01 Introduction & Scope
MedTech For Solutions Inc. (“MedTech,” “we,” “us,” or “our”) is a healthcare consulting and laboratory management company founded in 2005 and headquartered at 399 Knollwood Road, White Plains, NY 10603, USA. Since our founding, we have delivered end-to-end assisted reproductive technology (ART) practice support to fertility clinics, IVF laboratories, and reproductive medicine facilities across all 50 states — encompassing laboratory management and optimization, regulatory compliance, staffing and recruitment, Group Purchasing Organization (GPO) services, practice development, and comprehensive management services.
This Privacy Policy explains how MedTech collects, uses, discloses, retains, and protects personal information when you:
- Visit medtech4solutions.com or any linked MedTech web property (the “Site”);
- Submit an inquiry, schedule a consultation, or otherwise communicate with us;
- Engage MedTech as a service provider, vendor, or consulting partner;
- Apply for employment, temporary placement, or recruitment through our staffing services;
- Join or participate in our Group Purchasing Organization (GPO); or
- Use the OvaTools Laboratory Management System or any other MedTech platform.
Scope of This Policy
This Policy governs MedTech’s relationship with website visitors, prospective and active clients, GPO members, staffing candidates, and other business contacts. It is not a HIPAA Notice of Privacy Practices and does not supersede any Business Associate Agreement (BAA), service contract, or staffing agreement in place between you and MedTech — those instruments control where they apply.
By using the Site or providing information to us, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please discontinue use of the Site and do not submit information to us.
02 Information We Collect
We collect personal information in three ways: directly from you, automatically when you interact with the Site, and from third-party sources.
2.1 Information You Provide Directly
- Identity & contact details — name, job title, organization name, email address, phone number, and mailing address submitted through inquiry forms, contact pages, or direct correspondence.
- Practice & facility information — details about your fertility clinic or IVF laboratory (size, location, current vendors, services offered, regulatory status) shared during scoping or onboarding discussions.
- Service engagement records — correspondence, meeting notes, project documentation, operational metrics, laboratory data, and other materials exchanged in the course of delivering our services.
- Recruitment & staffing information — résumés, CVs, professional credentials (TS/ABB certification, HCLD designation, board certifications, state licenses), employment history, references, and background-check consent when you apply for placement or recruitment services.
- GPO membership data — entity legal name, federal tax identification number, authorized signatories, billing address, facility type, and purchasing volume information.
- Financial & payment information — billing address, invoicing contacts, and banking or ACH details for contract payments. Card payments, when accepted, are processed exclusively by PCI-DSS-compliant third-party processors; MedTech does not store full card numbers.
- Communications content — messages, feedback, survey responses, and support requests you send us by any channel.
2.2 Information Collected Automatically
- Device & connection data — IP address, browser type and version, operating system, screen resolution, language and time-zone settings.
- Usage & navigation data — pages visited, time on page, click paths, referring URL, and search terms used to arrive at the Site.
- Cookies & similar technologies — see the Cookie Policy in Section 7 for full details.
2.3 Information from Third Parties
- Referrals — basic identifying information when an existing client, partner, or industry contact refers you to us.
- Recruitment partners & licensing bodies — professional credentials or background information shared by staffing platforms, the American Board of Bioanalysis, state licensing boards, or similar entities in a recruitment context.
- Public professional sources — information available in professional directories, conference attendee lists, regulatory agency filings, and publicly accessible business records.
