HIPAA & Health Data Note
This Privacy Policy governs general website visitors and prospective business inquiries. Any Protected Health Information (PHI) or electronic PHI (ePHI) processed in connection with professional consulting engagements, Business Associate Agreements (BAAs), or Security Risk Assessments (SRAs) is strictly governed by our Master Services Agreement and applicable HIPAA Privacy and Security Rules.
1. Overview & Scope
Managed Compliance Group ("MCG," "we," "us," or "our") respects your privacy and is committed to protecting the personal and business information collected through our website and administrative services. This Privacy Policy describes how we collect, use, maintain, and safeguard information obtained from visitors, clients, and prospective clients.
2. Information We Collect
We collect information in two main categories: information you provide directly to us and information collected automatically through technical interaction with our platform.
A. Information Provided Directly
- Contact & Consultation Inquiries: Full name, professional email address, phone number, practice/organization name, and details regarding your compliance inquiry or requested assessment.
- Business Communications: Correspondence, administrative feedback, and questionnaire responses submitted through our online portals or direct email.
B. Technical & Usage Information
- Log & Device Data: IP address, browser type, operating system, referring URLs, access times, and pages viewed.
- Cookies & Tracking: Technical cookies used strictly for site navigation, security verification, and performance analytics. We do not sell tracking data to third-party advertisers.
3. How We Use Your Information
We use the collected information for operational, technical, and regulatory compliance purposes, including:
- Responding to consultation inquiries and scheduling Security Risk Assessment (SRA) reviews.
- Delivering tailored HIPAA compliance, technical safeguard, and administrative advisory services.
- Improving platform security, preventing unauthorized access, and detecting technical threats.
- Fulfilling legal, regulatory, and auditing obligations under state and federal law.
4. Data Sharing & Third-Party Vendors
We do not sell, rent, or trade your personal or business information. We may share information only in the following limited circumstances:
- Service Providers: Secure infrastructure, hosting, and communications providers bound by strict confidentiality and Business Associate Agreements (BAAs) where applicable.
- Legal Requirements: When required by law, subpoena, regulatory authority, or to protect our legal rights, property, or client safety.
5. Data Security Safeguards
In alignment with high security standards, Managed Compliance Group maintains physical, technical, and administrative safeguards designed to protect personal and business data against unauthorized access, disclosure, alteration, or destruction. Technical controls include standard transport encryption (TLS/SSL), full-disk encryption protocols, strict role-based access restrictions, and administrative access logging.
6. Your Data Rights & Choices
You have the right to request access to, correction of, or deletion of your personal contact information submitted through our website. To exercise these rights, please submit a request to our privacy team using the contact details provided below.
7. Updates to This Policy
We may update this Privacy Policy periodically to reflect changes in regulatory requirements, technical safeguards, or business operations. Updated revisions will be posted on this page with a revised "Last Updated" date.
8. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our compliance procedures, please contact our Privacy Office:
Managed Compliance Group
Washington, D.C. Metropolitan Area
privacy@managedcompliancegroup.com
Attn: Privacy & Data Security Officer