Legal
Privacy Policy
In short
- We collect what we need to run RateBench: your account and practice details, the NPIs, codes and payers you look up, and billing status. Card numbers stay with Stripe.
- No patient information. Underpayment files are totalled in your browser.
- Google Analytics runs only if you click Allow. We use no advertising cookies and we never sell your data.
- Rate alerts can be switched off at any time. Tips and offers are opt-in.
- Email hello@ratebench.health to see, correct or delete your data.
1. Who we are
RateBench is operated by Inorox LLC (“we,” “us”). We decide how the personal information described here is used, and we are responsible for it. This policy covers ratebench.health, app.ratebench.health, our emails, and our free rate lookup.
RateBench is a business service for medical practices and the organizations that work with them. Most of the data it handles is about providers and payers, and much of it is public.
2. What we collect
When you visit the website
- Free rate lookup: your email address, the NPI and payer you choose, your email choices, and the IP address and browser details from that request.
- Contact and partner forms: your name, email, organization and message.
- Cookie choice: whether you allowed analytics, with a random ID, the time, IP address and browser details, so we can show what you chose.
- Analytics, only if you allow it: pages viewed, referring site, device type and approximate location, collected by Google Analytics.
When you use the app
- Account: your name and email, and if you sign in with Google or Microsoft, the account identifier they share with us.
- Practice: practice name, specialties, team members and invitations.
- Fee schedules and lookups: the NPIs, tax IDs, billing codes and payers you choose, and the rates we find.
- Underpayment checks: totals by billing code, such as allowed amounts and claim counts. Your file is read and totalled in your browser, so individual claims and patient details never reach us.
- Billing: your plan, billing status and billing contact. Card details are entered directly with Stripe; we never see or store your full card number.
- Email settings and consent history: which emails you get, and a record of every change with its time, source, IP address and browser details.
- Service records: which lookups ran, how long they took and whether they worked, so we can keep the Service reliable.
Public data we use
Payers’ Transparency in Coverage files and public provider directories such as the NPPES NPI registry. These describe providers and contracted rates, not patients.
3. How we use it
- To provide the Service: run lookups, build fee schedules, run checks and keep your account working.
- To send service emails, such as sign-in and billing messages and notice that your fee schedule is ready, and the rate alerts described in Section 4.
- To send tips and offers, only if you opted in.
- To bill you, prevent fraud and abuse, and secure the Service.
- To understand and improve the Service, using analytics you allowed and aggregated, de-identified usage information.
- To meet legal obligations and enforce our Terms.
If you are in the European Economic Area or the United Kingdom, we rely on: performing our contract with you; our legitimate interests in running, securing and improving a business service; your consent (for analytics cookies and marketing email); and legal obligations.
4. The emails we send
- Always sent: sign-in, security and billing messages, and emails about fee schedules you asked us to build.
- Rate alerts (a payer changed one of your rates, your underpayment report, the monthly refresh): on for customers, and you can switch them off with the unsubscribe link in any alert or under Practice → Email.
- Website lookup updates: only if you ticked that box on the lookup form.
- Tips and offers: only if you opted in. Unsubscribe any time.
We keep a record of each consent you give or withdraw, including when and how, so we can honor your choices and show that we did.
7. Where it is processed
We store and process information mainly in the United States. Some of our providers may process it in other countries. Where they do, we rely on their contractual and security commitments to protect it.
8. How long we keep it
- Account and practice data: for as long as your account is open, and deleted within 90 days after it closes, except as below.
- Billing records: as long as tax and accounting law requires, generally up to 7 years.
- Website lookups and contact requests: up to 24 months, unless you ask us to delete them sooner.
- Consent records: as long as we need to show how and when your choices were made.
- Backups and service logs: overwritten on their normal cycle, generally within 90 days.
9. How we protect it
We encrypt data in transit, lock our database so only our own application can read or write it, and limit which staff can reach production systems. No system is perfectly secure; if a breach affects your personal information, we will notify you as the law requires.
10. Your choices and rights
You can ask us to tell you what personal information we hold about you, give you a copy, correct it, or delete it. You can also withdraw consent to analytics or marketing at any time, which doesn’t affect anything done before. Some information we must keep for legal reasons, and we’ll tell you if that applies.
California and other U.S. states: depending on where you live, you may have rights to know, access, correct, delete and port your information, and to opt out of its sale or sharing (we don’t sell or share it). We won’t treat you differently for using these rights. An authorized agent may act for you with proof of authority.
European Economic Area and United Kingdom: you also have rights to restrict or object to processing, and to complain to your local data protection authority.
To make a request, email hello@ratebench.health from the address on your account, or tell us which email you used on our website. We may need to verify your identity. We respond within 45 days, or sooner where the law requires.
11. Health information
RateBench is designed so you never need to send us protected health information, and we ask you not to. We are not a HIPAA business associate. If patient information reaches us by mistake, tell us at hello@ratebench.health and we will delete it.
12. Children
The Service is for businesses and is not directed to anyone under 18. We don’t knowingly collect information from children.
13. Changes to this policy
We will post any update here with a new effective date. If a change is material, we will tell customers by email or in the app before it takes effect.
14. Contact
Privacy questions and requests: hello@ratebench.health. Inorox LLC, operating RateBench.