MedEffects

MedEffects Privacy Policy

Effective date: September 8, 2026

Last updated: September 8, 2026

This Privacy Policy explains how MedEffects LLC (MedEffects, we, us, or our) collects, uses, discloses, and protects information through medeffectsllc.com and the MedEffects web, iOS, and Android applications and related support and business services (collectively, the Services).

The Services are a business-to-business platform for authorized healthcare practices, independent sales representatives, and MedEffects personnel. They support insurance verification requests (IVRs), product orders, shipments, invoices, statements, and payments. The Services are not a patient portal and are not directed to consumers seeking medical care.

1 Important information about HIPAA and patient data

Healthcare practices may submit patient names, Medicare Beneficiary Identifiers, other insurance information, eligibility information, and related documents. This information may be protected health information (PHI) under the Health Insurance Portability and Accountability Act and its implementing regulations (HIPAA).

When MedEffects creates, receives, maintains, or transmits PHI for a HIPAA covered entity or business associate, MedEffects acts as a business associate and handles that PHI under HIPAA and the applicable Business Associate Agreement (BAA). The BAA controls if it conflicts with this Privacy Policy concerning PHI. This Privacy Policy is not a healthcare provider's Notice of Privacy Practices, a patient authorization, or a substitute for a BAA.

The healthcare practice generally controls its patient records and is the appropriate contact for a patient seeking access, correction, restriction, an accounting, or another HIPAA right. If MedEffects receives a patient request concerning PHI held for a practice, MedEffects will direct or transmit the request to the practice unless law or the applicable BAA requires a different response.

2 Scope and roles

This Policy applies to information MedEffects handles through the Services and related support. It does not govern an independent third party's website, service, or privacy practice.

MedEffects LLC is responsible for the general privacy practices described here. Rockbound Solutions, LLC provides technology and platform services to MedEffects. Healthcare practices remain responsible for their own collection and use of patient information and for notices and choices they are legally required to provide.

3 Information we collect

3.1 Account and professional information

We collect name, business email address, business phone number, job title, professional role, practice or company affiliation, account status, user permissions, and authentication information. Passwords are stored in a protected hashed form rather than readable plain text.

3.2 Practice provider and representative records

We collect practice and billing contact details, addresses, provider information, sales-representative assignments, and related account and relationship records. Some clinic or customer records may be synchronized with Intuit QuickBooks.

3.3 Patient insurance and IVR information

Authorized users may submit patient names, dates of birth or other identity data when required, Medicare Beneficiary Identifiers or other member and policy identifiers, payer and plan information, provider and practice information, uploaded insurance documents, and information needed to request eligibility or benefit verification. We receive IVR responses, coverage indicators, payer messages, reference numbers, and status or review notes. This information may be PHI and sensitive personal information.

3.4 Orders shipments invoices and payments

We collect products, sizes, quantities, order dates, patient or practice associations, providers, representatives, delivery details, order notes, approvals, status, vendor and carrier information, shipment tracking, invoices, balances, statements, credits, payment status, and transaction identifiers.

When payment functionality is available, bank-account or other payment information may be collected directly by Intuit or another payment processor under its privacy notice and terms. MedEffects generally receives transaction status, account descriptors, authorization records, and processor identifiers rather than full bank credentials. Do not enter payment credentials outside the designated payment flow.

3.5 Files and communications

We collect documents or images an authorized user uploads, support requests, emails, feedback, and other communications. Users should include PHI only in fields and secure channels designated for that purpose.

3.6 Device usage and audit information

We and our service providers automatically collect information needed to operate and secure the Services, such as IP address, browser and device type, operating system, app version, timestamps, session and authentication events, pages or features used, searches, submissions, changes, approvals, downloads, errors, crash or diagnostic data, and audit-log events. We may infer approximate location from an IP address for security and fraud prevention, but we do not collect precise device geolocation unless a feature clearly requests permission and you choose to grant it.

3.7 Website technologies

We use cookies, local storage, tokens, and similar technologies that are necessary for sign-in, security, preferences, session continuity, and Service operation. We do not use third-party advertising networks or cross-context behavioral advertising trackers in the Services, and we do not use PHI for advertising.

