Privacy Policy.
We build systems for US healthcare. Data protection, least-privilege access, and HIPAA alignment aren't features—they are the foundation of everything we ship.
GetMax Healthcare Solutions ("GetMax", "we", "us", or "our") respects your privacy and is committed to protecting the information you entrust to us. This Privacy Policy describes how we collect, use, and share information when you visit our website or use our AI-native revenue cycle management platform and services (the "Services").
1. Protected Health Information (PHI) & HIPAA
As a provider of revenue cycle management software and services to US healthcare organizations, we process Protected Health Information (PHI) on behalf of our clients.
Our handling of PHI is strictly governed by the Health Insurance Portability and Accountability Act (HIPAA) and the Business Associate Agreement (BAA) we sign with each client. In the event of any conflict between this Privacy Policy and a signed BAA, the terms of the BAA will supersede this policy regarding PHI. We do not use PHI for marketing, advertising, or selling to third parties.
2. How We Handle AI Data Training
Trust is critical in healthcare AI. Our models are trained to improve revenue cycle efficiency, but we maintain strict boundaries:
- We do not use your patients' PHI to train public, generalized AI models (such as commercial LLMs).
- Data processed by our AI engines is sandboxed, encrypted in transit and at rest, and subjected to automated scrubbing of direct identifiers where feasible.
- Any localized model optimization done for a specific client is isolated exclusively to that client's secure tenant.
3. Information We Collect
Aside from PHI processed on behalf of clients, we may collect:
- Account & Business Information: Names, professional email addresses, phone numbers, and billing details provided when you schedule a demo, create an account, or contact us.
- Usage Data: Information about how you interact with our Services, including log files, system activity, and telemetry data to ensure platform stability and security.
- Device Information: IP addresses, browser types, and operating system details to monitor and prevent malicious activity.
4. How We Use Information
We use the non-PHI information we collect to:
- Provide, maintain, and improve the GetMax platform.
- Process transactions and send related administrative information.
- Investigate and prevent fraudulent, unauthorized, or illegal activity.
- Respond to your technical support requests and inquiries.
5. Data Security
We implement enterprise-grade technical, physical, and administrative safeguards to protect your data. This includes end-to-end encryption (TLS 1.2+ in transit, AES-256 at rest), least-privilege access controls, and continuous monitoring. However, no security system is impenetrable, and we cannot guarantee the absolute security of your data.
6. Changes to this Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by updating the "Effective Date" at the top of this policy and, in the case of significant changes, providing notice through our platform or via email.