Now accepting Q3 2026 pilot partnerships. Limited to three facilities. Reserve a slot ›

Privacy Policy

Effective date: July 22, 2026 Last updated: July 2026
01

Who We Are

Karepoint Billing Service LLP is a revenue cycle management company serving behavioral health and substance use disorder treatment facilities in the United States. We provide verification of benefits, prior authorization, concurrent review, and related billing services.

Important: This Privacy Policy applies to information collected through our website at mykarepoint.com. Our obligations regarding protected health information (PHI) handled in the course of providing services to client facilities are governed by separate Business Associate Agreements (BAA), HIPAA, and 42 CFR Part 2.

02

What We Collect

Through our website contact form, we collect the following information from prospective clients:

  • Your name and professional role
  • Business email address and phone number
  • Facility name and facility type
  • Questions or details you choose to share about your billing needs

We do not collect, store, or process patient information through our website. Our contact form explicitly prohibits the submission of protected health information.

Form Submission Method: Inquiry data is collected via Microsoft Forms or exported to Excel/SharePoint for lead management. Submissions are routed to info@mykarepoint.com and stored within our Google Workspace and Microsoft 365 environments.

03

How We Use Your Information

Information submitted through our website is used solely for the following purposes:

  • Responding to discovery call requests and service inquiries
  • Evaluating whether Karepoint is a good fit for your facility's needs
  • Scheduling and conducting discovery calls
  • Sending service-related communications you have requested

We do not sell, rent, or share your contact information with third parties for marketing purposes. We do not use your information for automated decision-making or profiling.

04

HIPAA Compliance

In our role as a business associate to HIPAA-covered entities, Karepoint handles protected health information in accordance with the Health Insurance Portability and Accountability Act (HIPAA) and its implementing regulations.

A signed Business Associate Agreement (BAA) is executed with every client facility before any protected health information is exchanged. The BAA governs our permitted uses and disclosures of PHI, our security obligations, our breach notification duties, and our compliance with all applicable regulations.

Note: No PHI should be submitted through our website contact form. All PHI-related communications and data handling occur under the terms of the applicable BAA after a client engagement has been formally established.

05

42 CFR Part 2 Compliance

Substance use disorder patient records that we handle on behalf of client facilities are subject to the federal confidentiality regulations at 42 CFR Part 2, which impose stricter protections than standard HIPAA requirements.

Our commitments under 42 CFR Part 2 include:

  • Tracking Part 2 patient consent separately from general PHI authorization at the data level
  • Never disclosing substance use disorder records without a valid, documented patient consent that meets Part 2 requirements
  • Applying redisclosure prohibitions to all downstream uses of Part 2-protected information
  • Training all staff specifically on Part 2 restrictions, separate from general HIPAA compliance training

These obligations are incorporated into every Business Associate Agreement we execute with client facilities serving patients whose records are subject to 42 CFR Part 2.

06

Third-Party Services

Our website and operations use the following third-party services:

  • Cloudflare Pages: Website hosting and content delivery. Cloudflare may collect access logs including IP addresses for security and performance analytics purposes. Cloudflare Analytics is enabled to track website traffic, visitor patterns, and performance metrics. These analytics do not identify individual visitors and are used solely to understand site usage and improve performance.
  • Google Workspace: Business email. Contact form submissions are routed via email to our team and stored within Google Workspace.
  • Microsoft 365: Business productivity suite. Lead inquiry data may be exported to Excel or SharePoint for lead management and CRM purposes.
  • Medium: Our Karepoint Insights blog is hosted on Medium (medium.com/@karepoint). Medium's own privacy policy applies when you visit our blog.

Data Sharing: We do not share your contact information with third parties for marketing purposes. Your data remains within Karepoint's systems (Google Workspace and Microsoft 365) and is not sold, rented, or disclosed outside of our organization except as required by law.

07

Data Security

We implement appropriate technical and organizational measures to protect contact information submitted through our website, including:

  • HTTPS encryption for all data in transit
  • Access controls limiting who can view inquiry emails
  • Business email accounts protected by multi-factor authentication
  • Microsoft 365 and Google Workspace security features (encryption, access logs, audit trails)

No system is 100% secure. We cannot guarantee absolute protection against all possible threats. However, we employ industry-standard safeguards consistent with the sensitivity of the data we handle.

08

Data Retention

Website inquiry data (contact form submissions) is retained for two years from the date of submission. This retention period allows us to nurture prospective relationships and respond to follow-up inquiries within a typical B2B sales cycle.

After two years, inquiry data is permanently deleted from our systems unless the prospect has become a paying customer.

If you become a customer: Your data transitions from our website inquiry system to our Business Associate Agreement (BAA) and is retained in accordance with HIPAA and applicable state law medical records retention requirements, which typically range from 6 to 10 years depending on your state and the services provided.

Deletion method: Data is permanently removed from all systems, including email archives, Excel records, and SharePoint repositories.

09

Your Rights

Regarding information you submit through our website, you may contact us to:

  • Request confirmation of what information we hold about you
  • Request correction of inaccurate information
  • Request deletion of your contact information (subject to any legal retention obligations)
  • Withdraw consent to further communications

To exercise any of these rights, contact us at the address below. We will respond within a reasonable timeframe.

Note: If you are a resident of California, the European Union, or the United Kingdom, you may have additional rights under applicable privacy laws (CCPA, GDPR, UK GDPR). Contact us for more information about your specific rights under your local jurisdiction.

10

Contact and Questions

For questions about this Privacy Policy, our data practices, or to exercise your rights, please contact us.

Privacy inquiries

For questions about this Privacy Policy, HIPAA compliance, 42 CFR Part 2 obligations, or to request information about your data, please reach out to our team directly.

info@mykarepoint.com
11

Business Associate Agreement

When you engage Karepoint as a service provider to handle protected health information (PHI) or substance use disorder patient records, a Business Associate Agreement (BAA) is executed before any PHI is processed or accessed.

Our BAA is based on the HHS Model Business Associate Agreement and incorporates all required HIPAA Safeguards Rules and 42 CFR Part 2 protections.

The BAA governs:

  • Our permitted uses and disclosures of PHI
  • Our obligations to maintain the confidentiality and security of PHI
  • Our breach notification duties
  • Our compliance with 42 CFR Part 2 redisclosure prohibitions
  • Your right to audit and inspect our security practices
  • Termination and return or destruction of PHI upon contract end

Important: This Privacy Policy addresses information collected through our website. The BAA is a separate, legally binding agreement that applies only to PHI handled in the course of providing services to client facilities.

No PHI should ever be submitted through our website contact form. All PHI-related communications occur under a signed BAA, with separate data handling, security protocols, and access controls.