Submit a Referral Refer a case
Legal

Website & Business Privacy Policy

For Website Visitors, Referral Partners, Employers, Insurance Carriers, and Commercial Contacts

Website & Business Privacy Policy and Terms of Service

For Website Visitors, Referral Partners, Employers, Insurance Carriers, and Commercial Contacts

Effective Date: September 11, 2026 | Last Updated: September 27, 2026

Parties Covered by This Policy

This Policy is issued jointly by PriMedical, Inc. and PriCare, Inc. d/b/a PriMed Solutions (together, the “Company,” “we,” “us,” or “our”). Both entities collect and process information as described below; where a practice, disclosure, or contact point differs between the two brands, this Policy says so explicitly. Otherwise, references to the “Company” apply equally to both.

Important: Privacy Notice for Injured Workers and Claimants

If you are an injured worker or claimant receiving workers' compensation medical case management services through the Company, your health information is protected under applicable state privacy laws, and the Company handles it to federal HIPAA privacy and security standards. That relationship — and the Company's handling of your protected health information (PHI) — is governed exclusively by our separate Privacy Notice for Injured Workers, available at https://primedicalinc.com/privacy/hipaa/ or upon request from our Privacy Officer. This Policy governs only non-PHI interactions: our website, marketing, business-to-business relationships, and general commercial data. Where this Policy references PHI in its data tables or disclosure descriptions, those references are included solely to inform readers that PHI may arise in the described context and to direct them to the Privacy Notice for Injured Workers; they do not expand this Policy's scope to govern PHI. Where anything in this Policy could be read to apply to PHI, the Privacy Notice for Injured Workers controls.

1. Scope and Application

This Policy applies to all users of primedicalinc.com and any Company website or online service (each, the “Website”), including:

  • General website visitors
  • Referral form submitters
  • Business partners and vendors
  • Insurance carriers and third-party administrators (TPAs)
  • Employers and HR professionals
  • Healthcare providers
  • Patients and claimants (for non-PHI interactions only — see Privacy Notice for Injured Workers above)

This Policy does not supersede the Privacy Notice for Injured Workers where PHI is involved.

2. Information We Collect

2.1 Information You Provide Directly

CategoryExamplesPurpose
Contact InformationName, email, phone, companyResponding to inquiries, service delivery
Professional InformationRole, employer, referral sourceRelationship management, compliance verification
Case Information (Non-PHI)Claim numbers, employer names, adjuster contactService coordination, claim tracking
PHI (When Applicable — see Privacy Notice for Injured Workers)Medical records, treatment informationNot governed by this Policy. Collection, use, and disclosure of PHI are governed exclusively by the Privacy Notice for Injured Workers. Listed here for informational completeness only.

2.2 Information Collected Automatically

TypeDescriptionLegal Basis
Cookies & TrackingEssential cookies and browser storage (a security token on the referral page, your cookie choice, and color theme). If you allow them: analytics and advertising cookies, pixels, and third-party tags.Consent for analytics and advertising cookies; necessary for site functionality and security
Device DataBrowser type, IP address, operating systemSecurity, functionality
Usage DataPages viewed, time on site, referral URLsAnalytics, service improvement

2.3 Information From Third Parties

  • Insurance carriers and TPAs who retain the Company's services
  • Treating healthcare providers (with proper Medical Record Authorization / MRA)
  • Employers providing work-status and accommodation information
  • State workers' compensation boards and administrative bodies

2.4 Online Referral Submissions

When you submit a referral on the Website’s referral page, the information you enter and any files you attach travel over an encrypted connection to the Company’s systems in Amazon Web Services (AWS), where they are stored encrypted. Attached files are scanned for malware before they are accepted. The referral and accepted files are then delivered to the Company’s intake mailbox over an encrypted connection, and a confirmation email with the reference number (and the claim number, if you gave one) is sent to the email address you entered. Referral information can include protected health information; see the Privacy Notice for Injured Workers for how PHI is handled.

