Privacy Policy
How MedTech For Solutions collects, uses, protects, and shares personal information — including how we handle protected health information in our role as a Business Associate to fertility clinics and ART practices nationwide.
01 Introduction & Scope
MedTech For Solutions Inc. (“MedTech,” “we,” “us,” or “our”) is a healthcare consulting and laboratory management company founded in 2005 and headquartered at location available upon request. Since our founding, we have delivered end-to-end assisted reproductive technology (ART) practice support to fertility clinics, IVF laboratories, and reproductive medicine facilities across all 50 states — encompassing laboratory management and optimization, regulatory compliance, staffing and recruitment, Group Purchasing Organization (GPO) services, practice development, and comprehensive management services.
This Privacy Policy explains how MedTech collects, uses, discloses, retains, and protects personal information when you:
- Visit this website or any linked MedTech web property (the “Site”);
- Submit an inquiry, schedule a consultation, or otherwise communicate with us;
- Engage MedTech as a service provider, vendor, or consulting partner;
- Apply for employment, temporary placement, or recruitment through our staffing services;
- Join or participate in our Group Purchasing Organization (GPO); or
- Use the OvaTools Laboratory Management System or any other MedTech platform.
By using the Site or providing information to us, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please discontinue use of the Site and do not submit information to us.
02 Information We Collect
We collect personal information in three ways: directly from you, automatically when you interact with the Site, and from third-party sources.
2.1 Information You Provide Directly
- Identity & contact details — name, job title, organization name, email address, phone number, and mailing address submitted through inquiry forms, contact pages, or direct correspondence.
- Practice & facility information — details about your fertility clinic or IVF laboratory (size, location, current vendors, services offered, regulatory status) shared during scoping or onboarding discussions.
- Service engagement records — correspondence, meeting notes, project documentation, operational metrics, laboratory data, and other materials exchanged in the course of delivering our services.
- Recruitment & staffing information — résumés, CVs, professional credentials (TS/ABB certification, HCLD designation, board certifications, state licenses), employment history, references, and background-check consent when you apply for placement or recruitment services.
- GPO membership data — entity legal name, federal tax identification number, authorized signatories, billing address, facility type, and purchasing volume information.
- Financial & payment information — billing address, invoicing contacts, and banking or ACH details for contract payments. Card payments, when accepted, are processed exclusively by PCI-DSS-compliant third-party processors; MedTech does not store full card numbers.
- Communications content — messages, feedback, survey responses, and support requests you send us by any channel.
2.2 Information Collected Automatically
- Device & connection data — IP address, browser type and version, operating system, screen resolution, language and time-zone settings.
- Usage & navigation data — pages visited, time on page, click paths, referring URL, and search terms used to arrive at the Site.
- Cookies & similar technologies — see the Cookie Policy in Section 7 for full details.
2.3 Information from Third Parties
- Referrals — basic identifying information when an existing client, partner, or industry contact refers you to us.
- Recruitment partners & licensing bodies — professional credentials or background information shared by staffing platforms, the American Board of Bioanalysis, state licensing boards, or similar entities in a recruitment context.
- Public professional sources — information available in professional directories, conference attendee lists, regulatory agency filings, and publicly accessible business records.
03 How We Use Information
We process personal information only for legitimate purposes related to operating and improving our services. Specific uses include:
- Responding to inquiries, scheduling consultations, and managing prospective client relationships;
- Delivering the IVF laboratory management, compliance, staffing, GPO, practice development, and management services you or your organization have engaged us to provide;
- Operating, maintaining, securing, and improving the Site and our internal platforms, including OvaTools LMS;
- Matching qualified embryologists, laboratory directors, and ART professionals with temporary or permanent placement opportunities;
- Administering GPO membership, vendor contracting, order facilitation, and rebate accounting across our 1,800+ vendor network;
- Sending operational communications — contract notices, service updates, compliance alerts, and invoices;
- Sending marketing communications about MedTech services where lawfully permitted; you may opt out at any time (see Section 10);
- Conducting aggregate or de-identified analytics, quality benchmarking, and outcome research to improve our laboratory programs;
- Complying with legal, regulatory, accreditation, and audit obligations — including FDA, CLIA, CAP, AABB, CMS, and applicable state requirements;
- Detecting, preventing, and investigating fraud, unauthorized access, and other unlawful activities; and
- Establishing, exercising, or defending legal claims.
