Our Commitment to Your Privacy
Generative Health Consulting LLCÂ
Effective Date: June 21, 2025Â
Last Updated: June 21, 2025Â
- IDENTIFICATION AND CONTACT INFORMATIONÂ
Data ControllerÂ
Company Name: Generative Health Consulting LLCÂ
Owner/Data Protection Officer: Tom RichardsÂ
Address: 26 Spear Street, NJ 08840Â
Email: tom@genhealthconsult.aiÂ
Phone: (908) 337-5164
Data Protection Officer (DPO)Â
For all privacy-related matters, inquiries, or to exercise your rights under this Privacy Policy, please contact:Â
Tom RichardsÂ
Email: tom@genhealthconsult.aiÂ
Phone: (908) 337-5164
- PURPOSES OF PROCESSINGÂ
Generative Health Consulting LLC processes personal information for the following specific purposes:Â
2.1 Consulting ServicesÂ
- Engaging consultants and healthcare professionals for specific consulting services
- Managing ongoing consulting relationships and contractual obligationsÂ
- Providing strategic healthcare consulting, regulatory compliance guidance, and business advisory services
- Facilitating communication and project management between partiesÂ
2.2 Research and DevelopmentÂ
- Conducting healthcare market research and data analysisÂ
- Supporting clinical research and scientific collaborationsÂ
- Developing healthcare insights and industry reportsÂ
- Analyzing healthcare trends and regulatory developmentsÂ
2.3 Compliance and Legal ObligationsÂ
- Meeting legal and regulatory requirements under HIPAA, New Jersey Privacy Act (NJPA), and other applicable lawsÂ
- Conducting transparency reporting and adverse event reporting as required
- Maintaining records for audit and inspection purposesÂ
- Ensuring compliance with healthcare industry standards and certificationsÂ
2.4 Business OperationsÂ
- Internal reporting and business development activitiesÂ
- Financial management and payment processingÂ
- Marketing our services to potential clientsÂ
- Maintaining business relationships with partners and vendorsÂ
- CATEGORIES OF PERSONAL DATA COLLECTEDÂ
3.1 Identifying InformationÂ
- Name, title, and professional credentialsÂ
- Contact details (business address, phone number, email address)Â
- Professional registration numbers and licensing informationÂ
- Company affiliation and job function
- Professional qualifications and certificationsÂ
3.2 Financial InformationÂ
- Bank account details for payment purposes (when providing consulting services)
- Billing addresses and payment informationÂ
- Tax identification numbers for contractor paymentsÂ
- Invoice and payment historyÂ
3.3 Consulting-Related DataÂ
- Information about consultant expertise, experience, and specializations
- Work product and deliverables from consulting engagementsÂ
- Performance evaluations and feedbackÂ
- Project documentation and communicationsÂ
- Intellectual property and proprietary information related to consulting workÂ
3.4 Communication DataÂ
- Email correspondence and other written communicationsÂ
- Meeting notes and call logsÂ
- Documentation of consulting agreements and contractsÂ
- Any information provided during the consulting relationshipÂ
3.5 Technical Information (Website Visitors)Â
- IP addresses and device informationÂ
- Browser type and operating systemÂ
- Website usage data and analyticsÂ
- Cookies and similar tracking technologiesÂ
- LEGAL BASIS FOR PROCESSING
4.1 Contractual NecessityÂ
Processing is necessary for the performance of consulting agreements and to fulfill our contractual obligations to clients and consultants.Â
4.2 Legitimate InterestsÂ
We process personal data based on our legitimate business interests, including:Â
- Providing high-quality healthcare consulting servicesÂ
- Maintaining professional relationshipsÂ
- Improving our services and operationsÂ
- Protecting our business interests and intellectual propertyÂ
We have balanced these interests against individuals' privacy rights and determined that our processing does not override those rights.Â
4.3 Legal ObligationsÂ
We process personal data to comply with legal requirements, including:Â
- HIPAA Privacy and Security Rules (when acting as a Business Associate)Â
- New Jersey Privacy Act (NJPA) requirementsÂ
- Tax and financial reporting obligationsÂ
- Healthcare industry regulatory requirementsÂ
- Anti-money laundering and fraud prevention lawsÂ