03 How We Use Information
We process personal information only for legitimate purposes related to operating and improving our services. Specific uses include:
- Responding to inquiries, scheduling consultations, and managing prospective client relationships;
- Delivering the IVF laboratory management, compliance, staffing, GPO, practice development, and management services you or your organization have engaged us to provide;
- Operating, maintaining, securing, and improving the Site and our internal platforms, including OvaTools LMS;
- Matching qualified embryologists, laboratory directors, and ART professionals with temporary or permanent placement opportunities;
- Administering GPO membership, vendor contracting, order facilitation, and rebate accounting across our 1,800+ vendor network;
- Sending operational communications — contract notices, service updates, compliance alerts, and invoices;
- Sending marketing communications about MedTech services where lawfully permitted; you may opt out at any time (see Section 10);
- Conducting aggregate or de-identified analytics, quality benchmarking, and outcome research to improve our laboratory programs;
- Complying with legal, regulatory, accreditation, and audit obligations — including FDA, CLIA, CAP, AABB, CMS, and applicable state requirements;
- Detecting, preventing, and investigating fraud, unauthorized access, and other unlawful activities; and
- Establishing, exercising, or defending legal claims.
Where required by law, we rely on the following legal bases: contractual necessity (delivering agreed services), legitimate interests (operating and improving our business, security), legal obligation (regulatory compliance), and consent (marketing communications where required). We do not sell personal information and do not use it for cross-context behavioral advertising.
04 HIPAA & Protected Health Information
MedTech For Solutions is generally not a HIPAA Covered Entity. However, certain services — including Real-Time Laboratory Monitoring, OvaTools LMS, and specified practice management engagements — involve receiving, creating, maintaining, or transmitting Protected Health Information (PHI) on behalf of our Covered Entity clients. In those circumstances, MedTech acts as a Business Associate under HIPAA.
Do Not Submit PHI Through This Website
The Site, our public email addresses, and our web inquiry forms are not secure channels for Protected Health Information. Do not include patient names, dates of birth, medical record numbers, treatment details, embryo or cycle outcomes, insurance information, or any other PHI in inquiry forms, voicemails, or general email. Secure, encrypted channels and a fully executed BAA will be established before any PHI is exchanged.
Business Associate Agreements (BAAs)
Before receiving any PHI, MedTech executes a written BAA with each Covered Entity client. The BAA, together with the HIPAA Privacy Rule (45 CFR Part 164, Subpart E), Security Rule (Subpart C), and Breach Notification Rule (Subpart D), governs our handling of that PHI — not this Privacy Policy. Each BAA specifies:
- Permitted and required uses and disclosures of PHI, limited to those necessary for the contracted services or required by law;
- Administrative, physical, and technical safeguards commensurate with the nature and sensitivity of the PHI;
- Subcontractor flow-down obligations — any subcontractor receiving PHI is bound by equivalent BAA terms;
- Breach notification to the Covered Entity within the timeframes required by 45 CFR § 164.410; and
- Disposition of PHI upon termination — return, destruction, or continued protection where return/destruction is infeasible.
Safeguards for PHI
For engagements involving PHI, MedTech implements the HIPAA Security Rule’s required and addressable safeguards, including: workforce training and access controls, encryption of PHI in transit and at rest, audit logging, workstation and device security, and a formal risk analysis and risk management program reviewed at least annually.
Patient Inquiries
MedTech is not a healthcare provider and is not the Covered Entity for any patient’s care. If you are a patient of one of our client clinics, please direct all clinical questions, medical record requests, accounting-of-disclosures requests, and similar HIPAA inquiries to your treating clinic. We will promptly route any patient inquiry that reaches us to the appropriate Covered Entity.
De-Identified & Aggregate Data
We may use de-identified data — from which all 18 HIPAA identifiers have been removed in accordance with the Safe Harbor or Expert Determination methods under 45 CFR § 164.514(b) — and aggregate statistics for benchmarking, research, quality improvement, and service development. De-identified data is not PHI and is not subject to HIPAA use or disclosure restrictions.
05 GDPR & International Privacy
MedTech operates primarily in the United States under U.S. law. We do not actively market to residents of the European Economic Area (EEA), the United Kingdom (UK), or Switzerland. If you are located in one of those jurisdictions and voluntarily provide us with personal information (for example, as a conference contact or international client), the following applies.
