Privacy Policy
Effective Date: May 15, 2025
Scope and Purpose
This Privacy Policy (“Policy”) outlines how LUCA (“LUCA,” “we,” “us,” or “our”), including affiliated entities, collects, uses, and protects information obtained through our websites and applications, including www.lucabilling.com (collectively, the “Sites”). It also covers data collected offline, such as through events, in-person interactions, or other means where this Policy is presented.
This Policy does not apply to third-party websites linked from our Sites or LUCA offerings that are governed by separate privacy policies. We are not responsible for the privacy practices of third-party sites.
LUCA processes data on behalf of healthcare providers under agreements that may include Business Associate Agreements in compliance with the Health Insurance Portability and Accountability Act (“HIPAA”). For details on how your healthcare provider handles data, please refer to their privacy policy.
Our Services
LUCA, headquartered in the United States, provides cloud-based and network-enabled solutions to healthcare providers, including electronic health records (EHR), revenue cycle management (RCM), medical coding, credentialing, and patient engagement tools. More details are available in the “About” section of www.lucabilling.com.
Communication Policy
Communication Channels
Text Messages (SMS):
Used solely for:
- Work-related communication with contracted clients
- Internal staff communications
Examples:
“Your billing update for February is available in the portal. – LUCA Billing”
“Reminder: Credentialing meeting tomorrow at 10 AM.”
✅ No promotional or marketing texts are sent.
8×8:
Used for secure communication with:
- Contracted healthcare clients
- Internal staff
- Prospective clients requesting callbacks
📌 We do not send SMS to providers who only submit contact forms. Initial outreach is always via phone call.
Client Communication
Once onboarded, clients may receive SMS or 8×8 messages about:
- Billing updates
- Credentialing & RCM support
- Technical assistance
Examples:
“Your coding issue has been resolved.”
“Reminder: Quarterly review scheduled for Friday.”
📴 Clients can opt out anytime by replying STOP. For help, reply HELP.
🚫 LUCA does not share client SMS consent or phone numbers with third parties.
Privacy & Security Commitments
1. HIPAA Compliance
- Encryption: Data encrypted in transit and at rest.
- Access Controls: Restricted access to PHI.
- Vendor Compliance: All vendors (e.g., 8×8) adhere to HIPAA.
- Training: Staff receives annual HIPAA compliance training.
2. Data Protection
- Secure Servers: HIPAA-compliant hosting with MFA.
- Confidentiality: No sale or rental of client data.
- Retention: Data stored only as long as legally required.
- No Spam: No unsolicited marketing messages.
Personal Data We Collect
We may collect the following based on user interaction:
- Identifiers: Name, email, IP address
- Contact Info: Address, phone number
- Commercial Data: Purchased services/products
- Device Info: Browser, OS, Site usage
- Professional Data: Job title, employer
- Geolocation: Based on IP or user-enabled GPS
How We Collect Data
- Directly: Via contact forms, surveys, event sign-ups
- Automatically: Through cookies, analytics tools, session replays
- From Third Parties: Via referral partners or social platforms
How We Use Personal Data
- To deliver requested services
- To enhance our Sites and offerings
- To send essential updates and confirmations
- To maintain compliance and legal integrity
- For aggregated and anonymized business analysis
Data Security & Retention
- We use encryption and access controls to protect personal data.
- Data is retained only as long as necessary under legal guidelines.
- Where deletion isn’t possible, data is blocked from further use.
Cookies & Automated Technologies
We use:
- Cookies
- JavaScript
- Pixels & Ad Tags
- Session replay tools
These technologies help improve performance, personalize experience, and measure site traffic. Preferences can be managed via the “Cookie Preferences” link at the bottom of our website.
State-Specific Privacy Rights
Depending on your jurisdiction, you may have the right to:
- Access or correct personal data
- Request deletion
- Opt out of targeted advertising or data sharing
📞 Call: 402-741-3200
📧 Email: info@lucabilling.com
📝 Submit a request via our contact form
Verification may be required. Appeals processes are available upon request.
Children’s Privacy
Our Sites are intended for users aged 18 and over. We do not knowingly collect data from children under 13. Contact us if you believe a child’s data has been collected.
International Users
By using our Sites from outside the United States, you consent to data processing under U.S. laws. Other countries may have different privacy regulations.
Policy Updates
We may modify this Privacy Policy at any time. Changes will be posted at www.lucabilling.com and take effect immediately upon posting.
Contact Us
LUCA Billing
📍 Lincoln, NE
📞 402-741-3200
📧 info@lucabilling.com
🌐 www.lucabilling.com