Enrollix Health
MediEnroll AI Platform
← Back to Home
Legal & Compliance

Privacy Policy

How Enrollix Health, Inc. collects, uses, protects, and respects your personal health information.

Effective Date: May 1, 2026 Last Updated: May 1, 2026 Version 1.0
🔒 HIPAA Compliant
🛡️ AES-256 Encrypted
✓ SOC 2 Ready
📋 TCPA Compliant
🏛️ CAN-SPAM Compliant
Section 01

Who We Are

Enrollix Health, Inc. ("Enrollix Health," "we," "us," or "our") is a Delaware corporation (EIN: 41-4965725) headquartered at 116 NW Harris Lake Dr, Lake City, FL 32055. We operate the MediEnroll AI platform, an artificial intelligence-powered Medicaid enrollment platform designed to help individuals determine eligibility for Medicaid and other government benefit programs and assist them in completing and submitting applications.

This Privacy Policy applies to all information collected through our website at enrollixhealth.com, our MediEnroll AI platform, our Navigator Portal, and any other services we offer (collectively, the "Services").

By using our Services, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree, please discontinue use of our Services.

Section 02

Information We Collect

We collect several types of information to provide and improve our Services:

Category Examples Purpose
Identity Information Name, date of birth, gender, race/ethnicity, citizenship status Medicaid eligibility determination and application
Contact Information Address, phone number, email address Application processing and follow-up communications
Federal ID / SSN 9-digit Federal Identification Code (stored encrypted, never in plaintext) Required for Medicaid application identity verification
Financial Information Monthly income, income sources, assets, household size Medicaid eligibility screening and Federal Poverty Level calculation
Insurance Information Current coverage, Medicare status, prior Medicaid history Eligibility determination
Medical/Health Information Disability status, pregnancy status, medical record numbers provided by referring facilities Program eligibility and application
Facility Information Referring facility name, MRN, encounter number, account number Coordination with referring health system or facility
Usage Data IP address, browser type, pages visited, time on site Platform improvement and security monitoring
Communications Notes, messages, SMS opt-in/opt-out records Application management and TCPA compliance
Section 03

How We Use Your Information

We use the information we collect for the following purposes:

  • Determining your eligibility for Medicaid and other government benefit programs
  • Completing and submitting Medicaid applications to state agencies on your behalf
  • Communicating with you regarding your application status and next steps
  • Coordinating with referring health systems, skilled nursing facilities, assisted living facilities, or clinics
  • Providing analytics and reporting to contracted health system clients regarding enrollment outcomes
  • Improving the accuracy and performance of the MediEnroll AI eligibility engine
  • Complying with applicable federal and state laws and regulations
  • Maintaining HIPAA-required audit trails and access logs
  • Preventing fraud and ensuring the security of our platform

We will never use your information for commercial advertising, sell it to data brokers, or share it with third parties for their own marketing purposes.

Section 04

HIPAA & Protected Health Information

Enrollix Health operates as a Business Associate under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) when providing services to covered entities such as hospitals, health systems, skilled nursing facilities, and clinics. In this capacity, we are required to:

  • Use and disclose Protected Health Information (PHI) only as permitted by our Business Associate Agreement (BAA) and applicable law
  • Implement appropriate administrative, physical, and technical safeguards to protect PHI
  • Report any breaches of unsecured PHI to the covered entity and, as required, to the U.S. Department of Health and Human Services
  • Ensure that any subcontractors who handle PHI on our behalf also agree to the same restrictions

When you interact with MediEnroll AI directly as a patient or community participant (not referred by a covered entity), we still apply HIPAA-equivalent privacy and security standards to all information you provide.

⚠️ Your Federal ID Code (Social Security Number) is encrypted using AES-256 encryption immediately upon entry and is never stored in plaintext anywhere in our systems. Every access to this field is logged to an immutable audit trail.

Section 05

How We Share Your Information

We do not sell your personal information. We share your information only in the following limited circumstances:

Recipient What We Share Why
State Medicaid Agencies Full application data as required To submit your Medicaid application
Referring Health System / Facility Enrollment status, application outcome Coordination of care and reporting under BAA
Anthropic (AI Provider) De-identified screening data processed by AI Eligibility determination via Claude API (under BAA)
Supabase (Database) Encrypted patient records Secure data storage (under BAA)
Twilio (Communications) Phone number, message content SMS and voice communications (under BAA)
Law Enforcement / Legal As required by law Legal compliance, court orders, or to protect rights

All third-party service providers who handle personal or health information on our behalf are required to sign Business Associate Agreements (BAAs) and maintain HIPAA-equivalent security standards.

Section 06

Data Security

We implement industry-leading security measures to protect your information:

  • Encryption at rest: All data is encrypted using AES-256 encryption
  • Encryption in transit: All data transmission uses TLS 1.2+ (HTTPS)
  • Row-level security: Database access is scoped to individual facilities — no cross-facility data access is possible
  • Role-based access control (RBAC): Staff access is limited to only the data required for their role
  • Immutable audit trails: Every action involving patient data is logged with actor, timestamp, IP address, and metadata
  • Federal ID protection: SSN/Federal ID is encrypted immediately, stored only in encrypted form, and every access is individually logged
  • Secure authentication: Multi-factor authentication available for all navigator accounts

While we implement these safeguards, no method of transmission over the internet or electronic storage is 100% secure. If you believe your information has been compromised, please contact us immediately at bryan@enrollixhealth.com.

Section 07

Communications & TCPA Compliance

Enrollix Health complies fully with the Telephone Consumer Protection Act (TCPA), CAN-SPAM Act, and applicable state communications laws.

SMS / Text Messages: We will only send you text messages if you have provided express written consent. You may opt out at any time by replying STOP to any text message. After opting out, we will send one confirmation message and no further texts.

Phone Calls: Automated or pre-recorded calls require prior express consent. You may request to be placed on our do-not-call list at any time by contacting us at bryan@enrollixhealth.com or (386) 965-6474. We do not place calls before 8:00 AM or after 9:00 PM in the recipient's local time zone.

Email: You may unsubscribe from non-transactional emails at any time. Transactional emails related to your active application (status updates, document requests) will continue until your application is resolved.

All opt-out requests are honored immediately and recorded in our system. We maintain records of all consent and opt-out events as required by law.

Section 08

Your Rights & Choices

You have the following rights regarding your personal information:

  • Right to Access: You may request a copy of the personal information we hold about you
  • Right to Correction: You may request correction of inaccurate or incomplete information
  • Right to Deletion: You may request deletion of your personal information, subject to legal retention requirements
  • Right to Restrict Processing: You may request that we limit how we use your information
  • Right to Data Portability: You may request your data in a structured, machine-readable format
  • Right to Withdraw Consent: Where processing is based on consent, you may withdraw consent at any time
  • Right to Opt Out of Communications: You may opt out of SMS, calls, and marketing emails at any time

To exercise any of these rights, contact us at bryan@enrollixhealth.com or (386) 965-6474. We will respond to all requests within 30 days.

If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA). Please contact us for more information.

Section 09

Data Retention

We retain your personal information for as long as necessary to fulfill the purposes described in this policy, comply with legal obligations, resolve disputes, and enforce our agreements. Specific retention periods:

  • Active application data: Retained for the duration of the application process plus 7 years as required by healthcare regulations
  • Audit logs and access records: Retained for a minimum of 6 years per HIPAA requirements
  • Communication records (SMS, call logs): Retained for 5 years for TCPA compliance
  • Consent records: Retained for the duration of the relationship plus 5 years
  • De-identified/anonymized data: May be retained indefinitely for platform improvement purposes

When data is no longer required, it is securely deleted or anonymized in accordance with industry best practices.

Section 10

Children's Privacy

Our Services are not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13 without verifiable parental consent. We may collect information about minor household members as part of a Medicaid eligibility screening when a parent or guardian initiates the application on their behalf.

If you believe we have inadvertently collected information from a child under 13 without appropriate consent, please contact us immediately at bryan@enrollixhealth.com and we will take steps to delete such information.

Section 11

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes, we will update the "Last Updated" date at the top of this page.

For material changes, we will provide notice through our platform or by email to registered users. Your continued use of our Services after such notice constitutes your acceptance of the updated policy.

We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information.

Section 12

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Privacy Officer — Enrollix Health, Inc.

Bryan Thomas — Founder & CEO

📍 116 NW Harris Lake Dr, Lake City, FL 32055

📧 bryan@enrollixhealth.com

📞 (386) 965-6474

🌐 enrollixhealth.com

For HIPAA-related complaints, you also have the right to file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights at hhs.gov/ocr. We will not retaliate against you for filing a complaint.