← Back to Healthvocate

Privacy Policy

Last updated: May 27, 2026 · Effective: May 27, 2026

1. Who we are

Healthvocate is a service operated by DYS Global Macro Trading Corp, located at 5830 E 2nd St, Ste 7000, Casper, WY 82609. You can contact us at support@healthvocate.com.

2. What this policy covers

This policy describes what information Healthvocate collects, how we use it, who we share it with, and the choices you have. It applies to anyone who uses the Healthvocate website or service.

Washington and Nevada law each require a separate consumer health data privacy policy, which cannot be folded into a general privacy policy. Ours is published at Consumer Health Data Privacy Policy. It governs consumer health data for consumers in those states; where it and this policy describe the same practice they are intended to agree, and if they ever conflict, that policy governs.

3. Information we collect

3.1 Information you provide directly

  • Account information: email, name, and password. Your password is hashed with bcrypt (cost 12) — we never see and cannot recover your plaintext password.
  • Profile and household information: date of birth, address, household members, marital status, dependents.
  • Income and assets: employment income, Social Security, pensions, retirement accounts, savings, real estate.
  • Healthcare information: health conditions, medications, healthcare providers, pharmacies, insurance plans, prior authorizations.
  • Documents you upload: explanation of benefits (EOBs), bills, insurance cards, authorization letters, denial letters.

What we do NOT collect: We do not request or store Social Security numbers or other government identification numbers. If you upload documents that include this information, we recommend redacting it first.

3.2 Information collected automatically

  • Technical data: IP address, browser type, device information, pages visited, timestamps.
  • Session cookie (always set when signed in): a standard PHP session cookie that keeps you signed in. Cleared when you sign out.
  • Affiliate-referral cookie (hv_ref, 90 days, only set if you arrive via an affiliate link such as ?ref=CODE): records the referral code so the correct affiliate is credited if you later create an account. The code is a short string only — no third-party data is stored in or read from this cookie.
  • No advertising or analytics cookies: we do not use Google Analytics, Facebook Pixel, or any third-party advertising or tracking pixels.
  • Audit log: we log security-relevant events (sign-in attempts, password changes, account modifications, data exports) along with the IP address, for security investigation purposes. You can view the most recent 20 events at any time under Account Settings → Recent Activity, and your full audit log is included in your data export.

4. How we use your information

  • To provide the Healthvocate service: identifying benefit programs, auditing bills, generating prior-authorization appeal letters, optimizing prescriptions and Medicare/Social Security choices.
  • To send transactional email related to your account: verification, password reset, audit completion notifications, trial-ending reminders, and reminders for prior-authorization deadlines you've asked us to track.
  • To detect and prevent fraud, abuse, and security incidents.
  • To improve the service in aggregate (no individual data is examined for product improvement without your explicit consent).

We do not send marketing email. We do not use your data for advertising, ad targeting, or profile-building beyond what is necessary to deliver the service you signed up for.

5. AI processing (Anthropic)

Healthvocate uses Anthropic's Claude API (operated by Anthropic, PBC) for part of the service. No request we send to Anthropic carries an account identifier of any kind — no user ID, no session ID, no email address, no customer number. Requests are not linkable to you, or to each other, from Anthropic's side. There are two distinct paths by which your data reaches Anthropic, and we want to be specific about both:

  • Document reading: when you upload a bill, EOB, denial letter, insurance card, pay stub, Social Security statement, medical record, or a blank form you need filled in, the file itself (the PDF or image) is base64-encoded and sent to Anthropic's API so that codes, amounts, dates, and other fields can be read off it. This is the one path where identifiers printed on your document — your name, member ID, or date of birth — are transmitted, because reading the page necessarily means reading all of it. This is why we recommend redacting anything you don't want read. The original file is held only as long as needed for extraction and any subsequent analyses you request.
  • Analysis: when you run an analysis (a benefits scan, a bill audit, a Medicare comparison, an appealability check, a surprise-bill check, an EOB explanation), we send only the specific facts the question needs — CPT and diagnosis codes, dollar amounts, provider name and specialty, state and ZIP, household size and income band. We do not send your name, date of birth, Social Security number, member ID, email address, address, account credentials, or audit-log contents on any of these paths. Where an analysis depends on how old someone is, we calculate the age on our own servers and send only the age — never the date of birth.