3.8 Information from other sources

We receive information from the healthcare practice or other Organization that creates or administers an account; authorized representatives and MedEffects personnel; pVerify and other eligibility sources; Intuit QuickBooks and payment services; vendors, suppliers, and carriers; and security, hosting, and support providers. We may also receive public or commercial business contact information for relationship management, subject to applicable law.

4 Why we use information

We use information to:

We use PHI only as permitted by the applicable BAA, HIPAA, and other applicable law. We apply role-based access and the minimum-necessary standard where it applies. We do not transmit patient identifiers to QuickBooks when creating practice invoices.

5 Legal bases where applicable

Where a law requires a legal basis, we process information as necessary to perform a contract or take requested steps; comply with legal obligations; pursue legitimate interests such as providing and securing a business service, preventing fraud, and managing customer relationships; protect a person's vital interests; or act with consent. PHI is processed under HIPAA and the applicable BAA. Consent may be withdrawn where consent is the basis, without affecting prior lawful processing.

6 How we disclose information

We do not sell personal information. We do not share personal information for cross-context behavioral advertising or use PHI for marketing.

We disclose information only as reasonably necessary for the purposes below and subject to contractual, legal, and technical safeguards appropriate to the information.

6.1 Organizations and authorized users

Information is available to the applicable practice or other Organization and its authorized administrators and users according to role and need. Authorized MedEffects personnel and representatives may access information needed to review IVRs, fulfill orders, resolve billing or support issues, secure the Services, and perform assigned duties. An Organization may be able to review its users' activity and audit records.

6.2 Service providers and HIPAA subcontractors

We use service providers to operate the Services. Depending on the feature, these include:

Providers may change as the Services evolve. They may process information only for the contracted service or as law permits. When a provider creates, receives, maintains, or transmits PHI on our behalf and qualifies as a HIPAA subcontractor, we require a written agreement with applicable HIPAA protections.

6.3 Payers and eligibility networks

We transmit the minimum information reasonably necessary for an authorized IVR to applicable eligibility sources, payers, plans, clearinghouses, or their contractors and return the result to authorized users.

6.4 Vendors carriers and transaction parties

We disclose order and delivery information to product vendors, suppliers, and carriers as needed to fulfill and track authorized orders. We disclose invoice and payment information to processors, financial institutions, and accounting providers as needed to complete and reconcile transactions. Patient identifiers are not included in QuickBooks practice invoices.

6.5 Legal safety and rights

We may disclose information when required by law, legal process, or a regulator; to protect patients, users, MedEffects, or others; to investigate fraud, security incidents, or violations; or to establish, exercise, or defend legal claims. When PHI is involved, we apply HIPAA, the BAA, and other applicable restrictions.

6.6 Corporate transactions

Information may be disclosed under appropriate safeguards in connection with due diligence, financing, reorganization, merger, acquisition, bankruptcy, or sale of all or part of a business. Any successor remains subject to applicable law, BAAs, and this Policy for information it receives.

6.7 At your direction

We may disclose information when an authorized user or Organization directs us to do so and the disclosure is permitted by law and applicable agreements.

7 Deidentified and aggregated information

Where permitted by the applicable BAA and law, we may create information that is de-identified under HIPAA or otherwise reasonably cannot be linked to an individual. We may use and disclose properly de-identified or aggregated information for lawful purposes such as analytics, security, capacity planning, and improving operations. We do not attempt to re-identify properly de-identified information.

8 Data security

We maintain administrative, physical, and technical safeguards designed to protect information, including encryption in transit, access controls, audit logging, role-based permissions, security monitoring, workforce safeguards, and incident-response processes. Safeguards are reviewed in light of the sensitivity of the information and reasonably anticipated risks. No system can be guaranteed completely secure.

Users and Organizations also play an essential role. They must maintain accurate access lists, protect credentials and devices, follow approved channels, train personnel, use only the minimum necessary PHI, and promptly report suspected incidents to support@medeffectsllc.com and the applicable Organization administrator.

9 Data retention and deletion

We retain information for no longer than reasonably necessary for the purposes described in this Policy, subject to the applicable BAA, Organization agreement, legal holds, and law. Retention depends on the record and may include:

When retention ends, we delete, destroy, de-identify, or return information using measures appropriate to its sensitivity and applicable agreements. Backup copies may persist for a limited period until overwritten or isolated from routine use. A deletion request does not require deletion of information that we or the applicable practice must retain or that is needed for security, fraud prevention, claims, or legal compliance.

