Your Data, Our Responsibility
Last updated: June 2026. We are committed to protecting the privacy and security of your facility's data and patient information.
HIPAA Compliance
Beacon Admit is designed for behavioral health facilities and adheres to HIPAA Privacy and Security Rules. We only process Protected Health Information (PHI) that is voluntarily shared during calls, and we maintain it solely for intake routing purposes. All PHI is encrypted in transit (TLS 1.3) and at rest (AES-256). We sign Business Associate Agreements (BAAs) with all customers and never use PHI for training or marketing purposes.
Data We Collect
- Call Metadata: Timestamps, duration, caller ID (when provided), call outcome (transferred, voicemail, etc.)
- Intake Information: Information voluntarily shared by callers including names, dates of birth, insurance details, and treatment needs. This data is processed solely for intake coordination and is never permanently stored beyond the retention period in your plan.
- Account Data: Facility name, contact information, staff credentials, and configuration settings necessary for service provision.
- Usage Analytics: Aggregate metrics on call volume, duration, and system performance to improve our service quality.
How We Use Your Data
- To provide and maintain the Beacon Admit service
- To route calls to appropriate staff members via warm transfer protocols
- To generate reports and analytics for facility management
- To communicate about service updates and support
- To comply with legal and regulatory obligations
Data Sharing and Disclosure
We do not sell, rent, or share your data with third parties except as follows:
- Service Providers: Infrastructure partners (AWS, database providers) who are bound by strict confidentiality and security requirements.
- Legal Compliance: When required by law, subpoena, or to protect rights and safety.
- Business Transfers: In the event of a merger or acquisition, with appropriate safeguards maintained.
Data Retention and Deletion
Call logs and intake data are retained according to your subscription plan: 7 days (Starter), 30 days (Growth), or 90 days (Enterprise). Upon request or account termination, we securely delete all data within 30 days. Facilities may request earlier deletion or export of their data at any time by contacting support.
Security Measures
We implement industry-standard security practices including:
- End-to-end encryption for all call data
- Role-based access controls for staff accounts
- Regular security audits and penetration testing
- Multi-factor authentication for administrative access
- Continuous monitoring and alerting systems
Cookies & Analytics
We use cookies and similar technologies to operate and improve our website:
- Essential Cookies: Required for authentication, session management, and security. These cannot be disabled.
- Analytics (Vercel Analytics): We use Vercel Analytics to understand page views and site performance. This is privacy-friendly, cookie-free, and does not track individual users or store personal data.
- No Third-Party Advertising Cookies: We do not use advertising cookies, retargeting pixels, or sell any browsing data to third parties.
Your Rights
You may access, correct, or delete your facility's data at any time. Contact us at privacy@beaconadmit.com or call (844) 444-2442. We will respond to all requests within 30 days.
This policy applies to Beacon Admit services. By using our platform, you acknowledge you have read and understood these practices. We may update this policy periodically; significant changes will be communicated via email or in-app notification.