Website & Business Privacy Policy and Terms of Service
For Website Visitors, Referral Partners, Employers, Insurance Carriers, and Commercial Contacts
Parties Covered by This Policy
This Policy is issued jointly by PriMedical, Inc. and PriCare, Inc. d/b/a PriMed Solutions (together, the “Company,” “we,” “us,” or “our”). Both entities collect and process information as described below; where a practice, disclosure, or contact point differs between the two brands, this Policy says so explicitly. Otherwise, references to the “Company” apply equally to both.
Important: Privacy Notice for Injured Workers and Claimants
If you are an injured worker or claimant receiving workers' compensation medical case management services through the Company, your health information is protected under applicable state privacy laws, and the Company handles it to federal HIPAA privacy and security standards. That relationship — and the Company's handling of your protected health information (PHI) — is governed exclusively by our separate Privacy Notice for Injured Workers, available at https://primedicalinc.com/privacy/hipaa/ or upon request from our Privacy Officer. This Policy governs only non-PHI interactions: our website, marketing, business-to-business relationships, and general commercial data. Where this Policy references PHI in its data tables or disclosure descriptions, those references are included solely to inform readers that PHI may arise in the described context and to direct them to the Privacy Notice for Injured Workers; they do not expand this Policy's scope to govern PHI. Where anything in this Policy could be read to apply to PHI, the Privacy Notice for Injured Workers controls.
1. Scope and Application
This Policy applies to all users of primedicalinc.com and any Company website or online service (each, the “Website”), including:
- General website visitors
- Referral form submitters
- Business partners and vendors
- Insurance carriers and third-party administrators (TPAs)
- Employers and HR professionals
- Healthcare providers
- Patients and claimants (for non-PHI interactions only — see Privacy Notice for Injured Workers above)
This Policy does not supersede the Privacy Notice for Injured Workers where PHI is involved.
2. Information We Collect
2.1 Information You Provide Directly
| Category | Examples | Purpose |
|---|---|---|
| Contact Information | Name, email, phone, company | Responding to inquiries, service delivery |
| Professional Information | Role, employer, referral source | Relationship management, compliance verification |
| Case Information (Non-PHI) | Claim numbers, employer names, adjuster contact | Service coordination, claim tracking |
| PHI (When Applicable — see Privacy Notice for Injured Workers) | Medical records, treatment information | Not governed by this Policy. Collection, use, and disclosure of PHI are governed exclusively by the Privacy Notice for Injured Workers. Listed here for informational completeness only. |
2.2 Information Collected Automatically
| Type | Description | Legal Basis |
|---|---|---|
| Cookies & Tracking | Essential cookies and browser storage (a security token on the referral page, your cookie choice, and color theme). If you allow them: analytics and advertising cookies, pixels, and third-party tags. | Consent for analytics and advertising cookies; necessary for site functionality and security |
| Device Data | Browser type, IP address, operating system | Security, functionality |
| Usage Data | Pages viewed, time on site, referral URLs | Analytics, service improvement |
2.3 Information From Third Parties
- Insurance carriers and TPAs who retain the Company's services
- Treating healthcare providers (with proper Medical Record Authorization / MRA)
- Employers providing work-status and accommodation information
- State workers' compensation boards and administrative bodies
2.4 Online Referral Submissions
When you submit a referral on the Website’s referral page, the information you enter and any files you attach travel over an encrypted connection to the Company’s systems in Amazon Web Services (AWS), where they are stored encrypted. Attached files are scanned for malware before they are accepted. The referral and accepted files are then delivered to the Company’s intake mailbox over an encrypted connection, and a confirmation email with the reference number (and the claim number, if you gave one) is sent to the email address you entered. Referral information can include protected health information; see the Privacy Notice for Injured Workers for how PHI is handled.
3. How We Use Information
3.1 Core Business Purposes
| Purpose | Data Categories Used | Legal Basis |
|---|---|---|
| Claims Administration | Case info, contact info; PHI if applicable (governed by Privacy Notice for Injured Workers) | Contract performance, legal obligation |
| Case Management Services | Employment info, provider data; PHI if applicable (governed by Privacy Notice for Injured Workers) | Contract performance |
| Billing & Payment | Financial data, service records | Contract performance, legal obligation |
| Regulatory Compliance | All categories as necessary | Legal obligation |
3.2 Business Improvement
- Quality assurance and case management oversight
- Staff training (using de-identified information where possible)
- Process optimization and service enhancement
- Fraud prevention and risk management
3.3 Marketing and Communications
- Service announcements and newsletters (opt-in required)
- Industry updates and compliance notifications
- Event invitations and webinar announcements
Opt-Out: You may opt out of marketing communications at any time by contacting privacy@primedicalinc.com or clicking the unsubscribe link in any email.
4. Information Sharing and Disclosure
4.1 We Do Not Sell Personal Information
The Company does not sell, rent, or trade personal information for monetary consideration. The Company may, however, permit third-party advertising and analytics partners to collect personal information through cookies and similar tracking technologies on the Website for purposes of cross-context behavioral advertising, which may constitute "sharing" under applicable state consumer privacy laws (see Section 4.2 and the cookie disclosures in Section 9.1). This commitment against sale for monetary consideration applies to all categories of data, including non-PHI.
