Privacy Policy
MEDSYNC ("we," "us," or "our") provides remote healthcare staffing and administrative services to healthcare providers across the United States and United Kingdom. This Privacy Policy explains how we collect, use, safeguard, and disclose information when you visit our website or engage our services.
Information we collect
- Information you provide: name, email, phone number, practice details, and any message content you submit through our contact or appointment forms.
- Usage information: basic analytics such as pages visited and device or browser type, collected to improve the site.
- Protected Health Information (PHI): when we deliver services, we may process PHI strictly on behalf of the covered entity under a Business Associate Agreement (BAA).
How we use information
- To respond to inquiries and schedule consultations.
- To deliver, maintain, and improve our staffing and administrative services.
- To comply with legal, regulatory, and contractual obligations.
HIPAA & data protection
We handle PHI in accordance with HIPAA and, where applicable, the UK GDPR and Data Protection Act 2018. All data is transmitted and stored using encryption, access is limited on a need-to-know basis, and our personnel complete privacy and security training. We do not retain PHI on local devices.
Sharing & disclosure
We do not sell your personal information. We share information only with service providers who support our operations under confidentiality obligations, or where required by law or to fulfill a BAA with a client.
Your rights
You may request access to, correction of, or deletion of the personal information we hold about you, subject to legal and contractual limits. To exercise these rights, contact us at Contact@medsyncplus.com.
Data retention
We keep personal information only as long as necessary for the purposes described here or as required by law and our client agreements, after which it is securely deleted.