Where required by law, we rely on the following legal bases: contractual necessity (delivering agreed services), legitimate interests (operating and improving our business, security), legal obligation (regulatory compliance), and consent (marketing communications where required). We do not sell personal information and do not use it for cross-context behavioral advertising.
04 HIPAA & Protected Health Information
MedTech For Solutions is generally not a HIPAA Covered Entity. However, certain services — including Real-Time Laboratory Monitoring, OvaTools LMS, and specified practice management engagements — involve receiving, creating, maintaining, or transmitting Protected Health Information (PHI) on behalf of our Covered Entity clients. In those circumstances, MedTech acts as a Business Associate under HIPAA.
Business Associate Agreements (BAAs)
Before receiving any PHI, MedTech executes a written BAA with each Covered Entity client. The BAA, together with the HIPAA Privacy Rule (45 CFR Part 164, Subpart E), Security Rule (Subpart C), and Breach Notification Rule (Subpart D), governs our handling of that PHI — not this Privacy Policy. Each BAA specifies:
- Permitted and required uses and disclosures of PHI, limited to those necessary for the contracted services or required by law;
- Administrative, physical, and technical safeguards commensurate with the nature and sensitivity of the PHI;
- Subcontractor flow-down obligations — any subcontractor receiving PHI is bound by equivalent BAA terms;
- Breach notification to the Covered Entity within the timeframes required by 45 CFR § 164.410; and
- Disposition of PHI upon termination — return, destruction, or continued protection where return/destruction is infeasible.
Safeguards for PHI
For engagements involving PHI, MedTech implements the HIPAA Security Rule’s required and addressable safeguards, including: workforce training and access controls, encryption of PHI in transit and at rest, audit logging, workstation and device security, and a formal risk analysis and risk management program reviewed at least annually.
Patient Inquiries
MedTech is not a healthcare provider and is not the Covered Entity for any patient’s care. If you are a patient of one of our client clinics, please direct all clinical questions, medical record requests, accounting-of-disclosures requests, and similar HIPAA inquiries to your treating clinic. We will promptly route any patient inquiry that reaches us to the appropriate Covered Entity.
De-Identified & Aggregate Data
We may use de-identified data — from which all 18 HIPAA identifiers have been removed in accordance with the Safe Harbor or Expert Determination methods under 45 CFR § 164.514(b) — and aggregate statistics for benchmarking, research, quality improvement, and service development. De-identified data is not PHI and is not subject to HIPAA use or disclosure restrictions.
05 GDPR & International Privacy
MedTech operates primarily in the United States under U.S. law. We do not actively market to residents of the European Economic Area (EEA), the United Kingdom (UK), or Switzerland. If you are located in one of those jurisdictions and voluntarily provide us with personal information (for example, as a conference contact or international client), the following applies.
Legal Bases for Processing (EEA / UK)
| Processing Purpose | Legal Basis (GDPR Art. 6) |
|---|---|
| Responding to inquiries and delivering contracted services | Art. 6(1)(b) — Performance of a contract / pre-contractual steps |
| Operating the Site, fraud prevention, security | Art. 6(1)(f) — Legitimate interests |
| Marketing communications (where applicable) | Art. 6(1)(a) — Consent (withdrawable at any time) |
| Compliance with legal obligations | Art. 6(1)(c) — Legal obligation |
Your GDPR / UK GDPR Rights
Where the GDPR or UK GDPR applies, you have the right to: access your personal data; rectify inaccurate data; request erasure (“right to be forgotten”) subject to legal retention obligations; restrict processing; object to processing based on legitimate interests; and receive your data in a portable format. You also have the right to lodge a complaint with your national supervisory authority (e.g., the ICO in the UK or a lead authority under the EU’s one-stop-shop mechanism).