Legal Bases for Processing (EEA / UK)
| Processing Purpose | Legal Basis (GDPR Art. 6) |
| Responding to inquiries and delivering contracted services | Art. 6(1)(b) — Performance of a contract / pre-contractual steps |
| Operating the Site, fraud prevention, security | Art. 6(1)(f) — Legitimate interests |
| Marketing communications (where applicable) | Art. 6(1)(a) — Consent (withdrawable at any time) |
| Compliance with legal obligations | Art. 6(1)(c) — Legal obligation |
Your GDPR / UK GDPR Rights
Where the GDPR or UK GDPR applies, you have the right to: access your personal data; rectify inaccurate data; request erasure (“right to be forgotten”) subject to legal retention obligations; restrict processing; object to processing based on legitimate interests; and receive your data in a portable format. You also have the right to lodge a complaint with your national supervisory authority (e.g., the ICO in the UK or a lead authority under the EU’s one-stop-shop mechanism).
International Data Transfers
Personal data transferred from the EEA, UK, or Switzerland to the United States is subject to appropriate safeguards. Where required, MedTech relies on Standard Contractual Clauses (SCCs) adopted by the European Commission, or the UK International Data Transfer Agreement (IDTA), as the transfer mechanism. Copies of applicable SCCs or IDTAs are available on request by emailing privacy@medtech4solutions.com.
EU/UK Representative
As MedTech does not have an establishment in the EEA or UK and processes EEA/UK data only on an incidental basis, we have not designated a formal EU/UK representative. If you are an EEA or UK data subject with a privacy concern, please contact our Privacy Office directly (see Section 15).
06 Sharing & Disclosure of Information
We share personal information only as necessary to operate our business and deliver our services, and only with parties bound by appropriate confidentiality and security obligations. Categories of recipients include:
| Recipient Category | Purpose & Conditions |
| Service providers & subcontractors |
IT hosting, cloud storage, email delivery, analytics, payroll processing for placed candidates, e-signature platforms, and similar operational services. All bound by written data processing agreements; BAAs executed where PHI is involved. |
| Placement clients (when you are a candidate) |
Professional credentials, CV, certifications, and references shared with prospective placement clients only with your prior consent as part of our staffing and recruitment process. |
| GPO vendors & contracted suppliers |
Member facility name, authorized-purchaser details, and purchasing category information shared with contracted vendors as required to fulfill orders, administer pricing agreements, and process rebates. |
| Covered Entity clients (BAA context) |
PHI handled only under a fully executed BAA, limited to uses and disclosures required to perform the contracted services or mandated by law. |
| Professional advisors |
Legal counsel, auditors, insurers, and accountants acting under professional or contractual confidentiality obligations. |
| Successors-in-interest |
In connection with a merger, acquisition, asset sale, or corporate restructuring, subject to confidentiality obligations and the continued application of this Privacy Policy to transferred data. |
| Government & legal authorities |
When compelled by valid legal process (subpoena, court order, regulatory demand) or when disclosure is necessary to comply with law, prevent fraud, protect health or safety, or defend legal claims. |
We do not sell, rent, or trade personal information to advertisers, data brokers, or unaffiliated third parties for their independent commercial use.
07 Cookie Policy
This section is our Cookie Policy. The Site uses cookies and similar technologies (collectively “cookies”) to make the Site function correctly, measure performance, and improve the visitor experience. We do not use cookies for behavioral advertising or programmatic ad targeting.
What Are Cookies?
Cookies are small text files stored on your device when you visit a website. They allow the site to remember certain information about your visit. Similar technologies include local storage, session storage, pixels, and browser fingerprinting — we use only cookies and local storage on the Site.
