Privacy Policy
Effective Date: May 20, 2026
1. Introduction
MediRescue ("we," "our," or "us") is committed to protecting the privacy of our patients, website visitors, and all individuals whose personal information we handle. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, use our telehealth platforms, book appointments, or receive medical services from us.
We comply with applicable privacy laws, including the Health Insurance Portability and Accountability Act (HIPAA) where relevant, and we treat all personal health information with the highest degree of confidentiality.
2. Information We Collect
We may collect the following categories of personal information:
- Identity & Contact Information: Full name, date of birth, email address, phone number, home address, emergency contact details, and government-issued identification numbers when required for medical records.
- Health & Medical Information: Medical history, current medications, allergies, diagnostic reports, treatment plans, physician notes, laboratory results, and imaging studies. This includes Protected Health Information (PHI) under HIPAA.
- Payment & Insurance Data: Credit card numbers, billing addresses, insurance policy and group numbers, and claims history — processed securely through encrypted channels.
- Technical & Usage Data: IP address, browser type, device identifiers, operating system, pages visited, time spent on pages, and referring website addresses. Collected automatically via cookies and similar technologies.
- Communication Records: Emails, chat logs, call recordings (when disclosed), and messages sent through our patient portal or contact forms.
3. How We Use Your Information
We use the collected information for the following purposes:
- To provide, coordinate, and manage your healthcare services and treatment.
- To process payments, verify insurance coverage, and manage billing and claims.
- To communicate with you about appointments, test results, follow-up care, and health-related reminders.
- To personalize your experience on our website and improve our content and service offerings.
- To send you newsletters, health tips, and promotional materials if you have opted in to receive such communications. You may unsubscribe at any time.
- To comply with legal obligations, respond to lawful requests, and protect the rights and safety of our patients and staff.
- To analyze aggregated, de-identified data for research, quality improvement, and public health reporting.
4. How We Share Your Information
We do not sell your personal information. We may share your information only under these circumstances:
- Treatment & Healthcare Operations: With other healthcare providers, laboratories, imaging centers, and specialists involved in your care. This includes referrals and care coordination.
- Payment & Billing: With your health insurance company, billing clearinghouses, and collection agencies as necessary to process claims and payments.
- Service Providers: With trusted third-party vendors who perform services on our behalf, such as appointment scheduling software, secure messaging platforms, and cloud hosting — bound by strict data processing agreements.
- Legal & Regulatory Requirements: When required by law, court order, or governmental authority, or to report vital statistics, communicable diseases, or abuse as mandated.
- With Your Consent: We will obtain your explicit consent before sharing your information for any purpose not covered by this policy.
5. HIPAA & Protected Health Information (PHI)
As a healthcare provider, we are bound by HIPAA regulations concerning Protected Health Information. Our Notice of Privacy Practices provides detailed information about your rights under HIPAA, including:
- The right to access and obtain a copy of your medical records.
- The right to request corrections to your health information.
- The right to receive an accounting of disclosures of your PHI.
- The right to request restrictions on certain uses and disclosures.
- The right to receive confidential communications through alternative means.
A copy of our HIPAA Notice of Privacy Practices is available at our facility and upon request. Please contact our Privacy Officer for more information.
6. Cookies and Tracking Technologies
Our website uses cookies, web beacons, and similar technologies to enhance your browsing experience, analyze site traffic, and understand how you interact with our content. You can control cookie preferences through your browser settings. Disabling certain cookies may affect website functionality.
We use both session cookies (which expire when you close your browser) and persistent cookies (which remain on your device for a set period). We may also use third-party analytics services like Google Analytics, which collect anonymized data about site usage.
7. Data Security
We implement a comprehensive set of administrative, technical, and physical safeguards to protect your personal information against unauthorized access, alteration, disclosure, or destruction. Measures include:
- 256-bit SSL/TLS encryption for data in transit.
- Firewalls, intrusion detection systems, and regular security assessments.
- Role-based access controls and multi-factor authentication for sensitive systems.
- Staff training on privacy and security policies.
- Secure, access-controlled data centers for physical records.
While we strive to use commercially acceptable means to protect your data, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.
8. Data Retention
We retain your personal information for as long as necessary to fulfill the purposes outlined in this policy, unless a longer retention period is required by law. Medical records are retained in accordance with state and federal regulations, typically for a minimum of seven to ten years after the last patient encounter.
9. Your Rights and Choices
Depending on your jurisdiction, you may have the right to:
- Request access to the personal data we hold about you.
- Request correction of inaccurate or incomplete data.
- Request deletion of your data, subject to legal retention requirements.
- Opt-out of marketing communications at any time by clicking the "unsubscribe" link in our emails or contacting us directly.
- File a complaint with a supervisory authority if you believe your privacy rights have been violated.
To exercise any of these rights, please contact us using the details below. We will respond to verifiable requests within the timeframe required by applicable law.
10. Children's Privacy
We do not knowingly collect personal information from children under the age of 13 without parental consent. If we become aware that a child under 13 has provided us with personal data, we will take steps to delete such information. For pediatric patients, information is collected with the authorization of a parent or legal guardian.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal obligations. The updated version will be posted on this page with a revised "Effective Date." We encourage you to periodically review this policy to stay informed about how we protect your information.
12. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our Privacy Officer:
- Email: privacy@medirescue.health
- Phone: 1-800-555-1234
- Postal Address: MediRescue Privacy Office, 1200 Medical Center Drive, Suite 100, New York, NY 10001