4.4 ConsentÂ
For certain specific processing activities, we may rely on explicit consent, particularly for:Â
- Marketing communicationsÂ
- Use of sensitive personal information beyond what is necessary for our services
- International data transfers where requiredÂ
- DATA SHARING AND DISCLOSURE
5.1 Internal UseÂ
Personal information may be shared within Generative Health Consulting LLC for the purposes outlined in this policy. As a sole proprietorship, this is limited to the owner, Tom Richards.Â
5.2 Third-Party Service ProvidersÂ
We may share personal information with trusted third-party service providers who assist us in operating our business, including:Â
- Cloud storage and computing providers (with appropriate safeguards)Â
- Payment processors and financial institutionsÂ
- IT support and cybersecurity servicesÂ
- Legal and professional advisorsÂ
- Audit and compliance service providersÂ
All third-party processors are required to maintain confidentiality and use appropriate security measures.Â
5.3 Business Associates and SubcontractorsÂ
When we act as a Business Associate under HIPAA, we may engage subcontractors who must also comply with HIPAA requirements through appropriate Business Associate Agreements.Â
5.4 Legal RequirementsÂ
We may disclose personal information when required by law, including:Â
- Responding to valid legal process (subpoenas, court orders)Â
- Reporting to regulatory authorities as requiredÂ
- Cooperating with law enforcement investigationsÂ
- Protecting our legal rights and interestsÂ
- Preventing fraud or protecting public safetyÂ
5.5 Business TransfersÂ
In the event of a business sale, merger, or acquisition, personal information may be transferred as part of the business assets, subject to appropriate confidentiality obligations.
- DATA RETENTIONÂ
6.1 Retention PeriodÂ
We retain personal data for the following periods:Â
- Consulting relationship data: For the duration of the consulting relationship plus 7 years after terminationÂ
- Financial records: 7 years from the date of the last transactionÂ
- Marketing communications: Until consent is withdrawn or 3 years of inactivity
- Website analytics: 26 months from collectionÂ
- Legal compliance records: As required by applicable law (typically 7-10 years)Â
6.2 Data DeletionÂ
After the retention period expires, we will securely delete or anonymize personal data unless:Â
- Legal obligations require longer retentionÂ
- The data is needed for legitimate business purposesÂ
- You have specifically consented to longer retentionÂ
- YOUR RIGHTSÂ
Under the New Jersey Privacy Act (NJPA), HIPAA (where applicable), and other privacy laws, you have the following rights:Â
7.1 Right to AccessÂ
You may request access to the personal data we hold about you, including:Â
- Categories of personal data processedÂ
- Purposes of processingÂ
- Recipients of the data
- Retention periodsÂ
7.2 Right to RectificationÂ
You may request correction of inaccurate or incomplete personal data.Â
7.3 Right to Erasure (Right to be Forgotten)Â
You may request deletion of your personal data under certain circumstances:Â
- The data is no longer necessary for the original purposeÂ
- You withdraw consent (where consent was the legal basis)Â
- The data has been unlawfully processedÂ
- Legal obligations require erasureÂ
7.4 Right to Restrict ProcessingÂ
You may request that we limit how we process your personal data in certain situations:Â
- You contest the accuracy of the dataÂ
- Processing is unlawful but you don't want erasureÂ
- We no longer need the data but you need it for legal claimsÂ
7.5 Right to Data PortabilityÂ
You may request a copy of your personal data in a structured, commonly used, and machine-readable format for transfer to another organization.Â
7.6 Right to ObjectÂ
You may object to processing based on legitimate interests, including for direct marketing purposes.Â
7.7 Right to Withdraw ConsentÂ
Where consent is the legal basis for processing, you may withdraw your consent at any time without affecting the lawfulness of processing before withdrawal.Â
7.8 Right to Opt-OutÂ
Under the NJPA, you have the right to opt-out of:
- Targeted advertisingÂ
- Sale of personal dataÂ
- Profiling in furtherance of decisions that produce legal or similarly significant effectsÂ