Cookies We Use
| Category | Purpose | Can Be Disabled? |
| Strictly Necessary |
Core Site functionality — session management, security tokens, load balancing, form submission continuity. Without these the Site cannot function correctly. |
No — these are essential |
| Analytics |
Aggregate, anonymized usage statistics (page views, session duration, approximate geography) that help us understand how the Site is used and improve its structure. We use a privacy-respecting analytics provider that does not set cross-site tracking cookies or share data with ad networks. |
Yes — via browser settings or opt-out |
| Preferences |
Non-sensitive local storage of UI choices, such as remembered cookie banner acceptance or expanded navigation states. |
Yes — clearing browser data removes them |
Your Cookie Choices
You can manage cookies through:
- Browser settings — most browsers allow you to refuse new cookies, delete existing cookies, or receive a warning before a cookie is stored. Refer to your browser’s help documentation.
- Private / Incognito mode — cookies are not stored beyond the session in private-browsing windows.
- Global Privacy Control (GPC) / Do Not Track (DNT) — we honor recognized GPC signals to the extent technically practicable for our analytics tools.
- Browser extensions — extensions such as uBlock Origin or Privacy Badger can block analytics cookies.
Disabling strictly necessary cookies will impair Site functionality. Disabling analytics cookies will not affect your ability to browse the Site.
Cookie Lifespan
Session cookies expire when you close your browser. Persistent cookies (analytics and preference types) typically expire within 12 months, after which they are renewed only if you continue using the Site.
Third-Party Cookies
The Site does not currently embed third-party ad networks or social-media tracking pixels. If this changes, we will update this section and, where required, obtain your consent before setting non-essential third-party cookies.
08 Data Security
MedTech implements administrative, physical, and technical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, loss, or destruction. Our security program includes:
- Encryption — TLS 1.2+ for all data in transit; encryption at rest for systems that process sensitive client, candidate, or PHI-adjacent data;
- Access controls — role-based access, principle of least privilege, and regular access reviews to limit exposure of personal data to authorized personnel only;
- Multi-factor authentication (MFA) — required for administrative access to all client-facing and internal platforms, including OvaTools LMS;
- Vulnerability management — regular vulnerability scanning, software patching, and annual penetration testing reviews;
- Vendor security — security assessments of key subprocessors and contractual flow-down of security obligations commensurate with data sensitivity;
- Employee training — annual HIPAA and information-security awareness training for all staff with access to personal or protected information; and
- Incident response — a documented incident response plan with defined escalation paths and notification timelines, including compliance with HIPAA’s Breach Notification Rule (45 CFR §§ 164.400–414) for PHI breaches.
Despite these measures, no method of electronic transmission or storage is 100% secure. If you believe your information has been compromised in connection with MedTech, please contact us immediately at privacy@medtech4solutions.com.
09 Data Retention
We retain personal information only as long as necessary to fulfil the purposes described in this Policy, to satisfy legal and regulatory obligations, to resolve disputes, and to enforce our agreements. Guiding retention periods are:
- Website inquiry & lead records — up to 24 months from last contact, then deleted or anonymized unless an engagement commences.
- Active client engagement records — duration of the engagement plus 6–7 years to meet professional standards, contractual requirements, and applicable statutes of limitations.
- Recruitment & staffing files — 3 years from last activity, unless a longer period is required by law or you have asked to remain in our active candidate pool.
- GPO membership records — duration of membership plus 7 years for rebate auditing and tax purposes.
- Financial, billing & tax records — as required by federal and state tax law (generally 7 years from the relevant tax year).
- PHI under a BAA — per the terms of the applicable BAA and HIPAA requirements, including 6-year documentation retention under 45 CFR § 164.530(j).
- Employee / HR records — as required by federal and state employment law, typically 3–7 years post-termination.
When personal information is no longer needed, we delete or securely destroy it, or anonymize it so it can no longer be associated with an individual.
