Effective Date: April 29, 2025
At TAS United, we are committed to protecting your privacy and safeguarding your personal information. This Privacy Policy outlines how we collect, use, disclose, and protect your data in compliance with the Texas Data Privacy and Security Act (TDPSA), which serves as our guiding framework for privacy practices nationwide. As a HITRUST-certified organization handling protected health information (PHI), we also adhere to the Health Insurance Portability and Accountability Act (HIPAA) and maintain rigorous security standards to ensure your data is secure.
1. Scope of This Policy
This Privacy Policy applies to all personal data collected by TAS United through our website (tasunited.com), call answering services, on-call portals, and other services we provide to healthcare organizations and their patients. Personal data includes any information that identifies or can be used to identify an individual, such as names, contact details, or health-related information.
2. Information We Collect
We collect the following categories of personal data, as permitted by TDPSA and HIPAA:
Personal Identifiers: Name, phone number, email address, mailing address, or other contact information provided when you interact with our services.
Protected Health Information (PHI): Health-related data, such as medical history or appointment details, collected on behalf of healthcare providers in compliance with HIPAA.
Usage Data: Information about how you interact with our website or services, including IP addresses, browser types, and page views.
Commercial Information: Billing or payment information, if applicable, for services rendered.
Sensitive Personal Data: As defined by TDPSA, this may include precise geolocation data, health data, or other sensitive information collected with your consent or as required by law.
We collect this information directly from you, from healthcare providers we serve, or automatically through cookies and similar technologies on our website.
3. How We Use Your Information
We use your personal data for the following purposes, in accordance with TDPSA, HIPAA, and HITRUST standards:
Service Delivery: To provide call answering, scheduling, and communication services for healthcare providers and their patients.
Compliance with Legal Obligations: To meet HIPAA requirements for safeguarding PHI and TDPSA requirements for consumer data rights.
Security: To protect your data through encryption, multi-factor authentication, and HITRUST-certified controls.
Website Functionality: To improve user experience and analyze website performance using aggregated, de-identified data.
Communication: To respond to inquiries, provide customer support, or send service-related notifications.
We do not sell your personal data or share it for cross-context behavioral advertising, as defined by TDPSA.
4. How We Share Your Information
We may share your personal data only in the following circumstances:
With Healthcare Providers: PHI is shared with authorized healthcare providers to facilitate patient care, in strict compliance with HIPAA.
With Service Providers: We engage HITRUST-certified vendors who process data on our behalf under strict confidentiality agreements.
For Legal Compliance: We may disclose data to comply with applicable laws, court orders, or government requests, as required by TDPSA or HIPAA.
With Your Consent: We share data only when you provide explicit consent, unless otherwise permitted by law.
5. Your Privacy Rights Under TDPSA
As a Texas resident or consumer interacting with our services, you have the following rights under TDPSA, which we extend to all users nationwide:
Right to Access: Request confirmation of whether we process your personal data and access details about what data we hold.
Right to Correct: Request correction of inaccurate personal data.
Right to Delete: Request deletion of your personal data, subject to HIPAA retention requirements.
Right to Opt-Out: Opt-out of the sale or sharing of your personal data for targeted advertising (not applicable, as we do not sell or share data for these purposes).
Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
To exercise these rights, contact our Compliance Officer at compliance@tasunited.com or call (800) 279-0537. We will respond within 45 days, as required by TDPSA, and verify your identity to protect your data.
6. HIPAA Compliance
As a business associate under HIPAA, we protect PHI through:
Safeguards: Physical, technical, and administrative measures, including encryption and access controls.
Breach Notification: Prompt notification to affected individuals and healthcare providers in the event of a data breach, as required by HIPAA.
Business Associate Agreements: Contracts with healthcare providers to ensure PHI is handled securely.
7. HITRUST Certification
Our HITRUST certification demonstrates our commitment to industry-leading security and privacy standards. We undergo regular audits to maintain compliance with HITRUST CSF requirements, ensuring robust protection of your data.
8. Data Security
We implement the following measures to secure your data:
Encryption: Data is encrypted in transit and at rest using industry-standard protocols.
Multi-Factor Authentication: Access to sensitive systems requires multiple verification steps.
Regular Audits: Continuous monitoring and testing to identify and address vulnerabilities.
Employee Training: Staff are trained on HIPAA, TDPSA, and HITRUST requirements to ensure compliance.
9. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes outlined in this policy or as required by law. PHI is retained in accordance with HIPAA requirements, typically for a minimum of six years. Other personal data is deleted upon request, subject to legal obligations, as per TDPSA’s “Right to Delete.”
10. Cookies and Tracking
Our website uses cookies to enhance functionality and analyze usage. You can manage cookie preferences through your browser settings. We do not use cookies for targeted advertising or profiling, in line with TDPSA requirements.
11. Children’s Privacy
Our services are not directed to individuals under 18. We do not knowingly collect personal data from children. If we learn that we have collected such data, we will delete it promptly.
12. International Data Transfers
As a U.S.-based company, we process data primarily in the United States. If data is transferred internationally, we ensure compliance with applicable privacy laws and use HITRUST-certified safeguards.
13. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our practices or legal requirements. We will notify you of material changes by posting the updated policy on our website and updating the effective date. Please review this policy periodically.
14. Contact Us
If you have questions about this Privacy Policy or wish to exercise your privacy rights, please contact our Compliance Officer:
Email: compliance@tasunited.com
Phone: (800) 279-0537
Mail: TAS United, Attn: Compliance Officer, 1503 Avenue J, Lubbock, TX 79401
We are committed to addressing your concerns promptly and in compliance with TDPSA, HIPAA, and HITRUST standards.