Some Healthvocate features use no AI at all: the Social Security Optimizer and the Prescription Optimizer are calculated by our own software against published data, and the prior-authorization appeal letter and external-review request are assembled by our software from fixed templates we wrote. On those paths nothing is sent to Anthropic.

When a letter needs your name, date of birth, or member ID, our software inserts it locally, on our server, after the AI is finished — the AI drafts around a placeholder and never receives the value. Free-text you paste into the EOB and surprise-bill tools is additionally scanned for email addresses, Social Security numbers, dates of birth, member IDs, and patient names, and those are stripped before the text is sent or stored. That text is deleted automatically after 7 days.

Anthropic acts as a sub-processor under our agreement. As of this writing, Anthropic states that API inputs and outputs are not used to train their models, and are retained only as necessary to provide the service and detect abuse. Refer to Anthropic's privacy policy for the most current terms.

6. Other API queries that include your information

To produce certain features Healthvocate queries other third-party APIs. Each query carries only the specific data needed to answer the question.

  • CMS NPPES Provider Registry (npiregistry.cms.hhs.gov): when you search for a healthcare provider by name, location, or NPI, those search terms are sent to CMS. CMS receives the search criteria; it does not receive your account identity.
  • CMS Open Payments (openpaymentsdata.cms.gov): when you view a provider's industry-payment history, that provider's NPI is sent to CMS. CMS receives the NPI you queried; it does not receive your account identity.
  • Stripe (stripe.com): when you start a subscription or update your billing, Stripe receives your email and payment-method details directly through Stripe's hosted checkout. We do not see or store your card number, CVV, or bank credentials — Stripe handles that and shares back only a customer reference, a subscription state, and the last four digits of your card.
  • Prescription pricing sources: when you run a prescription price check, the medication name, strength, and quantity are sent to a published prescription-pricing source to retrieve its price. That source receives the medication details it needs to return a price; it does not receive your account identity, your name, or any other information about you.
  • Email delivery: transactional emails are sent via SMTP through our configured email provider. The provider sees the recipient address and message body necessary to deliver the email.

We also consult several read-only public data sources to inform our analyses. These receive no information from us about you — they are bulk-imported reference data held on our own servers: CMS Medicare Physician Fee Schedules, CMS ZIP-to-locality crosswalk, the OIG List of Excluded Individuals/Entities (LEIE), and Social Security Administration parameters obtained via the U.S. Federal Register.

7. How we share information (and what we don't do)

We do not sell, rent, or trade your personal information. We do not share it with advertisers or data brokers. We do not build user profiles for resale.

We share information only:

  • With the service providers listed in sections 5 and 6, strictly as needed to run Healthvocate. A consolidated list is published at Subprocessors.
  • With our hosting provider (LyneHost / SupremeCluster), which provides server infrastructure and stores the database in which your data resides. Hosting providers necessarily have technical access to stored data; we restrict their access by policy and use encryption-at-rest for sensitive fields.
  • When required by law (subpoena, court order, or other valid legal process), and only to the extent legally required. Where permitted by law we will notify you first.
  • To protect rights, property, or safety in genuine emergencies.
  • In the event of a business sale, merger, or asset transfer, your information would transfer to the acquirer under the same privacy commitments. You'd be notified beforehand.

8. Data retention

Account data is retained as long as your account is active. When you delete your account (Account Settings → Delete Account):

  • All personal data is deleted immediately from the live database: profile, household, income, conditions, medications, providers, insurance plans, bills, prior authorizations, documents, notifications, and AI analysis results.
  • The audit-log entries from your account are retained (without other personal data) for legal-compliance and security-investigation purposes.
  • Database backups are maintained by our hosting provider per the provider's policy. Deleted personal data persists in backups only until those backups roll off the provider's retention schedule.

