medlitix Privacy Notice

Last Updated: 5/28/2026

This notice explains how medlitix collects, uses, and protects your information when you use our website or submit information to us. We’ve kept it in plain language. If you have questions, contact us at the information at the bottom.

Who we are

medlitix is a URAC-accredited Independent Review Organization (IRO). We provide independent medical reviews and related services to insurance carriers, health plans, third-party administrators, pharmacy benefit managers, government agencies, and individuals. Our service lines include workers’ compensation, commercial health plans, pharmacy and PBM, auto and liability, disability, and Veteran Nexus letters.

What information we collect

From insurance reviews and clinical determinations, we receive medical records, claims information, and supporting documentation from the entity referring the case (the carrier, plan, TPA, or government agency). This is provided to us under a Business Associate Agreement (BAA) or equivalent contract.
From individuals using our intake forms (such as the Veteran Nexus intake), we collect what you provide directly:

  • Identifying information: name, date of birth, mailing address, phone, email
  • Information about your case: representation status, claimed conditions, diagnoses, records status
  • Acknowledgments and your electronic signature
  • Technical information about your visit (browser type, IP address) collected automatically by standard web tools

We do not collect Social Security numbers, financial account numbers, or payment information through our public-facing intake forms.

How we use your information

We use what you give us to:

  • Evaluate whether we can help with your request
  • Coordinate with your representative (attorney, claims agent, or VSO) when you’ve given us permission
  • Communicate with you about your case
  • Conduct the medical or clinical review you or your referring entity has requested
  • Meet legal, regulatory, and accreditation requirements (URAC, state Department of Insurance, federal IDR program, etc.)
  • Maintain the security and integrity of our systems

We do not sell your information. We do not use your health information for advertising or marketing.

Who we share it with

We share information only when necessary to do the work you’ve asked us to do or when the law requires it:

  • Our clinical reviewers (board-certified physicians and pharmacists) who evaluate your case
  • Your representative, if you’ve given us permission to coordinate with them
  • The referring entity (insurance carrier, health plan, government agency) when our review is performed on their behalf
  • Our service providers (cloud hosting, secure file transfer, communication tools) under written agreements that require them to protect your information
  • Government agencies and accreditors when required by law or as part of regulatory oversight

We do not share your information with third parties for their own marketing purposes.

How long we keep it

We keep information as long as needed to complete the work, meet legal and accreditation requirements, and resolve any disputes. Medical review records are typically retained for a minimum of seven years, or longer when required by state law or contract.

How we protect it

We use industry-standard security measures, including:

  • Encrypted connections (HTTPS/TLS) for all data submitted through our website
  • Encrypted storage for sensitive information
  • Access controls so only authorized staff can view your records
  • Business Associate Agreements with all vendors handling protected health information
  • Regular security reviews and staff training

No system is completely immune to risk, but we take our responsibility to protect your information seriously and follow HIPAA Security Rule standards where applicable.

Your rights

Depending on your situation and the laws that apply to you, you may have the right to:

  • Access the health information we hold about you
  • Request corrections to information you believe is inaccurate
  • Request a copy of disclosures we’ve made about your information
  • Restrict certain uses or disclosures
  • File a complaint if you believe your privacy rights have been violated

Veterans whose information we hold in connection with a nexus letter request can ask us to release their records to them, their representative, or the VA. Send requests in writing to the contact at the bottom of this notice.

For HIPAA-related complaints, you may also file with the U.S. Department of Health and Human Services Office for Civil Rights. We will not retaliate against anyone for filing a complaint.

Cookies and analytics

Our website uses standard cookies and analytics tools to understand how visitors use the site and to improve it. This information is used in aggregate and is not tied to your medical information. You can disable cookies in your browser settings; some site features may not work without them.

Children's privacy

Our website and services are not directed at children under 13, and we do not knowingly collect personal information from children under 13.

Changes to this notice

We may update this notice from time to time. The “Last updated” date at the top will reflect the most recent change. Material changes will be posted on this page.

Contact us

If you have questions, want to exercise any of the rights above, or need to file a privacy complaint:

medlitix

Email: reviews@mlxiro.com | Phone: 855.323.3654

This notice describes our general privacy practices. It is not a substitute for the formal HIPAA Notice of Privacy Practices that applies when medlitix operates as a HIPAA Covered Entity or Business Associate for a specific engagement. If you’d like a copy of our formal Notice of Privacy Practices, contact us at the information above.