HIPAA & Patient Data
Last updated: August 25, 2026 — For MG Medical Transport LLC, 1205 Golden Eagle St, Pflugerville, TX 78660
MG Medical Transport handles ride, mobility, accessibility, contact, and coordination information that may be sensitive. We use privacy-conscious practices to limit unnecessary sharing and support secure transportation coordination — adapted from marketplace best practices to our direct-carrier operations.
1. When HIPAA May Apply
HIPAA applies to covered health plans, health care clearinghouses, certain health care providers, and their business associates. MG’s status depends on the relationship and service. We are not automatically a HIPAA-covered entity merely because a request relates to health care or contains mobility information.
If MG performs services on behalf of a HIPAA-covered entity that requires us to create, receive, maintain, or transmit protected health information (PHI), a Business Associate Agreement (BAA) and additional safeguards are required. We must not represent that a BAA relationship exists unless an appropriate agreement has been executed.
2. Consumer-Submitted Requests
When a patient, family member, or caregiver independently submits a private-pay transportation request to MG (by phone at (512) 669-3225 or web form), HIPAA may not govern MG in the same way it governs a covered health care provider or health plan. Other privacy, consumer-protection, contract, security, and Texas data-protection laws still apply, and we treat that information as confidential and ride-necessary only.
3. How MG Handles Ride Information
We aim to:
- Collect only information reasonably relevant to the ride (route, timing, mobility, equipment, stairs, contact).
- Avoid requesting unnecessary clinical records — we do not need full charts to dispatch a van.
- Share ride details only with staff/drivers who need them for that specific trip, plus payment processor for card handling.
- Restrict internal access by operational need and require confidentiality for patient information.
- Not use patient ride information for unrelated marketing or sale.
- Maintain reasonable security (access controls, audit logs, rate limits) and operational controls.
Passenger contact details are used for ride coordination and confirmations (SMS/email if provided). We do not sell contact lists.
4. Privacy Controls & Related Pages
- Clear identity: MG Medical Transport LLC, 1205 Golden Eagle St, Pflugerville, TX 78660, info@mgmedicaltransport.com. See Terms & Conditions.
- Direct carrier boundary: MG operates vehicles/drivers ourselves for ambulatory & wheelchair NEMT. For stretcher/ambulance we refer — those providers remain responsible for their licensing, insurance, and services.
- Privacy choices: See Privacy Policy for cookies, analytics (default denied unless you allow), and how to manage preferences.
- Data rights: Request access, correction, deletion, portability via info@mgmedicaltransport.com with subject “Data Rights Request” — see Privacy → Your Rights.
- Retention: Baseline categories described below; legal-hold and approval steps before deletion.
- Security: Admin/session controls, role-based permissions, and access logs support privacy operations.
5. Independent & Vendor Handling
When MG refers a stretcher trip to an independent carrier, that carrier is responsible for using request information only for that transportation, payment, safety, or legal purpose and for its own HIPAA/privacy obligations if applicable. Core vendors (e.g., email delivery, payment processor) receive only what is needed for their function and are contractually limited to that purpose.
6. Facilities & Covered Entities
A hospital, clinic, nursing facility, dialysis center, or health plan that wants MG to process PHI on its behalf should contact us before transmitting PHI so we can determine whether a BAA or other data-processing agreement is required. Do not send PHI through the general web form until that agreement is in place. Call (512) 669-3225 to coordinate.
7. Covered-Entity Workflow (Only via Written Arrangement)
When a BAA is executed, MG routes PHI only through approved channels:
- Confirm covered-entity / business-associate status and execute BAA before receiving PHI.
- Route PHI only through vendors/communication channels approved for that workflow.
- Disable non-essential analytics/advertising/non-BAA processing for that PHI.
- Limit email/SMS/voice content to minimum necessary.
- Document retention, confidentiality, and incident-reporting obligations.
- Maintain access, audit, retention, deletion, and incident-response evidence.
8. Retention & Deletion
- Ride records: Kept while needed for service completion, payment/dispute, safety, and compliance; then eligible for deletion/redaction per review.
- Marketing/analytics opts: Per your choices, with Global Privacy Control honored where applicable.
- Legal holds: Override scheduled deletion until hold released.
Deletion runs use approval steps — we do not bulk-purge without review.
9. Your Rights & Questions
For privacy or data questions, email info@mgmedicaltransport.com or call (512) 669-3225. Include “Privacy Request” in subject and describe the information you’d like reviewed. We review reasonable correction requests based on information reasonably available.
Educational content only — not legal advice. For benefits/eligibility confirm with your plan; for emergencies call 911.
Ready to Book Your Medical Transportation?


