Scope & Applicability
This Privacy Policy applies to MAG Healthcare Solutions ("we," "us," or "our") and governs the collection, use, and protection of information obtained through:
- Our website and all associated web pages
- Our analytics dashboards and reporting platforms delivered to healthcare clients
- Professional services, consulting engagements, and data projects
- Email communications, forms, and other digital interactions
By using our services, you agree to the practices described in this policy. This policy does not override any separate data processing agreements (DPAs) signed with enterprise clients.
Data We Collect
2.1 Information You Provide Directly
- Contact information: name, email address, job title, organisation name
- Inquiry content submitted via our contact form
- Project-specific data shared during engagements (governed by separate DPA)
2.2 Technical & Usage Data
- IP address (anonymised where required by GDPR)
- Browser type, operating system, device category
- Pages visited, session duration, referral source
- Error logs and performance metrics
2.3 Protected Health Information (PHI)
PHI Handling: When we process Protected Health Information on behalf of covered entities (hospitals, clinics, payers), we act exclusively as a Business Associate under HIPAA. All PHI is processed under a signed Business Associate Agreement (BAA) and is never used for purposes beyond those contractually agreed.
How We Use Your Data
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Respond to inquiries & proposals | Contact info, message content | Legitimate interest / contract |
| Deliver contracted analytics services | Client-provided data, PHI (under BAA) | Contractual necessity |
| Improve website performance | Usage & technical data | Legitimate interest |
| Comply with legal obligations | Any data subject to legal request | Legal obligation |
| Send relevant service updates | Email address (opt-in only) | Consent |
We do not sell, rent, or trade your personal information with third parties for marketing purposes.
Legal Basis for Processing
Under applicable data protection law (GDPR Article 6 and UK GDPR), we process personal data on the following lawful bases:
- Contractual necessity - processing required to fulfil a service agreement
- Legitimate interests - improving our services, website security, fraud prevention
- Legal obligation - compliance with healthcare regulations, tax, and legal requirements
- Consent - marketing communications and non-essential cookies
HIPAA Compliance
Business Associate Status: Where applicable, MAG Healthcare Solutions operates as a HIPAA Business Associate and adheres to all requirements of the Health Insurance Portability and Accountability Act (HIPAA) and the HITECH Act.
Our HIPAA Safeguards include:
- Administrative: Workforce training, access controls, incident response policies, risk assessments
- Physical: Restricted access to systems processing PHI, secure disposal of electronic media
- Technical: End-to-end encryption in transit (TLS 1.2+), encryption at rest (AES-256), audit logs, automatic session timeouts
Business Associate Agreement (BAA)
Any healthcare client sharing PHI with us must execute a signed BAA prior to data access. The BAA governs permitted uses, disclosures, safeguard requirements, and breach notification procedures in accordance with 45 CFR S 164.504(e).
Breach Notification
In the event of a breach involving unsecured PHI, we will notify the relevant covered entity within 60 days of discovery, in compliance with the HIPAA Breach Notification Rule (45 CFR SS 164.400-414).
Your Rights Under GDPR & UK GDPR
If you are located in the European Economic Area (EEA), the United Kingdom, or another jurisdiction with applicable data protection law, you have the following rights:
- Right of access - request a copy of the personal data we hold about you
- Right to rectification - correct inaccurate or incomplete data
- Right to erasure - request deletion of your data, subject to legal obligations
- Right to restriction - limit how we use your data in certain circumstances
- Right to data portability - receive your data in a structured, machine-readable format
- Right to object - object to processing based on legitimate interests or for direct marketing
- Rights related to automated decision-making - we do not make solely automated decisions that significantly affect you
To exercise any of these rights, please contact us at info-healthcare@mag-solutions.uk. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner Office (ICO) or your national supervisory authority.
Data Retention
We retain personal data only for as long as necessary for the purposes it was collected, or as required by law:
| Data Type | Retention Period |
|---|---|
| Website inquiry data | 24 months |
| Client contract data | 7 years (tax / legal compliance) |
| PHI processed under BAA | As specified in BAA (minimum 6 years per HIPAA) |
| Technical / server logs | 90 days |
| Marketing consent records | Duration of consent + 2 years |
Security Measures
We implement a layered security architecture appropriate to the sensitivity of health data:
- All data in transit encrypted using TLS 1.2 or higher
- Data at rest encrypted with AES-256
- Role-based access control (RBAC) with least-privilege principles
- Multi-factor authentication (MFA) for all system access
- Regular vulnerability assessments and penetration testing
- Comprehensive audit logging and anomaly detection
- Incident response plan with defined breach escalation procedures
Children Privacy
Our services are intended for healthcare professionals and enterprises. We do not knowingly collect personal information from individuals under the age of 18. If you believe we have inadvertently collected information from a minor, please contact us immediately and we will delete it promptly.
Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices, legal requirements, or service offerings. When we make material changes, we will update the effective date, notify existing clients via email for significant changes, and post a notice on our website for at least 30 days.
Contact Us
For any privacy-related questions, requests, or concerns, please reach out to our Privacy Team:
MAG Healthcare Solutions — Privacy Team
Email: info-healthcare@mag-solutions.uk
Subject line: "Privacy Request – [Your Name]"
We aim to respond to all privacy requests within 30 calendar days.