To exercise any of these rights, contact us at tom@genhealthconsult.ai or (908) 337-5164. We will respond within 30 days.Â
- SECURITY MEASURESÂ
We implement appropriate technical and organizational security measures to protect personal information:Â
8.1 Technical SafeguardsÂ
- End-to-end encryption for data transmission and storageÂ
- Secure, password-protected systems with multi-factor authenticationÂ
- Regular security updates and patchesÂ
- Firewall and intrusion detection systemsÂ
- Secure backup and disaster recovery proceduresÂ
8.2 Administrative SafeguardsÂ
- Regular security risk assessmentsÂ
- Employee training on data protection and HIPAA complianceÂ
- Incident response and breach notification proceduresÂ
- Access controls based on job responsibilitiesÂ
- Regular review and updating of security policiesÂ
8.3 Physical SafeguardsÂ
- Secure office facilities with controlled accessÂ
- Locked filing cabinets for physical documentsÂ
- Secure disposal of confidential documents
- Workstation and device security controlsÂ
- INTERNATIONAL DATA TRANSFERSÂ
If we transfer personal data internationally, we ensure appropriate safeguards are in place:Â
- Standard Contractual Clauses approved by relevant authoritiesÂ
- Adequacy decisions by regulatory bodiesÂ
- Binding Corporate Rules where applicableÂ
- Specific consent for the transfer when requiredÂ
Currently, Generative Health Consulting LLC primarily operates within the United States and does not regularly transfer data internationally.Â
- COOKIES AND TRACKING TECHNOLOGIESÂ
Our website may use cookies and similar technologies to:Â
- Analyze website usage and improve user experienceÂ
- Remember user preferencesÂ
- Provide personalized contentÂ
- Measure the effectiveness of our marketingÂ
You can control cookie settings through your browser preferences. However, disabling cookies may affect website functionality.Â
- HIPAA BUSINESS ASSOCIATE OBLIGATIONSÂ
When Generative Health Consulting LLC acts as a Business Associate under HIPAA:Â
11.1 Permitted Uses and DisclosuresÂ
We only use and disclose Protected Health Information (PHI) as permitted by our Business Associate Agreement and HIPAA regulations.
11.2 SafeguardsÂ
We maintain appropriate administrative, physical, and technical safeguards to protect PHI in accordance with HIPAA Security Rule requirements.Â
11.3 Breach NotificationÂ
We will notify covered entities of any breach of unsecured PHI within 60 days of discovery.Â
11.4 Individual RightsÂ
We will assist covered entities in fulfilling individual rights requests related to PHI.Â
- CHILDREN'S PRIVACYÂ
Our services are directed toward healthcare professionals and organizations. We do not knowingly collect personal information from children under 13 years of age. If we become aware that we have collected such information, we will take steps to delete it promptly.Â
- CALIFORNIA PRIVACY RIGHTSÂ
For California residents, additional rights may apply under the California Consumer Privacy Act (CCPA). Please contact us for information about these rights.Â
- CHANGES TO THIS PRIVACY POLICYÂ
We may update this Privacy Policy periodically to reflect changes in our practices, legal requirements, or business operations. We will:Â
- Post the updated policy on our websiteÂ
- Update the "Last Updated" dateÂ
- Notify affected individuals of material changes when required by law
- COMPLAINTS AND REGULATORY CONTACTÂ
If you have concerns about our privacy practices, you may:Â
Contact us directly:Â
Tom RichardsÂ
Email: tom@genhealthconsult.aiÂ
Phone: (908) 337-5164
File a complaint with regulatory authorities:Â
- HIPAA complaints: U.S. Department of Health and Human Services, Office for Civil Rights • New Jersey Privacy Act: New Jersey Division of Consumer AffairsÂ
- General privacy concerns: Federal Trade CommissionÂ
- CONTACT INFORMATIONÂ
For questions about this Privacy Policy or our privacy practices:Â
Generative Health Consulting LLCÂ
Tom Richards, Owner/Data Protection OfficerÂ
26 Spear StreetÂ
NJ 08840Â
Email: tom@genhealthconsult.aiÂ
Phone: (908) 337-5164
This Privacy Policy is effective as of June 21, 2025, and governs the collection, use, and disclosure of personal information by Generative Health Consulting LLC.