SettleTrack, LLC (“SettleTrack,” “we,” “us,” or “our”) is committed to protecting the privacy of our customers and their end users. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use the SettleTrack platform. This Privacy Policy is provided for informational purposes and is subject to, and governed by, the terms of your Customer agreement and any applicable Business Associate Agreement. Please read this policy carefully.
1. Information We Collect
Account Information: When you register for SettleTrack, we collect information such as your name, organization name, email address, phone number, job title, and billing details necessary to provision and maintain your account.
Usage Data: We automatically collect information about how you interact with the platform, including IP addresses, browser type, pages visited, features used, time spent, and actions taken within the application. This data is used for security monitoring, platform improvement, troubleshooting, capacity planning, billing verification, compliance, and other legitimate business operations.
Case and Clinical Data: As part of the core service, authorized users may input case information including patient identifiers, medical records, legal correspondence, and billing data. This information may constitute Protected Health Information (“PHI”) and is handled in accordance with our HIPAA obligations and the applicable Business Associate Agreement.
2. How We Use Your Information
We use the information we collect to: (a) provide, operate, and maintain the SettleTrack platform; (b) process transactions and send related administrative communications; (c) respond to support requests and inquiries; (d) send product updates, security notices, and other service-related communications; (e) monitor platform usage for security, fraud prevention, and compliance; and (f) improve the platform based on aggregated, de-identified analytics.
We will not use your organization's case or patient data for any purpose other than providing the contracted Service unless required by law or expressly authorized by you in writing.
3. HIPAA & Protected Health Information
SettleTrack is designed to support HIPAA-covered entities and their business associates in managing PHI in compliance with federal and state law. Where applicable, SettleTrack acts as a Business Associate and executes a Business Associate Agreement (“BAA”) with each Customer prior to any PHI processing.
PHI stored on the platform is encrypted at rest using industry-standard encryption (currently AES-256) and in transit using TLS 1.2 or higher, or such successor protocols as meet then-current industry standards. Access to PHI is restricted to authorized personnel and is governed by role-based access controls. All PHI access events are logged in a tamper-evident audit trail retained for a minimum of six (6) years in accordance with HIPAA requirements.
SettleTrack will not sell, lease, or otherwise monetize PHI. PHI will only be disclosed as permitted under the applicable BAA and HIPAA regulations, including for treatment, payment, or healthcare operations as directed by the Covered Entity.
4. Data Security
We implement and maintain comprehensive administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of all data processed through the platform. Our security program may include measures such as: encryption at rest and in transit, multi-factor authentication, automatic session timeouts, role-based access controls, continuous security monitoring, vulnerability management, and periodic third-party penetration testing.
In the event of a confirmed data breach involving PHI, SettleTrack will notify affected Customers within the timeframes required by applicable law, including HIPAA's Breach Notification Rule and relevant state breach notification statutes, following SettleTrack’s reasonable determination that a qualifying breach has occurred.
5. Data Retention
SettleTrack retains Customer data for the duration of the active subscription period and for a post-termination retention period as specified in the Customer agreement, typically ninety (90) days. Upon expiration of the retention period, data is securely deleted from production systems in accordance with NIST SP 800-88 media sanitization guidelines, and from backups in the ordinary course of backup rotation cycles.
Audit logs and de-identified usage analytics may be retained for longer periods as required by law or for legitimate security and operational purposes. Customers may request early deletion of their data subject to applicable legal holds, contractual obligations, and a reasonable processing period of up to thirty (30) days.
6. Third-Party Services
SettleTrack may engage trusted sub-processors and third-party service providers to support platform operations, including cloud infrastructure providers, payment processors, email delivery services, and security monitoring tools. All sub-processors are contractually bound to maintain confidentiality and comply with applicable data protection laws.
Where PHI is involved, all sub-processors with access to PHI enter into appropriate Business Associate Agreements before any data is shared. A current list of sub-processors is available to Customers upon request by contacting support@settletrack.io.
