Privacy Policy
Effective 10 August 2026 · Version 3.0 · Supersedes all prior versions
The short version. This website collects the details you type into a form, plus the advertising and referral parameters present in your URL, plus standard analytics. Five third-party providers process some of it, all named in section 6. We never sell it. This website is not a channel for patient data — do not send Protected Health Information through it. PHI we process for clients is governed by a Business Associate Agreement, not by this policy (section 14).
1. Scope and who we are
This policy describes how H Holdings Group LLC, a Wyoming limited liability company, trading as MedPrecision Billing, handles personal information collected through medprecisionbilling.com. H Holdings Group LLC is the controller of that information and is the entity responsible for it. Our registered address is 30 N Gould St, STE R, Sheridan, WY 82801, USA.
This policy covers this website only. It does not cover a third-party website you reach by following a link from here, and it does not cover PHI processed under a Business Associate Agreement — see section 2.
2. Website information vs. client PHI
We handle two entirely separate categories of information, under two separate legal regimes. Confusing them is the most common misreading of a medical billing company’s privacy notice, so we state the split plainly:
| Website personal information | Client protected health information |
|---|---|
| Business contact details you type into a form on this site | Patient data we process to bill claims for a contracted practice |
| Governed by this policy and US state privacy law | Governed by HIPAA and the executed BAA, not by this policy |
| Collected from you, the visitor | Received from the covered entity, never through this website |
| Rights exercised under section 15 | Rights exercised through the patient’s own provider |
If you are a patient looking for your own medical or billing records, we cannot help you directly. Contact your healthcare provider — they are the covered entity that holds your record and controls your HIPAA rights.
3. Information we collect
3.1 Information you give us
A lead form appears on most pages of this site, and on Get a Quote. It collects only what it visibly asks for: your name, email address, phone number, practice name, medical specialty, approximate monthly claim volume and state. Name and email are required; the rest are optional. The Contact page additionally accepts a free-text message of up to 1,000 characters.
Every form also contains one hidden field named website. It is a spam trap that is invisible to
you and left empty by a real person; a submission that fills it is silently discarded. It collects nothing
about you.
If you book a call, you provide your name, email and chosen time to our scheduling provider. If you email or telephone us, we keep that correspondence.
3.2 Attribution parameters sent with your form
Alongside the visible fields, each form submits eleven hidden attribution fields so we can tell which channel a request came from. We disclose them individually because they are not visible on the form:
- utm_source, utm_medium, utm_campaign, utm_term, utm_content — campaign tags present in the URL you arrived on;
- gclid, fbclid, msclkid — the Google, Facebook and Microsoft advertising click identifiers, if your arriving URL carried one;
- landing_page — the first page of ours you opened;
- referrer — the address of the page that linked you here, as reported by your browser;
- first_touch_at — the timestamp of that first visit.
These values are captured on your first visit and held in your browser’s local storage
under the key mp_attribution for 30 days, then deleted automatically. They are
attached to your submission and appear in the notification email we receive. They describe how you found us,
not who you are, and we do not use them to build an advertising profile.
3.3 Information collected automatically
- IP address on submission. Our server records the IP address of a form submission for one purpose: rate-limiting abuse, at five submissions per fifteen minutes per address.
- Server request logs. Our host records standard web-server logs — IP address, timestamp, URL requested, response status, user agent and referrer.
- A copy of the submission in our log. Each submission is written to our server log before the notification email is sent, so a lead is not lost if email delivery fails.
- Analytics and performance data. Page views, session and device characteristics, scroll depth, outbound-link clicks, click-to-call and click-to-email events, and page-load timings.
4. What we do not collect
We do not collect patient data through this website. No form asks for it and no page accepts it. Do not enter patient names, dates of birth, member or medical record numbers, diagnoses or claim detail into any field on this site, including the free-text message box. If you do, we will delete it as soon as we reasonably can.