International Data Transfers
Personal data transferred from the EEA, UK, or Switzerland to the United States is subject to appropriate safeguards. Where required, MedTech relies on Standard Contractual Clauses (SCCs) adopted by the European Commission, or the UK International Data Transfer Agreement (IDTA), as the transfer mechanism. Copies of applicable SCCs or IDTAs are available on request by emailing contact form.
EU/UK Representative
As MedTech does not have an establishment in the EEA or UK and processes EEA/UK data only on an incidental basis, we have not designated a formal EU/UK representative. If you are an EEA or UK data subject with a privacy concern, please contact our Privacy Office directly (see Section 15).
08 Data Security
MedTech implements administrative, physical, and technical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, loss, or destruction. Our security program includes:
- Encryption — TLS 1.2+ for all data in transit; encryption at rest for systems that process sensitive client, candidate, or PHI-adjacent data;
- Access controls — role-based access, principle of least privilege, and regular access reviews to limit exposure of personal data to authorized personnel only;
- Multi-factor authentication (MFA) — required for administrative access to all client-facing and internal platforms, including OvaTools LMS;
- Vulnerability management — regular vulnerability scanning, software patching, and annual penetration testing reviews;
- Vendor security — security assessments of key subprocessors and contractual flow-down of security obligations commensurate with data sensitivity;
- Employee training — annual HIPAA and information-security awareness training for all staff with access to personal or protected information; and
- Incident response — a documented incident response plan with defined escalation paths and notification timelines, including compliance with HIPAA’s Breach Notification Rule (45 CFR §§ 164.400–414) for PHI breaches.
Despite these measures, no method of electronic transmission or storage is 100% secure. If you believe your information has been compromised in connection with MedTech, please contact us immediately at contact form.
09 Data Retention
We retain personal information only as long as necessary to fulfil the purposes described in this Policy, to satisfy legal and regulatory obligations, to resolve disputes, and to enforce our agreements. Guiding retention periods are:
- Website inquiry & lead records — up to 24 months from last contact, then deleted or anonymized unless an engagement commences.
- Active client engagement records — duration of the engagement plus 6–7 years to meet professional standards, contractual requirements, and applicable statutes of limitations.
- Recruitment & staffing files — 3 years from last activity, unless a longer period is required by law or you have asked to remain in our active candidate pool.
- GPO membership records — duration of membership plus 7 years for rebate auditing and tax purposes.
- Financial, billing & tax records — as required by federal and state tax law (generally 7 years from the relevant tax year).
- PHI under a BAA — per the terms of the applicable BAA and HIPAA requirements, including 6-year documentation retention under 45 CFR § 164.530(j).
- Employee / HR records — as required by federal and state employment law, typically 3–7 years post-termination.
When personal information is no longer needed, we delete or securely destroy it, or anonymize it so it can no longer be associated with an individual.
10 Your Rights & Choices
Depending on your jurisdiction and the context in which you interact with us, you may have the following rights regarding your personal information:
- Access — request a copy of the personal information we hold about you, including the categories, sources, and purposes of processing;
- Correction / Rectification — ask us to correct inaccurate or incomplete personal information;
- Deletion / Erasure — request that we delete your personal information, subject to overriding legal or contractual retention requirements;
- Restriction of processing — ask us to pause certain processing activities while a dispute is resolved;
- Objection — object to processing based on our legitimate interests, including objection to direct marketing (which we will honor unconditionally);
- Data portability — receive the personal information you provided to us in a structured, machine-readable format, where technically feasible;
- Withdraw consent — where processing is based on consent (e.g., marketing emails), withdraw consent at any time without affecting the lawfulness of prior processing; and
- Opt out of marketing — use the unsubscribe link in any marketing email, or Message Us at any time, to stop receiving promotional communications.
