QuestLynk Privacy Policy
Effective and last updated: August 23, 2026
QuestLynk, LLC (“QuestLynk,” “we,” “us,” or “our”) provides medical-record retrieval, provider follow-up, record organization and indexing, missing-record review, medical-record analysis, and chronology services.
This Privacy Policy explains how we collect, use, disclose, retain, and protect information through our website, client portal, communications, and services.
By using our website or services, you acknowledge that you have reviewed this Privacy Policy.
1. Information We Collect
Depending on how you interact with QuestLynk, we may collect:
Account information: Name, organization, job title, email address, phone number, login information, and authorized-user details.
Request information: Patient name, date of birth, contact information, case or claim number, provider information, dates of treatment, insurance information, and request status.
Medical-record information: Signed authorizations and medical, pharmacy, billing, treatment, review, and chronology information when lawfully submitted through an approved channel.
Communications: Messages, forms, documents, and other information submitted through our website, client portal, email, support requests, or other approved methods.
Billing information: Billing contacts, invoices, transaction details, and payment status. Third-party payment processors generally handle complete payment-card information.
Technical information: IP address, browser and device information, pages viewed, referring websites, cookies, login activity, and website or portal usage information.
2. Website and Client Portal Providers
QuestLynk uses third-party service providers to host and operate its website, client portal, forms, communications, payment features, analytics, file storage, and other business systems.
These providers may process information such as:
Names and contact information.
Account and login information.
Messages, forms, and uploaded files.
Billing and transaction information.
IP addresses and device information.
Website and portal activity.
Cookies and similar technologies.
These providers process information to operate, secure, maintain, support, and improve the services they provide to QuestLynk.
Third-party providers may also independently collect or process information according to their own privacy policies. QuestLynk is not responsible for the independent privacy practices of third parties it does not control.
3. Protected Health Information
Do not submit medical records, completed medical authorizations, or other protected health information (“PHI”) through QuestLynk’s public website, ordinary email, or client portal unless QuestLynk expressly identifies the submission method as approved for PHI.
When PHI is required, QuestLynk will provide approved submission instructions.
QuestLynk may process PHI only as permitted by applicable law, valid authorization, contractual requirements, and any applicable Business Associate Agreement (“BAA”).
This Privacy Policy does not replace or expand a BAA.
4. How We Use Information
QuestLynk may use information to:
Create and manage client accounts.
Provide and manage requested services.
Verify authorizations.
Submit medical-record requests.
Communicate with providers and records custodians.
Conduct provider follow-ups.
Receive, verify, organize, and index records.
Identify missing or incomplete records.
Prepare medical-record reviews and chronologies.
Communicate about requests, invoices, support, security, and service changes.
Process payments and maintain business records.
Improve our website, portal, services, and internal processes.
Prevent fraud, misuse, and unauthorized access.
Comply with contracts, laws, court orders, and other legal requirements.
QuestLynk does not use client medical records or PHI to train public artificial-intelligence models.
QuestLynk’s medical-review and chronology services are performed without generative AI unless the client separately agrees in writing to a different process.
5. How We Disclose Information
QuestLynk does not sell or rent personal information.
We may disclose information when reasonably necessary to:
Serve the client and its authorized personnel.
Communicate with healthcare providers, pharmacies, medical facilities, billing departments, records custodians, release-of-information companies, insurers, and other parties involved in an authorized request.
Work with authorized medical reviewers and contractors.
Use providers that support website hosting, client portals, communications, secure transmission, file storage, email, fax, mail, information technology, customer support, analytics, billing, and payment processing.
Comply with laws, court orders, subpoenas, regulatory requests, legal claims, fraud-prevention needs, or safety requirements.
Complete a merger, financing, reorganization, sale, or transfer of all or part of QuestLynk, subject to appropriate protections.
When required, QuestLynk uses contracts or BAAs to restrict how service providers and subcontractors may use and protect PHI.
6. Cookies and Website Analytics
QuestLynk and its website or technology providers may use:
Necessary cookies that support website and portal functions.
Security cookies that help protect accounts and systems.
Preference cookies that remember user settings.
Analytics cookies that help measure website traffic and usage.
You may limit or decline certain cookies through our cookie banner or your browser settings. However, some website or portal features may not function properly.
Third-party integrations may also use cookies according to their own privacy policies.
7. Data Retention
QuestLynk retains information only as reasonably necessary to:
Provide requested services.
Follow client instructions.
Comply with contracts and legal requirements.
Resolve disputes.
Maintain required business and accounting records.
Prevent fraud and misuse.
Protect QuestLynk’s legal rights.
Medical records and authorizations may be returned, deleted, or retained according to the applicable service agreement, BAA, client instructions, legal hold, and backup cycle.
Billing, transaction, request, account, and communication records may be retained for legal, accounting, compliance, security, and dispute-resolution purposes.
Information maintained in system backups may remain temporarily until the applicable backup cycle is completed.
8. Security and Account Responsibility
QuestLynk uses administrative, technical, and physical safeguards designed to protect personal information.
QuestLynk also uses service providers that maintain their own security controls. However, no method of electronic transmission or storage can be guaranteed to be completely secure.
Users are responsible for:
Protecting their login credentials.
Using only authorized accounts.
Limiting access to personnel with a legitimate business need.
Keeping account information accurate.
Promptly reporting suspected unauthorized access or disclosure.
QuestLynk will provide security-incident notifications when required by law or contract.
9. Privacy Rights and Choices
Depending on your location and applicable law, you may request:
Access to certain personal information.
Correction of inaccurate information.
Deletion of certain information.
A copy of certain personal information.
QuestLynk may verify your identity and authority before completing a request.
A request may be limited when information must be retained to perform a contract, comply with law, satisfy a legal hold, maintain accounting records, prevent fraud, protect legal claims, or fulfill HIPAA or contractual responsibilities.
You may unsubscribe from marketing emails using the link provided in the message. QuestLynk may still send service, billing, security, and other non-marketing communications.
10. Minors’ Records
Our website and services are not directed to children.
QuestLynk may process a minor’s records only when supported by a valid authorization, parent or guardian authority, personal-representative authority, court order, or another lawful basis provided by an authorized client.
11. Client Responsibilities
Clients are responsible for:
Having lawful authority to provide information to QuestLynk.
Providing accurate information.
Limiting submissions to information reasonably necessary for the requested service.
Using only submission methods approved for the type of information being provided.
Managing access for their authorized personnel.
Promptly notifying QuestLynk when access should be changed or removed.
QuestLynk is not responsible for the independent privacy or security practices of clients or third parties it does not control. This does not limit QuestLynk’s responsibility for its own processing of personal information.
12. Changes to This Policy
QuestLynk may update this Privacy Policy to reflect changes in its services, practices, technology providers, or legal obligations.
The updated Policy will be posted with a revised effective date. Material changes may also be communicated through the client portal, email, or another reasonable method.
13. Contact Us
Questions, privacy requests, or security concerns may be sent to:
QuestLynk, LLC
Miami, Florida 33194
Email:info@questlynk.com