3. How We Use Information

3.1 Core Business Purposes

PurposeData Categories UsedLegal Basis
Claims AdministrationCase info, contact info; PHI if applicable (governed by Privacy Notice for Injured Workers)Contract performance, legal obligation
Case Management ServicesEmployment info, provider data; PHI if applicable (governed by Privacy Notice for Injured Workers)Contract performance
Billing & PaymentFinancial data, service recordsContract performance, legal obligation
Regulatory ComplianceAll categories as necessaryLegal obligation

3.2 Business Improvement

  • Quality assurance and case management oversight
  • Staff training (using de-identified information where possible)
  • Process optimization and service enhancement
  • Fraud prevention and risk management

3.3 Marketing and Communications

  • Service announcements and newsletters (opt-in required)
  • Industry updates and compliance notifications
  • Event invitations and webinar announcements

Opt-Out: You may opt out of marketing communications at any time by contacting privacy@primedicalinc.com or clicking the unsubscribe link in any email.

4. Information Sharing and Disclosure

4.1 We Do Not Sell Personal Information

The Company does not sell, rent, or trade personal information for monetary consideration. The Company may, however, permit third-party advertising and analytics partners to collect personal information through cookies and similar tracking technologies on the Website for purposes of cross-context behavioral advertising, which may constitute "sharing" under applicable state consumer privacy laws (see Section 4.2 and the cookie disclosures in Section 9.1). This commitment against sale for monetary consideration applies to all categories of data, including non-PHI.

4.2 “Sharing” for Cross-Context Behavioral Advertising

The Company uses certain third-party advertising and analytics tools on the Website that may collect personal information about your online activities on the Website’s general, non-health pages for purposes of cross-context behavioral advertising. Under applicable state consumer privacy laws, including the CCPA/CPRA, this activity may constitute "sharing" of personal information even though it does not involve monetary consideration. You may opt out of this sharing by adjusting your cookie preferences in the cookie consent manager or through the mechanisms described in Section 9.2, by sending a Global Privacy Control (GPC) signal, which the Website will try to accommodate (see Section 8.5), or by contacting privacy@primedicalinc.com.

4.3 Permitted Disclosures

RecipientPurposeLegal Basis
Insurance carriers & TPAsClaims administration, case managementContractual necessity, legal authorization
Treating providersCare coordination, medical record exchangeAuthorization via MRA
EmployersReturn-to-work coordination; any PHI disclosure governed by Privacy Notice for Injured WorkersWorkers' comp statutory authority
Vendors & SubcontractorsService delivery; any PHI involvement governed by Privacy Notice for Injured Workers and applicable BAAContractual necessity
Website service providersAmazon Web Services (hosting, security, referral storage, malware scanning, and email delivery); CompAI (Trust Center and security questionnaire requests)Contractual necessity
Regulatory BodiesRequired reporting, audits, investigationsLegal obligation
Legal CounselDefense of claims, legal adviceLegal obligation

4.4 Business Associate Agreements

When PHI is involved in vendor relationships, the Company executes Business Associate Agreements (BAAs) consistent with the HIPAA Privacy Rule (45 CFR §164.504(e)) and Security Rule (45 CFR §164.314(a)), obligating vendors to protect PHI at HIPAA-required standards. The terms of those BAAs and the handling of PHI thereunder are governed by the Privacy Notice for Injured Workers, not this Policy.

4.5 State Workers' Compensation Statutes

Disclosure permissions vary by state. The Company complies with the workers' compensation statutes and regulations of each state in which it operates. See Section 14 below for how to obtain state-specific guidance.

5. International Data Transfers

The Company operates exclusively within the United States. All data processing occurs on U.S.-based infrastructure. Users should be aware that U.S. privacy protections differ from those in other jurisdictions (e.g., EU GDPR).

6. Data Retention

Data CategoryRetention PeriodAuthority
Active Case FilesDuration of claim + applicable state minimumState workers' compensation statutes
Closed Case FilesMinimum 6–10 years post-closure (varies by state)See Section 14
Online Referral SubmissionsUnsubmitted referrals: deleted within 48 hours (uploaded files within 3 days). Submitted referrals and attachments: kept in the referral system for 2,220 days (about 6 years), then deleted. A referral the Company acts on is added to the case file and kept for as long as the case is active, then for the closed case file period above.Internal policy
Website Access & Security LogsUp to 1 yearInternal policy
Website Analytics26 months (max)Internal policy
Business Correspondence7 yearsTax/legal record retention

How protected health information is used and disclosed is described in the Privacy Notice for Injured Workers.

