patientprotect Privacy Policy

PatientProtect, Inc.

Effective Date: 9/18/2009 | Last Updated: 4/1/2026

1. Introduction and Scope

PatientProtect, Inc. ("PatientProtect," "we," "us," or "our") is committed to protecting the privacy and security of your personal information. This Privacy Policy describes how we collect, use, disclose, and safeguard information about you when you visit our website at www.patientprotect.com, use our services, or engage with our PatientProtect program (collectively, the "Services").

PatientProtect is designed to help patients navigate healthcare decisions, understand costs, provide financial protection and access high-quality discounted care.

By accessing or using our Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with the terms of this Policy, please do not use our Services.

You must be at least 18 years of age to use our Services. We do not knowingly collect, use, process, or disclose personally identifiable information from anyone under the age of 18. If we learn that a user is under the age of 18, we will promptly revoke access and delete their information.

2. About PatientProtect

PatientProtect is a healthcare transparency and cost comparison platform that empowers patients, employers, and health plans to make informed decisions about healthcare services. Our PatientProtect program extends these services to provide personalized patient advocacy, cost protection, and healthcare navigation support.

This Privacy Policy applies to all users of our Services, including individuals accessing the public-facing website, registered members, employers and plan sponsors, and participants in the PatientProtect program.

3. Information We Collect

3.1 Information You Provide Directly

We collect personal information that you voluntarily provide to us, including:

  • Registration and account information (name, username, password, email address, phone number)
  • Demographic information (date of birth, gender, ZIP code)
  • Insurance and coverage information (health plan name, member ID, group number)
  • Healthcare-related information you choose to share when using our Services, including treatment preferences, procedure interests, and healthcare provider selections
  • Payment and billing information when applicable
  • Communications you send to us, including support requests, feedback, and inquiries
  • Any other information you voluntarily enter into web forms, our platform, or applications

3.2 Protected Health Information (PHI)

In connection with PatientProtect and certain other Services, we may receive or process Protected Health Information ("PHI") as defined under the Health Insurance Portability and Accountability Act ("HIPAA"). PHI includes information relating to your past, present, or future physical or mental health or condition, healthcare services provided to you, or payment for those services that can be used to identify you. When we act as a Business Associate under HIPAA, we handle PHI in accordance with our HIPAA Notice of Privacy Practices, which is incorporated into this Privacy Policy by reference.

3.3 Information Collected Automatically

When you use our Services, certain information is collected automatically, including:

  • Device information (device type, operating system, browser type and version, language settings)
  • Network information (Internet Protocol (IP) address, mobile network data)
  • Usage data (pages viewed, features used, time spent, links clicked, search queries)
  • Location data (country and region inferred from IP address)
  • Cookies and similar tracking technologies (see Section 6 below)

3.4 Information From Third Parties

We may receive information about you from third parties, including:

  • Employers or plan sponsors who have enrolled you in our Services or PatientProtect
  • Health insurance carriers and third-party administrators (TPAs) for eligibility verification and benefit coordination
  • Healthcare providers and facilities in connection with care coordination or cost estimation
  • Analytics and data service providers who help us understand usage of our Services

4. How We Use Your Information

PatientProtect uses the information we collect for the following purposes:

4.1 Service Delivery

  • To provide, operate, and maintain our website and Services
  • To deliver PatientProtect program benefits, including cost protection and patient advocacy
  • To process your registrations, requests, and transactions
  • To verify your eligibility for benefits and Services
  • To match you with high-quality healthcare providers and facilities
  • To provide cost estimates, transparency data, and quality information

4.2 Communication and Support

  • To respond to your inquiries, questions, and support requests
  • To send you important notices about your account or the Services
  • To communicate with you about updates, new features, and program changes
  • To send marketing and promotional communications where you have consented or where permitted by law (you may opt out at any time)

4.3 Business Operations and Improvement

  • To analyze usage patterns and improve our Services
  • To conduct research and develop new features and products
  • To detect, prevent, and address fraud, security incidents, and illegal activity
  • To enforce our Terms of Use and legal agreements
  • To comply with applicable legal obligations, court orders, and regulatory requirements
  • For auditing, reporting, and internal administrative purposes

4.4 Legal Bases for Processing

We process your personal information on the following legal bases: performance of a contract with you; compliance with legal obligations to which we are subject; our legitimate business interests (such as improving our Services, fraud prevention, and security); and, where required, your explicit consent. You may withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

5. How We Share Your Information

PatientProtect does not sell your personal information. We may share your information in the following circumstances:

5.1 Service Providers and Business Partners

We share information with trusted vendors, contractors, and service providers who perform functions on our behalf, such as technology hosting, data analytics, customer support, payment processing, and communications. These parties are contractually obligated to protect your information and may only use it to perform the services we have engaged them to provide.

5.2 Employers and Plan Sponsors

If you access our Services through an employer-sponsored benefit program or through PatientProtect as offered by your health plan, we may share information with your employer, health plan, or TPA for purposes of administering your benefits, verifying eligibility, processing claims, and coordinating care.

5.3 Healthcare Providers

We may share relevant information with healthcare providers, hospitals, and facilities when you request care coordination, cost estimates, or referrals through our Services or PatientProtect.

5.4 Legal and Compliance Disclosures

We may disclose your information when required to do so by law or in response to valid legal process, including subpoenas, court orders, or government requests. We may also disclose information to protect the rights, safety, or property of PatientProtect, our users, or others, or to detect and prevent fraud or illegal activity.

5.5 Business Transfers

In the event of a merger, acquisition, reorganization, sale of assets, or bankruptcy, your information may be transferred as part of that transaction. We will notify you via email or prominent notice on our website if such a transfer materially changes this Privacy Policy.