4.2 “Sharing” for Cross-Context Behavioral Advertising
The Company uses certain third-party advertising and analytics tools on the Website that may collect personal information about your online activities on the Website’s general, non-health pages for purposes of cross-context behavioral advertising. Under applicable state consumer privacy laws, including the CCPA/CPRA, this activity may constitute "sharing" of personal information even though it does not involve monetary consideration. You may opt out of this sharing by adjusting your cookie preferences in the cookie consent manager or through the mechanisms described in Section 9.2, by sending a Global Privacy Control (GPC) signal, which the Website will try to accommodate (see Section 8.5), or by contacting privacy@primedicalinc.com.
4.3 Permitted Disclosures
| Recipient | Purpose | Legal Basis |
|---|---|---|
| Insurance carriers & TPAs | Claims administration, case management | Contractual necessity, legal authorization |
| Treating providers | Care coordination, medical record exchange | Authorization via MRA |
| Employers | Return-to-work coordination; any PHI disclosure governed by Privacy Notice for Injured Workers | Workers' comp statutory authority |
| Vendors & Subcontractors | Service delivery; any PHI involvement governed by Privacy Notice for Injured Workers and applicable BAA | Contractual necessity |
| Website service providers | Amazon Web Services (hosting, security, referral storage, malware scanning, and email delivery); CompAI (Trust Center and security questionnaire requests) | Contractual necessity |
| Regulatory Bodies | Required reporting, audits, investigations | Legal obligation |
| Legal Counsel | Defense of claims, legal advice | Legal obligation |
4.4 Business Associate Agreements
When PHI is involved in vendor relationships, the Company executes Business Associate Agreements (BAAs) consistent with the HIPAA Privacy Rule (45 CFR §164.504(e)) and Security Rule (45 CFR §164.314(a)), obligating vendors to protect PHI at HIPAA-required standards. The terms of those BAAs and the handling of PHI thereunder are governed by the Privacy Notice for Injured Workers, not this Policy.
4.5 State Workers' Compensation Statutes
Disclosure permissions vary by state. The Company complies with the workers' compensation statutes and regulations of each state in which it operates. See Section 14 below for how to obtain state-specific guidance.
5. International Data Transfers
The Company operates exclusively within the United States. All data processing occurs on U.S.-based infrastructure. Users should be aware that U.S. privacy protections differ from those in other jurisdictions (e.g., EU GDPR).
6. Data Retention
| Data Category | Retention Period | Authority |
|---|---|---|
| Active Case Files | Duration of claim + applicable state minimum | State workers' compensation statutes |
| Closed Case Files | Minimum 6–10 years post-closure (varies by state) | See Section 14 |
| Online Referral Submissions | Unsubmitted referrals: deleted within 48 hours (uploaded files within 3 days). Submitted referrals and attachments: kept in the referral system for 2,220 days (about 6 years), then deleted. A referral the Company acts on is added to the case file and kept for as long as the case is active, then for the closed case file period above. | Internal policy |
| Website Access & Security Logs | Up to 1 year | Internal policy |
| Website Analytics | 26 months (max) | Internal policy |
| Business Correspondence | 7 years | Tax/legal record retention |
How protected health information is used and disclosed is described in the Privacy Notice for Injured Workers.
7. Data Security
7.1 Technical Controls
- Encryption in transit (TLS 1.2+)
- Encryption at rest (AES-256 for sensitive data)
- Role-based access controls
- Multi-factor authentication for system access
- Regular vulnerability scanning and penetration testing
7.2 Administrative Controls
- Workforce privacy and security training
- Incident response procedures
- Vendor security assessments
- Regular compliance audits
7.3 Physical Controls
- Facility access controls at all offices
- Device and media disposal protocols
- Secure storage for physical records
8. Your Rights
8.1 General Website Users
- Access and review data we hold about you
- Request deletion (where legally permissible)
- Opt out of marketing communications
- Withdraw consent for cookie usage
8.2 California Residents (CCPA/CPRA)
- Right to know what data is collected
- Right to delete personal information
- Right to correct inaccurate data
- Right to opt out of sale/sharing (we do not sell; see Section 4.2 on “sharing”)
- Right to limit use of sensitive personal information
- Right to non-discrimination for exercising rights
California also requires certain website-level postings; see the “Required State Postings” table in Section 14. To exercise California rights: privacy@primedicalinc.com
8.3 Florida Residents (FDBR)
- Access personal data
- Correct inaccuracies
- Delete personal data
- Opt out of targeted advertising, sale, and profiling
8.4 Other States With Comprehensive Privacy Laws
As of the Last Updated date above, at least twenty states have enacted comprehensive consumer privacy laws, including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, and Rhode Island (18 states), in addition to California and Florida (addressed in Sections 8.2 and 8.3 above). Because new states adopt privacy legislation regularly, the Company reviews and updates this list quarterly rather than relying on a fixed enumeration. Contact privacy@primedicalinc.com for the current list applicable to your state.
