UPayBill Privacy Policy
Health Document Viewing & E-Signature Platform
06/15/2026 Effective Date
06/15/2026 Last Updated
1. Introduction and Scope
This Privacy Policy explains how UPayBill, Inc. ("we," "us," or "our") collects, uses, stores, and discloses your personal information, including Protected Health Information (PHI), when you use our website/platform (the "Service").
Because this Service facilitates the display of sensitive health records and the execution of legal documents, we take the protection of your privacy extremely seriously. Your use of our platform implies that you have read, understood, and agree to the terms set forth in this Privacy Policy and our associated Terms of Use.
A. Data Covered by This Policy: This policy applies to all data collected through both administrative delivery documentation (e-signatures) and the display/storage of pre-existing PHI documents.
2. Information We Collect
We collect several categories of information necessary for the proper function, security, and legal compliance of the Service.
A. Identifying and Contact Information:
* Name and aliases.
* Physical mailing address and email address.
* Phone numbers.
* Billing or insurance details.
B. Protected Health Information (PHI): When you upload, view, or interact with documents containing PHI, we may collect the following information:
* Diagnosis codes and descriptions.
* Treatment history and notes.
* Medical record numbers.
* Physician/Provider names and identifiers.
* Any other health-related data presented in the signed document display.
C. Signature Data (Electronic Records):
* The electronic capture of your signature (both digital image and metadata proof of signing, including time stamps and IP address).
* Information indicating your intent to agree or acknowledge documents.
D. Technical Usage Data:
* IP addresses, operating system details, and browser types.
* Pages viewed, time spent on site, and referral sources (collected via cookies and similar tracking technologies).
3. How We Use Your Information (The Purpose)
We use the collected information for specific, necessary purposes:
A. Providing Services: To display documents you have agreed to review, process signed delivery documentation, and manage your user account.
B. Legal Compliance & Security:
* To maintain an auditable record of who signed what, when, and where (required by HIPAA/HITECH regulations).
* To enforce our Terms of Use and investigate potential security breaches or misuse of the platform.
* To comply with applicable laws, regulations, and legal process (e.g., court orders).
C. Improvement: We may aggregate usage data to improve the functionality, user experience, and overall security architecture of our Service.
*Crucially, we DO NOT use PHI or your signed documents for marketing purposes without explicit, separate consent.
4. Disclosure and Sharing of Information (The "Who")
We treat all personal information as strictly confidential. We will not sell your data. We may share data only in the following limited circumstances:
A. Service Providers/Business Associates: We use third-party vendors (e.g., cloud hosting providers, payment processors, document storage services) to operate our Service. These third parties are contractually obligated to treat your data as if it were our own and must adhere to stringent privacy and security standards, including signing a Business Associate Agreement (BAA) compliant with HIPAA requirements.
B. Legal Requirements: If required by law, subpoena, or valid legal process, we may disclose your information to government agencies or legal authorities.
C. Operational Necessity: Information may be shared with the healthcare provider or entity that originally submitted the PHI document for viewing/signing purposes.
5. Data Security and Protection (The Safeguards)
Given the highly sensitive nature of PHI, we employ robust security measures to protect your data from loss, misuse, unauthorized access, disclosure, alteration, and destruction. These safeguards include:
* Technical Measures: Encryption is used for all PHI and signature data both in transit (when moving over the internet via SSL/TLS) and at rest (when stored on our servers).
* Physical Measures: Our physical infrastructure housing data is secured with restricted access controls.
* Organizational Measures: We implement rigorous internal policies, including mandatory staff training on HIPAA compliance and role-based access controls (meaning employees only access the minimum amount of data necessary to perform their job function).
*Compliance Note: We are committed to complying with the standards set forth by HIPAA, HITECH Act, and relevant state privacy laws.
6. Data Retention and Disposal
We retain your personal information and PHI for as long as is necessary to fulfill the purposes outlined in this Policy, including meeting legal obligations (e.g., retaining signed documents and audit trails for a minimum period required by law).
When data is no longer needed or legally required, we will securely dispose of it using industry best practices, ensuring that it is permanently anonymized or deleted from all systems.
7. User Rights and Choices
You retain certain rights regarding your personal information:
A. Right to Access: You have the right to request access to the PHI and records associated with your account.
B. Right to Correction: If you discover that any PHI we hold is inaccurate or incomplete, you may notify us, and we will take reasonable steps to correct it in accordance with regulatory standards.
C. Right to Deletion (Right to Be Forgotten): You can request the deletion of your account information. However, please note that due to legal compliance requirements related to signed documents and medical records, we may be legally unable to delete certain transaction-critical data (e.g., the record that you executed Document X on Date Y).
8. Third-Party Links and Policy Changes
A. Third Parties: Our Service may contain links to external websites (e.g., payment processors, insurer portals). These third parties are governed by their own privacy policies, and we recommend reviewing those directly.
B. Policy Modifications: We reserve the right to modify this Privacy Policy at any time. We will notify you of material changes via email or a prominent notice on the Service. Continued use of the Service after these changes constitutes your acceptance of the updated policy.
9. Contact Information
If you have any questions or concerns regarding this Privacy Policy, our data practices, or if you suspect a breach, please contact us immediately:
UPayBill, Inc.
Attention: Data Protection Officer/Privacy Team
6840 Carothers Pkwy Ste 430
Franklin, TN 37067
(615) 333-1900 Office
admin@upaybill.com