5.6 With Your Consent

We may share your information with third parties when you have given us your explicit consent to do so.

5.7 De-Identified and Aggregated Data

We may use and share de-identified or aggregated data that cannot reasonably be used to identify you for research, analytics, benchmarking, and reporting purposes. This data is not subject to the restrictions of this Privacy Policy.

6. Cookies and Tracking Technologies

We use cookies, web beacons, pixel tags, and similar tracking technologies to enhance your experience on our Services, understand usage, and deliver relevant content.

Types of cookies we use include:

  • Essential cookies: Required for the Services to function properly, including authentication and security
  • Analytics cookies: Help us understand how users interact with our Services (e.g., Google Analytics)
  • Preference cookies: Remember your settings and preferences
  • Marketing cookies: Used to deliver relevant communications and measure effectiveness

We use Google Analytics to better understand how users engage with our Services. Google may use this data in accordance with its own privacy policy. You may opt out of Google Analytics by visiting https://tools.google.com/dlpage/gaoptout.

Most web browsers allow you to control cookies through browser settings. Disabling certain cookies may affect the functionality of our Services. We currently do not respond to "Do Not Track" signals from browsers; however, you may opt out of certain tracking as described in Section 8.

7. Data Retention

We retain your personal information for as long as necessary to provide our Services, fulfill the purposes described in this Privacy Policy, comply with legal obligations, resolve disputes, and enforce our agreements. When personal information is no longer needed, we will securely delete or de-identify it. PHI is retained and disposed of in accordance with HIPAA requirements and applicable state law.

8. Your Privacy Rights and Choices

Depending on where you reside, you may have the following rights with respect to your personal information:

  • Access: Request a copy of the personal information we hold about you
  • Correction: Request that we correct inaccurate or incomplete information
  • Deletion: Request that we delete your personal information, subject to certain exceptions
  • Portability: Request that we provide your information in a structured, machine-readable format
  • Opt-Out: Opt out of marketing communications at any time by clicking "unsubscribe" in any email or contacting us directly
  • Restriction: Request that we limit the processing of your information in certain circumstances
  • Objection: Object to our processing of your information based on our legitimate interests

To exercise any of these rights, please contact us at privacy@patientprotect.com. We will respond to your request within the timeframe required by applicable law. We may need to verify your identity before fulfilling your request. We will not discriminate against you for exercising your privacy rights.

8.1 California Residents (CCPA/CPRA)

California residents have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), including the right to know what personal information is collected, the right to delete personal information, the right to opt out of the sale or sharing of personal information (we do not sell personal information), the right to correct inaccurate personal information, and the right to limit the use and disclosure of sensitive personal information. To submit a request, contact us at privacy@patientprotect.com or call our toll-free number listed in Section 15. You may also designate an authorized agent to make a request on your behalf.

8.2 Other State Privacy Rights

Residents of Colorado, Connecticut, Virginia, Texas, and other states with comprehensive privacy laws may have similar rights to access, correct, delete, and opt out of certain processing of their personal information. PatientProtect honors these rights as required by applicable state law. Contact us at privacy@patientprotect.com to submit a request.

9. Security of Your Information

PatientProtect implements industry-standard administrative, technical, and physical safeguards designed to protect your personal information from unauthorized access, disclosure, alteration, and destruction. These measures include data encryption in transit and at rest, access controls and authentication requirements, regular security assessments and testing, employee training on data privacy and security, and business continuity and incident response plans.

While we strive to protect your information, no security system is impenetrable. In the event of a data breach that affects your rights or freedoms, we will notify you and applicable regulatory authorities as required by law.


10. HIPAA and Health Information

PatientProtect may act as a Business Associate under HIPAA when handling PHI on behalf of Covered Entities such as health plans and healthcare providers. In such cases, our use and disclosure of PHI is governed by our Business Associate Agreements and HIPAA Notice of Privacy Practices, in addition to this Privacy Policy.

Individuals whose PHI is handled through PatientProtect have rights under HIPAA, including the right to access and request amendments to their health records, receive an accounting of disclosures, and file complaints. Please refer to our HIPAA Notice of Privacy Practices for complete information, or contact us at the address in Section 15.

PatientProtect does not use PHI for marketing purposes without your prior written authorization, and we do not sell PHI under any circumstances.

11. Children's Privacy

Our Services are not directed to individuals under 18 years of age. We do not knowingly collect personal information from children under 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at privacy@patientprotect.com. If we become aware that we have collected information from a child under 18 without verification of parental consent, we will take prompt steps to delete that information.

12. Third-Party Links and Services

Our Services may contain links to third-party websites, applications, or services. This Privacy Policy does not apply to those third parties, and we are not responsible for their privacy practices. We encourage you to review the privacy policies of any third-party services you access through our platform.

13. International Users

Our Services are operated in the United States. If you are accessing our Services from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your jurisdiction. By using our Services, you consent to the transfer and processing of your information in the United States.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you by posting the revised Policy on our website with a new effective date, and we may send you an email notification if we have your contact information. We encourage you to review this Privacy Policy periodically. Your continued use of our Services after any changes indicates your acceptance of the updated Policy.

15. How to Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:

PatientProtect, Inc.

Attn: Privacy Officer

13 Palafox Place, Suite 200

Pensacola, FL 32502

Email: privacy@patientprotect.com

Phone: 1-850-898-1410

For PatientProtect-specific privacy inquiries, please include "PatientProtect" in the subject line of your email or communication.

If you are a California resident and wish to submit a request under the CCPA/CPRA, please contact us via the methods above or submit a request at :  privacy@patientprotect.com.

This Privacy Policy was last updated on 4/1/2026. PatientProtect, Inc. — www.patientprotect.com