Privacy Policy
This Privacy Policy explains how DocLien ("DocLien", "we") collects, uses, shares and protects information through app.doclien.com (the "Service").
DocLien handles two kinds of information. Account information is about the people who use DocLien for law firms, medical practices and DocLien itself. Patient information is about injured people whose care is coordinated through DocLien. Patient health information is protected by HIPAA and California’s Confidentiality of Medical Information Act. DocLien handles it for medical providers as their "business associate", under written agreements, and never sells it or uses it for advertising.
1. Information we collect
From law firms, providers and their staff:
- Name, job title, work email, mobile number and password (stored only in scrambled form), and two-step sign-in settings.
- Organization details, such as name, phone, address, website, State Bar number, NPI, specialties and office locations.
- Notification preferences and the agreements you accept.
About patients, added by their attorney, their provider, DocLien or the patient:
- Name, date of birth, contact details and preferred language.
- Details about the injury and the case, insurance and coverage information, and the care needed.
- Appointments, medical records, bills, balances and lien details.
- Electronic signatures, and the time and device details of each signature.
Automatically:
- Sign-in times, IP address, browser and device type.
- A record of each time someone opens a case file or document, kept to protect patients.
- Essential cookies that keep you signed in. DocLien does not use advertising or tracking cookies.
2. How we use information
- To provide the Service: referrals, scheduling, sharing records and bills with the people on each case, electronic signatures, lien tracking and reports.
- To verify law firms and providers (for example, State Bar and NPI checks).
- To keep the Service and patient information secure, to investigate misuse, and to keep audit records.
- To send service messages. These never include patient details.
- To support you, and to meet legal obligations.
- To improve the Service and understand the provider network using de-identified or aggregate information.
DocLien does not sell personal information, does not share it for cross-context behavioral advertising, and does not use patient information for marketing.
3. Who we share information with
- The people on each case, according to their role: the patient’s attorney, the patient’s treating providers, the patient, and DocLien coordinators. Each sees only what their role needs.
- Service providers who run DocLien for us, under contracts that limit their use of the information: Supabase (database, sign-in and file storage, United States), Vercel (website hosting, United States), Twilio (text messages), and Resend (email; emails carry no patient details). Companies that handle patient health information do so under a business associate agreement.
- Public services the Service relies on: the U.S. Census Bureau geocoder receives provider office addresses (never patient information) to place offices on the map, and when you view the map your browser loads map images from OpenStreetMap, which sees your IP address.
- When the law requires it, for example a valid subpoena or court order, and to protect anyone’s safety or the security of the Service.
- If DocLien is merged, acquired or sells its business, the new owner must keep the same protections.
- With your permission, or the patient’s written authorization.
4. Text messages
DocLien texts sign-in codes and short update notices to the mobile numbers on accounts and cases. Message and data rates may apply; frequency varies. Reply STOP to stop or HELP for help. Mobile numbers and text-message consent are never shared with or sold to third parties or affiliates for marketing.
5. How we protect information
- Encryption in transit and at rest.
- Two-step sign-in for all law firm, provider and DocLien staff accounts.
- Database rules that let each person see only the cases their role allows.
- Private file storage. Files open only after the access is recorded.
- A permanent audit trail of changes and access.
- Agreements with our service providers, and confidentiality agreements and training for DocLien staff.
No system is perfectly secure. If a breach affects your information, DocLien will notify you, and the provider for its patients, as HIPAA and California law (including Civil Code section 1798.82) require.
6. How long we keep information
Account information is kept while the account is open and for as long afterwards as needed for legal, security and record-keeping purposes. Case information is kept as long as the case needs it and as the law and our agreements with providers require (HIPAA records, for example, at least six years). Signature and audit records are kept permanently. When information is no longer needed, we delete it or de-identify it.
7. Your choices and rights
You can update your profile and notification choices in Settings. To ask for a copy of your information, or to correct or delete it, email privacy@doclien.com. We will confirm your identity first. You may use an authorized agent.
California residents. Under the California Consumer Privacy Act you may ask to know, get a copy of, correct or delete personal information about you, and you will not be treated differently for asking. DocLien does not sell or share personal information for advertising, and uses sensitive information only to provide the Service. California’s "Shine the Light" law: DocLien does not give personal information to others for their own marketing.
Patient health information is handled under HIPAA and California medical privacy law instead of the Consumer Privacy Act. Patients can ask their treating provider for their records, or ask DocLien, and we will help. See our Patient Terms and Privacy Notice.
DocLien does not track you across other websites and honors Global Privacy Control signals.
8. Children
The Service is not meant for children to use. Information about an injured minor is added only by the minor’s parent or guardian, attorney or provider, and is protected like all patient information.
9. Changes to this policy
We may update this policy. The date and version are shown at the top. For important changes we will tell users in advance and ask them to review the new version when they sign in.
10. Contact
Privacy questions or requests: privacy@doclien.com.