10 Privacy choices and rights

10.1 Account information and communications

Authorized users may review or update certain profile information in the App or contact support. Transactional and security communications are necessary for the Services. You may use an unsubscribe link for optional marketing messages, if any, but will continue to receive necessary business communications.

10.2 Account deactivation and deletion

An Organization administrator may request deactivation of a business account. Individual requests may be submitted through the MedEffects account-deletion request page or to support@medeffectsllc.com. We will verify and process a request subject to the Organization's instructions, the BAA, required record retention, legal holds, and other applicable law.

10.3 Patient rights concerning PHI

Patients should contact the healthcare practice that submitted or controls their information. The practice is generally responsible for HIPAA requests and its Notice of Privacy Practices. MedEffects will assist as required by the applicable BAA and HIPAA.

10.4 United States state privacy rights

Depending on residence and whether an applicable law covers the information and MedEffects, a person may have rights to confirm processing; access, correct, or delete personal information; receive a portable copy; opt out of sale, targeted advertising, or certain profiling; limit certain uses of sensitive personal information; obtain information about disclosures; appeal a decision; and not receive discriminatory treatment for exercising a right.

We do not sell personal information or share it for cross-context behavioral advertising. Many state privacy laws exempt PHI governed by HIPAA and may exempt other information maintained by healthcare entities. These exemptions do not affect rights that apply under HIPAA or another law.

Submit a request or appeal to support@medeffectsllc.com or the account-deletion page above. We will verify identity and authority. An authorized agent may submit a request when permitted, but we may require proof of authority and identity verification. If we deny an appeal, we will provide any further complaint method required by applicable law.

10.5 California notice at collection

We collect the following categories of personal information for the business purposes described in Sections 3 and 4: identifiers and contact information; professional and employment-related information; account and authentication information; commercial, order, invoice, payment-status, and transaction information; internet, device, usage, and audit activity; approximate geolocation inferred from IP address; communications and uploaded content; and sensitive personal information, including account credentials and patient health and insurance identifiers when submitted by an authorized user. We retain each category as described in Section 9. We do not sell or share these categories for cross-context behavioral advertising. Collection of PHI and other medical information may be exempt from the California Consumer Privacy Act when governed by HIPAA or other specified healthcare laws.

11 Mobile device permissions

An iOS or Android feature may request permission to use a camera or photo library when an authorized user chooses to upload a document or image. The feature accesses only the content the user selects or captures for the authorized workflow. Device settings can revoke permission, although doing so may disable the feature. We do not access contacts, microphone, precise location, or other device resources unless a feature clearly requests permission and the user chooses to grant it.

12 Children

The Services are for authorized business users age 18 or older and are not directed to children. A healthcare practice may submit PHI about a minor patient when legally authorized and necessary for the permitted healthcare workflow. Such PHI is handled under HIPAA, the applicable BAA, and other law. We do not knowingly create App accounts for children.

13 United States processing

The Services are operated in the United States, and information is processed and stored in the United States. The Services are not offered for use outside the United States unless MedEffects expressly agrees in writing. A user accessing from another location is responsible for ensuring that the transfer and use are lawful.

14 Third party links and services

The Services may link to or interoperate with third parties. Their independent collection and use are governed by their own privacy notices. Review those notices before providing information directly to a third party. A third party acting as our service provider remains subject to its contract with us, and HIPAA subcontractor obligations apply when required.

15 Changes to this Policy

We may update this Policy to reflect changes in the Services, law, or practices. We will post the revised Policy with a new last-updated date and provide additional notice when required. If a change materially affects PHI, we will comply with the applicable BAA and HIPAA. Prior versions will be retained as reasonably necessary to document the notice in effect.

16 Contact and complaints

Questions, privacy requests, appeals, or complaints may be sent to:

MedEffects Privacy

Email: support@medeffectsllc.com

We will not retaliate against a person for making a good-faith privacy complaint or exercising a legal right. A patient may also contact the applicable healthcare practice. Where HIPAA applies, a person may file a complaint with the United States Department of Health and Human Services Office for Civil Rights.

Current mailing address
MedEffects LLC
PO Box 42
St Clair, MI 48079