Privacy Policy
Effective Date: April 23, 2026 Last Updated: April 23, 2026
This Privacy Policy describes how Just Live Clean, L.L.C. ("we," "us," or "our"), operating through imecase.com (the "Service"), collects, uses, shares, and protects information about visitors, claimants, patients, and their authorized representatives.
We are a medical-legal practice that conducts Independent Medical Examinations (IMEs), workers' compensation evaluations, personal injury evaluations, and — for a subset of individuals — ongoing clinical treatment and chronic-condition maintenance. Because we operate in both non-treating (IME) and treating (patient) capacities, this Policy addresses both contexts.
If you have questions about this Policy or our privacy practices, contact us using the information in Section 13 below.
1. Scope and Who This Applies To
This Policy applies to:
- Website visitors to imecase.com and its public pages.
- Claimants — individuals who are the subject of an IME or similar evaluation we conduct, typically referred by a third party such as an insurance adjuster, attorney, employer, or case manager.
- Patients — individuals for whom we provide clinical treatment or chronic-condition maintenance. A claimant may become a patient if the provider determines treatment is appropriate. Typical patient relationships are short treatment courses (approximately 10–20 sessions) or ongoing maintenance visits (every 3–6 months).
- Authorized representatives — family members, legal guardians, healthcare powers of attorney, and other individuals authorized by a claimant or patient to receive information about them.
- Referring parties and case contacts — insurance adjusters, attorneys, case managers, and employers who refer claimants to us or are otherwise involved in a case.
- Staff users of the Service operated on our behalf.
This Policy does not apply to third-party websites linked from our Service.
2. The Distinction Between Claimants and Patients
Because our privacy obligations differ meaningfully based on the relationship, we want to be explicit:
When you are a claimant (IME or evaluation only):
- There is no doctor-patient treatment relationship.
- There is no doctor-patient confidentiality or privilege. Statements made during the evaluation can be used in legal proceedings and are generally not protected communications.
- The results of your evaluation — including our report — will be disclosed to the referring party (the insurer, attorney, employer, or case manager who requested the evaluation). This disclosure is the purpose of the evaluation; it is not optional.
- We still treat your information as sensitive and apply the security measures described in this Policy.
When you are a patient (in treatment or maintenance with us):
- A full treating-provider relationship exists.
- We are a HIPAA-regulated Covered Entity with respect to your records, and the protections of HIPAA and the Nevada health records statutes apply.
- We will only share your information with third parties for treatment, payment, or healthcare operations ("TPO"), or with your written authorization, or when law requires or permits disclosure without authorization.
If you transition from claimant to patient (or have been both at different times), the rules applicable to each relationship apply to the information collected during that relationship.
3. Information We Collect
3.1 From You Directly
- Identifying information: name, date of birth, address, phone number, email address, Social Security Number (only when legally required for billing or reporting).
- Clinical/health information: medical history, current symptoms, test results and responses, examination findings, diagnosis, treatment notes, and related clinical documentation.
- Communication preferences: consent to SMS, email, or portal-based communication, and your election to revoke any of those.
- Authorized representatives: contact information and scope for individuals you authorize us to speak with about your care or case.
- Payment information when you pay us directly. Card data is handled by a PCI-compliant payment processor and is not stored by us.
- Signatures on intake forms, fee agreements, consent forms, and policy acknowledgments.
3.2 From Third Parties
- Referring parties (insurance companies, attorneys, case managers, employers) provide us your contact information, a description of the claim, relevant prior records, and the scope of the evaluation.
- Prior treating providers may send us medical records at the request of the referring party or with your authorization.
- Payers (insurers, responsible parties) provide claim status, remittance, and eligibility information.
- Our clearinghouse (Claim.MD) returns claim processing status.
3.3 Automatically
When you visit imecase.com or use the Service, we may automatically collect:
- IP address and approximate location.
- Device, browser, and operating system details.
- Pages viewed and actions taken, for security, troubleshooting, and to improve the Service.
- Cookies and similar technologies (see Section 9).
We do not use session-replay tools on authenticated pages in a way that captures PHI, and we do not share analytics data with third parties who have not signed a Business Associate Agreement where required.
4. How We Use Your Information
We use the information we collect to:
- Conduct the evaluation you were referred for and produce the corresponding report for the referring party (claimants).
- Provide, coordinate, and document treatment (patients).
- Schedule appointments, send reminders, and confirm attendance.
- Process billing and claims, including submission through our clearinghouse.
- Communicate with you through your preferred channels about logistics, case status, and updates.
- Verify the identity of third parties who contact us about a case, and respond appropriately.
- Operate, secure, and improve the Service, including troubleshooting, fraud prevention, and compliance with legal obligations.
- Comply with law, including responding to subpoenas, court orders, and regulatory inquiries.
5. How We Share Your Information
We share information only as described below, and never sell personal or health information.
5.1 For Claimants — Disclosures to the Referring Party
The central purpose of an IME or similar evaluation is to produce a report for the referring party. We will share:
- The evaluation report and related clinical findings.
- Testing results and scores.
- Documentation relevant to the scope of the evaluation as defined by the fee agreement.
This disclosure is the purpose of the engagement and does not require your separate authorization.
5.2 For Patients — Treatment, Payment, and Healthcare Operations (TPO)
Consistent with HIPAA, we may share your information:
- For treatment — with other providers involved in your care.
- For payment — with payers, clearinghouses, and billing agents to obtain reimbursement.
- For healthcare operations — quality improvement, care coordination, internal administration.
Other disclosures require your written authorization, except where HIPAA or other law permits or requires disclosure without authorization (for example, public-health reporting, certain law-enforcement requests, or threats to safety).
5.3 Service Providers Operating on Our Behalf
We use service providers to operate the Service. Where they handle PHI, they are bound by a Business Associate Agreement (BAA). These include:
- Amazon Web Services (AWS) — hosting, databases, file storage, transactional email (SES), and logging. AWS BAA on file.
- Claim.MD — medical billing clearinghouse. BAA on file.
- Twilio — SMS and voice transmission. We do not send protected health information in SMS messages and we do not record calls (see Section 7). Twilio is operated under the HIPAA "conduit" framework for voice transmission.
- Authorize.net — payment card processing for payments made through the Service. PCI-compliant processor.
We update this list as providers change. A current list is available on request.
5.4 Authorized Representatives and Legal Authority
- We share information with individuals whom you have designated as authorized representatives on your intake form, within the scope you specified (for example, scheduling only, case status, billing, or full access).
- We share information with individuals who have legal authority to receive it — including the parent or legal guardian of a minor, a healthcare power of attorney, a court-appointed guardian, or the executor of a deceased patient's estate — on presentation of appropriate documentation.
5.5 Legal Requirements
We may disclose information when required by law or legal process, including in response to subpoenas, court orders, regulatory inquiries, or reporting obligations (for example, mandatory reporting of abuse).
5.6 Business Transfers
If we undergo a business transition (merger, acquisition, asset transfer, reorganization), information may be transferred as part of the transaction. We will ensure any successor honors the commitments in this Policy, and we will notify you as required by law.
6. Your Rights
6.1 If You Are a Patient (HIPAA Rights)
You have the right to:
- Access a copy of your records, in paper or electronic form, consistent with HIPAA and Nevada law.
- Request amendment of information you believe is inaccurate or incomplete.
- Request an accounting of disclosures of your information we have made (other than TPO and certain other categories).
- Request restrictions on certain uses and disclosures (we will consider but are not always required to agree).
- Request confidential communications through a specific channel or at a specific location.
- Receive a copy of our Notice of Privacy Practices (NPP), which provides more detail on HIPAA rights.
- File a complaint with us or with the U.S. Department of Health and Human Services, Office for Civil Rights.
To exercise any of these rights, contact us at the information in Section 13.
6.2 If You Are a Claimant (IME only)
Claimant rights depend on the context of the evaluation and the rules of the referring forum (for example, a workers' compensation matter or litigation). You may:
- Request access to the records we maintain about you. We will provide access consistent with applicable law, which may be subject to the terms of the engagement with the referring party.
- Request correction of factually inaccurate information about you (distinct from professional opinions or findings, which are not subject to amendment).
