Last Updated: May 28, 2026
Privacy Policy
This Privacy Policy explains how Evrcad LLC collects, uses, and protects your information when you use the Evrcad Insurance Suite.
01Scope and Relationship to HIPAA
Evrcad provides the Service to licensed Medicare insurance agents and agencies. In many cases, Evrcad acts as a Business Associate or subcontractor Business Associate under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) when handling Protected Health Information (“PHI”) on behalf of covered entities or other business associates.
This Privacy Policy applies to all information we collect through the Service, including PHI, non-PHI personal information, and usage data. It supplements, and does not replace, any Business Associate Agreement executed between Evrcad and your organization. This Privacy Policy is not a Business Associate Agreement (BAA) under HIPAA. For BAA inquiries, contact legal@evrcad.com.
02Information We Collect
We collect the following categories of information:
Account and Profile Information. Name, email address, business address, phone number, organization/agency name and role, and login credentials and authentication information.
Client and PHI Data. Agents and agencies may store client information including beneficiary name and contact information, demographic information such as date of birth and address, Medicare-related data such as plan type, plan name, and enrollment dates, notes and documentation about client interactions, SOA forms and related documents, call recordings of marketing and enrollment calls, and SMS content sent via the platform subject to PHI restrictions in the Terms of Service. These data may be considered PHI under HIPAA when associated with a beneficiary.
Geolocation and Device Data. IP address and approximate location inferred from IP, GPS coordinates at specific compliance events (SOA signing, appointment completion, clock-in/clock-out), and device identifiers, browser type, and operating system. Evrcad does not perform continuous background tracking. Geolocation is captured only at discrete compliance-related events.
Usage Data. Access times and dates, pages and features accessed, clickstream data, and error logs and performance metrics.
Payment Information. Subscription payments are processed by Stripe. We receive limited information such as card type, last 4 digits, and billing status but do not store full payment card numbers or CVV codes.
03How We Use Information
- To provide, operate, and maintain the Service and create and manage user accounts.
- To process and store client data, call recordings, SOA forms, and other information needed to provide the Service.
- To provide AI-assisted features such as summarizing interactions or drafting messages for your review.
- To support compliance with HIPAA, CMS Medicare rules, and other applicable regulations including maintaining audit logs and retention of call recordings and SOAs.
- To respond to inquiries, provide support, and communicate about the Service.
- To monitor, detect, and prevent fraud, abuse, security incidents, and other harmful activity.
- To analyze usage patterns and improve the Service’s performance, usability, and features.
- To comply with legal obligations and enforce our Terms.
- We do not use PHI or personal information to train shared AI models or for unrelated marketing purposes.
04AI Features and Your Data
AI Providers and Scope. Evrcad uses AWS Bedrock to provide AI functionality such as drafting suggested responses or summarizing interactions. PHI used in AI prompts is limited to what is necessary for the feature (e.g., first name, context of prior messages, agent/agency name). We do not include Medicare Beneficiary ID numbers, dates of birth, diagnoses, or specific plan identifiers in AI prompts.
No Model Training on Your Data.Under AWS Bedrock’s policy, prompts and outputs sent through Bedrock are not used to train or improve the underlying foundation models used by other customers. Your AI usage is logically isolated to your AWS account.
AI Is Optional and Assistive. AI outputs are suggestions only. You retain control and responsibility for reviewing, editing, and approving all AI-generated content before sending it to clients.
05How We Share Information
We do not sell personal information.
Service Providers and Subprocessors.We share information with: Amazon Web Services (AWS) for cloud hosting, databases (RDS), storage (S3), authentication (Cognito), logging (CloudWatch/CloudTrail), and AI inference (Bedrock) — Evrcad has executed a BAA with AWS for HIPAA-eligible services. Twilio for voice and SMS delivery as a communications conduit — call recordings are stored directly in AWS S3 and SMS message bodies are delivered to Evrcad’s systems by webhook and not retained by Twilio beyond transit and minimal processing; Twilio retains limited metadata such as timestamps and phone numbers. Stripe for payment processing. AWS SES for transactional email (covered under AWS BAA), configured to avoid PHI. Google for OAuth authentication if you choose to log in with your Google account. These service providers are contractually obligated to use information only to provide services to Evrcad and to implement reasonable security measures.