7. Data Security

7.1 Technical Controls

  • Encryption in transit (TLS 1.2+)
  • Encryption at rest (AES-256 for sensitive data)
  • Role-based access controls
  • Multi-factor authentication for system access
  • Regular vulnerability scanning and penetration testing

7.2 Administrative Controls

  • Workforce privacy and security training
  • Incident response procedures
  • Vendor security assessments
  • Regular compliance audits

7.3 Physical Controls

  • Facility access controls at all offices
  • Device and media disposal protocols
  • Secure storage for physical records

8. Your Rights

8.1 General Website Users

  • Access and review data we hold about you
  • Request deletion (where legally permissible)
  • Opt out of marketing communications
  • Withdraw consent for cookie usage

8.2 California Residents (CCPA/CPRA)

  • Right to know what data is collected
  • Right to delete personal information
  • Right to correct inaccurate data
  • Right to opt out of sale/sharing (we do not sell; see Section 4.2 on “sharing”)
  • Right to limit use of sensitive personal information
  • Right to non-discrimination for exercising rights

California also requires certain website-level postings; see the “Required State Postings” table in Section 14. To exercise California rights: privacy@primedicalinc.com

8.3 Florida Residents (FDBR)

  • Access personal data
  • Correct inaccuracies
  • Delete personal data
  • Opt out of targeted advertising, sale, and profiling

8.4 Other States With Comprehensive Privacy Laws

As of the Last Updated date above, at least twenty states have enacted comprehensive consumer privacy laws, including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, and Rhode Island (18 states), in addition to California and Florida (addressed in Sections 8.2 and 8.3 above). Because new states adopt privacy legislation regularly, the Company reviews and updates this list quarterly rather than relying on a fixed enumeration. Contact privacy@primedicalinc.com for the current list applicable to your state.

8.5 Global Privacy Control (GPC)

The Website will try to accommodate a Global Privacy Control (GPC) signal sent by your browser. When we detect one, marketing cookies start off in the cookie consent manager. You keep the right to set your own preferences at any time in the cookie consent manager, and the choices you make there apply to this Website.

8.6 Nevada Residents

Nevada law (NRS 603A) gives residents the right to opt out of the sale of certain covered information, even though the Company does not currently sell such information. Nevada residents may submit a request through our designated request form as required by statute.

8.8 Other State Privacy Laws

The Company complies with applicable state privacy statutes not separately listed above. Contact our Privacy Officer for jurisdiction-specific guidance.

For health information about injured workers and claimants, please refer to our Privacy Notice for Injured Workers.

9. Cookies and Tracking Technologies

9.1 Types of Cookies We Use

Cookie TypePurposeDurationOpt-Out
Essential — security token (aws-waf-token)Set on the referral page to confirm a real browser is submitting and to block automated abuseShort-lived; renewed while you use the pageCannot disable; blocking it prevents referral submission
Essential — preferences (browser storage)Remembers your cookie notice choice and color themeUntil you clear your browser storageClear site data in your browser
AnalyticsUsage statistics, performanceUp to 26 monthsSet only after you choose Accept; turn off in Customize, browser settings, GPC, or opt-out links
MarketingAdvertising, remarketingVariesSet only after you choose Accept; turn off in Customize, industry opt-out portals, or GPC

Analytics and marketing cookies are not set until you choose Accept in the cookie notice, or save them in Customize. You can turn them off at any time in Customize. They are used only on the Website’s general pages and are always off on the referral page, which is where health information is submitted; no health information is sold or shared for advertising.

Most browsers allow cookie configuration through privacy settings. You may also use:

  • Your AdChoices opt-out options
  • The Network Advertising Initiative opt-out page
  • The Google Analytics opt-out browser extension
  • A Global Privacy Control-enabled browser or extension (see Section 8.5)

Note: Disabling cookies may impact site functionality.

