Privacy
Privacy Policy
Effective May 14, 2026
ProvCreda LLC provides provider credentialing, provider enrollment, payer follow-up, and related healthcare administration support. This policy describes how information may be handled through the public website, invite-based portal, and approved secure service channels.
Information We Process
The public contact form may collect business contact details, organization information, service interest, and non-sensitive operational context. The portal may process approved user profiles, provider organization records, provider enrollment workflow data, payer follow-up notes, reports, and uploaded operational documents from authorized users.
Sensitive Information
Do not submit passwords, payer portal credentials, PHI, Social Security numbers, date-of-birth details, license images, claims information, or sensitive provider records through public website forms. Private records should only be shared through approved secure channels established by ProvCreda.
HIPAA and Business Associate Context
When ProvCreda creates, receives, maintains, or transmits PHI or ePHI on behalf of a covered entity or another business associate, the work is expected to be governed by appropriate written agreements, secure workflows, and production safeguards. Public website submission does not create a HIPAA-compliant intake channel or business associate relationship by itself.
How Information Is Used
Information is used to respond to inquiries, manage authorized services, support credentialing and payer enrollment workflows, administer accounts, create reporting, and maintain security and audit records.
Access Controls
Portal access is invite-based. Admins assign roles and provider organization access. Provider users are scoped to their organization. Employee users receive access according to operational responsibilities. The HIPAA readiness model includes least-privilege access, unique user accounts, MFA requirements for workforce/admin PHI workflows, session timeout expectations, and access removal when responsibilities change.
Security
ProvCreda's security model uses environment-managed secrets, hashed passwords, role-based access control, audit logs, secure deployment practices, restricted portal access, upload limits, security headers, link-only notifications for sensitive records, and controls designed to keep PHI out of public forms, URLs, analytics, and email bodies. PHI-handling workflows are being aligned to BAA-covered infrastructure, AWS-ready protected storage/database architecture, encryption, backups, vendor review, incident response, and documented administrative, physical, and technical safeguards.
Contact
Questions about this policy can be sent to support@provcreda.com.