We also do not collect payment card details, bank details, Social Security numbers, government identifiers, precise geolocation, biometric data, or any of the categories US state privacy laws treat as sensitive personal information, through this website. There is no advertising pixel, no retargeting tag and no third-party ad network on this site.
5. How we use information
| Purpose | Information used |
|---|---|
| Respond to your enquiry and deliver the audit or quote you asked for | Name, email, phone, practice, specialty, claim volume, state, message |
| Send the confirmation email acknowledging your submission | Name, email |
| Follow up about our services and, if you become a client, administer the engagement | Contact and practice details |
| Understand which channels produce enquiries | Attribution parameters, analytics data |
| Operate, secure and improve the website; prevent spam, fraud and abuse | IP address, request logs, spam-trap field |
| Meet legal, tax, accounting and regulatory obligations, and establish or defend legal claims | Whatever the obligation or claim requires |
We do not use your information for automated decision-making that produces a legal or similarly significant effect on you, and we do not profile you for targeted advertising.
6. Service providers who receive it
The following providers process information on our behalf, under contract and for no purpose of their own. This list is complete as of the effective date above.
| Provider | What it does | What it receives |
|---|---|---|
| Vercel | Hosts this website, processes requests, and provides page-performance measurement | Every request, including IP address; a logged copy of each form submission |
| Resend | Delivers the notification email to us and the confirmation email to you | The full contents of a quote or audit submission, including attribution fields |
| Calendly | Powers the booking widget on the Contact page. It loads only if you open the “Book a Call” tab | Your name, email and selected time; IP address once the widget loads |
| Google Analytics 4 measures site usage. Separately, Google Fonts serves the icon font used on every page | Analytics events and identifiers; and, for the font, your IP address on every page load. Neither receives your form contents |
Each provider is bound to use the information only to perform its service for us. We do not authorise any of them to sell it or to use it for their own marketing.
7. Other disclosures
We may also disclose personal information:
- to our professional advisers — lawyers, accountants, auditors and insurers — where they need it and are bound by confidentiality;
- where required by law, subpoena, court order, regulator or other lawful request, or to establish, exercise or defend a legal claim;
- to protect the rights, property or safety of H Holdings Group LLC, our clients or the public, including to prevent fraud or abuse;
- in connection with a merger, acquisition, financing, reorganisation or sale of assets, in which case the recipient remains bound by this policy for information transferred, and we will note any change of controller here.
8. Sale and sharing of personal information
We do not sell your personal information, and we have not sold it in the preceding twelve months. We do not share it for cross-context behavioural advertising, and we do not disclose it to any third party for that third party’s own marketing. We do not knowingly sell or share the personal information of anyone under 16.
We disclose personal information to the service providers in section 6 only so they can perform their service for us. Under California law those are disclosures to service providers or contractors, not sales.
9. Cookies, local storage and analytics
Google Analytics 4 loads on every page and sets cookies that measure page views and site
usage. Vercel Speed Insights measures page-load performance. Our own script writes the
attribution record described in section 3.2 to your browser’s local storage under the key
mp_attribution, with a 30-day expiry. The Calendly widget sets its own cookies,
but only if you open the booking tab.
Your choices:
- Browser settings. Block or clear cookies and site data at any time. Clearing site data also removes the
mp_attributionrecord. - Content blockers. An ad or tracker blocker prevents the analytics scripts from loading at all. We do not attempt to detect or defeat blockers.
- Global Privacy Control. We treat a GPC signal from your browser as a valid opt-out of any sale or sharing, in the states where that signal must be honoured.
- Google opt-out. Google publishes a browser add-on that disables Google Analytics measurement across all sites.
Because the site carries no advertising or retargeting technology, we do not currently display a cookie consent banner to US visitors. Blocking cookies does not prevent you from using any part of this website.
10. Email, phone and text messages
When you submit a form, you are asking us to contact you, and we will — by email and, if you gave a number, by telephone. Two kinds of message follow, and they work differently:
- Transactional messages — the confirmation of your submission, the audit or quote you requested, and messages about an active engagement. These are part of the service and cannot be unsubscribed from while the matter is open.
- Marketing messages — anything promotional. Every one carries a working unsubscribe link, we honour opt-outs promptly, and we comply with the CAN-SPAM Act, 15 U.S.C. 7701 to 7713.
We do not operate an SMS marketing programme and we do not use an autodialler. If we ever introduce text messaging, it will require your separate express written consent as the Telephone Consumer Protection Act, 47 U.S.C. 227, requires, and this policy will be updated before that starts. To stop all contact, email [email protected].
11. Payment information
No payment is taken on this website. There is no checkout, no cart and no card field on any page. Clients are invoiced under a signed Service Agreement and pay by ACH or, where we make it available, by card.
Where card payment is used, card details are captured and processed by our payment processor under its own privacy terms. We do not receive, process or store full card numbers or security codes. We retain only what we need for accounting: the amount, the date, an invoice reference, and a truncated identifier such as the last four digits and card brand. Refunds are handled as described in our Refund Policy.
12. Retention
We keep information for as long as the purpose it was collected for requires, and then delete it:
| Category | Retention |
|---|---|
| Enquiries that do not become clients | Kept while we are in contact and for a reasonable follow-up period afterwards, then deleted on request or on review |
| Client contact and engagement records | Kept for the term of the engagement and for as long afterwards as tax, accounting, insurance and limitation periods require |
| Email correspondence | Kept in our mail systems in line with the above |
| Server and analytics logs | Kept for the period set by our host and by Google Analytics data-retention settings |
| Browser attribution record | 30 days, then deleted automatically by your browser |
We may keep information longer where a legal obligation, an audit, or an actual or anticipated legal claim requires it.
13. Security
We implement administrative, technical and physical safeguards to protect information. Our systems use encryption in transit and at rest, access controls, and regular security audits. This website is served over HTTPS, so everything you submit is encrypted in transit. Form input is length-limited and escaped before it is placed into an email, submissions are rate-limited by IP address, and a spam trap discards automated submissions.
No system can be guaranteed absolutely secure, and no transmission over the internet is entirely without risk. We take commercially reasonable steps, and you are responsible for keeping any credentials we issue you confidential.
14. HIPAA and protected health information
As a medical billing service provider, H Holdings Group LLC acts as a Business Associate under HIPAA when it processes billing data for a covered entity. That work is governed by a Business Associate Agreement satisfying 45 CFR 164.504(e), which defines the permitted uses and disclosures of PHI, the required safeguards, subcontractor obligations and breach duties. Where the BAA and this policy differ as to PHI, the BAA controls.
On discovering a breach of unsecured PHI, we notify the affected covered entity without unreasonable delay and in no case later than 60 calendar days after discovery, as 45 CFR 164.410 requires. Our compliance programme is described at HIPAA compliance.
This website neither collects, transmits nor stores PHI.
15. Your privacy rights
We extend the following rights to every visitor, wherever you live, rather than only to residents of states whose laws mandate them:
- Know and access — what personal information we hold about you, where it came from, why we have it, and who we disclosed it to.
- Portability — a copy in a portable, readily usable format.
- Correction — have inaccurate information corrected.
- Deletion — have your information deleted, including the copies in our email records and server logs, subject to legal retention obligations.
- Opt out — of any sale, any sharing for targeted advertising, and any profiling with legal or similarly significant effects. We do none of these, so there is nothing to opt out of; the right stands anyway.
- Limit use of sensitive information — we collect none through this website.
- Non-discrimination — we will not deny service, change pricing, or provide a lesser experience because you exercised a right.
- Withdraw consent — where we rely on your consent, you may withdraw it at any time without affecting processing already carried out.
These rights apply to website personal information. They do not reach PHI we hold for a client — a patient exercises HIPAA rights through their own provider.
