NOTICE OF PRIVACY PRACTICES — PROTECTED HEALTH INFORMATION
This Privacy Policy serves as IntakeAccess.ai's Notice of Privacy Practices as required by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the HITECH Act. It describes how medical information about you may be used and disclosed, and how you can access this information. Please review it carefully.
 Table of Contents
  1. Who We Are
  2. Information We Collect
  3. How We Use Your Information
  4. Permitted Disclosures of PHI
  5. Business Associates
  6. AI Services and PHI
  7. SMS & Electronic Communications
  8. Data Security
  9. Data Retention
  10. Your HIPAA Patient Rights
  11. Breach Notification
  12. California Privacy Rights
  13. Children's Privacy
  14. Cookies & Tracking
  15. Third-Party Services
  16. International Transfers
  17. Mental Health Protections
  18. Medicare & Medicaid Data
  19. Policy Updates
  20. Contact & Complaints
1

Who We Are

INTAKEACCESS.AI LLC (DBA: Intake Access Health Solutions) is an AI-powered healthcare platform headquartered at 181 W Valley Ave STE 245-1742, Birmingham, AL 35209. We provide a comprehensive suite of services including AI patient intake, prior authorization processing, insurance verification, telepsychiatry, telemedicine, secure messaging, e-prescribing, wound imaging AI, post-acute care (PAC) management, Medicaid claims processing, and a patient portal with multi-factor authentication.

As a healthcare technology platform, we function as a Business Associate under HIPAA with respect to the covered entity healthcare providers and facilities using our platform, and as a Covered Entity in certain direct-service contexts. All Protected Health Information (PHI) is governed by the HIPAA Privacy Rule (45 C.F.R. Parts 160 and 164) and the HITECH Act.

This Privacy Policy applies to all users of IntakeAccess.ai, including patients, healthcare providers, licensed clinicians, facility administrators, and any other individuals or entities interacting with our platform or Website at https://intakeaccess.ai.

2

Information We Collect

We collect information from multiple sources across several user categories. All PHI is collected solely for lawful healthcare purposes.

Patient Data (Protected Health Information — PHI)

CategorySpecific Data PointsCollection Method
DemographicsFull name, date of birth, gender, contact details (phone, email, address)Patient intake forms, voice-enabled intake, portal registration
Government & Insurance IDsDriver's license, passport, Medicare ID, Medicaid ID, policy numbersIntake forms, insurance verification workflow
Clinical DataMedical history, diagnoses (ICD-10), medications, prescriptions, lab results, treatment plans, progress notesProvider entries, EHR integration, e-prescribing module
Mental Health DataPHQ-9, GAD-7, MDQ assessment responses, telepsychiatry notes, crisis assessmentsAssessment modules, telepsychiatry suite
Wound ImagingWound photographs, measurements, AI analysis outputs, healing progression recordsWound imaging AI module, provider uploads
Payment & BillingPayment method details, billing address, insurance claims data, EOBStripe integration, claims processing
CommunicationsSecure patient-provider messages, appointment reminders, telehealth session records (with consent)Secure messaging, SMS/email, telemedicine platform

Provider & Facility Data

Technical & Platform Data

3

How We Use Your Information

We use collected information for the following lawful purposes. PHI is used only to the minimum extent necessary (the HIPAA "Minimum Necessary Standard") for each stated purpose.

Treatment, Payment & Healthcare Operations (TPO)

Additional Uses

AI Is Assistive OnlyAI-generated outputs, clinical decision support suggestions, wound assessments, and prior authorization predictions are assistive tools only. All clinical decisions remain the sole responsibility of licensed healthcare providers. See Section 6 for full AI disclaimers.
4

Permitted Disclosures of PHI

For Treatment

For Payment

As Required by Law

PHI Is Never SoldProtected Health Information is never sold, rented, or disclosed to any third party for advertising, marketing, or commercial purposes unrelated to your healthcare. This prohibition is absolute.

