Contact Us

Global Health Information Privacy Policy

Effective Date: December 1, 2025

At Monument Systems, we are deeply committed to protecting the privacy, security, and confidentiality of all information entrusted to us, particularly Protected Health Information (PHI). This policy outlines the practices of Monument Systems (referred to as "we," "us," or "our") concerning the collection, use, disclosure, and safeguarding of information across our business activities, including our website and our Xpress™ claims processing platform.

1. Scope and Applicability (Our Role as a Business Associate)

This Policy applies to all data handled by Monument Systems globally, including digital, paper, and verbal communications.

Business Associate Status

Monument Systems acts as a Business Associate to our clients (Health Plans and Payers), and our processing of PHI is governed by the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the HIPAA Omnibus Rule of 2013, and the specific contractual agreements (including the Business Associate Agreement or BAA) executed with each client.

Applicability

  • Website Visitors: Personal data collected via our website (e.g., contact forms).
  • Client Data (PHI/PII): Data processed through our platform as a service provider.
  • Employee & Contractor Data: Information collected for employment and HR processes.

Jurisdiction

We comply with applicable US federal and state laws, including HIPAA and the California Consumer Privacy Act (CCPA)/California Privacy Rights Act (CPRA), and any other data protection laws in the jurisdiction where we or our clients operate.

2. Information Collection

Monument Systems collects, uses, and stores data only as needed to deliver our products and services, manage our business, and fulfil contractual and legal requirements.

A. Client and Platform Data (PHI/PII)

As a Business Associate, we collect and use PHI and Personally Identifiable Information (PII) as strictly needed to deliver our services under contract. This information may include, but is not limited to:

  • Patient identification details (e.g., name, address, date of birth).
  • Medical history, current health status, and treatment records.
  • Insurance and coverage details.

B. Website Visitor Data

We collect information that is voluntarily provided when you visit our website, submit inquiries, or request a demo:

  • Identity & Contact Data: Name, job title, company, email, and phone number.
  • Technical Data: IP address, browser type, operating system, and website usage data (collected via cookies and analytics).

C. Employee / Contractor / Supplier Data

We collect standard HR and administrative data (contact info, employment background, government-issued IDs, etc.) solely for employment administration, compliance, reporting to government agencies, and managing business relationships.

3. Use of Information

The information we collect is used solely for the following relevant, appropriate, and customary purposes:

A. Business Healthcare Operations (PHI)

PHI is used only to fulfil our contractual obligations, including but not limited to:

  • Processing medical claims, premium billing, and complex adjudication.
  • Providing customer support and service management for our clients.
  • Conducting Initial Clinical Reviews for Utilization Review (if applicable).
  • Other purposes expressly agreed upon in the Master Service Agreement (MSA) with the respective client.

B. Website & Business Administration

  • Responding to inquiries, providing advice, and inviting individuals to company events.
  • Processing contracts and transactions.
  • Improving our service offerings and platform functionality.

4. Disclosure of Information

PHI and PII will not be disclosed outside of Monument Systems except in the following limited circumstances:

  • Service Fulfillment: As necessary to fulfil our contractual obligations to our clients, including sharing with subcontractors who are also bound by appropriate confidentiality and data protection agreements.
  • Legal Obligation: When required by law, such as in response to a subpoena, court order, or other legal process, or to meet national security or law enforcement requirements.
  • Emergency Situations: In situations involving imminent danger to an individual’s health or safety.

5. Data Protection and Security

We implement a comprehensive range of security measures to protect data against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Encryption: Encryption of PHI and PII, both in transit and at rest.
  • Access Controls: Strict access limitations based on the employee's role and function (need-to-know basis).
  • Secure Storage: Secure digital and physical storage facilities.
  • Training & Audits: Mandatory privacy and security training for all personnel, and regular security audits and vulnerability assessments.

6. Client Policy Precedence & Guidelines

As a Business Process Management provider, our PHI handling procedures are bound by the respective client’s contract. To the extent of client’s business operation processes:

  • The Notice of Privacy Practices (NPP) of the respective clients shall prevail over this policy regarding patient rights.
  • All Monument Systems personnel adhere to and comply with the respective client’s policies and procedures related to information handling, modification, change, or deletion of PHI.

7. Breach Notification

In the event of a breach involving unsecured PHI, we will:

  • Notify affected individuals and clients promptly, in accordance with applicable state and federal laws and contractual agreements.
  • Investigate the breach thoroughly and take all necessary corrective actions to mitigate harm.
  • Document all incidents and the measures taken for regulatory reporting purposes.

8. Policy Updates

This Privacy Policy may be updated periodically to reflect changes in our business practices or legal requirements. Any changes will be posted on this website with an updated revision date.

9. Contact Information

For any questions or concerns regarding our privacy practices or the handling of information, please contact:

RoleContact Information
Privacy Contactpraley@monument-systems.com
Phone(415) 823-1925
Address315 3rd St #F
Huntington Beach, CA 92648

Terms and Conditions

Last Updated: December 1, 2025

1. Acceptance of Terms

By accessing and using monument-systems.com (the "Site"), you agree to be bound by these Terms and Conditions.

2. Intellectual Property Rights

The content, features, and functionality of this Site—including but not limited to text, graphics, logos, and software code related to the Xpress platform—are the exclusive property of Monument Systems.

3. Use License and Restrictions

Permission is granted to temporarily view the materials on Monument Systems’ website for personal, non-commercial viewing only. This license is read-only. You may not reproduce, modify, reverse engineer, or publicly display any material from this Site without our express written permission.

4. Disclaimer

The materials on Monument Systems’ website are provided on an 'as is' basis. Monument Systems makes no warranties, expressed or implied.

  • Not Medical Advice: Our software solutions are designed for administrative claims processing and premium billing. Nothing on this Site constitutes medical advice or creates a provider-patient relationship.

5. Limitations of Liability

In no event shall Monument Systems be liable for any damages arising out of the use or inability to use the materials on the Site.

6. Governing Law

These terms and conditions are governed by and construed in accordance with the laws of the State of California, and you submit to the exclusive jurisdiction of the courts in that State or location.

7. Contact Information

For any questions regarding these Terms, please contact us at praley@monument-systems.com.

8. Definitions

AbbreviationTermDefinition
PHIProtected Health InformationIndividually identifiable health information held or transmitted by a Covered Entity or Business Associate, as defined by HIPAA.
PIIPersonally Identifiable InformationInformation that can be used to distinguish or trace an individual’s identity.
HIPAAHealth Insurance Portability and Accountability Act The U.S. federal law governing the privacy and security of PHI.
BAABusiness Associate Agreement A written agreement between a Covered Entity and a Business Associate that mandates the Business Associate’s compliance with HIPAA.