See it
Ask for a copy of the file we hold on you (portal record or lead request).
Licensed agents available — Mon–Fri 9am–6pm ET
+1 908-827-6223HIPAA · PHI
There is no HIPAA certificate. This page is the public proof of the controls in this product — what we collect, who can see it, and what we refuse.
INSUREitALL LLC is a licensed Medicare insurance agency. We are not Medicare, CMS, or a health plan. Optional doctor names and medication names you type so a licensed agent can prepare are treated as protected health information in this product. They stay with INSUREitALL (staff desk and your portal). They are not emailed in lead alerts. artificialBRIDGE does not receive identifiable health details for training — only de-identified or aggregated data. We never collect SSN or Medicare numbers on this site.
We do not claim a HIPAA “certification” — none exists. We claim the controls below, which you can inspect on this site.
If a BRIDGEt conversation is kept for product improvement, it is text only. Audio is never stored. Each turn is run through HIPAA Safe Harbor (45 CFR 164.514(b)(2)) before it is written. Expert determination and limited data sets are not used. We do not keep a key that could put the identifiers back.
Each row is something this product actually does. If a row would be theater, it is not on this list.
| Control | Where | Proof |
|---|---|---|
No Medicare number or SSN fields 45 CFR 164.502(b) · minimum necessary | Public forms, portal file, BRIDGEt widget | Those inputs do not exist. Free-text is scanned and rejected if it looks like an SSN or Medicare Beneficiary Identifier. |
BRIDGEt cannot see the needs file 45 CFR 164.514 · de-identification / minimum necessary | Widget + /bridget | Live chat does not open your portal or needs file. Doctor and medication names you type into a form stay with INSUREitALL. If anything is later used to train BRIDGEt or improve the product, it is only de-identified or aggregated under the design-partner license — never SSN or Medicare numbers. |
Safe Harbor strip before training 45 CFR 164.514(b)(2) · Safe Harbor | BRIDGEt voice transcript | Individual-level text is stored only after the 18 identifiers in 45 CFR 164.514(b)(2) are removed. Audio is never stored (voiceprints are identifiers). 5-digit ZIP is reduced to 3 digits, or dropped if the area is under 20,000 people. Ages 90+ are grouped. No re-identification key is kept. |
Staff desk is team-email only 45 CFR 164.312(a) · access control | /console | Only signed-in users on team-iia.com, insureitallins.com, insureitall-llc.com, or insureitall.com. Outside agents cannot open the lead desk. |
A consumer sees only their own file 45 CFR 164.312(a) · unique user identification | /portal | Portal reads and writes are keyed to the signed-in account. Share codes are revocable and open only inside the INSUREitALL ops workspace. |
Cross-site session riding is blocked 45 CFR 164.312(e) · transmission security | Server functions | Scripted cross-site requests are rejected. Session cookies are not usable from a sibling site. |
Encryption in transit 45 CFR 164.312(e) · encryption | Production HTTPS | The live site is served over TLS. Security headers include nosniff and a strict referrer policy. We do not frame-lock the page (preview and partner embeds). |
TCPA consent is enforced on the server Administrative · intake integrity | /lead · /needs-analysis | A checkbox is not enough. The server refuses the lead unless consent is true. Honeypots are dropped. Submits are rate-limited. |
We do not sell PHI 45 CFR 164.502 · uses and disclosures | Privacy Policy | Optional doctor and medication names are used so a licensed agent can prepare. They are not sold. They are not emailed in lead alerts. Training or product improvement uses de-identified or aggregated data only. See the GLBA notice. |
BRIDGEt cannot open your file. Outside agents and agencies cannot open the staff desk.
Ask for a copy of the file we hold on you (portal record or lead request).
Tell us what is wrong. We will correct it or note the dispute.
Email or call and we will delete the portal account and lead file we control, unless a carrier or law requires a retention copy.
You may send a needs analysis with zip and phone only. Doctor and medication fields are optional.
If unsecured PHI is breached, we will investigate and notify you and HHS as HIPAA requires — without unreasonable delay and no later than 60 days after we discover it. Call or email the Privacy Official the same day you think something is wrong.
Full legal terms for what we collect live in the Privacy Policy. How we share nonpublic personal information lives in the GLBA Privacy Notice. How the advocate is walled off lives in the AI Disclosure. The written security program and BAA policy live in Information Security.
Last reviewed August 25, 2026. 3550 Buschwood Park Dr, Ste 180, Tampa, FL 33618.