Disclosures Requiring Your Authorization

For any disclosure not described above — including disclosure to employers, life insurers, or for marketing — we will obtain your written authorization first. You may revoke any authorization in writing at any time.

5

Business Associates

We engage third-party service providers ("Business Associates") who may receive, create, maintain, or transmit PHI. All Business Associates must sign a Business Associate Agreement (BAA) before accessing PHI.

ProviderPurposeBAA StatusData Handled
TwilioSMS, video, secure messaging, email✓ ExecutedPHI (appointment data, patient comms)
Firebase / Google CloudDatabase, hosting, authentication✓ ExecutedAll PHI (AES-256 encrypted at rest)
StripePayment processing✓ ExecutedBilling/financial data
EDI PartnersClaims, prior auth, insurance verification✓ ExecutedClaims data, insurance IDs
SendGridEmail communications✓ ExecutedLimited PHI (appointment notifications)
AWSHIPAA-compliant backend infrastructure✓ ExecutedInfrastructure-level PHI
Make.comAutomation (non-PHI demos only)⏳ In ProgressNo live PHI until BAA executed
Request a BAAHealthcare providers and facilities must execute a Business Associate Agreement with us before accessing PHI. Contact: compliance@intakeaccess.ai
6

AI Services and PHI

IntakeAccess.ai uses AI and machine learning to assist healthcare providers. All AI features are assistive tools only — designed to support, not replace, licensed clinical professionals.

AI Features That Process PHI

Critical AI Limitations DisclosureAI models may produce errors, omissions, or outputs that do not reflect the full clinical picture. No AI output should be acted upon without independent clinical review by a licensed professional. The platform does not constitute the practice of medicine, nursing, or any licensed healthcare profession.
7

SMS & Electronic Communications

IntakeAccess.ai Healthcare Communications ProgramA2P 10DLC program disclosures in compliance with CTIA guidelines and carrier requirements.

SMS Program Details

Opt-In / Opt-Out

Opt in during patient intake, by texting START, or via portal registration. Text STOP at any time to unsubscribe immediately. Opt-out requests are logged in our HIPAA-compliant audit system.

No Marketing Use of Mobile NumbersMobile phone numbers and SMS opt-in data are never shared with third parties for marketing. SMS is limited to healthcare-related content only.
8

Data Security

IntakeAccess.ai implements a multi-layered security framework in accordance with the HIPAA Security Rule (45 C.F.R. §§ 164.302–164.318).

Technical Safeguards

Administrative & Physical Safeguards

9

Data Retention

Data TypeRetention PeriodLegal Basis
Patient Medical Records / PHI7 years from last encounter (10 years for minors)HIPAA, state medical record laws
Mental Health RecordsAs required by applicable state lawState mental health statutes
Medicare/Medicaid Claims Records10 years42 C.F.R. § 422.504(d); CMS requirements
Billing & Payment Records7 yearsIRS requirements, state tax law
Audit Logs (PHI Access)6 years from creationHIPAA Security Rule § 164.312(b)
Provider Account DataDuration of relationship + 7 yearsContractual, HIPAA
SMS Opt-In/Opt-Out Records4 yearsCTIA guidelines, TCPA
Website Technical Data26 monthsAnalytics standard

Upon expiration, PHI is permanently deleted or de-identified per the HIPAA Safe Harbor or Expert Determination standard. Data export requests are fulfilled within 30 days of request.

10

Your HIPAA Patient Rights

As a patient whose PHI is processed through IntakeAccess.ai, you have the following rights under the HIPAA Privacy Rule. Contact your healthcare provider or use Section 20 to exercise these rights.

Right of Access (45 C.F.R. § 164.524)

Inspect and obtain a copy of your PHI within 30 days of request. Electronic copies provided at no or reasonable cost-based fee.

Right to Amend (45 C.F.R. § 164.526)

Request amendment to PHI you believe is inaccurate or incomplete. We will act within 60 days.