7. Cookies and Tracking
SettleTrack uses strictly necessary session cookies to maintain authenticated sessions. These cookies are HTTP-only and secure, meaning they cannot be accessed by client-side scripts and are only transmitted over encrypted connections. No PHI is stored in cookies.
We do not use third-party advertising cookies or behavioral tracking technologies. We may use limited first-party analytics to understand aggregate platform usage patterns. You can configure your browser to refuse cookies, but doing so may prevent you from using certain features of the Service.
8. Your Rights
Depending on your jurisdiction, you or your organization may have rights with respect to personal data we hold about you, including the right to access, correct, delete, or restrict processing of your data. With respect to case and clinical data, your organization is the responsible party (data controller), and SettleTrack processes such data solely on its behalf. Requests relating to PHI must be directed to the applicable Covered Entity (your organization), which is responsible for honoring patient rights under HIPAA.
To exercise any privacy rights related to your account or organization data, please contact us at support@settletrack.io. We will respond to verifiable requests within the timeframes required by applicable law, and in any event no later than forty-five (45) days, subject to permitted extensions. Certain requests may be subject to legal limitations or our contractual obligations with your organization.
9. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify Customers of material changes by email to the primary account administrator and by posting an updated notice on the platform at least thirty (30) days before the changes take effect.
Your continued use of the Service following the effective date of any update constitutes your acceptance of the revised Privacy Policy, except where changes materially affect the handling of PHI, in which case we will obtain affirmative acknowledgment from affected Customers. We encourage you to review this policy periodically.
10. Governing Law; Venue and Jurisdiction
THIS PRIVACY POLICY SHALL BE GOVERNED BY AND CONSTRUED IN ACCORDANCE WITH THE LAWS OF THE STATE OF DELAWARE, WITHOUT REGARD TO ITS CONFLICT OF LAW PRINCIPLES OR ANY SUBSTANTIVE LAW THAT WOULD RESULT IN THE APPLICATION OF ANY LAW OTHER THAN THE STATE OF DELAWARE. EACH PERSON HERETO (I) IRREVOCABLY SUBMITS TO THE EXCLUSIVE JURISDICTION OF (A) KENT COUNTY AND (B) THE UNITED STATES DISTRICT COURTS FOR THE DISTRICT OF DELAWARE, AS WELL AS TO THE JURISDICTION OF ALL COURTS FROM WHICH AN APPEAL MAY BE TAKEN FROM SUCH COURT(S), FOR THE PURPOSE OF ANY ACTION, SUIT OR OTHER PROCEEDING WHICH IS BROUGHT BY A PARTY OR ITS SUCCESSOR AND ASSIGNS, ARISING OUT OF THIS AGREEMENT, AND (II) HEREBY IRREVOCABLY AGREES THAT ALL CLAIMS IN RESPECT OF ANY SUCH ACTION SUIT OR PROCEEDING MAY BE HEARD AND DETERMINED IN ANY SUCH COURT(S), (III) AGREES NOT TO COMMENCE ANY ACTION, SUIT OR PROCEEDING OF ANY KIND OR TYPE RELATING TO THIS AGREEMENT EXCEPT IN SUCH COURT(S), AND (IV) TO THE FULLEST EXTENT PERMITTED BY APPLICABLE LAW, HEREBY WAIVES, AND AGREES NOT TO ASSERT AS A DEFENSE OR OTHERWISE IN ANY SUCH ACTION, SUIT OR PROCEEDING ANY CLAIM THAT IT IS NOT PERSONALLY SUBJECT TO THE JURISDICTION OF ANY SUCH COURT(S), THAT THE ACTION, SUIT OR PROCEEDING IS BROUGHT IN AN INCONVENIENT FORUM, OR THAT THE VENUE OF THE ACTION, SUIT OR PROCEEDING IS IMPROPER. EACH PARTY HEREBY WAIVES ALL RIGHTS OF ANY OTHER JURISDICTION WHICH IT MAY NOW OR HEREAFTER HAVE BY REASON OF ITS PRESENT OR SUBSEQUENT RESIDENCE OR DOMICILE.
11. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
SettleTrack, LLC
Email: support@settletrack.io