10 Your Rights & Choices
Depending on your jurisdiction and the context in which you interact with us, you may have the following rights regarding your personal information:
- Access — request a copy of the personal information we hold about you, including the categories, sources, and purposes of processing;
- Correction / Rectification — ask us to correct inaccurate or incomplete personal information;
- Deletion / Erasure — request that we delete your personal information, subject to overriding legal or contractual retention requirements;
- Restriction of processing — ask us to pause certain processing activities while a dispute is resolved;
- Objection — object to processing based on our legitimate interests, including objection to direct marketing (which we will honor unconditionally);
- Data portability — receive the personal information you provided to us in a structured, machine-readable format, where technically feasible;
- Withdraw consent — where processing is based on consent (e.g., marketing emails), withdraw consent at any time without affecting the lawfulness of prior processing; and
- Opt out of marketing — use the unsubscribe link in any marketing email, or email us at any time, to stop receiving promotional communications.
How to Submit a Rights Request
Email
privacy@medtech4solutions.com from the address associated with your account or request, or write to our Privacy Office (see Section 15). Include your full name, organization, and a description of your request. We will respond within 30 days (or the period required by applicable law) and may need to verify your identity before fulfilling the request.
For PHI handled under a BAA, HIPAA rights requests (accounting of disclosures, access, amendment) must be directed to your treating Covered Entity clinic — MedTech is not the appropriate party to respond to those requests.
11 California Residents — CCPA / CPRA
If you are a California resident, the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 (collectively “CCPA/CPRA”) grants you additional rights in addition to those described in Section 10.
Categories of Personal Information Collected
In the past 12 months we have collected the categories of personal information described in Section 2, which include: identifiers; professional or employment-related information; commercial information (GPO purchasing records); internet or electronic network activity; and inferences drawn to create a profile about business preferences. We collected this information for the business purposes described in Section 3 and disclosed it to the categories of recipients in Section 6.
No Sale or Sharing for Behavioral Advertising
MedTech has not sold and does not sell personal information as defined by the CCPA/CPRA. MedTech has not shared and does not share personal information for cross-context behavioral advertising.
Your CCPA/CPRA Rights
- Right to Know — the categories and specific pieces of personal information collected about you and how it was used and shared;
- Right to Delete — deletion of personal information, subject to exceptions for completing transactions, security, legal obligations, and other permitted uses;
- Right to Correct — correction of inaccurate personal information;
- Right to Opt Out of Sale/Sharing — not applicable as we do not sell or share for advertising; and
- Right to Non-Discrimination — you will not receive discriminatory treatment for exercising any CCPA/CPRA right.
To exercise your CCPA/CPRA rights, contact us as described in Section 15. You may authorize an agent to submit a request on your behalf by providing written authorization and identity verification. We will respond within 45 days, with a possible 45-day extension where reasonably necessary.
12 Children’s Privacy
The Site and MedTech’s services are directed exclusively to healthcare professionals, fertility clinic operators, IVF laboratory directors, and practice managers. We do not knowingly collect personal information from children under 13 (or under 16 where a higher age threshold applies under applicable law). If we learn that we have inadvertently collected personal information from a minor, we will delete it promptly. If you believe we hold personal information about a child, please contact us at privacy@medtech4solutions.com.
13 Third-Party Links & Services
The Site may contain links to vendor portals, professional association websites, regulatory agency resources, and other third-party platforms. Once you leave the Site, this Privacy Policy no longer applies. We are not responsible for the privacy practices or content of third-party sites. We encourage you to review the privacy policy of any third party before providing personal information.
Third-party services embedded in or linked from the Site (such as scheduling tools, e-signature platforms, or GPO vendor portals) operate under their own privacy policies and, where applicable, data processing agreements with MedTech.
14 Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our services, practices, or legal requirements. The “Last Updated” date at the top of this page indicates the most recent revision. We will notify you of material changes by posting a prominent notice on the Site and, where feasible, by email to active clients or GPO members, at least 30 days before the changes take effect.
Your continued use of the Site or engagement with MedTech services after an updated Policy takes effect constitutes acceptance of the revised terms. If you do not agree with a material change, you may discontinue use of the Site and contact us to discuss your options.
Prior versions of this Privacy Policy are available on request by emailing privacy@medtech4solutions.com.