Privacy Policy
Effective September 27, 2026. This policy explains what information Revelrex collects through this website and its client and student portals, how it is used, who it is shared with, and the choices available to you.
1. Who we are and how to reach us
Revelrex ("Revelrex", "we", "us") provides revenue cycle management, practice transformation, healthcare technology and training services to healthcare organizations across the United States. Revelrex is the controller of the personal information described in this policy. For privacy questions or requests, write to info@revelrex.com.
2. Scope
This policy covers the public website, the client dashboard, the student dashboard, and email and telephone communications with Revelrex. It does not replace the Business Associate Agreement (BAA) and Master Services Agreement that govern how Revelrex handles protected health information (PHI) on behalf of a client practice. Where this policy and a signed agreement differ, the agreement controls for the information it covers.
3. Information we collect
3.1 Information you provide directly
- Contact and enquiry forms: name, practice or organization name, work email, phone number, state, specialty, the services you are interested in, and the message you write.
- Service requests and estimates: the services you select and the volumes you enter (for example monthly encounters, average collection per encounter, number of providers). Estimates are stored with your request so a representative can prepare a proposal.
- Booking a call: name, email, phone, practice, the topic you want to discuss and the appointment time you choose.
- Training enrollment requests: name, email, phone, state, the program you are interested in and any background you share.
- Certificate verification: the certificate number you enter.
- Client dashboard: practice profile, locations, providers, contacts, agreements and electronic signatures, invoices and payment records, support tickets and replies, documents you upload, and system-access information you choose to provide for services (stored encrypted, see section 7).
- Student dashboard: profile, enrollments, class attendance, assignment submissions, grades, certificates and training EHR credentials.
3.2 Information collected automatically
- Technical data: IP address, browser type and version, device type, operating system, referring page, pages viewed and timestamps.
- Security logs: sign-in attempts, session activity and an audit trail of sensitive actions in the dashboards (for example viewing an encrypted access record or signing an agreement). Audit records include the user, the action, the time and the IP address.
- Form protection: submission counts per address over short periods, used to limit automated abuse. A hidden form field is used to detect bots; it collects nothing from people.
3.3 Information from clients about their practice
When a practice engages Revelrex, it may provide information about its providers (names, NPI numbers, licenses, credentialing documents), its payers and contracts, and system access. This information is used only to deliver the contracted services.
3.4 Protected health information
Please do not enter patient information into public website forms. Revelrex receives and processes PHI only inside a client engagement covered by a BAA, and only through the client's own systems or secure channels agreed in writing. The training EHR uses synthetic patients only; entering real patient data into it is prohibited.
4. How we use information
- To respond to enquiries, prepare proposals, and schedule, confirm and remind you about calls.
- To deliver contracted services and operate the client and student dashboards, including agreements, invoicing, notifications, support and training records.
- To send service communications: confirmations, reminders, invoice notices, ticket updates, class schedules and certificate issuance. These are not marketing and you cannot opt out of them while you use the service.
- To send occasional updates about Revelrex services or training if you have asked for them. Every marketing email includes an unsubscribe link.
- To protect the website and portals: authentication, rate limiting, fraud and abuse prevention, and audit logging.
- To understand how the website is used and improve it, in aggregate.
- To comply with legal obligations, enforce our agreements, and establish or defend legal claims.
Revelrex does not sell personal information and does not share it with third parties for their own marketing.
5. Cookies and browser storage
- Session cookie: set when you sign in to a dashboard so the portal recognizes you. It expires when you sign out or after a period of inactivity.
- Browser storage: the services you add to a request are stored in your browser so they are still there when you return. Nothing is sent to Revelrex until you submit the request. You can clear it from your browser at any time.
- Analytics: if analytics is enabled, a third-party analytics service may set cookies to measure visits in aggregate. You can block these cookies in your browser without affecting the website.
Revelrex does not use advertising cookies or cross-site tracking.
6. When we share information
- Service providers that host the website and portals, deliver email, provide compliance monitoring and support operations. They may process information only on our instructions and under contracts that restrict its use. Where they may encounter PHI, a business associate agreement is in place.
- Within a client account: information in a client dashboard is visible to the users the client has authorized for that account and to Revelrex staff whose role requires it.
- Payers, credentialing bodies and program administrators when a client has engaged Revelrex to act with them on the practice's behalf (for example submitting an enrollment application).
- Legal requirements: when required by law, subpoena or court order, or to protect the rights, safety and property of Revelrex, its clients or others.
- Business transfers: if Revelrex is involved in a merger, acquisition or sale of assets, information may be transferred as part of that transaction, subject to this policy.
7. How we protect information
- Encryption in transit (TLS) for the website, portals and email where supported.
- System-access information provided by clients is encrypted at rest with a key unique to the installation, masked on screen, and every reveal is recorded in the audit log.
- Least-privilege roles for staff, client users and students; multi-factor authentication for privileged accounts; automatic lock-out after repeated failed sign-ins.
- Workforce HIPAA and security training, background checks, and immediate removal of access when someone leaves.
- A documented incident response plan and client notification procedures aligned to the BAA.
No method of transmission or storage is completely secure. If you believe your information has been compromised, contact us immediately at info@revelrex.com. More detail is on the Security & Compliance page.
8. How long we keep information
| Information | Retention |
|---|---|
| Website enquiries and estimates | Up to 24 months after the last contact, unless they become a client engagement |
| Booking records | 24 months after the meeting date |
| Client account records, agreements and invoices | The term of the agreement plus the period required by law or the agreement (typically seven years for financial records) |
| Student records and certificates | Certificates and completion records are kept so they can be verified; other course activity for five years after completion |
| Security and audit logs | At least six years, as HIPAA documentation requirements expect |
| System-access information | Deleted or returned at the end of the engagement as the BAA requires |
9. Your choices and rights
- Access and correction: you may ask for a copy of the personal information we hold about you and ask us to correct it. Dashboard users can update most profile information themselves.
- Deletion: you may ask us to delete personal information. We will do so unless we must keep it under a client agreement, a legal obligation, or to maintain the integrity of audit records and issued certificates.
- Marketing: use the unsubscribe link in any marketing email or write to us.
- Cookies: control them in your browser settings.
Residents of California and other states with privacy laws may have additional rights, including the right to know the categories of information collected and the right not to be discriminated against for exercising their rights. Revelrex does not sell or share personal information for cross-context behavioral advertising. To exercise any right, email info@revelrex.com with "Privacy request" in the subject line. We will verify your identity and respond within the time the applicable law requires, usually within 45 days.
10. Text messages (SMS)
If you check the SMS consent box on our contact form, you agree to receive text messages from Revelrex at the number you provide about your enquiry, appointments, agreements, invoices and support. Message frequency varies. Message and data rates may apply. You can opt out at any time by replying STOP, and reply HELP for help. Consent to receive texts is not a condition of any purchase. Mobile phone numbers and SMS opt-in consent will not be shared with or sold to third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent are used only to deliver the messages you asked for.
11. Children
The website and services are intended for healthcare professionals and adult learners. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided information to us, contact us and we will delete it.
12. Third-party links
The website links to other sites, such as payer portals, program administrators and social networks. Their privacy practices are their own; review their policies before providing information.
13. Location of processing
Revelrex operates in the United States and stores information on servers located in the United States. If you access the website from elsewhere, you understand that your information will be processed in the United States.
14. Changes to this policy
We will post any changes on this page with a new effective date. For significant changes affecting client or student accounts, we will also notify account holders by email or dashboard notification.
15. Contact
Revelrex
Email: info@revelrex.com
This policy is provided for information and should be reviewed by your own counsel for your jurisdiction and circumstances.