Phone: (512) 961-5350
    • Mail: PO BOX 310906, New Braunfels, TX 78131

    We will respond to your request within 30 days (or as required by applicable law).

    Cookies and Tracking Technologies

    We use cookies and similar technologies to enhance your experience on our website. For detailed information about our cookie practices, please see our Cookie Policy.

    Your Cookie Choices

    • Use our cookie preference center to manage your settings
    • Configure your browser to block or delete cookies
    • Opt out of interest-based advertising
    • Enable Global Privacy Control (GPC) in your browser
    International Data Transfers

    Our services are primarily operated from the United States. If you are located outside the United States, your information may be transferred to and processed in the United States, where data protection laws may differ from those in your jurisdiction.

    Safeguards for International Transfers

    • Standard Contractual Clauses for EU data transfers
    • Adequacy decisions where applicable
    • Additional safeguards for sensitive healthcare data
    • Regular review of transfer mechanisms
    Children's Privacy

    Our services are designed for healthcare professionals and business entities. We do not knowingly collect personal information from children under 13 years of age. If we become aware that we have collected personal information from a child under 13, we will take steps to delete such information promptly.

    Changes to This Privacy Policy

    We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of any material changes by:

    • Posting the updated policy on our website
    • Updating the "Effective Date" at the top of this policy
    • Sending email notification for significant changes (where required)
    • Requesting renewed consent where legally required

    We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.

    Contact Us

    If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:

    General Inquiries

    Privacy Officer

    • info@zhcsolutions.com
    • Data Protection Inquiries

    Mailing Address

    Zenith Healthcare Solutions
    Attn: Privacy Officer
    PO BOX 310906
    New Braunfels, TX 78131
    United States