Legal
Privacy Policy
Effective date: April 22, 2026 · Last updated: April 22, 2026
1. Introduction
MyCareTrail, LLC ("MyCareTrail," "we," or "us") operates the MyCareTrail platform (the "Service"), a compliance management system designed for licensed Minnesota home and community-based services (HCBS) providers operating under Minnesota Statutes chapter 245D.
This Privacy Policy explains how we collect, use, disclose, and safeguard information when you or your organization uses the Service. Because the Service is used to manage care for individuals with disabilities and related health conditions, some of the information we process constitutes Protected Health Information (PHI) as defined by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the Health Information Technology for Economic and Clinical Health (HITECH) Act.
By accessing or using the Service, you agree to the collection and use of information in accordance with this Policy. If you do not agree, please do not use the Service.
2. Definitions
- Business Associate
- MyCareTrail acts as a Business Associate to Covered Entities (245D licensed providers) as defined under HIPAA. We handle PHI on your behalf pursuant to a Business Associate Agreement (BAA) entered into at the time of service activation.
- Covered Entity
- Your organization — a licensed 245D HCBS provider — is the Covered Entity under HIPAA. You are responsible for ensuring that your use of the Service complies with all applicable HIPAA requirements.
- Protected Health Information (PHI)
- Individually identifiable health information — including names, dates of birth, DHS Person Marginal Identifiers (PMI), service authorization numbers, diagnoses, care plans, and related records — that we process on behalf of your organization.
3. Information We Collect
3.1 Information You Provide
- Account and organization data — company name, NPI/UMPI, license number, administrator name and email, contact information, and billing details provided during registration and in your tenant profile.
- Worker records — names, email addresses, roles, background check records, course completion status, and compliance documents for the direct support professionals your organization employs.
- Client records (PHI) — names, dates of birth, PMI numbers, county of residence, case manager information, service types, admission and discharge dates, service authorization details, diagnosis codes, and related 245D intake documentation. This information is considered PHI and is governed by our BAA.
- Documents and support plans — PDFs and other files you upload to the Service, including DHS-issued care support plans, service authorization letters, and signed forms.
- Communications — announcements, messages, and notes created within the platform.
3.2 Information Collected Automatically
- Usage data — pages visited, features used, timestamps, IP address, browser type, and device type. This data is used exclusively for service operation, security monitoring, and product improvement.
- Log data — server-side logs recording API requests, authentication events, and system errors. Logs are retained for 90 days.
- Cookies and local storage — We use browser
localStorageto store your authentication token and session preferences. We do not use third-party advertising cookies. You can clear stored data by logging out or clearing your browser storage.
3.3 AI Processing
When you upload a DHS support plan PDF and request AI-assisted extraction, the text content of that document is sent to our AI subprocessor for processing. That subprocessor handles the data under an enterprise agreement that prohibits training on your data. You should ensure you have appropriate authorization to share PHI with subprocessors before using this feature. The current named subprocessor is available on request.
4. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Service;
- Process and store client records and documentation required for 245D HCBS compliance;
- Automate intake timelines, compliance deadlines, and audit records;
- Send notifications and announcements within your organization's account;
- Generate compliance reports and the 245D Admission and Discharge Register;
- Authenticate users and manage access control;
- Detect, investigate, and prevent fraud and security incidents;
- Improve and develop new features of the Service;
- Comply with legal obligations and respond to lawful requests.
We do not sell your information, rent it to third parties, or use PHI for any purpose other than providing the Service as described in our BAA.
5. HIPAA and PHI
MyCareTrail is designed and operated in compliance with HIPAA and HITECH. As a Business Associate, we commit to:
- Using and disclosing PHI only as permitted by our BAA and applicable law;
- Implementing administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of electronic PHI (ePHI);
- Reporting any known or suspected breach of unsecured PHI to the applicable Covered Entity within the timeframes required by HIPAA;
- Making available its practices, policies, and procedures relating to the safeguarding of PHI to the Secretary of Health and Human Services upon request;
- Returning or destroying all PHI upon termination of the BAA, to the extent feasible.
Your organization, as the Covered Entity, is responsible for obtaining all necessary consents and authorizations from clients and their legal representatives before entering their PHI into the Service.
6. Data Sharing and Disclosure
We may share your information with:
- Service providers — cloud hosting, email delivery, AI extraction, and payment processing vendors who are contractually required to protect your data and may only use it to provide services to us.
- Legal and regulatory authorities — when required by law, court order, or governmental regulation, including the Minnesota Department of Human Services and the U.S. Department of Health and Human Services.
- Business transfers — in connection with a merger, acquisition, or sale of assets, provided the acquiring party agrees to honor this Privacy Policy and applicable BAAs.
We do not share PHI with any third party other than as described above or as permitted by our BAA.
7. Data Storage and Security
All data is stored on servers located within the United States. We implement industry-standard security measures including:
- TLS encryption for all data in transit;
- Encryption of sensitive data at rest;
- Role-based access controls limiting data access to authorized users;
- Audit logging of authentication and sensitive data access events;
- Regular security reviews and vulnerability assessments.
No method of electronic transmission or storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee its absolute security.
8. Data Retention
We retain account and operational data for the duration of your subscription plus 7 years following termination, or as required by Minnesota Statutes §245D.11 and applicable DHS rules, whichever is longer.
Client PHI is retained per the terms of your BAA and applicable Minnesota and federal recordkeeping requirements. Upon written request and termination of services, we will return or securely destroy PHI in accordance with our BAA.
9. Your Rights
Depending on your role and location, you may have the right to:
- Access — request a copy of the personal information we hold about you as a platform user (not PHI, which is governed by HIPAA and your organization's privacy practices);
- Correction — request correction of inaccurate personal information in your user account;
- Deletion — request deletion of your user account, subject to our legal retention obligations;
- Portability — request an export of your organization's data in a machine-readable format.
For rights requests, contact us at privacy@mycaretrail.com. We will respond within 30 days.
10. Children's Privacy
The Service is not intended for direct use by individuals under the age of 18. Some clients served by 245D providers may be minors; their PHI is handled in accordance with HIPAA and applicable state law and subject to the same protections as all other PHI.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify Tenant Administrators by email and in-app announcement at least 14 days before material changes take effect. Continued use of the Service after the effective date constitutes acceptance of the revised Policy.
12. SMS / Text Messaging
With your consent, MyCareTrail sends transactional SMS notifications (appointment and compliance reminders, document-signing prompts, and announcements) to opted-in users. Express consent is collected through an explicit, unchecked-by-default checkbox on a client or worker profile in the Service; no text is sent unless consent is granted and a mobile number is on file. Text messages contain no protected health information.
Message frequency varies and message & data rates may apply. Reply STOP to any message to opt out, or HELP for help.
SMS opt-in consent and mobile phone numbers are never sold, and are not shared with third parties or affiliates for their own marketing purposes. They are shared only with the telecommunications providers strictly necessary to deliver the messages you requested.
13. Contact Us
If you have questions about this Privacy Policy or wish to exercise your rights, contact us at:
MyCareTrail, LLCPrivacy Officer
Minneapolis, Minnesota
privacy@mycaretrail.com