Privacy Policy & HIPAA Data Protection
Effective Date: January 1, 2026 • Last Reviewed: March 2026 • Crescentech Solutions LLC.
Policy Table of Contents
1. Scope & Covered Entities
This Privacy Policy governs the practices of Crescentech Solutions LLC ("Crescentech", "we", "our", or "us") across our website, proprietary applications, client intake portals, and electronic health record integration modules.
Where Crescentech provides digital engineering, cloud infrastructure, or revenue cycle management (RCM) services to covered healthcare providers, hospitals, clinics, or billing entities, our handling of Protected Health Information (PHI) is governed additionally by a formal, bilateral Business Associate Agreement (BAA) pursuant to 45 CFR § 164.502(e) and § 164.504(e).
2. Protected Health Information (PHI) Handling
In our capacity as a Business Associate under HIPAA and the HITECH Act, Crescentech strictly enforces:
- Zero client-side caching of identifiable patient records in public browser storage.
- FIPS 140-2 validated encryption algorithms for all data at rest (AES-256) and in transit (TLS 1.3).
- Strict role-based access control (RBAC) and mandatory multi-factor authentication (MFA) across all administrative enclaves.
- Immutable, cryptographically signed audit logs recording all data ingestion, query, and transmission events.
3. Information We Collect
We collect information strictly necessary to provide high-performance engineering, medical billing consultation, and responsive technical support:
4. How We Use and Process Data
Crescentech does not sell, license, rent, or trade your personal or institutional data. Data collected is used exclusively for:
- Evaluating prospective technical architectures, WordPress headless projects, and RCM scope.
- Executing contractual deliverables outlined in approved Statements of Work (SOWs).
- Enforcing information security, DDoS protection, and regulatory compliance obligations.
- Maintaining 99.99% system uptime and continuous performance telemetry.
5. Technical & Physical Safeguards
Our infrastructure operates in dedicated, isolated SOC2 Type II audited cloud facilities (AWS GovCloud / HIPAA-compliant clusters). We perform continuous automated vulnerability scanning, periodic third-party penetration testing, and annual HIPAA security audits.
6. Third-Party Sharing & Clearinghouses
Data is transferred only to authorized downstream subcontractors who have signed HIPAA BAA agreements or rigorous non-disclosure agreements, including accredited electronic claim clearinghouses (e.g., Change Healthcare, Availity) and certified cloud infrastructure providers.
7. Your Rights & Access Controls
Under applicable privacy laws (including GDPR, CCPA/CPRA, and state healthcare privacy laws), clients have the right to request access to, rectification of, or secure deletion of their organizational information, subject to statutory healthcare record retention rules.
8. Privacy & Compliance Officer Contact
If you have questions regarding this Privacy Policy, wish to execute a Business Associate Agreement, or require compliance documentation, please reach out to our team: