Privacy Policy

Privacy Policy

HomeHealth-TX web, mobile, support, and agency billing privacy practices

Effective Date: July 4, 2026
Last Updated: July 4, 2026

1. Introduction

HomeHealth-TX ("HomeHealth-TX," "we," "us," or "our") provides web and mobile software that helps home care agencies, caregivers, and authorized family members coordinate home care services (the "Service"). This Privacy Policy explains what information we collect, how we use and disclose it, and the choices and rights available to individuals.

This policy applies to:

  • The HomeHealth-TX agency web application
  • The HomeHealth-TX Caregiver and Family mobile applications
  • The HomeHealth-TX website and support services
  • HomeHealth-TX's commercial billing relationship with its agency customers

2. Our Role Under HIPAA

The Health Insurance Portability and Accountability Act of 1996 ("HIPAA") applies to certain individually identifiable health information.

When HomeHealth-TX provides services to a home care agency that is a HIPAA Covered Entity, HomeHealth-TX acts as the agency's Business Associate under a Business Associate Agreement ("BAA"). The agency controls the Protected Health Information ("PHI") processed through the Service, and the agency's Notice of Privacy Practices governs its handling of patient PHI. HomeHealth-TX processes PHI only as permitted by the applicable BAA, the agency's instructions, and applicable law.

When HomeHealth-TX interacts directly with an individual outside a Covered Entity relationship, HIPAA may not apply to that interaction. Other federal or state privacy laws may still apply, and HomeHealth-TX uses safeguards designed to protect sensitive information regardless of its legal classification.

HomeHealth-TX is not the home care provider and does not issue the agency's patient-facing Notice of Privacy Practices.

3. Information We Collect

3.1 Account and contact information

Depending on how a person uses the Service, we may collect:

  • Name
  • Email address and telephone number
  • Business or service address
  • Organization and job role
  • Login, authentication, and account-security information
  • Professional credentials for caregivers or agency personnel

3.2 Agency customer and commercial billing information

To establish and manage HomeHealth-TX's commercial relationship with a home care agency, we may collect:

  • Agency legal or business name
  • Agency billing contact name and business email address
  • Agency billing and mailing address
  • HomeHealth-TX subscription plan, licensed features, and account identifiers
  • Invoice number, invoice date, billing period, due date, amount, balance, and payment status
  • Payment method type, tokenized payment identifiers, and limited card details such as card brand and last four digits when supplied by the payment processor
  • Accounting identifiers and transaction references returned by QuickBooks Online

HomeHealth-TX does not store full payment card numbers, card verification values, or bank-account credentials when payment information is entered directly into an Intuit or other payment-provider interface.

3.3 Health and care information

The Service may process health and care information on behalf of an agency, including:

  • Care plans, preferences, and service instructions
  • Visit schedules, visit notes, observations, and care documentation
  • Medications, wellness information, or vital signs entered by authorized users
  • Care-related messages, photographs, and documents
  • Emergency contact information

This information may be PHI when HomeHealth-TX processes it for a Covered Entity. It remains within systems and service providers approved for HomeHealth-TX's HIPAA-regulated workflows. It is not sent to QuickBooks Online.

3.4 Location information

With appropriate device permissions, the Service may collect caregiver location during an active visit for visit verification, safety, and operational coordination. The Service may also process a care recipient's service address and an approximate device location when a user asks the app to help populate an address.

HomeHealth-TX does not send patient addresses, service locations, caregiver routes, or visit-location data to QuickBooks Online.

3.5 Device, usage, and security information

We may collect device type, operating-system and app version, IP address, session and security events, feature interactions, crash data, and diagnostic information. We use this information to authenticate users, protect the Service, troubleshoot errors, and improve reliability.

3.6 Communications

We may collect messages sent through the Service and communications with our support or business teams. We do not use PHI for advertising and do not use PHI to train third-party artificial-intelligence models.

