Privacy Policy
Effective April 25, 2026
This Privacy Policy describes how Supreme Medical Evaluation Group, LLC (“SMEG”) collects, uses, and shares information through suprememedicalevaluationgroup.com (the “Site”) and controlled pilot/service conversations.
1. Information we collect
1.1 Account and billing information
When you request a demo, pilot conversation, or service scope, SMEG may collect:
- Name, work email, work phone, job title, and organization name.
- Billing contact information if a paid engagement is created. Payment-processing details will be handled through an approved payment processor if/when enabled.
1.2 Service-use data
A future service would require separate written authorization, applicable agreements, verified security/access controls, approved intake and retention/deletion procedures, and qualified reviewer/QA assignments. Its data inventory would be agreed before any records are accepted and may include:
- Therapy notes and supporting documentation that you submit through the approved intake path for documentation-risk review. To the extent these contain PHI, they are governed by your executed Business Associate Agreement and the SMEG HIPAA Notice — not this Privacy Policy.
- Usage telemetry: pages viewed, features used, request timestamps, error logs. Telemetry is associated with your account, not with individual patients.
- Device and connection metadata: IP address, browser user-agent, language, OS.
1.3 Lead-magnet and form submissions
The facility review scope planner and request-draft forms run in your browser. They do not automatically submit their contents. If you choose to send an organization-only inquiry separately, SMEG uses the information you send to respond and follow up. Do not include patient-specific details.
1.4 Cookies and analytics
The current marketing site is designed to avoid PHI collection. If analytics or cookies are added, they should be limited to site operations and privacy-respecting measurement; this policy will be updated if material tracking changes.
2. How we use information
- Provide agreed services. Respond to inquiries, scope pilots, run approved documentation-risk review, and provide reports when contracted.
- Operate and improve. Diagnose website errors and address abuse. Any future use of record-derived information would require separate authority and documented data-use limits; it is not enabled by this public demo.
- Communicate with you. Service notices, billing, security alerts, and (where you've opted in) product updates and documentation-risk updates.
- Comply with legal obligations. Respond to lawful requests, audit demands, and safety obligations.
SMEG does not use your data for any purpose materially different from those above without first notifying you.
3. Website hosting and future vendor review
SMEG will use only approved vendors for hosting, communications, payment processing, and any PHI-handling workflow. PHI-handling vendors require appropriate contracts/BAAs before PHI is exchanged.
| Subprocessor | Purpose | BAA / DPA |
|---|---|---|
| Marketing-site hosting | This public site is not an approved patient-record intake path. | Website vendor terms; not a PHI approval |
| Approved secure storage/intake vendor | Used only if a PHI-enabled pilot/service is signed. | BAA or equivalent healthcare-appropriate agreement required before PHI |
| Payment processor | Payment processing if/when enabled. | No PHI flows here |
| Approved AI/vendor services | Only as scoped for non-PHI, de-identified, or contract-approved processing. | No-train/zero-retention or BAA-backed terms as applicable |
The future service vendor list, contracts, data flows, and change-notice process must be finalized before a real-record pilot. This table is not a list of approved patient-data vendors. Email smeg@suprememedicalevaluationgroup.com with subject "Vendor readiness" to discuss the current scope and outstanding requirements.
4. How we share information
SMEG shares information only:
- With Subprocessors as listed above, under written contracts.
- With your authorized users within your organization.
- If required by law, valid legal process, or to protect rights and safety, with notice to you where lawful.
- In connection with a corporate transaction (merger, acquisition, financing, or sale of assets), with successor obligations to honor this Policy.
SMEG does not sell or share personal information for cross-context behavioral advertising as those terms are defined under the California Consumer Privacy Act ("CCPA").
5. Retention
Public planner and draft-form entries stay in your browser unless you choose to send them separately. A written retention/deletion schedule and its implementation must be verified before any real-record pilot, including relevant vendor and backup handling. No implemented patient-record retention period is represented by this page.
6. Your rights
Regardless of where you live, SMEG honors the following requests for the personal information we control:
- Access. A copy of the personal information we hold about you.
- Correction. Update inaccurate information.
- Deletion. Erase personal information, subject to legal-hold exceptions.
- Portability. Receive a machine-readable export.
- Opt out of sale / sharing. SMEG does not sell or share for behavioral advertising; the Global Privacy Control signal is honored as a valid request.
- Withdraw consent for marketing communications at any time via the unsubscribe link or by emailing smeg@suprememedicalevaluationgroup.com.
For PHI access, amendment, restriction, or accounting of disclosures, the request flows through your Covered Entity; see /legal/hipaa.
7. Security
The public demo is not approved for patient records. Proposed future safeguards and outstanding requirements are described at /legal/hipaa; they are not a completed security assessment or a claim that all controls are implemented. Security/access testing and incident procedures must be completed before a real-record pilot.
8. International transfers
Any future cross-border service or data transfer requires separate legal and vendor review. This public demonstration does not establish an approved international processing arrangement.
9. Children's privacy
The Service is intended for adult skilled-nursing and clinical workforce users. SMEG does not knowingly collect personal information from individuals under the age of 18 outside the context of a Covered Entity's clinical record (where it is governed by HIPAA and the BAA, not this Policy).
10. Changes to this policy
SMEG will post material changes to this Policy on this page and update the "Effective" date above. Where required by law, SMEG will provide additional notice (e.g., email to account contacts) for material changes.
11. Contact
Privacy questions, requests, and complaints:
- Email: smeg@suprememedicalevaluationgroup.com (subject line: "Privacy request")
- Phone: (818) 468-4099
- Mail: Supreme Medical Evaluation Group, LLC, 5786 Pawstand Ave, Las Vegas, NV 89122