10. Children's Privacy

The Website is not directed to individuals under age 18. We do not knowingly collect personal information from children under age 18. Under federal law (COPPA), parental consent is required to collect personal information from children under age 13; under Florida law (Florida Digital Bill of Rights), a "child" is defined as a consumer under age 18. If we discover that personal information from a child under 18 has been collected without appropriate consent, we will take steps to delete it promptly.

11. Changes to This Policy

  • Material Changes: Will be posted with an updated effective date
  • Notice Period: Significant changes may be announced via email (where contact information is on file)
  • Continued Use: Using the Website after updates constitutes acceptance of the revised terms
  • Historical Versions: Archived versions maintained for reference upon request

12. Terms of Service

12.1 Acceptance of Terms

By accessing or using the Company's Website, you agree to be bound by these Terms of Service. If you do not agree, do not use this Website.

12.2 Authorized Use

You agree to use the Website only for lawful purposes consistent with the Company's business objectives. Unauthorized commercial scraping, automated data collection, or harassment is prohibited.

12.3 Intellectual Property

All Website content, trademarks, logos, and proprietary materials are owned by the Company or its licensors. Unauthorized reproduction is prohibited.

12.4 Disclaimer of Warranties

The Website and its content are provided “as is” without warranties of any kind, express or implied. The Company disclaims all warranties regarding accuracy, completeness, or fitness for a particular purpose.

12.5 Limitation of Liability

To the maximum extent permitted by law, the Company's total liability arising from your use of the Website shall not exceed the greater of $100 USD or the amount paid directly by you to the Company during the prior twelve (12) month period. Consequential, indirect, and incidental damages are excluded where permissible.

12.6 Indemnification

You agree to indemnify and hold harmless the Company from claims arising from your use of the Website, violation of these terms, or infringement of third-party rights.

12.7 Governing Law

These Terms shall be governed by the laws of the State of Florida, excluding conflict-of-law principles, except to the extent that a mandatory consumer-protection or privacy statute of another state expressly applies to residents of that state and cannot be waived by contract. Any disputes not subject to such mandatory state law shall be resolved in state or federal courts located in Miami-Dade County, Florida.

13. Contact Information

PriMedical, Inc.

5727 NW 7th Street, Suite #84, Miami, FL 33126

General Inquiry — Phone: 888-370-0883 | Email: referral@primedicalinc.com

Privacy Officer: Frank Imperato | Email: privacy@primedicalinc.com | Phone: 888-370-0883

PriCare, Inc. d/b/a PriMed Solutions

5727 NW 7th Street, Suite #84, Miami, FL 33126

General Inquiry — Phone: 866-846-2442 | Email: info@primed-solutions.com

Privacy Officer: Frank Imperato | Email: privacy@primed-solutions.com | Phone: 866-846-2442

14. State-Specific Notes & Required Postings

The Company complies with the workers' compensation and consumer-privacy statutes of every state in which it operates. Because these requirements vary and change frequently, we do not attempt to enumerate all fifty states here. If you have a question about how a specific state's law applies to your matter, contact our Privacy Officer at privacy@primedicalinc.com and we will provide jurisdiction-specific guidance.

Illustrative State Variations

StateNotable Variation
CaliforniaAdditional medical privacy protections under the Confidentiality of Medical Information Act (Civ. Code §§56–56.37); CCPA/CPRA consumer rights; “Shine the Light” disclosure law
TexasSpecific medical-records authorization requirements under the Texas Workers' Compensation framework
FloridaChapter 440 provisions; specific timeframes for record production
New YorkWorkers' Compensation Board forms; mandatory authorization language
NevadaStatutory opt-out-of-sale mechanism (NRS 603A); separate Consumer Health Data law (SB 370)
WashingtonMy Health My Data Act may apply to non-HIPAA consumer health data collected via the Website

Required Website Postings (do not remove)

  • A “Do Not Sell or Share My Personal Information” link on any page where personal information is collected, if the sale/sharing threshold is met (California)
  • Accommodation of the Global Privacy Control signal (see Section 8.5)
  • This Policy's effective date and a description of categories collected, displayed on the Website (California/Nevada/Delaware baseline online-privacy-policy requirements)
  • A designated Nevada opt-out request contact (Section 8.6)