Privacy Policy
How Medical Legal Spider collects, uses, and protects your information, including protected health information handled under HIPAA.
Overview
Medical Legal Spider (“MLS,” “we,” “us,” or “our”) provides medical record review, structuring, and summarization services to legal and insurance professionals. We take the privacy and security of your information seriously, particularly the protected health information (PHI) contained in the records you send us. This policy explains what we collect, why, how we protect it, and the choices you have.
This policy covers information collected through medicallegalspider.com (the “Site”) and through our services. It does not change any obligations set out in a Business Associate Agreement (BAA) or Master Services Agreement (MSA) between MLS and a client; where those agreements and this policy differ, the signed agreement controls.
Information we collect
When you request a demo, download samples, contact us, or open an account, we collect the details you provide, typically your name, company or firm, email, phone number, and any message content.
To perform our services, clients transmit medical records that may contain protected health information about third parties (claimants, patients). We process this information solely to deliver the contracted service, as a business associate under HIPAA where applicable, and under the terms of the governing BAA.
When you use the Site, we and our service providers may collect standard technical data: IP address, browser type, device information, pages viewed, and referring URLs. See our Cookie Policy for detail.
We use reCAPTCHA and similar tools to prevent abuse; these may collect device and usage signals as described by their own providers.
How we use information
— To deliver, maintain, and improve our services and the Site
— To respond to demo requests, sample downloads, and support inquiries
— To communicate about your account, cases, and service updates
— To send marketing communications, which you can opt out of at any time
— To protect the security and integrity of our systems
— To comply with legal, regulatory, and contractual obligations
We do not sell your personal information, and we do not sell or use PHI for any purpose beyond providing the contracted service.
Protected health information (HIPAA)
Where MLS acts as a business associate, we handle PHI in accordance with HIPAA, the HITECH Act, and the applicable BAA. We use PHI only to perform the services, apply administrative, physical, and technical safeguards to protect it, limit access to personnel who need it, and return or destroy it as the agreement requires. We maintain ISO 9001:2015 and ISO 27001:2022 certified processes across our operation.
How we share information
We share information only as needed to run our business and deliver services:
— Service providers who process data on our behalf under confidentiality and security obligations (for example, hosting, email, analytics, security)
— Within the engagement, with the client who submitted the case
— Legal and regulatory disclosures where required by law, subpoena, or court order
— Business transfers, in connection with a merger, acquisition, or sale of assets, subject to this policy
We do not share your personal information or PHI with third parties for their own marketing.
Data security
We apply appropriate administrative, physical, and technical safeguards to protect information against loss, misuse, and unauthorized access, including encrypted transfer of records, access controls, and personnel training. No system is perfectly secure, but security is a core requirement of how we operate, not an afterthought.
Data retention
We keep personal information for as long as needed to provide services, meet legal and contractual obligations, resolve disputes, and enforce agreements. Case records and PHI are retained, returned, or destroyed according to the governing BAA or MSA.
Your choices and rights
Unsubscribe from any marketing email, or contact us to be removed.
You may request access to, or correction of, the personal information we hold about you, subject to legal and contractual limits. Requests about PHI are directed to the client that submitted the case, as the covered entity.
Depending on your state of residence (for example, California under the CCPA/CPRA), you may have additional rights to access, delete, or limit the use of your personal information. [Confirm which state frameworks apply and detail here.]
To exercise any of these, contact us using the details below.
Children’s privacy
The Site and our services are directed to businesses and professionals, not to children, and we do not knowingly collect personal information from children under 13.
International users
We are a US-based company serving the United States and Canada. If you access the Site from elsewhere, your information will be processed in the United States.
Changes to this policy
We may update this policy from time to time. Material changes will be posted here with a revised “Last updated” date. Continued use of the Site after changes take effect constitutes acceptance.
Questions about this policy?
Reach our team directly and we will route your request to the right person, whether it concerns marketing preferences, an active case, or a record request.
Frisco, TX 75033, United States