Effective Date: 9/18/2009 | Last Updated: 4/1/2026
PatientProtect, Inc. ("PatientProtect," "we," "us," or "our") is committed to protecting the privacy and security of your personal information. This Privacy Policy describes how we collect, use, disclose, and safeguard information about you when you visit our website at www.patientprotect.com, use our services, or engage with our PatientProtect program (collectively, the "Services").
PatientProtect is designed to help patients navigate healthcare decisions, understand costs, provide financial protection and access high-quality discounted care.
By accessing or using our Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with the terms of this Policy, please do not use our Services.
You must be at least 18 years of age to use our Services. We do not knowingly collect, use, process, or disclose personally identifiable information from anyone under the age of 18. If we learn that a user is under the age of 18, we will promptly revoke access and delete their information.
PatientProtect is a healthcare transparency and cost comparison platform that empowers patients, employers, and health plans to make informed decisions about healthcare services. Our PatientProtect program extends these services to provide personalized patient advocacy, cost protection, and healthcare navigation support.
This Privacy Policy applies to all users of our Services, including individuals accessing the public-facing website, registered members, employers and plan sponsors, and participants in the PatientProtect program.
We collect personal information that you voluntarily provide to us, including:
In connection with PatientProtect and certain other Services, we may receive or process Protected Health Information ("PHI") as defined under the Health Insurance Portability and Accountability Act ("HIPAA"). PHI includes information relating to your past, present, or future physical or mental health or condition, healthcare services provided to you, or payment for those services that can be used to identify you. When we act as a Business Associate under HIPAA, we handle PHI in accordance with our HIPAA Notice of Privacy Practices, which is incorporated into this Privacy Policy by reference.
When you use our Services, certain information is collected automatically, including:
We may receive information about you from third parties, including:
PatientProtect uses the information we collect for the following purposes:
We process your personal information on the following legal bases: performance of a contract with you; compliance with legal obligations to which we are subject; our legitimate business interests (such as improving our Services, fraud prevention, and security); and, where required, your explicit consent. You may withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
PatientProtect does not sell your personal information. We may share your information in the following circumstances:
We share information with trusted vendors, contractors, and service providers who perform functions on our behalf, such as technology hosting, data analytics, customer support, payment processing, and communications. These parties are contractually obligated to protect your information and may only use it to perform the services we have engaged them to provide.
If you access our Services through an employer-sponsored benefit program or through PatientProtect as offered by your health plan, we may share information with your employer, health plan, or TPA for purposes of administering your benefits, verifying eligibility, processing claims, and coordinating care.
We may share relevant information with healthcare providers, hospitals, and facilities when you request care coordination, cost estimates, or referrals through our Services or PatientProtect.
We may disclose your information when required to do so by law or in response to valid legal process, including subpoenas, court orders, or government requests. We may also disclose information to protect the rights, safety, or property of PatientProtect, our users, or others, or to detect and prevent fraud or illegal activity.
In the event of a merger, acquisition, reorganization, sale of assets, or bankruptcy, your information may be transferred as part of that transaction. We will notify you via email or prominent notice on our website if such a transfer materially changes this Privacy Policy.
We may share your information with third parties when you have given us your explicit consent to do so.
We may use and share de-identified or aggregated data that cannot reasonably be used to identify you for research, analytics, benchmarking, and reporting purposes. This data is not subject to the restrictions of this Privacy Policy.
We use cookies, web beacons, pixel tags, and similar tracking technologies to enhance your experience on our Services, understand usage, and deliver relevant content.
Types of cookies we use include:
We use Google Analytics to better understand how users engage with our Services. Google may use this data in accordance with its own privacy policy. You may opt out of Google Analytics by visiting https://tools.google.com/dlpage/gaoptout.
Most web browsers allow you to control cookies through browser settings. Disabling certain cookies may affect the functionality of our Services. We currently do not respond to "Do Not Track" signals from browsers; however, you may opt out of certain tracking as described in Section 8.
We retain your personal information for as long as necessary to provide our Services, fulfill the purposes described in this Privacy Policy, comply with legal obligations, resolve disputes, and enforce our agreements. When personal information is no longer needed, we will securely delete or de-identify it. PHI is retained and disposed of in accordance with HIPAA requirements and applicable state law.
Depending on where you reside, you may have the following rights with respect to your personal information:
To exercise any of these rights, please contact us at privacy@patientprotect.com. We will respond to your request within the timeframe required by applicable law. We may need to verify your identity before fulfilling your request. We will not discriminate against you for exercising your privacy rights.
California residents have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), including the right to know what personal information is collected, the right to delete personal information, the right to opt out of the sale or sharing of personal information (we do not sell personal information), the right to correct inaccurate personal information, and the right to limit the use and disclosure of sensitive personal information. To submit a request, contact us at privacy@patientprotect.com or call our toll-free number listed in Section 15. You may also designate an authorized agent to make a request on your behalf.
Residents of Colorado, Connecticut, Virginia, Texas, and other states with comprehensive privacy laws may have similar rights to access, correct, delete, and opt out of certain processing of their personal information. PatientProtect honors these rights as required by applicable state law. Contact us at privacy@patientprotect.com to submit a request.
PatientProtect implements industry-standard administrative, technical, and physical safeguards designed to protect your personal information from unauthorized access, disclosure, alteration, and destruction. These measures include data encryption in transit and at rest, access controls and authentication requirements, regular security assessments and testing, employee training on data privacy and security, and business continuity and incident response plans.
While we strive to protect your information, no security system is impenetrable. In the event of a data breach that affects your rights or freedoms, we will notify you and applicable regulatory authorities as required by law.
PatientProtect may act as a Business Associate under HIPAA when handling PHI on behalf of Covered Entities such as health plans and healthcare providers. In such cases, our use and disclosure of PHI is governed by our Business Associate Agreements and HIPAA Notice of Privacy Practices, in addition to this Privacy Policy.
Individuals whose PHI is handled through PatientProtect have rights under HIPAA, including the right to access and request amendments to their health records, receive an accounting of disclosures, and file complaints. Please refer to our HIPAA Notice of Privacy Practices for complete information, or contact us at the address in Section 15.
PatientProtect does not use PHI for marketing purposes without your prior written authorization, and we do not sell PHI under any circumstances.
Our Services are not directed to individuals under 18 years of age. We do not knowingly collect personal information from children under 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at privacy@patientprotect.com. If we become aware that we have collected information from a child under 18 without verification of parental consent, we will take prompt steps to delete that information.
Our Services may contain links to third-party websites, applications, or services. This Privacy Policy does not apply to those third parties, and we are not responsible for their privacy practices. We encourage you to review the privacy policies of any third-party services you access through our platform.
Our Services are operated in the United States. If you are accessing our Services from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your jurisdiction. By using our Services, you consent to the transfer and processing of your information in the United States.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you by posting the revised Policy on our website with a new effective date, and we may send you an email notification if we have your contact information. We encourage you to review this Privacy Policy periodically. Your continued use of our Services after any changes indicates your acceptance of the updated Policy.
If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:
PatientProtect, Inc.
Attn: Privacy Officer
13 Palafox Place, Suite 200
Pensacola, FL 32502
Email: privacy@patientprotect.com
Phone: 1-850-898-1410
For PatientProtect-specific privacy inquiries, please include "PatientProtect" in the subject line of your email or communication.
If you are a California resident and wish to submit a request under the CCPA/CPRA, please contact us via the methods above or submit a request at : privacy@patientprotect.com.
This Privacy Policy was last updated on 4/1/2026. PatientProtect, Inc. — www.patientprotect.com