Exigere Solutions (“Exigere,” “we,” “us,” or “our”) provides medical-legal transcription and documentation services. This Privacy Policy explains what information we collect through our website at exigeresolutions.com(the “Site”) and through our services (the “Services”), how we use and protect it, and the choices available to you. By using the Site or Services, you agree to the practices described here.
1. Information we collect
Information you provide
- Contact / intake details — your name, work email, organization, and the contents of any message you submit through our request form or by email.
- Client content — audio, video, dictation, documents, and related materials you submit for transcription, which may contain confidential, privileged, or health information.
- Account and billing information — where applicable to deliver and invoice the Services.
Information collected automatically
- Standard server and security logs (e.g., IP address, browser type, timestamps) used to operate, secure, and troubleshoot the Site.
- Essential cookies required for the Site to function. We do not use the Site to sell advertising.
2. Protected Health Information (HIPAA)
When we transcribe records that contain Protected Health Information (“PHI”) on behalf of a covered entity or another business associate, Exigere acts as a Business Associateunder the Health Insurance Portability and Accountability Act (“HIPAA”). In those engagements we handle PHI strictly in accordance with a Business Associate Agreement (BAA) and applicable law. PHI is used and disclosed only as permitted by the BAA and only to perform the Services. A BAA is available on request to clients with qualifying engagements.
3. How we use information
- To provide, maintain, and deliver the Services you request.
- To respond to inquiries and communicate about engagements.
- To secure our systems, prevent abuse, and maintain audit trails.
- To comply with legal, regulatory, and contractual obligations.
- To improve and develop our Services and proprietary technology, using de-identified data.
We do not sell personal information, and we never use client content or PHI for advertising or share it with third parties to train their models. We may use appropriately de-identifieddata — in accordance with HIPAA’s de-identification standards — to improve and develop our Services and proprietary technology.
4. How we share information
We disclose information only as follows:
- Service providers / subprocessors bound by confidentiality and, where PHI is involved, by a BAA — used solely to support the Services (e.g., secure hosting, email delivery).
- Legal and safety — when required by law, subpoena, or to protect rights, safety, and the integrity of our Services.
- Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this Policy.
5. Data security
We maintain administrative, technical, and physical safeguards designed to protect information, including encryption in transit and at rest, role-based access controls, the principle of least privilege, and audit logging. No method of transmission or storage is perfectly secure, but we work to protect information in a manner appropriate to its sensitivity.
6. Data retention
We retain information only as long as necessary to deliver the Services, satisfy the terms of the applicable engagement or BAA, and meet legal, accounting, or recordkeeping requirements, after which it is securely deleted or de-identified. Specific retention and return/destruction terms for PHI are governed by the applicable BAA.
7. Your rights and choices
Depending on your jurisdiction (including under the CCPA/CPRA and, where applicable, the GDPR), you may have rights to access, correct, delete, or restrict the processing of your personal information, and to receive a copy of it. Requests concerning PHI are handled through the relevant covered entity under HIPAA. To make a request, contact us at privacy@exigeresolutions.com. We will not discriminate against you for exercising these rights.
8. International users
Exigere is based in the United States and our Services are performed by U.S.-based specialists. If you access the Site from outside the U.S., you understand your information will be processed in the United States.
9. Children’s privacy
The Site and Services are intended for businesses and professionals and are not directed to children under 13. We do not knowingly collect personal information from children.
10. Changes to this Policy
We may update this Policy from time to time. Material changes will be reflected by updating the “Last updated” date above and, where appropriate, by additional notice.
11. Contact us
Questions about this Policy or our privacy practices may be directed to privacy@exigeresolutions.com.