Right to Accounting of Disclosures (45 C.F.R. § 164.528)

Request a list of disclosures of your PHI made in the prior six years, excluding TPO disclosures and those you authorized.

Right to Request Restrictions (45 C.F.R. § 164.522)

Request restrictions on certain uses and disclosures. We must restrict disclosure to a health plan for services you paid out-of-pocket in full.

Right to Confidential Communications

Request communication by alternative means or at an alternative location. We will accommodate reasonable requests.

Right to File a Complaint

File a complaint with IntakeAccess.ai (Section 20) or with HHS OCR at www.hhs.gov/ocr or 1-800-368-1019. We will not retaliate against you.

11

Breach Notification

IntakeAccess.ai maintains a documented Breach Notification Policy in compliance with the HIPAA Breach Notification Rule (45 C.F.R. §§ 164.400–414) and the HITECH Act.

Notification Timelines

12

California Privacy Rights (CCPA / CPRA)

Information qualifying as PHI under HIPAA is exempt from CCPA/CPRA to the extent maintained as PHI. The rights below apply to non-PHI personal information collected by IntakeAccess.ai.

Submit verifiable requests to privacy@intakeaccess.ai with subject line "California Privacy Rights Request." Responses within 45 days (extendable to 90 with notice).

13

Children's Privacy

IntakeAccess.ai does not knowingly collect personal information from children under 13 except as part of a healthcare relationship where a parent or legal guardian has provided verifiable consent. All applicable HIPAA, COPPA, and state minor patient privacy laws apply.

Certain state laws allow providers to maintain confidentiality of sensitive health information (reproductive health, mental health, substance use) even from parents or guardians. Our platform supports these legal frameworks.

14

Cookies & Tracking Technologies

Our Website uses cookies and similar technologies. See our separate Cookie Policy for full details. In summary:

PHI is never stored in cookies. Session tokens are encrypted, time-limited, and invalidated upon logout or 15-minute timeout.

15

Third-Party Services

Beyond Business Associates (Section 5), our platform may link to third-party services. We are not responsible for the privacy practices of third-party websites not operating under a BAA with us. All third-party integrations involving PHI require an executed BAA before any PHI access is permitted.

16

International Data Transfers

IntakeAccess.ai is operated in the United States. All PHI is stored and processed in HIPAA-compliant U.S.-based data centers and is not transferred outside the United States. For GDPR rights for EEA residents, see our GDPR/CCPA Addendum.

17

Mental Health Information — Special Protections

Mental health information — including PHQ-9, GAD-7, and MDQ results, telepsychiatry session notes, crisis assessments, and substance use disorder treatment records (42 C.F.R. Part 2 where applicable) — receives heightened protection. Mental health PHI will not be disclosed without explicit authorization except as required for emergency treatment, imminent safety threats, or applicable law.

Crisis ResourcesIf you or someone you know is experiencing a mental health crisis, call or text 988 (Suicide & Crisis Lifeline) or call 911. These resources are also accessible directly within the IntakeAccess.ai telepsychiatry platform.
18

Medicare & Medicaid Data

IntakeAccess.ai processes Medicare and Medicaid beneficiary data in accordance with CMS data use requirements and applicable CMS program integrity requirements. Medicare and Medicaid identifiers are treated as PHI and receive all applicable HIPAA protections. Providers are responsible for ensuring all claims are accurate, medically necessary, and compliant with CMS billing guidelines.

19

Amendments to This Policy

IntakeAccess.ai reserves the right to amend this Privacy Policy at any time. Material changes will be communicated by posting a prominent notice on the Website, updating the "Last Updated" date, and where feasible, notifying registered users by email. A paper copy of this Notice of Privacy Practices is available upon request.

20

Contact Us & Filing Complaints

INTAKEACCESS.AI LLC

Filing a Complaint with HHS

No RetaliationIntakeAccess.ai will not retaliate against any patient, provider, or employee who exercises their HIPAA rights or files a good-faith complaint with HHS or any other regulatory authority.