Skip to content

Privacy Policy

Last updated

Template — legal review pending

This document is a working draft prepared for the Lien Hunt launch and has not yet been reviewed or approved by counsel. It is published for transparency about how the product is built, and it is not the final agreement. Passages that need a business or legal decision appear in square brackets. The executed version will replace this page before general availability.

This policy explains what information Lien Hunt collects, why we collect it, who we share it with, and how long we keep it. Protected health information that a practice enters into Lien Hunt is handled separately, and more strictly, than the account information we collect about the practice itself — section 4 covers that distinction.

1.Who this policy covers

Lien Hunt (“Lien Hunt”, “we”, “us”) is practice-management software operated by [legal entity name], [registered address]. This policy applies to the Lien Hunt marketing site at lienhunt.com, the application at app.lienhunt.com, the attorney portal, and our API.

It does not apply to how a medical practice using Lien Hunt handles its own patients’ information. Practices are independent covered entities under HIPAA and publish their own notices of privacy practices. If you are a patient and want to know what your provider holds about you, contact the provider directly.

2.Information we collect

  • Account information. Name, work email address, password (stored only as a salted hash), role, and two-factor authentication enrolment status for each staff or attorney user.
  • Practice information. Legal and trading name, business type, locations, business hours, branding, and tax identification number where a practice chooses to store one.
  • Customer data, including PHI. The patient, accident, case, insurance, treatment, lien, settlement, document and communication records a practice creates in Lien Hunt. This routinely includes protected health information. We process it on the practice’s instructions, as its business associate.
  • Usage and security records. Sign-in events, IP address, browser and device description, session activity, feature usage counts, and the audit-log entries the product writes for every create, update, delete and sensitive-record view.
  • Support communications. Messages, attachments and ticket history when you contact us for help.
  • Billing information. When paid plans launch, subscription and invoice records. Card details are handled by our payment processor; we do not receive or store full card numbers.

3.How we use information

  • To provide, operate, secure and support the service, including authentication, permission checks, notifications and backups.
  • To generate the alerts, dashboards, reports and exports the practice asks for inside its own workspace.
  • To detect, investigate and prevent abuse, fraud and security incidents, and to satisfy our audit obligations.
  • To communicate with you about service changes, security notices, billing and support.
  • To improve the product using aggregated, de-identified usage statistics that cannot be traced back to a patient.

We do not sell personal information, we do not share it with advertising networks, and we do not use protected health information to train machine-learning models.

4.Protected health information and HIPAA

For customer data, the practice is the covered entity and Lien Hunt is its business associate. We will enter into a Business Associate Agreement with every practice that requires one, and that agreement governs our handling of protected health information wherever it is more specific than this policy.

In plain terms: we use PHI only to run the service for the practice that entered it, we restrict access to the smallest number of personnel who need it to operate the platform, every such access is logged, and we do not disclose PHI except as the practice directs or the law requires.

Note that no software product is “HIPAA certified” — no such certification exists. We provide HIPAA-conscious controls intended to support your compliance program; compliance itself remains a shared responsibility.

5.Service providers we rely on

We use a small number of vendors to run Lien Hunt, each under contract and, where they may encounter protected health information, under a Business Associate Agreement:

  • Cloud hosting and managed database services (application servers, database, backups) — United States regions.
  • Transactional email delivery, for verification, password-reset and notification messages. Notification emails are written so that they never contain patient information.
  • Error and performance monitoring, configured to scrub request bodies and identifiers.
  • A payment processor, once paid subscriptions launch.

[A current list of subprocessors will be maintained and linked here.]

6.Security

Data is encrypted in transit with TLS and at rest by our hosting and database providers. Access inside the application is governed by role-based permissions; each practice’s records are separated from every other practice’s by database-enforced row-level security. Staff accounts support app-based two-factor authentication, and a practice can require it organization-wide. Sessions expire on both an idle and an absolute timer, and users can revoke their own sessions.

Every change to a record, and every view of a masked identifier, is written to an append-only audit log with the actor, the timestamp and a field-level before-and-after diff. No security programme is perfect; if a breach affects your data we will notify you without undue delay and within the timeframes our agreements and applicable law require.

7.Retention and deletion

Records deleted inside the application are soft-deleted first, so an accidental deletion can be restored, and permanent deletion requires a documented reason and is itself audited. We retain customer data for as long as the practice’s subscription is active.

After termination, customer data is retained for [30] days so the practice can export it, then deleted from active systems, with encrypted backups ageing out on a rolling [35]-day cycle. Audit-log entries and records we must keep for legal, tax or security reasons are retained for [the period required by law].

8.Your choices and rights

Staff and attorney users can view and correct their own profile, manage two-factor authentication, and see and revoke their active sessions from the application. Practice administrators can export their organization’s data at any time in CSV, XLSX or PDF form.

Requests from patients to access, correct or delete their health information should go to the treating practice, which is the covered entity holding that record; we will support the practice in responding. For information Lien Hunt holds about you directly — for example your staff account — contact [email protected]. Depending on where you live you may have additional rights, including under [applicable state privacy laws].

9.Cookies and tracking

Lien Hunt uses strictly necessary cookies only: a session cookie to keep you signed in and a security token to protect form submissions. Your light or dark theme preference is stored in your browser, not on our servers. We do not run advertising trackers, and the fonts and scripts the site needs are served from our own domains rather than a third-party network.

10.Children

Lien Hunt is a workplace tool and is not directed to children. Staff accounts are for adults. A practice may of course treat, and therefore record information about, minor patients; that information is customer data under section 4 and is handled under the practice’s own authority and its Business Associate Agreement with us.

11.Where your data is processed

Lien Hunt is hosted in the United States and customer data is processed there. If we ever process data elsewhere we will update this policy and put an appropriate transfer mechanism in place first.

12.Changes to this policy

We will post any revised version on this page with a new “last updated” date, and for material changes we will notify practice administrators by email or in the application at least [30] days before the change takes effect.

13.Contact us

Privacy questions, requests and complaints: [email protected]. General enquiries: [email protected]. Postal address: [legal entity name, registered address]. [A named privacy officer and, if required, a HIPAA security officer will be listed here.]