Privacy Policy
How we handleyour information.
This policy explains what CareMax collects, why we collect it, how it is protected, and the choices available to you. It applies to our website and to the business services we deliver to client organizations.
01Information we collect
When you contact us through this website we collect the details you provide — name, organization, email address, phone number, specialty and any information you include in a message.
When we deliver services under a client agreement, we process business and operational data supplied by that client. Where that data includes protected health information (PHI), it is handled strictly under the terms of an executed Business Associate Agreement.
We also collect limited technical information automatically, such as browser type, referring page and general geographic region, in order to keep the site secure and understand how it is used.
02How we use information
Contact details are used to respond to your enquiry, schedule consultations and deliver the services you request. We do not sell personal information, and we do not share it with third parties for their own marketing.
Client data is used solely to perform the contracted services — claim submission, coding, posting, reporting, security assessment, technology administration or financial analysis, depending on the engagement.
03Protected health information
CareMax acts as a Business Associate as defined by HIPAA. PHI is accessed only by workforce members who require it to perform their role, under documented least-privilege access controls.
PHI is encrypted in transit and at rest using 256-bit encryption. Access is logged, reviewed and revoked promptly upon role change or separation.
We do not use or disclose PHI other than as permitted by the applicable Business Associate Agreement, as required by law, or as necessary for the proper management of our operations.
04Safeguards
Our security program is aligned to the HIPAA Security Rule, the NIST Cybersecurity Framework and CIS Critical Controls. It includes administrative, physical and technical safeguards, documented policies, workforce training and periodic risk assessment.
Multi-factor authentication is enforced for administrative access. Backups are maintained with tested restoration procedures, and incident response and business continuity plans are documented and exercised.
05Retention
Enquiry information is retained only as long as needed to respond and to maintain a record of the correspondence.
Client data is retained according to the retention schedule set out in the applicable services agreement and any legal or regulatory obligation that applies to the record type. Upon termination, data is returned or securely destroyed as directed by the client.
06Your choices
You may request access to, correction of, or deletion of the personal information we hold about you by contacting us using the details below. Requests concerning PHI held on behalf of a covered entity are directed to that covered entity, which controls the record.
You may opt out of any non-essential communication at any time. Service-related messages necessary to deliver a contracted engagement will continue.
07Changes to this policy
We may update this policy to reflect changes in our practices or legal obligations. Material changes will be reflected in the "last updated" date shown alongside this page, and where appropriate we will notify affected clients directly.
Questions about this policy?
Contact us at info@caremaxbilling.com or call +1 (951) 717-8925. Written correspondence may be sent to 1301 N Broadway STE 32050, Los Angeles, CA 90012, USA.
Free revenue audit
Find out what your practice is leaving on the table.
A free revenue audit takes 30 minutes and shows you exactly where claims are being denied, underpaid or never followed up on. No obligation, no setup fee, no sales theatre.
- No setup fees
- HIPAA-compliant intake
- Reply within 1 business day