HIPAA and Your Information

Healthcare Consumer First, LLC

Effective Date: July 30, 2026

People often ask whether HCC FIRST is "HIPAA compliant." It is a fair question, and the honest answer is more useful than a yes or a no. This page explains what HIPAA is, who it applies to, where Healthcare Consumer First sits, and what actually protects the medical bills and insurance statements you give us.

We describe ourselves as HIPAA-aware. That is a deliberate choice of words, and this page explains what it means.

What HIPAA Is

The Health Insurance Portability and Accountability Act, together with the rules issued under it, sets federal standards for how certain organizations handle health information.

HIPAA does not apply to all health information everywhere. It applies to specific categories of organizations, called covered entities, and to the vendors that handle health information on their behalf, called business associates.

Covered entities are:

Your hospital is a covered entity. Your insurer is a covered entity. Their billing companies are typically business associates.

Where Healthcare Consumer First Sits

Healthcare Consumer First is not a covered entity. We are not a health care provider, a health plan, or a clearinghouse. We do not treat patients, we do not pay claims, and we do not process transactions on a provider's behalf.

That means the bills, explanations of benefits, and other documents you upload to HCC FIRST are not, in our hands, governed by HIPAA in the way they were in your provider's hands.

This is not a loophole and it is not unusual. It is how the law is written. HIPAA follows the organization, not the document. The same statement that was protected health information at the hospital becomes ordinary personal health information when you download it and put it somewhere of your own choosing.

What matters is that something still governs it. Several things do.

What Actually Governs Your Information Here

The FTC Health Breach Notification Rule. Healthcare Consumer First is a vendor of personal health records under this rule. If your identifiable health information held by us were acquired without your authorization, we are required to notify you, to notify the Federal Trade Commission, and in some circumstances to notify the media. This obligation is not optional and does not depend on our size.

State privacy and health data laws. A growing number of states regulate consumer health data directly, and several of them apply from the first resident we serve, with no minimum size or volume threshold. These laws govern how we collect, use, share, and retain your information, and they give you rights over it.

The Federal Trade Commission Act. Statements we make about how we handle your information are enforceable. If we described our practices one way and behaved another way, that is a deceptive practice. This page, our Privacy Policy, and our Terms of Service are commitments, not marketing.

Our own agreements with you. The Privacy Policy and the Terms of Service govern what we may do with what you give us. The Bill Negotiation Agreement, if you sign one, governs what we may say about you to a provider.

Where HIPAA Does Reach Us

HIPAA is not irrelevant to your experience of HCC FIRST. It reaches us in three ways.

When we contact your provider on your behalf. Your hospital and your insurer are covered entities, and they may not discuss your account with anyone you have not authorized. That is why bill negotiation requires your signed authorization, and why some providers also ask you to confirm verbally that we may speak for you. Those steps exist because HIPAA protects you at the provider's end, and we work within it rather than around it.

Through agreements with our vendors. We have business associate agreements in place with the vendors that store or process the health information you give us. A business associate agreement contractually binds a vendor to HIPAA-level handling standards. We put these in place because they are the strongest widely recognized standard available, not because we are required to.

If your employer sponsors your membership. An employer-sponsored health plan is a covered entity. Where HCC FIRST is offered through an employer's plan, we may act as a business associate of that plan, and HIPAA obligations would apply to us directly in that relationship.

What "HIPAA-Aware" Means

We use the word deliberately. It means we hold your information to the handling standards HIPAA describes, because that is the right way to treat medical documents, while being accurate that we are not a covered entity and cannot claim a compliance status that does not apply to us.

Concretely, it means:

We would rather tell you exactly what we are than claim a label that sounds better and means something else.

What We Never Do

Your Choices

You control what you upload and what we do with it.

Some records must be retained after an account closes when the law requires it, including authorization records, transaction records, and records of completed services. Our Privacy Policy describes this in detail.

If Something Goes Wrong

If your identifiable health information held by us were acquired by an unauthorized person, we will notify you without unreasonable delay, and we will notify the Federal Trade Commission and, where required, state authorities. We will tell you what happened, what information was involved, and what we are doing about it.

We will not wait to be asked.

Questions

Questions about this page, about how your information is handled, or about anything else on this subject may be sent to:

Healthcare Consumer First, LLC

Email: privacy@hccfirst.com

Mailing Address: 1500 1st Ave N, Birmingham, AL 35203

This page explains our practices and is not legal advice. Our Privacy Policy and Terms of Service govern our relationship with you; where this page and those documents differ, those documents control.