Within Your Organization. If you are an agent within an agency, your data including client records, call recordings, and logs may be accessible to your agency administrators for supervision, compliance, and management purposes.
Legal and Safety. We may disclose information as necessary to comply with applicable laws, regulations, legal processes, or government requests; protect the rights, property, or safety of Evrcad, our users, or the public; detect, prevent, or address security or technical issues, fraud, or abuse; and enforce our Terms, policies, or other agreements.
Business Transfers. If Evrcad is involved in a merger, acquisition, financing, or sale of all or a portion of its business or assets, information may be transferred as part of that transaction, subject to obligations consistent with this Privacy Policy and no less protective of PHI and regulatory records than those described herein. We will provide notice of any such transfer consistent with applicable law. Any acquiring entity will be bound by the same CMS and HIPAA data retention obligations.
Aggregated and De-identified Data. We may share aggregated or de-identified data that does not reasonably identify you or any individual for analytics, research, or other business purposes.
06HIPAA and PHI
BAA with Customers. Evrcad will enter into Business Associate Agreements with eligible covered entities and business associates upon request. Contact legal@evrcad.com to request a BAA. This Privacy Policy does not modify any BAA and is not a substitute for a BAA.
PHI Storage Locations. Evrcad stores PHI only in HIPAA-eligible AWS services under the AWS BAA, including RDS and S3. Call recordings and SOA documents are stored in encrypted S3 buckets. SMS content is stored in RDS. Logging systems may contain PHI as necessary for audit and security purposes.
Twilio as Conduit.Twilio is used solely to transmit voice calls and SMS messages and is configured so that call recordings are written directly to Evrcad’s S3 bucket via Twilio’s external storage configuration and are not retained by Twilio after transfer, and SMS message bodies are delivered to Evrcad’s systems by webhook and stored only on Evrcad’s AWS infrastructure; Twilio retains limited metadata such as from/to numbers and timestamps. Evrcad implements additional measures including disabling MMS and prohibiting PHI in SMS to further minimize PHI exposure in transit.
Multi-Tenant Data Isolation.Evrcad implements logical separation of customer data through tenant identifiers in the data model, Row-Level Security (RLS) rules in the database, and strict access controls in application logic. Agency administrators can access data for their organization’s users. Agents can access only clients and records to which their organization grants access. Users from one organization cannot access another organization’s data.
07SMS Messaging Consent and Opt-Out
When an insurance agent using Evrcad documents your consent to receive SMS communications, your phone number is stored in Evrcad’s encrypted database and associated with that agent’s account. Your consent record includes the timestamp and method of consent.
Types of messages you may receive: appointment reminders, Scope of Appointment (SOA) document requests, policy update notifications, enrollment follow-ups, and general service communications from your insurance agent. Evrcad does not send promotional or marketing SMS on its own behalf to end-users.
Opt-out: Reply STOPto any message at any time to opt out of SMS from your agent’s Evrcad number. You will receive one final confirmation and no further messages. You may also contact support@evrcad.com to request removal from an agent’s messaging list.
Help: Reply HELPto any message for support contact information. Msg & data rates may apply.
No PHI in SMS:Evrcad’s Terms of Service prohibit agents from including Protected Health Information in SMS messages. Sensitive Medicare details are communicated by phone or in person only.
No third-party marketing use: Your phone number and SMS consent are never sold, rented, or shared with third-party marketers.
08Data Retention and Service Continuity
We retain information as long as necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements.
- SOA Forms: At least ten (10) years to comply with CMS requirements.
- Call Recordings: At least ten (10) years for CMS compliance and carrier audit support.
- HIPAA Audit Logs: At least six (6) years, consistent with HIPAA documentation retention requirements.
