Privacy Policy
We design, build, and maintain data pipelines for highly regulated industries. We take data governance, security, and privacy seriously. This Privacy Policy describes how we collect, process, and protect information when you visit our website, communicate with our team, or utilize our development services.
HIPAA Compliance & Protected Health Information (PHI)
We specialize in healthcare data science, EHR extraction pipelines, and automated state/federal grant reporting. In carrying out these services, we act as a "Business Associate" to our covered clinical partners.
Any Protected Health Information (PHI) accessed during database migrations, query optimizations, or automated report packaging is managed in strict compliance with the Health Insurance Portability and Accountability Act (HIPAA). We operate under signed Business Associate Agreements (BAAs), utilizing encrypted transit tunnels (TLS 1.3), automated zero-retention filters for clinical identifiers, and audit logging to verify full clinical privacy.
Information We Collect
We collect minimal information to facilitate communication and provide engineering services:
- Contact Inquiry Information: If you submit a request via our consultation form, we collect your name, email address, phone number, organization, and message content to address your request.
- Technical Logs & Telemetry: To monitor server performance and detect errors on our platform, we capture standard network parameters (IP addresses, request headers, browser configurations) with immediate anonymization.
- Client Project Configurations: We store project schemas, database connections, and api credentials in secure, encrypted hardware vaults (e.g. Secret Manager) with zero-retention of the underlying clinical or financial patient records.
Third-Party Services & Integrations
To process contact inquiries, we integrate with secure contact relationship management APIs (e.g., PaperCRM). Any data entered in our consultation form is securely routed to our integration endpoints. We do not sell, rent, or lease your information to third-party marketing companies.
Security Controls
We implement industry-standard physical, administrative, and technical safeguards. This includes role-based access control, automated vulnerability scanning, mandatory encryption for data in transit and at rest, and multi-factor authentication across all engineering environments.
Contact Information
For questions regarding our privacy practices, data governance workflows, or HIPAA compliance policies, please reach out to our team at:
Morgan Dixon Consulting LLC Engineering Office
Coeur d'Alene, Idaho
Email: security@mercuryfuture.com