Legal
Privacy Policy.
EFFECTIVE AUGUST 15, 2026
This policy explains what Go Credentialing, a trade name of Go Medical Billing LLC, collects, why, who we share it with, and what you can ask us to do about it. It covers gocredentialing.com and our client and provider portals.
The short version: we collect what credentialing actually requires and nothing extra. We do not run advertising trackers, we do not use analytics cookies, and we do not sell personal information to anyone.
1. What we collect
Contact and account information. Name, email address, phone number, practice name, and the details you enter when you request information or create an account.
Provider credentialing information. The data payers require in order to credential a provider: legal name, National Provider Identifier, taxonomy, licenses and their numbers and expiry dates, DEA and CDS registrations, board certifications, education, five year work history, hospital affiliations and privileges, malpractice coverage and history, and any disciplinary or adverse action disclosures.
Sensitive identifiers. Social Security number and date of birth, because payer and Medicare applications require them. These fields are encrypted at rest.
Practice information. Group NPI, tax identification number, locations, authorized official, pay-to and remittance details. Tax identification numbers are encrypted at rest.
Documents you upload. Licenses, certificates of insurance, W-9s, bank letters, CVs, board certificates, and similar credentialing documents.
Third-party portal credentials. Where you ask us to work inside a payer portal, CAQH, or PECOS on your behalf, the credentials you provide. These are encrypted at rest and used only to perform the Services.
Account security data. Password hashes and, where you enable two-factor authentication, an encrypted authenticator secret.
Records of our work. Application status, correspondence with payers, notes of calls including the representative name and reference numbers, and the audit trail of changes to your records.
Communications. Emails you send us, messages in the portal, and calls to or from our phone numbers. Calls may be recorded, and where recording occurs a notice plays at the start of the call.
Basic technical data. Server logs necessary to run and secure the Site, such as IP address and request time.
2. What we do not collect
We do not use advertising pixels, analytics cookies, session recording, or cross-site trackers anywhere on this Site. The only cookies we set are the ones required to keep you signed in.
We do not seek patient information. The Services concern provider and practice business data, not patient records, and you should not upload patient charts or identifiable claims data to the portal.
3. Where the information comes from
Directly from you and from people you authorize, such as your practice administrator. From public federal sources, principally the NPPES registry maintained by CMS, which we query by NPI to prefill and verify records. From payers and agencies in the course of your applications. From federal exclusion sources during screening.
4. Why we use it
To prepare, submit, and pursue your applications. To maintain your provider and practice records and the compliance calendar that keeps them current. To screen against federal exclusion lists. To communicate with you about your work. To invoice and take payment. To secure the platform and investigate misuse. To meet our legal obligations.
We do not use your information for advertising, and we do not build profiles for marketing purposes.
5. Automated processing and AI providers
We use artificial intelligence services to read documents you upload and extract fields, to map roster spreadsheets, to draft follow-up correspondence, and to answer your questions about your own records. Document content and record context necessary for those tasks are transmitted to our AI providers, currently Groq and Anthropic, for processing.
We do not permit that content to be used to train public models, and the automated output is always reviewed before it affects an application. If you would prefer we not use automated document reading on your account, tell us and we will process your documents manually.
7. How we protect it
Encryption in transit over TLS. Encryption at rest for the sensitive fields named above, using AES-256-GCM. Access limited to the people performing your work. Portal access by unique link or by password with optional two-factor authentication, and the ability to regenerate any portal link at any time. Regular backups of the database and uploaded documents.
No system is perfectly secure. If a breach affects your personal information we will notify you and any regulator as required by applicable state and federal law, without unreasonable delay.
8. How long we keep it
We keep credentialing records for as long as you are a client and afterwards for as long as needed to meet legal, tax, and audit obligations, generally seven years, because credentialing files are frequently re-examined during recredentialing, revalidation, and payer audits. You may ask us to delete records sooner and we will do so where no legal obligation requires us to keep them.
9. Your rights
You may ask us to give you a copy of the information we hold about you, correct anything inaccurate, delete information we are not required to keep, export your records in a usable format, or stop using automated document processing on your account. Write to hello@gocredentialing.com and we will respond within thirty days. We will not discriminate against you for exercising any of these rights.
10. California privacy rights
If you are a California resident, the California Consumer Privacy Act as amended by the CPRA gives you the right to know what personal information we collect and why, the right to access and to receive a copy of it, the right to correct inaccurate information, the right to delete it subject to legal retention obligations, and the right not to be discriminated against for exercising those rights.
Categories collected. Identifiers, professional and employment information, education information, government identifiers including Social Security number, financial account information for remittance, and internet activity limited to server logs. These are collected for the business purposes described in section 4.
Sensitive personal information. We collect Social Security number and date of birth solely to perform credentialing and enrollment. We do not use or disclose sensitive personal information for any purpose other than performing the Services, which means the right to limit its use does not arise.
Sale and sharing. We do not sell personal information and we do not share it for cross-context behavioral advertising, including of anyone under 16.
How to exercise. Email hello@gocredentialing.com or call 888-515-8060. We will verify your identity before acting, and an authorized agent may act for you with written permission.
11. Other state privacy rights
Residents of other states with comprehensive privacy laws, including Virginia, Colorado, Connecticut, Utah, and Texas, have broadly similar rights of access, correction, deletion, and portability, and a right to appeal a refusal. Use the same contact details and tell us which state you are writing from.
12. Text messages and calls
If you give us your phone number we may contact you by call or text about your account and the work you have engaged us to do. Message and data rates may apply. Reply STOP to opt out of text messages, or HELP for help. Opting out of texts does not stop the emails and calls necessary to perform the Services. We do not share your phone number with third parties for their marketing.
13. Children
The Site is not directed to anyone under 18 and we do not knowingly collect information from children. If you believe a child has given us information, contact us and we will delete it.
14. Changes and contact
We will post any change to this policy on this page with a new date, and will tell clients directly about material changes. Questions, requests, or complaints: hello@gocredentialing.com, 888-515-8060, or 3350 SW 148th Avenue, Suite 110, Miramar, FL 33027.