For PHI handled under a BAA, HIPAA rights requests (accounting of disclosures, access, amendment) must be directed to your treating Covered Entity clinic — MedTech is not the appropriate party to respond to those requests.
11 California Residents — CCPA / CPRA
If you are a California resident, the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 (collectively “CCPA/CPRA”) grants you additional rights in addition to those described in Section 10.
Categories of Personal Information Collected
In the past 12 months we have collected the categories of personal information described in Section 2, which include: identifiers; professional or employment-related information; commercial information (GPO purchasing records); internet or electronic network activity; and inferences drawn to create a profile about business preferences. We collected this information for the business purposes described in Section 3 and disclosed it to the categories of recipients in Section 6.
No Sale or Sharing for Behavioral Advertising
MedTech has not sold and does not sell personal information as defined by the CCPA/CPRA. MedTech has not shared and does not share personal information for cross-context behavioral advertising.
Your CCPA/CPRA Rights
- Right to Know — the categories and specific pieces of personal information collected about you and how it was used and shared;
- Right to Delete — deletion of personal information, subject to exceptions for completing transactions, security, legal obligations, and other permitted uses;
- Right to Correct — correction of inaccurate personal information;
- Right to Opt Out of Sale/Sharing — not applicable as we do not sell or share for advertising; and
- Right to Non-Discrimination — you will not receive discriminatory treatment for exercising any CCPA/CPRA right.
To exercise your CCPA/CPRA rights, contact us as described in Section 15. You may authorize an agent to submit a request on your behalf by providing written authorization and identity verification. We will respond within 45 days, with a possible 45-day extension where reasonably necessary.
12 Children’s Privacy
The Site and MedTech’s services are directed exclusively to healthcare professionals, fertility clinic operators, IVF laboratory directors, and practice managers. We do not knowingly collect personal information from children under 13 (or under 16 where a higher age threshold applies under applicable law). If we learn that we have inadvertently collected personal information from a minor, we will delete it promptly. If you believe we hold personal information about a child, please contact us at contact form.
13 Third-Party Links & Services
The Site may contain links to vendor portals, professional association websites, regulatory agency resources, and other third-party platforms. Once you leave the Site, this Privacy Policy no longer applies. We are not responsible for the privacy practices or content of third-party sites. We encourage you to review the privacy policy of any third party before providing personal information.
Third-party services embedded in or linked from the Site (such as scheduling tools, e-signature platforms, or GPO vendor portals) operate under their own privacy policies and, where applicable, data processing agreements with MedTech.
14 Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our services, practices, or legal requirements. The “Last Updated” date at the top of this page indicates the most recent revision. We will notify you of material changes by posting a prominent notice on the Site and, where feasible, by email to active clients or GPO members, at least 30 days before the changes take effect.
Your continued use of the Site or engagement with MedTech services after an updated Policy takes effect constitutes acceptance of the revised terms. If you do not agree with a material change, you may discontinue use of the Site and contact us to discuss your options.
Prior versions of this Privacy Policy are available on request by emailing contact form.
15 Privacy Contact & Inquiries
For questions, requests, complaints, or concerns about this Privacy Policy or MedTech’s handling of personal information, please contact our Privacy Office:
Email: info@medtech4solutions.com
Phone: (866) 634-9144
Fax: (866) 482-5058
Web: https://medtech4solutions.com/
We aim to acknowledge all privacy inquiries within 5 business days and to resolve them within 30 days. Complex requests (e.g., data portability or PHI-related disputes) may require additional time; we will inform you of any extension.
For questions about a Business Associate engagement or PHI handled under a BAA, please contact your MedTech account lead directly and reference your BAA. For clinical, patient-record, or HIPAA rights questions as a patient of one of our client clinics, please contact your treating clinic — MedTech is not your healthcare provider and cannot respond to patient-record requests.
If you are located in the EEA or UK and are not satisfied with our response, you have the right to lodge a complaint with your local supervisory authority. A directory of EEA supervisory authorities is available at edpb.europa.eu; the UK ICO can be reached at ico.org.uk.