Skip to main content
REGULATORY & HEALTHCARE DATA COMPLIANCE

Privacy Policy & HIPAA Data Protection

Effective Date: January 1, 2026 • Last Reviewed: March 2026 • Crescentech Solutions LLC.

HIPAA BAA COMPLIANT SOC2 TYPE II CONTROLS TLS 1.3 & AES-256 GDPR & CCPA READY

Policy Table of Contents

Need a dedicated HIPAA Business Associate Agreement (BAA)? Contact our compliance counsel

1. Scope & Covered Entities

This Privacy Policy governs the practices of Crescentech Solutions LLC ("Crescentech", "we", "our", or "us") across our website, proprietary applications, client intake portals, and electronic health record integration modules.

Where Crescentech provides digital engineering, cloud infrastructure, or revenue cycle management (RCM) services to covered healthcare providers, hospitals, clinics, or billing entities, our handling of Protected Health Information (PHI) is governed additionally by a formal, bilateral Business Associate Agreement (BAA) pursuant to 45 CFR § 164.502(e) and § 164.504(e).

2. Protected Health Information (PHI) Handling

In our capacity as a Business Associate under HIPAA and the HITECH Act, Crescentech strictly enforces:

  • Zero client-side caching of identifiable patient records in public browser storage.
  • FIPS 140-2 validated encryption algorithms for all data at rest (AES-256) and in transit (TLS 1.3).
  • Strict role-based access control (RBAC) and mandatory multi-factor authentication (MFA) across all administrative enclaves.
  • Immutable, cryptographically signed audit logs recording all data ingestion, query, and transmission events.

3. Information We Collect

We collect information strictly necessary to provide high-performance engineering, medical billing consultation, and responsive technical support:

Commercial Inquiries:Contact details such as name, work email address, telephone number, organization name, practice specialty, and scoping messages submitted via discovery forms.
Technical Telemetry:Aggregated non-identifiable performance metrics including browser user agent, IP address (truncated), time-to-first-byte (TTFB), Core Web Vitals, and server response codes.

4. How We Use and Process Data

Crescentech does not sell, license, rent, or trade your personal or institutional data. Data collected is used exclusively for:

  • Evaluating prospective technical architectures, WordPress headless projects, and RCM scope.
  • Executing contractual deliverables outlined in approved Statements of Work (SOWs).
  • Enforcing information security, DDoS protection, and regulatory compliance obligations.
  • Maintaining 99.99% system uptime and continuous performance telemetry.

5. Technical & Physical Safeguards

Our infrastructure operates in dedicated, isolated SOC2 Type II audited cloud facilities (AWS GovCloud / HIPAA-compliant clusters). We perform continuous automated vulnerability scanning, periodic third-party penetration testing, and annual HIPAA security audits.

6. Third-Party Sharing & Clearinghouses

Data is transferred only to authorized downstream subcontractors who have signed HIPAA BAA agreements or rigorous non-disclosure agreements, including accredited electronic claim clearinghouses (e.g., Change Healthcare, Availity) and certified cloud infrastructure providers.

7. Your Rights & Access Controls

Under applicable privacy laws (including GDPR, CCPA/CPRA, and state healthcare privacy laws), clients have the right to request access to, rectification of, or secure deletion of their organizational information, subject to statutory healthcare record retention rules.

8. Privacy & Compliance Officer Contact

If you have questions regarding this Privacy Policy, wish to execute a Business Associate Agreement, or require compliance documentation, please reach out to our team:

Crescentech Solutions LLC — Office of Clinical Data Privacy
Email: compliance@crescentech.com • privacy@crescentech.com
Direct Line: +1 (800) 482-9174
Response SLA: Within 24 business hours.