Effective Date:April 19, 2026
Last Updated:April 19, 2026

1) Scope of the Policy

This Privacy Policy applies to the Hospital Data Center platform and all associated web applications (the "Site"). It explains what data we process, how we safeguard your privacy, and clarifies the nature of the public healthcare datasets we utilize. It does not govern external links or third-party facilities mentioned on the platform.

2) Data Collection and Sources

2.1 Personal Information You Provide

  • Contact details such as name and email address when you voluntarily use our contact forms.
  • Feedback and communications sent directly to our support or data correction teams.

2.2 Information Collected Automatically

  • Anonymized technical data (browser type, device settings) for site optimization.
  • Usage statistics and aggregated analytics to trace traffic origins and improve page load times.
  • Strictly necessary cookies to maintain site functionality (see section 6).

2.3 Public Healthcare Data Integration

Important Disclaimer: We do NOT collect, process, or store personal medical records (PHI/HIPAA protected data). Our platform operates exclusively on official, publicly available datasets regarding healthcare providers. This includes the Centers for Medicare & Medicaid Services (CMS) datasets such as HCAHPS (Patient Experience), Timely & Effective Care, Healthcare-Associated Infections (HAI), and Complication metrics. We only index facility-level provider information, not patient-level privacy records.

3) Purpose of Data Usage

  • To present unbiased, structured healthcare provider benchmarks and quality ratings.
  • To answer inquiries submitted via the platform regarding potential dataset map corrections.
  • To secure the platform against automated bots, bulk scraping, or malicious server requests.

4) Data Processing and Automation Methodology

The Hospital Data Center relies on rigid schema matching and delta updates from CMS. We do not use generative Artificial Intelligence to give medical advice, and we absolutely do not use any user-submitted personal data to train public Language Models. Summarizations of facility performances are exclusively deterministic outputs based on our proprietary parsing and aggregation of CMS metric reporting schemas.

5) Embedded Services and Third-Party API Usage

Pages featuring geocoded visuals may rely on Google Maps or similar mapping API frameworks. These third-party plugins operate under their respective Privacy Policies. We only utilize maps to plot the geographic coordinates assigned to hospital campuses as registered in public datasets.

6) Tracking Technologies

We employ minimal, performance-based tracking to measure the effectiveness of our user interface. By using the platform, you understand that basic analytics cookies may establish aggregate patterns (such as which state or city pages are most visited). We respect your privacy configuration and refrain from deploying aggressive cross-site remarketing pixels.

7) Zero Sale of Personal Data Policy

We do not sell, rent, or commercialize your personal contact information to any third parties, clinics, or healthcare marketers. We may only disclose aggregated, anonymized trends or share necessary technical logs with our infrastructure providers to maintain vital server uptime and security.

8) Data Security Framework

Despite not handling PHI, we enforce a strict security framework over the Platform via HTTPS TLS encryption, explicit Content Security Policies (CSP), and automated defenses against scraping. While we safeguard our backend systems, no web transmission is strictly 100% impenetrable.

9) Privacy Rights and Opt-Outs

  • Record Erasure: You may contact us anytime to delete correspondence records we hold regarding your direct inquiries.
  • Cookie Opt-Out: Users can manually block non-essential cookies via their local browser preferences safely.

Note for Healthcare Providers: If you discover a material error in the CMS dataset displayed on our Platform, the standard protocol is to petition CMS directly. We strictly mirror and parse official upstream updates.

10) Children's Protection (COPPA)

Our index of hospitals and comparative benchmark scores is designed for adult researchers, policymakers, and adult patients. We do not knowingly request, collect, or store personal contact information from minors under the legal age of 13.

11) Policy Revisions

As we integrate additional State-level directories and benchmark modules, this Privacy Policy will be revised over time. The updated date at the document header defines the most current, ruling version.

12) Privacy Contact Point

Should you require clarification on how we handle user privacy or structure our CMS dataset imports, please direct your questions to our administration team: