Patient Billing. Resolved.

Legal & Compliance

Privacy Policy

Patriot Pay is committed to protecting the privacy and security of all information entrusted to us — including Protected Health Information (PHI) processed on behalf of our healthcare clients.

Last updated: July 9, 2026  ·  Effective date: May 1, 2025

HIPAA Business Associate

Patriot Pay operates as a HIPAA Business Associate. All Protected Health Information (PHI) processed through our platform is subject to a Business Associate Agreement (BAA) with the applicable covered entity. We maintain SOC 2 Type II certification and follow HIPAA Security Rule requirements for all PHI we handle.

1. Information We Collect

We collect information that you provide directly to us and information generated through your use of our platform.

    Information You Provide:

  • Contact information (name, email address, phone number, job title, organization name)
  • Account credentials (username, password, security questions)
  • Payment and billing information
  • Communications with our support team

    Information Collected Automatically:

  • Usage data and platform analytics
  • Device and browser information
  • IP addresses and general location data
  • Log data and performance metrics

Protected Health Information (PHI): As a Business Associate under HIPAA, we process PHI on behalf of our covered entity clients pursuant to the terms of our Business Associate Agreements (BAAs). We do not use PHI for any purpose other than to provide our contracted services.

2. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and improve the Patriot Pay platform and services
  • Process patient billing transactions and resolve outstanding balances
  • Send administrative communications, including service updates and billing notifications
  • Respond to your comments, questions, and requests
  • Monitor and analyze usage patterns and trends to improve user experience
  • Detect, investigate, and prevent fraudulent transactions and other illegal activities
  • Comply with legal obligations and enforce our terms of service
  • Train and improve our AI models (using de-identified or synthetic data only)

3. HIPAA Compliance

Patriot Pay operates as a Business Associate under the Health Insurance Portability and Accountability Act (HIPAA). We maintain comprehensive HIPAA compliance across our platform:

    Safeguards We Maintain:

  • Administrative safeguards including workforce training and access management policies
  • Physical safeguards for our data center and office environments
  • Technical safeguards including access controls, audit controls, and encryption

    Our Commitments:

  • We enter into a Business Associate Agreement (BAA) with every covered entity client
  • We use PHI only to provide services described in the BAA
  • We maintain appropriate physical, electronic, and procedural safeguards
  • We report any known security incidents or breaches in accordance with HIPAA requirements
  • We ensure our subcontractors who access PHI also maintain HIPAA compliance

4. Data Security

We take the security of your information seriously and implement industry-leading security measures:

  • Encryption:: AES-256 encryption for all data at rest; TLS 1.3 for all data in transit
  • Access Control:: Role-based access control (RBAC) and principle of least privilege
  • Authentication:: Multi-factor authentication (MFA) required for all administrative access
  • Monitoring:: 24/7 security monitoring, intrusion detection, and automated threat response
  • Auditing:: Comprehensive audit logs for all data access and patient interactions
  • Infrastructure:: SOC 2 Type II certified infrastructure hosted in HIPAA-eligible cloud environments
  • Penetration Testing:: Regular third-party security assessments and penetration tests
  • Incident Response:: Documented incident response plan and breach notification procedures

5. Data Sharing and Disclosure

We do not sell your personal information or PHI to third parties. We may share information in the following limited circumstances:

Service Providers: We work with trusted third-party vendors who assist us in providing our services (e.g., cloud hosting, payment processing, analytics). These vendors are contractually required to protect your information and use it only for the services they provide to us.

Legal Requirements: We may disclose information when required by law, court order, or other legal process, or when necessary to protect our rights, property, or safety, or the rights, property, or safety of others.

Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity, subject to the same privacy protections.

With Your Consent: We may share your information for other purposes with your explicit consent.

6. Data Retention

We retain information for as long as necessary to provide our services and comply with legal obligations:

  • Account Information:: Retained for the duration of your account and for 7 years after closure to comply with healthcare recordkeeping requirements
  • PHI:: Retained in accordance with your BAA terms and applicable state and federal regulations
  • Financial Records:: Retained for 7 years to comply with tax and accounting requirements
  • Audit Logs:: Retained for a minimum of 6 years in accordance with HIPAA requirements
  • Communications:: Retained for up to 3 years for support and service improvement purposes

Upon expiration of the applicable retention period, we securely delete or de-identify your information.

7. Your Rights and Choices

Depending on your location and applicable law, you may have certain rights regarding your personal information:

Access and Portability: You may request a copy of the personal information we hold about you.

Correction: You may request that we correct inaccurate or incomplete personal information.

Deletion: You may request deletion of your personal information, subject to our legal obligations to retain certain records.

Restriction: You may request that we restrict certain processing of your personal information.

Patient Rights: Patients whose PHI we process as a Business Associate should direct rights requests (access, amendment, accounting of disclosures) to the covered entity healthcare organization, which is the controller of that PHI.

To exercise any of these rights, contact us at support@patriotpay.ai.

8. Cookies and Tracking Technologies

We use cookies and similar technologies to run the site, remember your choices, and — only with your consent — to understand how the site is used. When you first visit, a banner lets you choose Accept all, Only essentials, or Reject all. Until you consent, non-essential cookies are not set: Google Consent Mode is set to "denied" by default, so analytics and advertising storage stay off until you opt in.

    Essential Cookies (always active):

  • Required for security, page delivery, and to remember your cookie choice (for example, the `pp_consent` cookie). These do not require consent and cannot be switched off.

    Analytics Cookies (only with your consent):

  • We use Google Analytics 4 to measure page views, traffic sources, and general usage so we can improve the site. Typical cookies include `_ga` and `_ga_*`. They are enabled only after you choose "Accept all," and IP addresses are handled in anonymized form.

    Preference Cookies (only with your consent):

  • Remember settings such as language or display preferences for a more personalized experience.

    Advertising Cookies:

  • We do **not** use third-party advertising or cross-site tracking cookies, and we do not sell your personal information.

    Managing your choices:

  • You can change or withdraw your consent at any time using the **"Cookie Preferences"** link in the website footer, or by clearing cookies in your browser. Disabling essential cookies may affect how the site works.

This cookie notice applies to our public marketing website. Protected Health Information (PHI) processed within the Patriot Pay platform is governed by the HIPAA sections above and the applicable Business Associate Agreement.

9. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by:

  • Posting a notice on our website and platform
  • Sending an email to the address associated with your account
  • Displaying an in-platform notification

We encourage you to review this policy periodically. Your continued use of our services after any changes indicates your acceptance of the updated policy.

Have questions, concerns, or requests regarding this Privacy Policy or our privacy practices? We're here to help.

Contact us