Effective Date: 02/01/2025
Due North Transportation LLC (“Due North,” “we,” “our,” or “us”) respects the privacy and confidentiality of the individuals we serve. This Privacy Policy explains how we collect, use, disclose, and protect personal information, including health information, in compliance with:
- The Telephone Consumer Protection Act (TCPA)
- The Health Insurance Portability and Accountability Act (HIPAA) and its implementing regulations
- The Health Information Technology for Economic and Clinical Health (HITECH) Act
- Applicable state privacy and consumer protection laws.
By using our services, you acknowledge and agree to the terms of this Privacy Policy.
- Information We Collect
We may collect the following categories of information to provide transportation and related services:
- Personal Identifiers: Name, address, phone number(s), email address, date of birth.
- Protected Health Information (PHI): Medical conditions, mobility status, healthcare provider information, treatment details necessary to coordinate transportation.
- Payment Information: Insurance information, Medicaid/Medicare details, billing information.
- Communication Preferences: Consent to receive calls, texts, or emails regarding scheduling, reminders, or service updates.
- Device/Technical Information: When using our website or digital platforms, limited technical information such as IP address, browser type, and usage statistics.
- How We Use Information
We use your information to:
- Provide, coordinate, and manage non-emergency medical transportation services.
- Communicate with you about appointments, scheduling, billing, and service updates.
- Respond to inquiries, feedback, or complaints.
- Meet federal and state regulatory, billing, and reporting obligations.
- Improve the quality and safety of our services.
TCPA Compliance:
By providing your telephone number(s), you consent to receive calls and text messages from us for service-related purposes, including appointment reminders, scheduling confirmations, and transportation updates. You may revoke this consent at any time by following the opt-out instructions provided in communications or by contacting us directly. We will never use autodialed or prerecorded telemarketing calls without your express written consent.
- How We Share Information
We do not sell personal or health information. We may share information only as permitted or required by law, including:
- With Healthcare Providers, Insurers, and State Agencies: To coordinate care and process claims.
- With Business Associates: Vendors who perform services on our behalf under written agreements requiring HIPAA/HITECH compliance.
- For Legal and Safety Reasons: To comply with applicable law, regulation, court order, or in response to lawful requests by public authorities.
- With Your Authorization: Any other disclosure will only occur with your written authorization, which you may revoke at any time.
- Your Rights
As a consumer and patient, you have the following rights under HIPAA, HITECH, and state law:
- Access and Copies: You may request access to your PHI and obtain copies.
- Amendments: You may request corrections to inaccurate or incomplete information.
- Restrictions: You may request limitations on certain uses or disclosures.
- Confidential Communications: You may request that we communicate with you in a certain way (e.g., by mail instead of phone).
- Accounting of Disclosures: You may request a record of certain disclosures of your PHI.
- Revocation of Consent: You may revoke your consent to receive communications under the TCPA at any time.
- State-Specific Rights: Minnesota, Wisconsin, and Iowa consumers may have additional rights related to data access, correction, and deletion under state law. We will comply with these requirements.
Requests to exercise these rights should be submitted in writing to the Privacy Officer (see Section 8).
- Data Security
We maintain administrative, technical, and physical safeguards designed to protect the confidentiality, integrity, and availability of personal and health information, including:
- Encryption of electronic PHI where required by HITECH.
- Access controls and role-based permissions.
- Secure data storage and transmission practices.
- Workforce privacy and security training.
Despite these safeguards, no system can guarantee 100% security. We will notify affected individuals and regulators of any breach of unsecured PHI in accordance with HIPAA, HITECH, and applicable state data breach notification laws.
- Data Retention
We retain information only as long as necessary to provide services, meet legal and contractual obligations, and maintain business records in accordance with federal and state retention requirements.
- Children’s Privacy
Our services are not directed to children under 13 without parental or guardian consent. We comply with all applicable child privacy laws.
- Contact Information
For questions about this Privacy Policy, or to exercise your rights, please contact:
Privacy Officer
Due North Transportation LLC
2710 Commerce St, La Crosse, WI 54603
(608) 394-4900
- Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in law, regulation, or business practices. Updated policies will be posted with a new effective date.
