510.347.5858 Support@MedRecAps.com

Privacy Policy

Effective Date: June 1, 2026

Last Updated: June 1, 2026


Please Note: MedRecAps is committed to protecting the confidentiality, integrity, and security of personal information and Protected Health Information (PHI). This policy explains how information is collected, used, and protected when you use our services.

Welcome to MedRecAps. We are a medical records retrieval and document management company headquartered in California and serving healthcare providers, law firms, insurers, employers, third-party administrators, and authorized requestors throughout the United States.

We are committed to protecting the privacy, confidentiality, and security of personal information and protected health information (PHI) entrusted to us.

This Privacy Policy explains how we collect, use, disclose, and safeguard information when you visit our website at www.medrecaps.com and platform at app.medrecaps.com to communicate with us, or use our services.

1. Scope of This Privacy Policy

This Privacy Policy applies to information collected through:

  • Our Website
  • Online portals and forms
  • Email and electronic communications
  • Customer support interactions
  • Business relationships and service operations

This Privacy Policy does not replace any Business Associate Agreement (BAA), service agreement, authorization, or HIPAA notice provided by a healthcare provider or client.

2. Information We Collect

A. Personal Information

We may collect the following categories of personal information:

  • Name
  • Mailing address
  • Email address
  • Telephone number
  • Employer or organization name
  • Job title
  • Account login credentials
  • Billing and payment information
  • Government-issued identifiers when required for verification
  • Electronic signatures

B. Protected Health Information (PHI)

As part of our medical records retrieval services, we may receive, process, transmit, or store PHI on behalf of covered entities and authorized requestors in accordance with applicable law, including the Health Insurance Portability and Accountability Act (HIPAA).

Examples may include:

  • Medical records
  • Treatment information
  • Insurance information
  • Patient identifiers
  • Dates of service
  • Diagnostic and billing information

We process PHI only as authorized by our clients, applicable law, and contractual agreements.

C. Automatically Collected Information

When you use our Website, we may automatically collect:

  • IP address
  • Browser type
  • Device identifiers
  • Operating system
  • Website usage activity
  • Referral URLs
  • Cookies and tracking technologies

3. How We Use Information

We may use collected information to:

  • Provide medical records retrieval and document management services
  • Verify identities and authorizations
  • Process requests and fulfill orders
  • Communicate with clients and users
  • Maintain and improve our Website and services
  • Respond to inquiries and customer support requests
  • Comply with legal, regulatory, and contractual obligations
  • Prevent fraud, unauthorized access, or misuse
  • Maintain security and audit logs
  • Enforce our agreements and policies

We do not sell personal information or PHI.

4. HIPAA Compliance

Where applicable, we operate as a Business Associate under HIPAA and maintain administrative, technical, and physical safeguards designed to protect PHI.

Our workforce members receive privacy and security training, and access to PHI is limited to authorized personnel with a legitimate business need.

While we strive to protect all information, no method of electronic transmission or storage is completely secure.

5. Disclosure of Information

We may disclose information:

  • To healthcare providers, insurers, attorneys, employers, or authorized requestors as permitted by law and authorization
  • To vendors and service providers performing services on our behalf
  • To comply with subpoenas, court orders, legal process, or regulatory obligations
  • To law enforcement or government agencies where required by law
  • In connection with a merger, acquisition, financing, or sale of assets
  • To protect the rights, safety, or security of our Company, users, or others

Any disclosure of PHI is made in accordance with HIPAA and other applicable laws.

6. Cookies and Tracking Technologies

Our Website may use cookies, analytics tools, and similar technologies to:

  • Operate and secure the Website
  • Improve user experience
  • Analyze traffic and usage trends
  • Maintain user sessions

You may modify your browser settings to refuse cookies; however, some Website features may not function properly.

7. California Privacy Rights

If you are a California resident, you may have rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), including the right to:

  • Know what personal information we collect
  • Request deletion of certain personal information
  • Correct inaccurate personal information
  • Request access to your personal information
  • Limit use of sensitive personal information where applicable
  • Not be discriminated against for exercising privacy rights

Certain information, including PHI governed by HIPAA, may be exempt from portions of the CCPA/CPRA. To exercise your California privacy rights, contact us using the information below.

8. Additional State Privacy Rights

Residents of certain states may have additional rights under applicable privacy laws. We will honor verified requests as required by law.

9. Data Retention

We retain information only as long as necessary to:

  • Provide services
  • Comply with legal obligations
  • Resolve disputes
  • Enforce agreements
  • Meet record retention requirements

Retention periods may vary depending on the nature of the information and applicable law.

10. Data Security

We implement reasonable administrative, technical, and physical safeguards designed to protect information from unauthorized access, disclosure, alteration, or destruction. Security measures may include:

  • Encryption
  • Access controls
  • Secure file transmission
  • Audit logging
  • Employee confidentiality obligations
  • Vendor due diligence

11. Third-Party Services and Links

Our Website may contain links to third-party websites or services. We are not responsible for the privacy practices or content of third parties. Users should review third-party privacy policies before providing information.

12. Children's Privacy

Our Website and services are not directed to children under 13 years of age, and we do not knowingly collect personal information directly from children through the Website.

13. Nationwide Operations

Although headquartered in California, we provide services throughout the United States and may process information across state lines in accordance with applicable federal and state laws.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated effective date. Your continued use of the Website after changes are posted constitutes acceptance of the revised Privacy Policy.

15. Contact Information

If you have questions about this Privacy Policy or our privacy practices, please contact:

MedRecAps LLC

1777 Abrams Court, Suite 2191

San Leandro, CA 94577

Phone: (510) 347-5858

Email: support@medrecaps.com

Website: www.medrecaps.com