Privacy
Policy
How we collect, use, protect, and handle your information.
Effective Date: January 1, 2026 | Last Updated: January 24, 2026
TABLE OF CONTENTS
1. Introduction
Integrus Group LLC ("Integrus," "we," "us," or "our") is committed to protecting the privacy and security of your personal information. This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you use our MHCP Revalidation Support Services or visit our website at www.integrusgroup.com.
By using our Services or submitting information through our website, you consent to the practices described in this Privacy Policy. If you do not agree with this Privacy Policy, please do not use our Services.
2. Information We Collect
2.1 Information You Provide Directly
When you engage our Services, we collect the following categories of information:
| Category | Types of Data | Purpose |
|---|---|---|
| Business Information | Legal business name, DBA, FEIN, NPI, service addresses, phone numbers, email addresses | MPSE portal submission, account setup |
| Owner/Operator Information | Full legal names, Social Security Numbers (SSN), dates of birth (DOB), ownership percentages | DHS-required disclosure for owners with 5%+ interest |
| Credential Information | Training certificates, licenses, background study status, Waiver Provider 101 completion | Verification of enrollment eligibility |
| Insurance Information | Certificate of Liability Insurance (COI), policy numbers, coverage dates, carrier information | DHS compliance verification |
| Financial Information | EFT details, Supplier ID, Location Code, bank account information (for DHS payments) | MPSE portal submission |
| Portal Credentials | MN-ITS username and password (if provided), secondary user credentials | Portal access for revalidation submission |
| Payment Information | Credit card number, billing address (processed by third-party payment processor) | Service fee payment |
2.2 Information We Collect Automatically
When you visit our website, we automatically collect:
- IP address and approximate geographic location
- Browser type and version
- Device type and operating system
- Pages viewed and time spent on pages
- Referring website or source
- Date and time of visits
2.3 Information from Third Parties
We may receive information from:
- MN-ITS/MPSE Portal: Existing enrollment data when we access your account with your authorization
- Payment Processors: Transaction confirmation and fraud prevention data
- Public Records: Verification of business registration and licensing status
3. How We Use Your Information
3.1 Primary Service Purposes
We use your information to:
- Prepare and submit your MHCP revalidation application via the MPSE portal
- Verify the accuracy and completeness of your enrollment data
- Cross-reference credentials against DHS requirements
- Respond to Requests for More Information from DHS
- Communicate with you about your revalidation status
- Process payments and send invoices
3.2 Operational Purposes
We also use your information to:
- Improve our Services and develop new offerings
- Analyze usage patterns and website performance
- Prevent fraud and ensure security
- Comply with legal obligations
- Enforce our Terms of Service
- Sell your personal information to third parties
- Use your information for marketing unrelated products or services
- Share your information with other healthcare providers
- Use your SSN or DOB for any purpose other than DHS submissions
4. How We Share Your Information
4.1 Authorized Disclosures
We share your information only in the following circumstances:
| Recipient | Information Shared | Purpose |
|---|---|---|
| Minnesota DHS | All enrollment and owner data | Revalidation submission (at your direction) |
| Payment Processor (Stripe) | Payment card information | Process service fees |
| Cloud Service Providers | Encrypted data storage | Secure data hosting |
| Professional Advisors | As required | Legal, accounting, or audit services |
4.2 Legal Requirements
We may disclose your information if required by law, court order, or government request, or if we believe disclosure is necessary to:
- Comply with applicable laws or legal processes
- Protect the rights, property, or safety of Integrus Group, our clients, or others
- Investigate potential violations of our Terms of Service
- Respond to claims that content violates the rights of third parties
4.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity. We will provide notice before your information becomes subject to a different privacy policy.
