Privacy Policy

Privacy Policy

Last Updated: March 29, 2026

This Privacy Policy describes how HIPAABank, LLC d/b/a MedEx ("MedEx," "we," "our," or "us") collects, uses, discloses, and protects information when you use MedEx services, including onboarding, account, billing, messaging, reminder, calendar, and related practice communications services.

1. Scope and Role

MedEx provides services to healthcare practices and related organizations. Depending on the service, MedEx may act as a service provider and/or Business Associate under HIPAA. Where required, service is governed by a Business Associate Agreement (BAA) and applicable law.

2. Information We Collect

  • Account and admin data: administrator name, email, phone, credentials, organization details.
  • Practice configuration data: providers, facilities, service selections, callback URLs, integration metadata.
  • Message and delivery data: communication destination, send status, delivery outcomes, opt-out events.
  • Security and fraud prevention data: IP address, timestamps, user-agent/device metadata, verification events, rate-limit and abuse indicators.
  • Billing and transaction data: subscription and transaction identifiers, invoice/receipt details, payment status.
  • Support and operations data: support requests, troubleshooting logs, and service diagnostics.

3. How We Use Information

  • Provide, secure, and operate MedEx services.
  • Verify administrator identity during onboarding (including one-time passcode workflows).
  • Process subscriptions, usage billing, receipts, and account notices.
  • Send operational communications required to run your account and contracted services.
  • Prevent abuse, fraud, and unauthorized use (including throttling, monitoring, and block controls).
  • Comply with legal, contractual, and regulatory obligations.

4. Communications, Consent, and Opt-Out

We send onboarding, account, billing, and service-operational messages by email and, when enabled, SMS or voice. You are responsible for collecting and maintaining any patient-facing or end-user consent required by law for messages sent on your behalf.

  • Operational/account notices are considered service-related and may be required to maintain your account.
  • Marketing communications, if any, include unsubscribe instructions.
  • SMS recipients may opt out using standard opt-out keywords supported by the applicable delivery channel.
  • We honor suppression/opt-out records in our systems and apply them to applicable message flows.

5. Disclosures and Service Providers

We disclose information only as needed to provide services, perform contracted functions, or comply with law. This includes infrastructure, communications delivery, and payment-processing providers. We do not sell protected health information (PHI).

Where PHI is involved, disclosures follow HIPAA requirements, including the minimum necessary standard, applicable agreements, and required safeguards.

6. Payment Processing

Payment card processing is performed by PCI-compliant payment processors integrated with MedEx billing workflows. MedEx does not store full primary account numbers (full card numbers). Transaction metadata necessary for billing, reconciliation, fraud prevention, and receipts is retained.

7. Security

We use administrative, technical, and physical safeguards designed to protect information against unauthorized access, use, alteration, and disclosure. Controls include access management, encryption in transit, logging/monitoring, and operational security controls appropriate to service risk and legal requirements.

8. Retention

We retain information for as long as needed to provide services, support customer operations, enforce agreements, resolve disputes, and satisfy legal/regulatory obligations. Retention periods may vary by data type (for example, billing records, audit/security logs, and support records).

9. Your Choices and Rights

Practice administrators may request access, correction, or deletion of account data where legally permitted. Some data may be retained when required by law, contract, audit, fraud prevention, or security obligations.

10. Cross-Border and U.S. Processing

MedEx services are operated primarily for U.S.-based healthcare workflows. Data may be processed in systems located in the United States or other jurisdictions used by our authorized service providers, subject to applicable legal and contractual safeguards.

11. Children

MedEx is a business platform for healthcare organizations and is not directed to children under 13. We do not knowingly collect personal information directly from children through consumer-facing workflows.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material updates will be posted on this page with a revised "Last Updated" date. Continued use of the services after an update means the updated policy applies.

13. Contact

If you have questions about this Privacy Policy or MedEx privacy practices, contact:
MedEx Support
Email: support@medexbank.com