We are in the business of helping healthcare and regulated organizations stay compliant, so protecting your information is not a side concern for us. It is the work. This notice explains, in plain language, what we collect, why we collect it, who we share it with, and the choices you have. If anything here is unclear, ask us. We would rather answer the question than leave you guessing.
This notice applies to the people and organizations we work with while providing credentialing, provider enrollment, compliance, and HR services. That includes:
It does not cover information that has been anonymized or aggregated so that it no longer identifies anyone.
We collect information in three main ways:
What we handle depends on the service, and for credentialing it is sensitive by nature. We treat it that way. It can include:
We practice data minimization. We ask for what the work requires, and nothing more.
We use your information to:
We do not sell your information, we do not build advertising profiles, and we do not feed your data into third-party artificial intelligence products.
We share your information only as needed to do the work or to meet a legal obligation:
We do not sell your personal information, and we do not share it for anyone else's advertising.
When we handle protected health information on behalf of a covered entity, we act as a Business Associate under HIPAA, and we sign a Business Associate Agreement before that work begins. In that role we use and disclose protected health information only as the agreement and the law allow. We also handle consumer health data consistent with the Washington My Health My Data Act and comparable Oregon requirements. Where an engagement involves a federally assisted substance use disorder program, we handle those records under 42 CFR part 2, which is stricter than HIPAA: consent is required before records are used or disclosed for treatment, payment or operations, records are not used in any proceeding against a patient absent consent or a qualifying court order, and every onward disclosure carries the notice that rule requires. Since February 16, 2026 those obligations have been enforced under HIPAA’s civil and criminal penalty scheme, and we hold ourselves to them accordingly. If you have a question about how your health information is handled, ask, and we will walk you through it.
We use administrative, technical, and physical safeguards suited to the sensitivity of what we handle, including access controls, encryption where appropriate, secure storage, confidentiality agreements with everyone who touches your file, and multi-factor authentication on the systems that support it. No safeguard is perfect, and we will not pretend otherwise, but security is part of the service, not an afterthought. If a breach affecting your information ever occurs, we will notify you and the appropriate authorities as required by law.
Depending on where you live, you may have the right to access the information we hold about you, ask us to correct information that is wrong, ask us to delete information, and ask how we collected and used it. To make a request, email service@brightrowan.com. We will verify your identity first, to protect you, and we will respond within the time the law requires. Exercising a right will never cause us to treat you differently. Some information we may be required to keep, for example to bill for services, meet credentialing recordkeeping rules, or comply with the law, and we will tell you when that is the case.
We keep information for as long as the engagement requires, and as long as the law, our professional obligations, and credentialing recordkeeping standards require, then we dispose of it securely. Retention periods vary by the type of information and the reason we hold it.
If you join the Bright Rowan Insights research panel, we collect your email address and the role you select, and nothing else. We do not collect your name, your employer, or any identifier that would let us or anyone else connect an answer back to you. Survey questions are closed-response only, with no free-text boxes.
Your answers are reported in aggregate. No finding is published on fewer than ten responses. Your employer never receives your individual answers, and neither does any sponsor. Panel members are not solicited for Bright Rowan consulting work.
We keep panel contact details for twenty-four months from your last response, then delete them. You can leave the panel at any time by emailing service@brightrowan.com, and we will delete your record.
We keep this notice current. When we make a meaningful change, we will update the date at the top. Changes that affect information we already hold will not apply retroactively without your consent where the law requires it.
Questions, requests, or concerns about your privacy can go to:
Bright Rowan, LLC
Vancouver, WA
service@brightrowan.com
We answer within one business day.