Legal

Privacy Policy

Last updated: [Date — placeholder, update before publishing]

This Privacy Policy explains how WhiteCoat Ops Ltd ("WhiteCoat Ops", "we", "us", or "our") collects, uses, discloses, and protects information in connection with our website and our medical billing and healthcare administrative services. It is intended to comply with the UK General Data Protection Regulation ("UK GDPR"), the Data Protection Act 2018, and, where applicable to US-facing engagements, the Health Insurance Portability and Accountability Act ("HIPAA").

This policy is a template structure and general statement of our approach. It should be reviewed by a qualified legal professional and updated with your organisation's specific registration details, Data Protection Officer contact (if applicable), and operational specifics before publication.

1. Who We Are

WhiteCoat Ops Ltd is a provider of medical billing and healthcare administrative services, registered in the United Kingdom. Our registered address is [Business Address Line 1 — placeholder], [City, Postcode — placeholder]. Company registration number: [Company Registration Number — placeholder]. Our Information Commissioner's Office (ICO) registration number: [ICO Registration Number — placeholder].

2. Information We Collect

We may collect the following categories of information:

  • Website visitors: contact details you submit through our contact or consultation forms (name, email, phone number, practice name, and message content), and standard technical data such as IP address and browser type collected through normal web server operation.
  • Prospective and current clients: business contact details, practice information, and details relevant to scoping and delivering our services.
  • Patient billing data (processed on behalf of clients): where we provide medical billing or revenue cycle management services, we may process patient billing information — which may constitute Protected Health Information (PHI) under HIPAA or special category / health data under UK GDPR — strictly on behalf of, and under instruction from, our healthcare provider clients, who remain the data controller for that information.

3. How We Use Information

We use the information described above to:

  • Respond to enquiries submitted through our website
  • Schedule and prepare for consultation requests
  • Deliver contracted medical billing and administrative services to clients
  • Maintain accurate business and financial records
  • Comply with our legal and regulatory obligations

4. Legal Basis for Processing (UK GDPR)

Where UK GDPR applies, we rely on the following legal bases depending on context: consent (for example, when you voluntarily submit a form), performance of a contract (for clients engaging our services), and legitimate interests (for example, responding to general enquiries). Where we process patient billing data on behalf of a healthcare provider client, we do so as a data processor acting under a written agreement and the client's documented instructions.

5. HIPAA-Aligned Handling

For engagements involving the billing information of US-based patients, we structure our internal processes around the safeguards expected under HIPAA's Privacy and Security Rules, and, where appropriate, operate under a Business Associate Agreement (BAA) with the relevant healthcare provider.

6. Data Sharing

We do not sell personal information. We may share information with trusted sub-processors (such as hosting or email delivery providers) strictly as necessary to operate our website and services, and only under appropriate confidentiality and data protection terms. We may also disclose information where required by law.

7. Data Retention

We retain personal information only for as long as necessary for the purposes described in this policy, or as required by applicable law, regulatory, or contractual obligations. Retention periods for patient billing data are determined in agreement with the relevant healthcare provider client and applicable regulatory requirements.

8. Data Security

We apply administrative, technical, and physical safeguards designed to protect personal and patient billing information against unauthorised access, disclosure, alteration, or destruction, consistent with our obligations under UK GDPR, the Data Protection Act 2018, and HIPAA where applicable. Further detail is available on our Compliance & Security page.

9. Your Rights

Subject to applicable law, you may have the right to request access to, correction of, or deletion of your personal information, to object to or restrict certain processing, and to data portability. To exercise these rights, contact us at info@whitecoatops.com. If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) or your relevant supervisory authority.

10. Cookies

Our website's use of cookies and similar technologies is described in our Cookie Policy.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be reflected by an updated "last updated" date at the top of this page.

12. Contact Us

For questions about this Privacy Policy or our data practices, contact us at info@whitecoatops.com or +44 (0) 000 000 0000.