- Client and PHI Data: For the duration of your subscription and any applicable retention period required by law or carrier contract. PHI is deactivated but not deleted while retention obligations remain active.
- Payment and Billing Records: As required by tax, accounting, and financial regulations and by Stripe’s retention policies.
- Support Communications and Usage Logs: As needed for security, support, and audit purposes.
Retention Following Service Discontinuation. If Evrcad discontinues the Service, regulatory records subject to mandatory retention periods including SOA forms, call recordings, and HIPAA audit logs will be maintained in a secure, accessible form for the remainder of their applicable retention periods. Evrcad may fulfill this obligation through a read-only archive, transfer to a compliant third-party custodian, delivery to customers, or other reasonable means communicated in any discontinuation notice. You are independently responsible for maintaining copies of your own compliance records.
Business Transfers. In the event of a merger, acquisition, or asset sale, Customer Data including PHI may be transferred to the acquiring entity subject to obligations no less protective than those in this Privacy Policy. We will provide notice of any such transfer consistent with applicable law. The acquiring entity will be bound by the same data retention and HIPAA obligations.
After applicable retention periods expire, Evrcad may securely delete or de-identify information consistent with HIPAA disposal standards and our data management policies.
09Data Security
- Encryption of data in transit (TLS) and at rest (AES-256).
- Role-based access controls and least-privilege principles.
- Network segmentation and firewall rules.
- Logging and monitoring of access and key events via AWS CloudTrail and CloudWatch.
- Regular backups and disaster recovery planning.
- No security measures are perfect, and we cannot guarantee absolute security, but we take reasonable steps to reduce risk consistent with HIPAA’s Security Rule and industry standards.
10Your Choices and Rights
Access and Correction.If you have an account, you may access and update profile information through the Service. End clients of an agency should direct requests for access or correction to the agency; Evrcad acts as a processor on the agency’s behalf.
Data Export and Portability.Agency administrators may request a comprehensive export of their organization’s data including client records, SOA forms, call recordings, SMS history, and audit logs at any time through account settings or by contacting support@evrcad.com. Exports will be provided in standard formats within a commercially reasonable time.
Deletion. Because Evrcad must comply with regulatory retention requirements (CMS and HIPAA), we cannot delete PHI or regulated records on request while mandatory retention periods remain active. Where deletion is legally permissible, we will honor requests from authorized account owners or administrators.
Retention Acknowledgment. When you download a data export, you agree to accept responsibility for the secure storage and maintenance of SOA forms, call recordings, and related compliance documentation for the full applicable retention period under CMS requirements and HIPAA.
Marketing Communications. Evrcad does not use PHI for marketing. For non-transactional product communications, you may opt out via unsubscribe links in those emails.
California Privacy Rights (CCPA/CPRA). California residents may have rights to know, access, delete, correct, and opt out of sale or sharing of personal information. Evrcad does not sell personal information. Because Evrcad functions primarily as a service provider to agencies, California residents who are end clients should direct requests to the agency that controls their data. Direct customers may contact privacy@evrcad.com with “CCPA Request” in the subject line and sufficient information to verify identity.
11Cookies and Similar Technologies
We use cookies and similar technologies for essential purposes such as authentication, session management, and security. We do not use third-party advertising cookies. You may adjust your browser settings to manage cookies, but disabling essential cookies may limit functionality.
12Children's Privacy
The Service is intended for use by licensed insurance professionals and agency staff. It is not directed to individuals under 18 years of age. We do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13, we will take steps to delete it as required by law.
13International Users
The Service is designed for use by U.S.-based agencies and agents serving U.S. Medicare beneficiaries. If you access the Service from outside the United States, you understand that your information will be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your country.
14Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice by email or within the Service and update the “Last Updated” date at the top. Your continued use of the Service after the effective date of an updated Privacy Policy constitutes your acceptance of the changes.
15Contact Us
Privacy inquiries: privacy@evrcad.com
Legal / BAA requests: legal@evrcad.com
Support: support@evrcad.com