Privacy Policy
Effective 27 September 2026 · Last updated 27 September 2026
EliCheck (“we”, “us”) provides insurance eligibility checks, scheduling and appointment reminders to medical and dental practices. This policy explains what information we handle, why, and what choices people have. It covers the EliCheck application and this website.
Two kinds of people, two different roles
Practices and their staff are our customers. We hold their account information directly and this policy governs it.
Patients are their patients, not ours. We handle patient information only on a practice's instructions, as part of running that practice's eligibility checks, schedule and appointment reminders. The practice decides what is collected and why; we act on its behalf under a written agreement, including a business associate agreement where HIPAA applies. If you are a patient and want your information corrected or removed, ask your practice — they hold your record, control it, and can reach us on your behalf.
How to stop appointment reminders
Every reminder carries an unsubscribe link at the bottom. Using it stops reminders to that address immediately, with no account or password needed, and the choice is recorded so it cannot be silently reversed.
You can also tell your practice, or write to support@elicheck.com and we will pass it to them. We do not send marketing email to patients at all, so there is nothing else to opt out of.
What we handle
- Practice and staff information: practice name, address, NPI, staff names, work email addresses, roles, and sign-in records.
- Patient information, on the practice's behalf: name, date of birth, insurance member and group identifiers, the payer's response about coverage and benefits, appointment details, and the contact details needed to send a reminder.
- Billing information for practices: plan, usage counts and invoices. Card details are handled by our payment processor and are never stored by us.
- Technical records: application logs and audit records of who did what and when. Patient names, dates of birth, member identifiers and contact details are stripped from application logs before they are written.
We do not collect patient information from anywhere other than the practice. We do not buy, rent, scrape or import contact lists, and we never sell or rent anyone's information.
Why we handle it
- To check insurance coverage with the payer, at the practice's request.
- To run the practice's calendar and send the appointment reminders it has configured.
- To bill the practice for its use of the service.
- To keep the service secure, diagnose faults, and maintain the audit record a practice needs to answer who did what.
We do not use patient information to advertise anything, to train models, or for any purpose other than delivering the service to the practice that provided it.
Who else sees it
We use a small number of service providers, each under contract and each limited to what its job requires:
- A clearinghouse, to exchange eligibility requests and responses with payers.
- Amazon Web Services, which hosts the application and its database in the United States, and which sends reminder email.
- A payment processor, for practice subscriptions and invoices. It receives usage counts and billing details, and no patient information.
We disclose information otherwise only where the law requires it, and we will tell the affected practice unless we are prohibited from doing so.
Where it is held, and for how long
Information is stored in the United States. Each practice's data is separated from every other practice's at the database level, and that separation is tested on every release.
We keep information for as long as the practice's account is active. After an account closes, we delete the practice's data — including patient records and the payer responses held against them — within 30 days. That window gives the practice time to export anything it still needs. Audit and billing records are kept longer than other data because we are required to retain them.
Security
Access is limited by role, and every action is written to an append-only audit record that cannot be altered or deleted. Data is encrypted in transit and at rest. Sign-in to the application requires a second factor.
The separation between practices is enforced by the database itself rather than by application code, so a mistake in the application cannot expose one practice's data to another. That separation is covered by automated tests, and it is verified against the running system as part of each release.
No service can promise that nothing will ever go wrong. If information is breached, we will notify the affected practice without undue delay and cooperate with the notifications it is required to make.
Choices for practices
A practice can see, correct and export its data from within the application, switch reminders off at any time, and ask us to delete its data when it leaves. Requests go to support@elicheck.com.
Children
This service is sold to practices, not to individuals, and it is not directed at children. Where a practice treats children, we handle their information the same way we handle any other patient information: only on that practice's instructions.
Changes to this policy
If we change this policy in a way that materially affects how we handle information, we will update the date at the top and tell practices before the change takes effect.
Contact
EliCheck
support@elicheck.com · (732) 444-7364