4. How We Use Information

We use information to:

  • Provide, maintain, secure, and support the Service
  • Authenticate users and enforce role-based access
  • Coordinate visits, communications, and authorized care workflows
  • Create invoices for HomeHealth-TX subscription and platform services purchased by agency customers
  • Send those commercial invoices and synchronize their status with QuickBooks Online
  • Process and reconcile payments made by agency customers
  • Maintain accounting, tax, audit, and transaction records
  • Detect fraud, misuse, security incidents, and technical problems
  • Respond to support and privacy requests
  • Meet contractual and legal obligations
  • Improve the Service using appropriately limited or de-identified information

5. QuickBooks Online and Intuit

5.1 Purpose of the integration

HomeHealth-TX connects to a HomeHealth-TX-controlled QuickBooks Online account through Intuit's API. The integration is used only to create, send, track, and reconcile invoices that HomeHealth-TX issues to its agency customers for HomeHealth-TX subscription, platform, implementation, or related business services.

The integration is private and is not offered as a public application in the Intuit App Marketplace. Its private status does not change the privacy and security controls described in this policy.

5.2 Information sent to QuickBooks Online

HomeHealth-TX may send the following limited agency-level commercial information to Intuit:

  • Agency legal or business name
  • Agency billing contact name, business email address, and business billing address
  • A HomeHealth-TX agency account or billing identifier
  • Generic HomeHealth-TX product or subscription description
  • Invoice number, invoice date, billing period, due date, amount, and balance
  • Payment status and transaction or reconciliation identifiers

This information is used to generate and deliver HomeHealth-TX's commercial invoices, process or record agency payments, and maintain HomeHealth-TX's accounting records.

5.3 Information excluded from QuickBooks Online

HomeHealth-TX does not send or store any patient or care-recipient information in QuickBooks Online. The integration excludes:

  • Patient or care-recipient names, initials, email addresses, telephone numbers, or addresses
  • Medical-record, patient, visit, caregiver, or care-plan identifiers
  • Diagnoses, medications, allergies, vital signs, clinical notes, care plans, or photographs
  • Patient service dates, visit dates, visit times, or locations
  • Descriptions of care delivered to a particular patient
  • Insurance-member, Medicare, Medicaid, Social Security, or other patient identifiers
  • Any free-text field originating in a patient, visit, care-plan, clinical, or messaging record

QuickBooks Online is not used as a clinical system, patient ledger, designated record set, or repository for PHI. Patient health information remains within the HomeHealth-TX environment and approved HIPAA-regulated service providers.

5.4 Intuit's privacy practices

Intuit independently processes information it receives through QuickBooks Online and QuickBooks Payments under its own terms and privacy practices. For more information, review the Intuit Global Privacy Statement.

HomeHealth-TX does not rely on QuickBooks Online to store or process PHI.

5.5 Disconnecting the integration

An authorized HomeHealth-TX administrator may disconnect the QuickBooks Online integration. Disconnecting stops new API synchronization and revokes HomeHealth-TX's active authorization tokens. Information already stored in QuickBooks Online remains subject to HomeHealth-TX's accounting-retention obligations and Intuit's terms and privacy practices.

6. How We Share Information

We may disclose information:

  • To authorized agency personnel, caregivers, family members, or other participants as needed to provide the Service
  • To service providers that host, secure, authenticate, support, or deliver the Service
  • To Intuit for the limited agency invoicing, accounting, and payment purposes described in Section 5
  • To professional advisers, auditors, insurers, or financial institutions subject to appropriate confidentiality duties
  • When required by law, legal process, or a valid governmental request
  • To protect the rights, safety, and security of HomeHealth-TX, its customers, or others
  • In connection with a merger, financing, acquisition, reorganization, or sale, subject to applicable privacy obligations

We do not sell PHI or personal information. We do not share PHI with advertising networks or data brokers.

Where a service provider creates, receives, maintains, or transmits PHI for HomeHealth-TX, we require an appropriate BAA before PHI is provided to that service provider. Intuit is not used for such PHI processing.

7. Payment Processing

An agency customer may be directed to an Intuit-hosted or other payment-provider interface to submit payment information. The payment provider may collect payment-card, bank-account, fraud-prevention, device, and transaction information directly under its own privacy notice and terms.