5. Data Security
5.1 Technical Safeguards
- Encryption: All data transmitted to and from our systems is encrypted using TLS 1.3
- Storage Encryption: Sensitive data is encrypted at rest using AES-256 encryption
- Access Controls: Role-based access controls limit data access to authorized personnel only
- Multi-Factor Authentication: Required for all internal system access
- Regular Security Audits: Periodic vulnerability assessments and penetration testing
5.2 Administrative Safeguards
- Employee Training: All staff receive training on data handling and privacy requirements
- Background Checks: Employees with access to PII undergo background screening
- Confidentiality Agreements: All employees sign confidentiality and non-disclosure agreements
- Incident Response Plan: Documented procedures for responding to security incidents
5.3 Physical Safeguards
- Secure office facilities with controlled access
- Clean desk policy for physical documents
- Secure document destruction procedures
6. Data Retention
6.1 Retention Periods
| Data Category | Retention Period | Rationale |
|---|---|---|
| Engagement Records | 7 years from completion | Legal and regulatory requirements |
| Submission Confirmations | 7 years from submission | Proof of service delivery |
| Portal Credentials | Deleted within 30 days of engagement completion | Minimization of access risk |
| SSN/DOB Data | Deleted within 90 days of submission | Minimization of PII exposure |
| Payment Records | 7 years | Tax and accounting requirements |
| Website Analytics | 26 months | Standard analytics retention |
6.2 Deletion Requests
You may request deletion of your personal information, subject to our legal retention obligations. See Section 8 (Your Rights) for details.
7. Sensitive Personal Information (PII)
7.1 Collection Limitations
We collect SSNs and DOBs only when required for DHS revalidation submissions. This information is necessary because DHS mandates disclosure of all owners with 5% or greater ownership interest.
7.2 Processing Restrictions
- Local Processing: SSNs and DOBs are processed locally on secure systems and are never transmitted to third-party AI or cloud processing services
- Limited Access: Only essential personnel have access to SSN/DOB data
- No Logging: SSNs are not included in system logs or error reports
- Masked Display: SSNs are displayed only as last 4 digits in internal systems after initial entry
7.3 Breach Notification
In the event of a data breach involving SSNs or other sensitive PII, we will:
- Notify affected individuals within 72 hours of discovery
- Report to applicable regulatory authorities as required by Minnesota law
- Provide information about protective measures and resources
- Offer credit monitoring services for affected individuals
8. Your Rights
8.1 Access & Portability
You have the right to:
- Request a copy of the personal information we hold about you
- Receive your data in a commonly used, machine-readable format
- Know what categories of information we have collected
8.2 Correction
You have the right to request correction of inaccurate personal information. Note that corrections to data already submitted to DHS may require a formal amendment process.
8.3 Deletion
You may request deletion of your personal information, subject to the following exceptions:
- Data required for legal or regulatory compliance
- Data necessary to complete a transaction or provide requested services
- Data required for our legitimate business interests (e.g., fraud prevention)
8.4 Opt-Out
You may opt out of:
- Marketing communications (email preference center or unsubscribe link)
- Non-essential cookies (via browser settings or our cookie banner)
8.5 Exercising Your Rights
To exercise any of these rights, contact us at:
- Email: privacy@integrusgroup.com
- Subject Line: "Privacy Rights Request"
We will respond to verified requests within 45 days.
9. Third-Party Services
9.1 Service Providers
We use the following third-party services:
| Service | Provider | Purpose |
|---|---|---|
| Payment Processing | Stripe, Inc. | Credit card processing |
| Google Workspace | Business email communications | |
| Forms | Tally.so | Intake form collection |
| Analytics | Google Analytics | Website usage analysis |
| Cloud Hosting | Amazon Web Services / Google Cloud | Secure data storage |
9.2 Third-Party Links
Our website may contain links to third-party websites (e.g., DHS, MN-ITS). We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies.
10. Cookies & Tracking
10.1 Types of Cookies
- Essential Cookies: Required for website functionality (session management, security)
- Analytics Cookies: Help us understand how visitors interact with our website
- Preference Cookies: Remember your settings and choices
10.2 Managing Cookies
You can control cookies through:
- Browser settings (most browsers allow you to block or delete cookies)
- Our cookie consent banner (where applicable)
- Opt-out tools provided by analytics providers
10.3 Do Not Track
We do not currently respond to "Do Not Track" browser signals. However, you can opt out of analytics tracking using the methods described above.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be effective when posted to our website. We will indicate the "Last Updated" date at the top of this page.
For material changes that significantly affect how we handle your personal information, we will provide notice through:
- Email notification to active clients
- Prominent notice on our website
Your continued use of our Services after changes are posted constitutes acceptance of the updated Privacy Policy.
12. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us:
Integrus Group LLC
Privacy Inquiries
Minneapolis, Minnesota
Email: privacy@integrusgroup.com
Website: www.integrusgroup.com
By using Integrus Group's services, you acknowledge that you have read and understood this Privacy Policy.