Skip to content
PRIVACY

Privacy Policy

How Medical Legal Spider collects, uses, and protects your information, including protected health information handled under HIPAA.

EFFECTIVE DATE  ·  [September 3, 2026]
LAST UPDATED  ·  [September 3, 2026]
OVERVIEW

Overview

Medical Legal Spider (“MLS,” “we,” “us,” or “our”) provides medical record review, structuring, and summarization services to legal and insurance professionals. We take the privacy and security of your information seriously, particularly the protected health information (PHI) contained in the records you send us. This policy explains what we collect, why, how we protect it, and the choices you have.

This policy covers information collected through medicallegalspider.com (the “Site”) and through our services. It does not change any obligations set out in a Business Associate Agreement (BAA) or Master Services Agreement (MSA) between MLS and a client; where those agreements and this policy differ, the signed agreement controls.

DATA COLLECTED

Information we collect

Information you give us

When you request a demo, download samples, contact us, or open an account, we collect the details you provide, typically your name, company or firm, email, phone number, and any message content.

Case records and PHI

To perform our services, clients transmit medical records that may contain protected health information about third parties (claimants, patients). We process this information solely to deliver the contracted service, as a business associate under HIPAA where applicable, and under the terms of the governing BAA.

Information collected automatically

When you use the Site, we and our service providers may collect standard technical data: IP address, browser type, device information, pages viewed, and referring URLs. See our Cookie Policy for detail.

Information from security tools

We use reCAPTCHA and similar tools to prevent abuse; these may collect device and usage signals as described by their own providers.

PURPOSE

How we use information

—  To deliver, maintain, and improve our services and the Site

—  To respond to demo requests, sample downloads, and support inquiries

—  To communicate about your account, cases, and service updates

—  To send marketing communications, which you can opt out of at any time

—  To protect the security and integrity of our systems

—  To comply with legal, regulatory, and contractual obligations

We do not sell your personal information, and we do not sell or use PHI for any purpose beyond providing the contracted service.

HIPAA

Protected health information (HIPAA)

Where MLS acts as a business associate, we handle PHI in accordance with HIPAA, the HITECH Act, and the applicable BAA. We use PHI only to perform the services, apply administrative, physical, and technical safeguards to protect it, limit access to personnel who need it, and return or destroy it as the agreement requires. We maintain ISO 9001:2015 and ISO 27001:2022 certified processes across our operation.

DISCLOSURE

How we share information

We share information only as needed to run our business and deliver services:

—  Service providers who process data on our behalf under confidentiality and security obligations (for example, hosting, email, analytics, security)

—  Within the engagement, with the client who submitted the case

—  Legal and regulatory disclosures where required by law, subpoena, or court order

—  Business transfers, in connection with a merger, acquisition, or sale of assets, subject to this policy

We do not share your personal information or PHI with third parties for their own marketing.

SAFEGUARDS

Data security

We apply appropriate administrative, physical, and technical safeguards to protect information against loss, misuse, and unauthorized access, including encrypted transfer of records, access controls, and personnel training. No system is perfectly secure, but security is a core requirement of how we operate, not an afterthought.

RETENTION

Data retention

We keep personal information for as long as needed to provide services, meet legal and contractual obligations, resolve disputes, and enforce agreements. Case records and PHI are retained, returned, or destroyed according to the governing BAA or MSA.

YOUR RIGHTS

Your choices and rights

Marketing opt-out

Unsubscribe from any marketing email, or contact us to be removed.

Access and correction

You may request access to, or correction of, the personal information we hold about you, subject to legal and contractual limits. Requests about PHI are directed to the client that submitted the case, as the covered entity.

State privacy rights

Depending on your state of residence (for example, California under the CCPA/CPRA), you may have additional rights to access, delete, or limit the use of your personal information. [Confirm which state frameworks apply and detail here.]

To exercise any of these, contact us using the details below.

CHILDREN

Children’s privacy

The Site and our services are directed to businesses and professionals, not to children, and we do not knowingly collect personal information from children under 13.

JURISDICTION

International users

We are a US-based company serving the United States and Canada. If you access the Site from elsewhere, your information will be processed in the United States.

UPDATES

Changes to this policy

We may update this policy from time to time. Material changes will be posted here with a revised “Last updated” date. Continued use of the Site after changes take effect constitutes acceptance.

CONTACT

Questions about this policy?

Reach our team directly and we will route your request to the right person, whether it concerns marketing preferences, an active case, or a record request.

MEDICAL LEGAL SPIDER
ADDRESS
2770 Main Street, Suite 93
Frisco, TX 75033, United States
EMAIL
info@medicallegalspider.com
PHONE
1-855-677-4337
CERTIFICATION
ISO 9001:2015  ·  ISO 27001:2022