Licensed agents available — Mon–Fri 9am–6pm ET

+1 908-827-6223

HIPAA · PHI

How we handle health information.

There is no HIPAA certificate. This page is the public proof of the controls in this product — what we collect, who can see it, and what we refuse.

Privacy Official
info@team-iia.com
Entity
INSUREitALL LLC · NPN 20114179
Last reviewed
August 25, 2026

Our role

INSUREitALL LLC is a licensed Medicare insurance agency. We are not Medicare, CMS, or a health plan. Optional doctor names and medication names you type so a licensed agent can prepare are treated as protected health information in this product. They stay with INSUREitALL (staff desk and your portal). They are not emailed in lead alerts. artificialBRIDGE does not receive identifiable health details for training — only de-identified or aggregated data. We never collect SSN or Medicare numbers on this site.

We do not claim a HIPAA “certification” — none exists. We claim the controls below, which you can inspect on this site.

Safe Harbor de-identification

If a BRIDGEt conversation is kept for product improvement, it is text only. Audio is never stored. Each turn is run through HIPAA Safe Harbor (45 CFR 164.514(b)(2)) before it is written. Expert determination and limited data sets are not used. We do not keep a key that could put the identifiers back.

  1. Names
  2. Places smaller than a state (street, city, county, 5-digit ZIP)
  3. Dates except year, and ages 90+
  4. Phone numbers
  5. Fax numbers
  6. Email addresses
  7. Social Security numbers
  8. Medical record numbers
  9. Health plan / Medicare Beneficiary Identifiers
  10. Account numbers
  11. Certificate and license numbers
  12. Vehicle identifiers and plates
  13. Device identifiers and serial numbers
  14. Web URLs
  15. IP addresses
  16. Biometrics, including voiceprints — we do not keep audio
  17. Full-face photographs
  18. Any other unique identifying number or code — no re-identification key

You may share

  • Name, phone, email, zip, and a callback window
  • Doctors you want to keep — if you type them
  • Medication names — if you type them
  • Budget comfort and notes you choose to share

Never on this site

  • Social Security numbers
  • Medicare numbers (the number on the red, white, and blue card)
  • Bank accounts or payment cards
  • Uploaded medical records, lab PDFs, or images of insurance cards

Control map

Each row is something this product actually does. If a row would be theater, it is not on this list.

ControlWhereProof

No Medicare number or SSN fields

45 CFR 164.502(b) · minimum necessary

Public forms, portal file, BRIDGEt widgetThose inputs do not exist. Free-text is scanned and rejected if it looks like an SSN or Medicare Beneficiary Identifier.

BRIDGEt cannot see the needs file

45 CFR 164.514 · de-identification / minimum necessary

Widget + /bridgetLive chat does not open your portal or needs file. Doctor and medication names you type into a form stay with INSUREitALL. If anything is later used to train BRIDGEt or improve the product, it is only de-identified or aggregated under the design-partner license — never SSN or Medicare numbers.

Safe Harbor strip before training

45 CFR 164.514(b)(2) · Safe Harbor

BRIDGEt voice transcriptIndividual-level text is stored only after the 18 identifiers in 45 CFR 164.514(b)(2) are removed. Audio is never stored (voiceprints are identifiers). 5-digit ZIP is reduced to 3 digits, or dropped if the area is under 20,000 people. Ages 90+ are grouped. No re-identification key is kept.

Staff desk is team-email only

45 CFR 164.312(a) · access control

/consoleOnly signed-in users on team-iia.com, insureitallins.com, insureitall-llc.com, or insureitall.com. Outside agents cannot open the lead desk.

A consumer sees only their own file

45 CFR 164.312(a) · unique user identification

/portalPortal reads and writes are keyed to the signed-in account. Share codes are revocable and open only inside the INSUREitALL ops workspace.

Cross-site session riding is blocked

45 CFR 164.312(e) · transmission security

Server functionsScripted cross-site requests are rejected. Session cookies are not usable from a sibling site.

Encryption in transit

45 CFR 164.312(e) · encryption

Production HTTPSThe live site is served over TLS. Security headers include nosniff and a strict referrer policy. We do not frame-lock the page (preview and partner embeds).

TCPA consent is enforced on the server

Administrative · intake integrity

/lead · /needs-analysisA checkbox is not enough. The server refuses the lead unless consent is true. Honeypots are dropped. Submits are rate-limited.

We do not sell PHI

45 CFR 164.502 · uses and disclosures

Privacy PolicyOptional doctor and medication names are used so a licensed agent can prepare. They are not sold. They are not emailed in lead alerts. Training or product improvement uses de-identified or aggregated data only. See the GLBA notice.

Who can see it

  • You, in your portal file, after you sign in.
  • Licensed INSUREitALL team members on the staff desk, so they can call you back.
  • BRIDGEt and the site: health information used to train or improve the site moves only to a contracted service provider, as de-identified data, or with your authorization. Live chat still cannot open your file.
  • A carrier, if you ask us to enroll or to work a claim — not because you typed a form.
  • Vendors who process communications for us, under agreements that limit their use. We execute a Business Associate Agreement before a vendor creates, receives, maintains, or transmits PHI for us.

BRIDGEt cannot open your file. Outside agents and agencies cannot open the staff desk.

Your rights

See it

Ask for a copy of the file we hold on you (portal record or lead request).

Fix it

Tell us what is wrong. We will correct it or note the dispute.

Delete it

Email or call and we will delete the portal account and lead file we control, unless a carrier or law requires a retention copy.

Limit it

You may send a needs analysis with zip and phone only. Doctor and medication fields are optional.

If something goes wrong

If unsecured PHI is breached, we will investigate and notify you and HHS as HIPAA requires — without unreasonable delay and no later than 60 days after we discover it. Call or email the Privacy Official the same day you think something is wrong.

Full legal terms for what we collect live in the Privacy Policy. How we share nonpublic personal information lives in the GLBA Privacy Notice. How the advocate is walled off lives in the AI Disclosure. The written security program and BAA policy live in Information Security.

Last reviewed August 25, 2026. 3550 Buschwood Park Dr, Ste 180, Tampa, FL 33618.

INSUREitALL — Insurance Made Easy

INSUREitALL LLC is a licensed Medicare insurance agency helping people understand their coverage options.

NPN: 20114179

Contact

+1 908-827-6223

Mon–Fri 9am–6pm ET · TTY 711

By calling, you will be connected to a licensed insurance agent. Calls are recorded and monitored for quality, training, and compliance.

info@team-iia.com

3550 Buschwood Park Dr
Ste 180
Tampa, FL 33618

Legal

We do not offer every plan available in your area. Currently we represent 14 organizations which offer 14 products in your area. Any information we provide is limited to those plans we do offer in your area. Please contact Medicare.gov, 1-800-MEDICARE, or your local State Health Insurance Program (SHIP) to get information on all of your options.

Insure It All is not connected with or endorsed by the U.S. Government or the federal Medicare program.

Privacy PolicyHIPAA & PHIGLBA Privacy NoticeInformation SecurityTerms of UseAI DisclosureAccessibility

Licensed in 41 states: AK, AL, AR, AZ, CO, CT, FL, GA, HI, IA, ID, IL, IN, KS, KY, LA, MD, ME, MI, MN, MO, MS, MT, NC, ND, NE, NH, NJ, OH, OK, PA, RI, SC, SD, TN, TX, UT, VA, VT, WA, WY

© 2026 INSUREitALL LLC. All rights reserved.

Team Login