For active accounts, we also apply the following automated retention rules:

  • Audit log: entries older than 365 days are archived to a separate store for security investigation but remain part of your account export.
  • AI jobs and analysis results: each analysis is stored with an expiration time set at creation. Expired results are purged daily; analyses you want to keep can be re-run at any time.
  • Notifications: read notifications older than their retention window are purged daily.

9. Your rights

Depending on your jurisdiction (GDPR for the EU/EEA, UK-GDPR for the UK, CCPA for California, and similar laws elsewhere), you have rights including:

If you are in Washington or Nevada, you have additional rights over consumer health data specifically — including confirmation, access, withdrawal of consent, deletion, and a right of appeal if we refuse. Those are set out, with the procedure for exercising them, in our Consumer Health Data Privacy Policy.

  • Right of access & portability (GDPR Art. 15, 20): download a complete copy of your data in machine-readable JSON via Account Settings → Export My Data.
  • Right to rectification (GDPR Art. 16): correct your profile, email, password, or any other record from its feature page.
  • Right to erasure (GDPR Art. 17): permanently delete your account via Account Settings → Delete Account.
  • Right not to be subject to solely automated decisions (GDPR Art. 22): see the disclosure on the Account Settings page. Healthvocate's AI features produce informational analyses, not decisions; every consequential action (submitting an appeal, signing a dispute letter) requires your explicit review and digital signature first.
  • Right to lodge a complaint (GDPR Art. 77): if you believe we have mishandled your personal data, you have the right to complain to your local data-protection supervisory authority.
  • CCPA "do not sell" right (California): we do not sell personal information, so this right is moot in our case; we honor it by default.

To exercise rights not directly available in the app, email support@healthvocate.com.

10. Security

We protect your data using:

  • Encryption-at-rest for designated sensitive fields (such as case numbers), using AES-256-GCM with random per-record nonces.
  • Encryption-in-transit: HTTPS (TLS) for all browser connections, TLS for outbound SMTP and AI-API calls.
  • Password hashing with bcrypt (cost factor 12) — your plaintext password is never stored.
  • Optional two-factor authentication (TOTP) on your account, with recovery codes stored only as bcrypt hashes.
  • CSRF tokens on every state-changing form submission.
  • Rate limiting on sign-in, registration, and password-reset endpoints to slow brute-force attacks.
  • Comprehensive audit logging of security-relevant events.
  • Defense-in-depth headers: Content Security Policy, X-Frame-Options, HSTS, Referrer-Policy.

No security is perfect. If a breach affecting your personal data occurs, we will notify you according to the breach-notification law of your jurisdiction.

11. Children's privacy

Healthvocate is not directed to children under 13 (or under 16 in jurisdictions where that is the applicable threshold). We do not knowingly collect personal information from children. If you believe we have collected information from a child, contact us at support@healthvocate.com and we will delete it.

12. Changes to this policy

We may update this policy. Material changes will be communicated via email to the address on your account at least 30 days before they take effect. The current version is always linked from the footer of every page, and the date at the top of this page reflects the most recent update.

13. Contact

Questions about this privacy policy: support@healthvocate.com
Mailing address: 5830 E 2nd St, Ste 7000, Casper, WY 82609

← Back to Healthvocate · Terms of Service

Healthvocate

A system on your side when you're navigating the healthcare and benefits maze.

Product
Home About Guides Affiliate Program Blog Enterprise Press Sign in Create account
Legal
Privacy Policy Terms of Service Disclaimer Washington Health Data Nevada Health Data
© 2026 Healthvocate. All rights reserved. Healthvocate is an independent commercial service and is not affiliated with CMS, SSA, the VA, or any insurer. It provides software tools — not medical, legal, or financial advice — and no individual outcome is guaranteed. Before pursuing any medical, legal, or financial action, consult the relevant professional — a clinician, attorney, or financial advisor.