Privacy Policy
Patriot Pay is committed to protecting the privacy and security of all information entrusted to us — including Protected Health Information (PHI) processed on behalf of our healthcare clients.
Last updated: July 9, 2026 · Effective date: May 1, 2025
Patriot Pay operates as a HIPAA Business Associate. All Protected Health Information (PHI) processed through our platform is subject to a Business Associate Agreement (BAA) with the applicable covered entity. We maintain SOC 2 Type II certification and follow HIPAA Security Rule requirements for all PHI we handle.
1. Information We Collect
We collect information that you provide directly to us and information generated through your use of our platform.
- Contact information (name, email address, phone number, job title, organization name)
- Account credentials (username, password, security questions)
- Payment and billing information
- Communications with our support team
Information You Provide:
- Usage data and platform analytics
- Device and browser information
- IP addresses and general location data
- Log data and performance metrics
Information Collected Automatically:
Protected Health Information (PHI): As a Business Associate under HIPAA, we process PHI on behalf of our covered entity clients pursuant to the terms of our Business Associate Agreements (BAAs). We do not use PHI for any purpose other than to provide our contracted services.
2. How We Use Your Information
We use the information we collect to:
- Provide, operate, and improve the Patriot Pay platform and services
- Process patient billing transactions and resolve outstanding balances
- Send administrative communications, including service updates and billing notifications
- Respond to your comments, questions, and requests
- Monitor and analyze usage patterns and trends to improve user experience
- Detect, investigate, and prevent fraudulent transactions and other illegal activities
- Comply with legal obligations and enforce our terms of service
- Train and improve our AI models (using de-identified or synthetic data only)
3. HIPAA Compliance
Patriot Pay operates as a Business Associate under the Health Insurance Portability and Accountability Act (HIPAA). We maintain comprehensive HIPAA compliance across our platform:
- Administrative safeguards including workforce training and access management policies
- Physical safeguards for our data center and office environments
- Technical safeguards including access controls, audit controls, and encryption
Safeguards We Maintain:
- We enter into a Business Associate Agreement (BAA) with every covered entity client
- We use PHI only to provide services described in the BAA
- We maintain appropriate physical, electronic, and procedural safeguards
- We report any known security incidents or breaches in accordance with HIPAA requirements
- We ensure our subcontractors who access PHI also maintain HIPAA compliance
Our Commitments:
4. Data Security
We take the security of your information seriously and implement industry-leading security measures:
- Encryption:: AES-256 encryption for all data at rest; TLS 1.3 for all data in transit
- Access Control:: Role-based access control (RBAC) and principle of least privilege
- Authentication:: Multi-factor authentication (MFA) required for all administrative access
- Monitoring:: 24/7 security monitoring, intrusion detection, and automated threat response
- Auditing:: Comprehensive audit logs for all data access and patient interactions
- Infrastructure:: SOC 2 Type II certified infrastructure hosted in HIPAA-eligible cloud environments
- Penetration Testing:: Regular third-party security assessments and penetration tests
- Incident Response:: Documented incident response plan and breach notification procedures
5. Data Sharing and Disclosure
We do not sell your personal information or PHI to third parties. We may share information in the following limited circumstances:
Service Providers: We work with trusted third-party vendors who assist us in providing our services (e.g., cloud hosting, payment processing, analytics). These vendors are contractually required to protect your information and use it only for the services they provide to us.
Legal Requirements: We may disclose information when required by law, court order, or other legal process, or when necessary to protect our rights, property, or safety, or the rights, property, or safety of others.
Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity, subject to the same privacy protections.
With Your Consent: We may share your information for other purposes with your explicit consent.
6. Data Retention
We retain information for as long as necessary to provide our services and comply with legal obligations:
- Account Information:: Retained for the duration of your account and for 7 years after closure to comply with healthcare recordkeeping requirements
- PHI:: Retained in accordance with your BAA terms and applicable state and federal regulations
- Financial Records:: Retained for 7 years to comply with tax and accounting requirements
- Audit Logs:: Retained for a minimum of 6 years in accordance with HIPAA requirements
- Communications:: Retained for up to 3 years for support and service improvement purposes
Upon expiration of the applicable retention period, we securely delete or de-identify your information.
7. Your Rights and Choices
Depending on your location and applicable law, you may have certain rights regarding your personal information:
Access and Portability: You may request a copy of the personal information we hold about you.
Correction: You may request that we correct inaccurate or incomplete personal information.
Deletion: You may request deletion of your personal information, subject to our legal obligations to retain certain records.
Restriction: You may request that we restrict certain processing of your personal information.
Patient Rights: Patients whose PHI we process as a Business Associate should direct rights requests (access, amendment, accounting of disclosures) to the covered entity healthcare organization, which is the controller of that PHI.
To exercise any of these rights, contact us at support@patriotpay.ai.
9. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by:
- Posting a notice on our website and platform
- Sending an email to the address associated with your account
- Displaying an in-platform notification
We encourage you to review this policy periodically. Your continued use of our services after any changes indicates your acceptance of the updated policy.
Have questions, concerns, or requests regarding this Privacy Policy or our privacy practices? We're here to help.
Contact us