Guaranteed: Privacy Policy
Privacy Policy
LAST UPDATED: MAY 29, 2026
1. Who We Are and What This Policy Covers
Guaranteed Health, Inc. ("Guaranteed," "we," "our," or "us") operates the platform accessible at https://www.onguaranteed.com (the "Platform"). The Platform is a B2B software service designed for hospice agencies, home health agencies, and other serious-illness care organizations (collectively, "Agencies") to automate eligibility identification, intake documentation, and compliance recordkeeping.
This Privacy Policy describes how we collect, use, retain, and disclose information — including Personally Identifiable Information ("PII") and Protected Health Information ("PHI") — through the Platform and its associated services (the "Services"). PHI includes information relating to health status, medical history, treatment, insurance, or other data that could be used to identify an individual patient.
By accessing or using the Platform, you agree to this Privacy Policy. If you are using the Services on behalf of an Agency, you represent that you are authorized to bind that organization to this Policy.
2. Information We Collect
We collect several types of information in connection with the Services:
Agency and User Account Information. When an Agency registers for the Platform, we collect business information (organization name, address, NPI number, service lines, payer contracts) and information about individual users (name, email address, job title, phone number, account credentials).
Patient and Clinical Information (PHI). In order to provide eligibility screening, intake documentation, and compliance services, Guaranteed processes PHI submitted by or on behalf of Agencies. This includes patient demographics, diagnosis and clinical information, insurance and Medicare/Medicaid benefit status, referral source data, and prior authorization records. All PHI is stored in HIPAA-compliant infrastructure and handled in accordance with applicable law and any executed Business Associate Agreement ("BAA").
Automatically Collected Information. We collect standard log and usage data when you interact with the Platform, including IP address, browser type, pages visited, timestamps, and device identifiers. This information is used for security, system integrity, and service improvement purposes.
Information from Third Parties. We may receive information from referring providers, health information exchanges (HIEs), payer systems, and other third-party integrations authorized by the Agency to facilitate the Services.
3. How We Use Information
We use the information we collect to:
- Provide and operate the Platform and Services, including eligibility screening, intake automation, audit documentation generation, and compliance monitoring
- Process and transmit PHI as directed by the Agency and as permitted under HIPAA and any applicable BAA
- Verify insurance and Medicare/Medicaid eligibility and benefit periods
- Generate clinical narratives, audit packets, and compliance documentation
- Monitor system performance, security, and integrity
- Communicate with Agency users about account activity, updates, and support
- Comply with applicable law, regulatory requirements, and legal process
- Improve and develop the Platform using aggregated, de-identified data
We do not sell PHI or PII to third parties. We do not use PHI for advertising or marketing purposes.
4. HIPAA and Protected Health Information
Guaranteed is a Business Associate under HIPAA with respect to PHI processed on behalf of covered entity Agencies. We maintain a HIPAA-compliant infrastructure and enter into a Business Associate Agreement with each Agency prior to processing PHI. Our BAA is available upon request and governs our obligations with respect to the use, disclosure, and safeguarding of PHI.
PHI is stored in encrypted, access-controlled environments hosted on HIPAA-compliant cloud infrastructure. Access to PHI is restricted to authorized personnel and systems on a need-to-know basis. We implement administrative, physical, and technical safeguards consistent with the HIPAA Security Rule.
In the event of a breach of unsecured PHI, we will notify affected Agencies in accordance with the HIPAA Breach Notification Rule.
5. How We Share Information
We share information only as described below:
Service Providers. We share information with third-party vendors and service providers that support the operation of the Platform, including cloud hosting, data storage, analytics, and security. All service providers are contractually bound to appropriate data protection obligations. Current infrastructure providers include AWS and GCP. DNS and hosting services are provided through Netlify.
Health Information Exchanges and Payer Systems. With Agency authorization, we exchange patient data with HIEs, payer portals, and other clinical systems to support eligibility verification and record retrieval.
Legal Requirements. We may disclose information when required by law, court order, or government authority, or when we believe disclosure is necessary to protect the rights, property, or safety of Guaranteed, our customers, or the public.
Business Transfers. In connection with a merger, acquisition, or sale of assets, information may be transferred to the successor entity, subject to the same privacy obligations.
With Consent. We may share information for other purposes with your explicit consent.
We do not share PHI for marketing, advertising, or any purpose not authorized under HIPAA and the applicable BAA.
6. Data Retention
We retain information for as long as necessary to provide the Services, fulfill the purposes described in this Policy, and comply with applicable legal and regulatory obligations. Clinical documentation and PHI are retained in accordance with HIPAA requirements and any applicable state law governing medical record retention. Agency account data is retained for the duration of the service relationship and for a reasonable period thereafter.
You may request deletion of your personal information by contacting us at info@onguaranteed.com. Certain data may be exempt from deletion where retention is required by law, necessary for compliance obligations, or integral to the performance of services you have requested.
7. Security
We implement a comprehensive set of administrative, physical, and technical safeguards to protect the information we hold, including encryption of data in transit and at rest, role-based access controls, multi-factor authentication, audit logging, and regular security assessments. No system can guarantee absolute security. If you believe your account has been compromised or you have identified a security vulnerability, please contact us immediately at info@onguaranteed.com.
8. Cookies and Tracking Technologies
The Platform uses cookies and similar technologies to maintain session state, support authentication, and collect usage analytics. We use Google Analytics to understand how the Platform is used. Analytics data is aggregated and not combined with PHI. You may configure your browser to reject cookies, though doing so may affect Platform functionality.
9. Your Privacy Rights
Depending on your location, you may have the right to access, correct, delete, or restrict the processing of your personal information. To exercise these rights, contact us at info@onguaranteed.com. We will respond to verified requests within the timeframe required by applicable law.
California Residents. California residents have additional rights under the CCPA and CPRA, including the right to know what personal information is collected and how it is used, the right to request deletion, the right to correct inaccurate information, and the right to opt out of the sale of personal information. We do not sell personal information. To submit a California privacy request, email info@onguaranteed.com with "California Privacy Rights" in the subject line.
Nevada Residents. Nevada residents may request information about our data sharing practices by emailing info@onguaranteed.com with "Nevada Privacy Rights" in the subject line. We do not sell personal information.
EU/EEA Residents. If you are located in the EU or EEA, you have rights under the GDPR including access, rectification, erasure, restriction, portability, and the right to object. Contact us at info@onguaranteed.com with "GDPR Request" in the subject line.
10. Children
The Platform is a B2B service designed for use by healthcare organizations and their authorized personnel. It is not directed at individuals under 18. We do not knowingly collect personal information directly from minors.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated Policy on the Platform and update the "Last Updated" date. Material changes will be communicated to Agency administrators by email. Continued use of the Platform following notice of changes constitutes acceptance of the updated Policy.
13. No Warranty Implied by Name
The name "Guaranteed" is a trade name and brand identifier for Guaranteed Health, Inc. and its Services. The use of the word "Guaranteed" in the Company name, on the Platform, in marketing materials, or in any other context does not constitute, and shall not be construed as, a representation, warranty, promise, or guarantee of any kind — express or implied — including without limitation any warranty as to outcomes, results, audit success, regulatory compliance, eligibility determinations, clinical findings, or any other matter. All disclaimers of warranties set forth in the applicable Terms of Service apply in full. No inference of any warranty or guarantee should be drawn from the use of the Company name under any circumstances.
14. Contact Us
If you have questions, concerns, or requests related to this Privacy Policy, please contact us:
Guaranteed Health, Inc. 234 Fifth Ave, Floor 2 New York, NY 10001 Email: info@onguaranteed.com