8.5 Global Privacy Control (GPC)
The Website will try to accommodate a Global Privacy Control (GPC) signal sent by your browser. When we detect one, marketing cookies start off in the cookie consent manager. You keep the right to set your own preferences at any time in the cookie consent manager, and the choices you make there apply to this Website.
8.6 Nevada Residents
Nevada law (NRS 603A) gives residents the right to opt out of the sale of certain covered information, even though the Company does not currently sell such information. Nevada residents may submit a request through our designated request form as required by statute.
8.8 Other State Privacy Laws
The Company complies with applicable state privacy statutes not separately listed above. Contact our Privacy Officer for jurisdiction-specific guidance.
8.9 PHI-Related Rights
For health information about injured workers and claimants, please refer to our Privacy Notice for Injured Workers.
10. Children's Privacy
The Website is not directed to individuals under age 18. We do not knowingly collect personal information from children under age 18. Under federal law (COPPA), parental consent is required to collect personal information from children under age 13; under Florida law (Florida Digital Bill of Rights), a "child" is defined as a consumer under age 18. If we discover that personal information from a child under 18 has been collected without appropriate consent, we will take steps to delete it promptly.
11. Changes to This Policy
- Material Changes: Will be posted with an updated effective date
- Notice Period: Significant changes may be announced via email (where contact information is on file)
- Continued Use: Using the Website after updates constitutes acceptance of the revised terms
- Historical Versions: Archived versions maintained for reference upon request
12. Terms of Service
12.1 Acceptance of Terms
By accessing or using the Company's Website, you agree to be bound by these Terms of Service. If you do not agree, do not use this Website.
12.2 Authorized Use
You agree to use the Website only for lawful purposes consistent with the Company's business objectives. Unauthorized commercial scraping, automated data collection, or harassment is prohibited.
12.3 Intellectual Property
All Website content, trademarks, logos, and proprietary materials are owned by the Company or its licensors. Unauthorized reproduction is prohibited.
12.4 Disclaimer of Warranties
The Website and its content are provided “as is” without warranties of any kind, express or implied. The Company disclaims all warranties regarding accuracy, completeness, or fitness for a particular purpose.
12.5 Limitation of Liability
To the maximum extent permitted by law, the Company's total liability arising from your use of the Website shall not exceed the greater of $100 USD or the amount paid directly by you to the Company during the prior twelve (12) month period. Consequential, indirect, and incidental damages are excluded where permissible.
12.6 Indemnification
You agree to indemnify and hold harmless the Company from claims arising from your use of the Website, violation of these terms, or infringement of third-party rights.
12.7 Governing Law
These Terms shall be governed by the laws of the State of Florida, excluding conflict-of-law principles, except to the extent that a mandatory consumer-protection or privacy statute of another state expressly applies to residents of that state and cannot be waived by contract. Any disputes not subject to such mandatory state law shall be resolved in state or federal courts located in Miami-Dade County, Florida.
13. Contact Information
PriMedical, Inc.
5727 NW 7th Street, Suite #84, Miami, FL 33126
General Inquiry — Phone: 888-370-0883 | Email: referral@primedicalinc.com
Privacy Officer: Frank Imperato | Email: privacy@primedicalinc.com | Phone: 888-370-0883
PriCare, Inc. d/b/a PriMed Solutions
5727 NW 7th Street, Suite #84, Miami, FL 33126
General Inquiry — Phone: 866-846-2442 | Email: info@primed-solutions.com
Privacy Officer: Frank Imperato | Email: privacy@primed-solutions.com | Phone: 866-846-2442
14. State-Specific Notes & Required Postings
The Company complies with the workers' compensation and consumer-privacy statutes of every state in which it operates. Because these requirements vary and change frequently, we do not attempt to enumerate all fifty states here. If you have a question about how a specific state's law applies to your matter, contact our Privacy Officer at privacy@primedicalinc.com and we will provide jurisdiction-specific guidance.
Illustrative State Variations
| State | Notable Variation |
|---|---|
| California | Additional medical privacy protections under the Confidentiality of Medical Information Act (Civ. Code §§56–56.37); CCPA/CPRA consumer rights; “Shine the Light” disclosure law |
| Texas | Specific medical-records authorization requirements under the Texas Workers' Compensation framework |
| Florida | Chapter 440 provisions; specific timeframes for record production |
| New York | Workers' Compensation Board forms; mandatory authorization language |
| Nevada | Statutory opt-out-of-sale mechanism (NRS 603A); separate Consumer Health Data law (SB 370) |
| Washington | My Health My Data Act may apply to non-HIPAA consumer health data collected via the Website |
Required Website Postings (do not remove)
- A “Do Not Sell or Share My Personal Information” link on any page where personal information is collected, if the sale/sharing threshold is met (California)
- Accommodation of the Global Privacy Control signal (see Section 8.5)
- This Policy's effective date and a description of categories collected, displayed on the Website (California/Nevada/Delaware baseline online-privacy-policy requirements)
- A designated Nevada opt-out request contact (Section 8.6)