- Contact us at the information in Section 13 with any privacy concerns.
6.3 All Individuals
You may:
- Revoke SMS or email consent at any time by replying STOP to any SMS we send, by updating your preferences in the claimant or patient portal, or by contacting us directly.
- Request deletion of non-record information (note: we are legally obligated to retain clinical records for the periods described in Section 10).
7. How We Communicate With You
We use the following channels and protections:
- SMS text messages — We use SMS for appointment reminders, confirmations, and brief logistical messages. We do not include diagnosis, treatment, or other sensitive clinical details in SMS. For anything substantive, we send a link to our secure portal. You can revoke SMS consent at any time by replying STOP.
- Voice calls — We do not record calls. Staff follows a verbal consent script at the start of any case-discussion call.
- Email — Transactional emails (confirmations, notices) may contain your own name and appointment information. We do not include clinical details about other individuals, and we do not send marketing or health content in bulk emails. Outbound email enforces TLS encryption.
- Portal — Our secure authenticated portal is the preferred channel for any substantive communication involving your health information.
- Postal mail — Used when other channels are not available or when specifically required by law.
8. Security
We apply administrative, physical, and technical safeguards designed to protect your information, including:
- Encryption of data at rest (databases, file storage) and in transit (TLS).
- Multi-factor authentication for staff accounts and session timeouts.
- Role-based access and least-privilege principles.
- Audit logging of access to sensitive records.
- Signed-URL access for files, with no public links.
- Business Associate Agreements with service providers that handle PHI.
- Staff training and written HIPAA policies.
No system is perfectly secure, and we cannot guarantee the absolute security of information transmitted to us. If we become aware of a breach affecting your information, we will notify you as required by HIPAA and applicable Nevada law.
9. Cookies and Analytics
We use limited cookies and similar technologies to:
- Keep you signed in (session cookies).
- Remember your preferences.
- Understand how the Service is used in aggregate, for security and operational purposes.
We do not use third-party advertising cookies. We do not sell cookie or browsing data. Where analytics vendors are used for authenticated pages, they are bound by a Business Associate Agreement and configured to scrub personal and health information.
You can control cookies through your browser settings. Some features of the Service may not work correctly if cookies are disabled.
10. Retention
We retain records as follows:
- Clinical records — at least five (5) years, consistent with Nevada Revised Statutes § 629.051. For records concerning minors, we retain through the age of majority plus any applicable statute of limitations. We may retain longer when federal law, a BAA, or good clinical practice requires.
- Billing and payment records — consistent with tax, regulatory, and claims-processing requirements.
- Communications and audit logs — as long as needed for compliance, incident response, and operational purposes.
- Website and operational data — for the period needed to serve its operational purpose.
When records are no longer required to be retained, we dispose of them securely.
11. Children's Privacy
We serve minors in two contexts:
- As claimants in an evaluation referred by a third party (for example, an evaluation of an injured minor); and
- As patients in treatment when a parent or guardian consents.
The Service is not directed at children as general consumers. We do not knowingly collect information from children under 13 for marketing purposes or outside the context of an evaluation or treatment arranged by a parent, guardian, or referring party.
12. Changes to This Policy
We may update this Policy from time to time. When we do, we will post the updated Policy at app.imecase.com/privacy-policy and update the "Last Updated" date. Where a change materially affects how we use your information, we will provide additional notice consistent with applicable law.
13. Contact Us
Privacy Officer — Just Live Clean Email: privacy@imecase.com Postal: 2660 South Rainbow Blvd, Unit G-110, Las Vegas, NV 89146 Phone: (725) 239-1032
To make a HIPAA-specific complaint, you may also contact: U.S. Department of Health and Human Services, Office for Civil Rights 200 Independence Avenue, SW Washington, DC 20201 https://www.hhs.gov/ocr/
Jurisdiction
This Policy is governed by the laws of the State of Nevada and applicable federal law (including HIPAA). Nothing in this Policy limits rights granted to you by law that cannot be waived.
Draft prepared for internal review. Attorney review recommended before publication. Items in brackets [ ] must be finalized before publication.