HomeHealth-TX may receive confirmation of the payment, payment status, amount, date, processor transaction identifier, and limited payment-method details. HomeHealth-TX does not receive or store card verification values and does not intentionally receive full payment-card or bank-account credentials.

8. Data Retention

We retain information for only as long as reasonably necessary for the purposes described in this policy, contractual obligations, legal requirements, dispute resolution, security, and enforcement.

Typical retention periods include:

InformationTypical retention
Active account informationLife of the account plus a limited closure period
Care and visit records held for an agencyAccording to the agency's instructions and applicable healthcare-record requirements
HomeHealth-TX invoices, payment, accounting, and tax recordsGenerally seven years
Authentication and security logsAccording to the applicable security and compliance schedule
Support correspondenceGenerally three years
De-identified aggregate informationAs needed for legitimate business purposes

Legal holds, investigations, contractual requirements, or applicable law may require longer retention. Deletion of a HomeHealth-TX account does not require deletion of accounting records that HomeHealth-TX or Intuit must retain by law.

9. Security

HomeHealth-TX uses administrative, physical, and technical safeguards designed to protect personal information and PHI. Depending on the system and risk, these safeguards include:

  • Encryption in transit and at rest
  • Role-based access and least-privilege controls
  • Multi-factor authentication for privileged access
  • Audit logging and security monitoring
  • Segregation of clinical workflows from commercial accounting workflows
  • An explicit allowlist controlling fields sent to QuickBooks Online
  • Automated tests designed to prevent patient or clinical fields from entering QuickBooks payloads
  • Protection and rotation of API credentials and authorization tokens
  • Incident-response, backup, and recovery procedures
  • Workforce privacy and security training
  • Vendor review and appropriate contractual protections

No system can be guaranteed completely secure. Users should protect their credentials and promptly report suspected unauthorized access.

10. Individual Rights and Choices

Subject to applicable law and the role in which HomeHealth-TX holds the information, an individual may request:

  • Access to personal information
  • Correction of inaccurate personal information
  • A copy or export of applicable information
  • Deletion of an account or personal information that is not subject to a legal or contractual retention requirement
  • Information about applicable disclosures or processing

When HomeHealth-TX holds PHI as a Business Associate, HIPAA requests generally must be submitted to the relevant agency or other Covered Entity. HomeHealth-TX assists the Covered Entity as required by the BAA.

Agency billing contacts may update certain business-contact information through their account or by contacting HomeHealth-TX. Information stored in QuickBooks Online may also be subject to Intuit's privacy-request and account-management procedures.

To submit a request, contact privacy@homehealth-tx.ai. We may verify the requester's identity and authority before acting.

11. HIPAA Breach and Security-Incident Notice

When HomeHealth-TX acts as a Business Associate, it reports breaches of unsecured PHI to the relevant Covered Entity as required by the BAA and applicable law. HomeHealth-TX maintains incident-response procedures for investigating suspected unauthorized access, containing incidents, preserving evidence, and meeting applicable notification obligations.

12. Cookies and Analytics

Our website and applications may use strictly necessary cookies or similar technologies for authentication, security, preferences, and service operation. If optional analytics are enabled, we will provide any notice or choice required by applicable law and will configure those services so they are not used to receive PHI.

We do not use patient health information for targeted advertising.

13. Children's Privacy

The Service is not directed to children under 13, and children may not independently create accounts. An agency or authorized adult may provide information about a minor care recipient as part of a permitted care workflow. That information is protected under the same safeguards and contractual restrictions applicable to other care information.

14. Changes to This Policy

We may update this policy to reflect changes in the Service, vendors, legal requirements, or privacy practices. We will update the date above and provide additional notice when a material change requires it.

15. Contact Us

HomeHealth-TX Privacy Officer Email: privacy@homehealth-tx.ai Website: https://www.homehealth-tx.ai/privacy

For questions specifically about information held by an agency or requests involving agency-controlled PHI, contact the applicable agency first. For security reports, contact security@homehealth-tx.ai.