16. How to exercise your rights, and how to appeal
Email [email protected] with the right you wish to exercise and the email address or phone number you used, so we can locate your record.
- Acknowledgement — within 10 business days.
- Verification — we may ask you to confirm details already in our records. We will not ask for a government identifier. If we cannot verify you, we will explain why.
- Response — within 45 days, extendable once by a further 45 days where reasonably necessary, in which case we will tell you before the first period ends.
- Cost — free, unless a request is manifestly unfounded, excessive or repetitive, in which case we will explain the reason and any fee before proceeding.
Authorised agents. You may use an authorised agent. We will require written proof of authority and may ask you to confirm it directly.
Appeals. If we refuse a request, you may appeal by replying to our decision with the word “appeal” and your reasons. A person who was not involved in the original decision will review it and respond in writing, with reasons, within 45 days. If we deny the appeal, we will tell you how to complain to your state attorney general. Residents of Colorado, Connecticut, Virginia and other states with a statutory appeal right may rely on this process; we make it available to everyone.
17. Additional notice for California residents
Under the California Consumer Privacy Act as amended by the CPRA, Cal. Civ. Code 1798.100 and following, the categories of personal information we have collected through this website in the preceding twelve months are:
| CCPA category | Collected | Examples on this site |
|---|---|---|
| Identifiers | Yes | Name, email, phone, IP address |
| Customer records information | Yes | Practice name, specialty, state, claim volume |
| Commercial information | Yes | Services enquired about; billing history for clients |
| Internet or network activity | Yes | Pages viewed, referrer, landing page, analytics events |
| Inferences | No | We build no profile from this information |
| Sensitive personal information | No | Not collected through this website |
| Biometric, geolocation, audio, education, employment | No | Not collected |
Sources, purposes and recipients for each category are set out in sections 3, 5 and 6. We have not sold or shared any category in the preceding twelve months. California residents also have a “Shine the Light” right to request details of disclosures for third-party direct marketing — we make none, and will confirm that in writing on request to [email protected].
18. Children
This website is a business-to-business service and is not directed at children. We do not knowingly collect personal information from anyone under 18, and no part of this site is designed to appeal to a child. If you believe a child has given us information, email [email protected] and we will delete it.
19. Visitors outside the United States
This website is operated from the United States and our services are offered only to organisations in the United States. We do not target, market to, or offer services to individuals in the European Economic Area, the United Kingdom or Switzerland.
If you access this site from outside the United States, your information will be transferred to, stored in and processed in the United States, where privacy laws differ from those of your country and may offer less protection. By using this website you understand that transfer takes place. Where a non-US privacy law does apply to us despite the above, we will honour the rights it grants you.
20. Data breach notification
If a security incident compromises personal information, we will investigate, contain it, and notify affected individuals and regulators as applicable law requires. Where the information is PHI, the HIPAA Breach Notification Rule applies and we notify the covered entity within the 60-day period at 45 CFR 164.410. Where it is personal identifying information covered by Wyoming law, we notify under Wyo. Stat. Ann. 40-12-501 and 40-12-502, and under the breach-notification statute of your own state where that applies.
21. Changes to this policy
We may update this policy. The effective date at the top always reflects the current version, and we keep the version number so you can tell one from another. Where a change is material — a new category of information, a new processor, or a new purpose — we will give notice on this website before it takes effect, and by email to clients. Continued use after the effective date is acceptance. Prior versions are available on request.
22. Contact
Privacy requests and questions about this policy: [email protected]
H Holdings Group LLC, a Wyoming limited liability company, trading as MedPrecision Billing
30 N Gould St, STE R, Sheridan, WY 82801, USA
General email: [email protected]
Telephone: +1-872-297-2815
Related policies: Terms of Service · Refund Policy · HIPAA Compliance
Ready to see what better billing looks like? Start with a free, no-obligation audit of your revenue cycle.
Get a Free Billing Audit arrow_forward